The Bahlog

"Tech Talk" from the President

6905 Zachary Dr.    Carpentersville, IL 60110    847-426-9548    info@qualitysystemssolutions.com

Friday, January 2, 2009

Social Networking as a Business Tool

You gotta love it when this happens....

I've been thinking about today's topic for a while. Early this morning I responded to a question in one of my LinkedIn Groups that basically said, "Now what?" I have an account on LinkedIn, Facebook and Spoke. Big deal, what do I do with them?

I started working on my post and then became distracted with some other tasks. Up pops an email from my The E-Myth Insider newsletter and what do you suppose the topic is? "Getting on Board the Social Network"

If you query Google for "social networking" business tool , over 400, 000 articles will be returned. A quick review of the “top 10” indicates that the perceived value is, “Social computing and networking can enable organic and bottom-up innovation (as opposed to the traditional top-down model of organizational hierarchy).” Or, Social Networking for Recruitment. The general consensus is, “Social Networking is a tool that allows people, regardless of physical location, to connect over shared interests, discuss relevant issues and share information in a faster, and often more efficient way than ever before.

All of this may be true, but I think that most of us are missing the boat. I think that we are going about it all wrong. Let's look at LinkedIn specifically. What do most people do when they create an account on that site? They "link" with people they know (good), most likely people doing exactly what they do (bad). We tend to adopt the "birds of a feather" mentality. Techies link with Techies. Retailers with Retailers. You get the picture. The network has a strong tendency to be affinity based.

Where is the business value in that? I KNOW the answer, but that is NOT the value that I am looking for. As the owner of a small business, what I Really want is new business. I don't really need to expand my relationships with people IN my business. I need to establish relationships with new clients and customers.

I think that what we really want to do is to build our "network" with potential clients and customers. The easiest way to do that is through Groups. Rather than joining groups composed of your peers, try and join groups composed of your potential customers. The beauty of the social network model is the EXPANDED network. You only need to link to a few people to be associated with an exponentially larger pool of potential customers.

Once you are in the right group, follow the Discussions. If there aren't any, create some. Focus on addressing the principle problems and issues that group is facing. This is after all why you are in business, isn't it. If your business, does not solve problems for your customers, you don't really have a business. Seek to become the "resident" expert for the group. Techies are especially good at this. They'll post all day long on how to solve various problems. The PROBLEM is that they are posting for other Techies, not for potential customers!

LinkedIn Groups also have News. If there is News, comment on it. If there isn't any, create some!

The real opportunity here is to REACH new customers. Once your "customer" network is in place you can then begin to reach out to your 2nd level contacts. I would recommend that you use InMail and that you create an individualize email leveraging your 1st level relationship. You don't want to spam folks, but we are all here to Network, so if your message is relevant and sincere, you shouldn't have any problems.

We are in day 2 of a new year. I would challenge each of you to give this a shot. Look at your current list of contacts. If you don't have a potential new customer in the list, invite one. Once you have that first customer contact, search the 2nd level contacts and ENGAGE!. Try and introduce yourself to at least one 2nd level a week. Let me know how that works out for you.

Labels: , , ,

Thursday, January 1, 2009

SANS Institute Security Newsletter for Computer Users Volume 6, Number 1

1. Consumer Awareness: Spyware Q & A
Q: What is spyware?
A: Spyware is malicious software installed on your computer without your knowledge or consent that monitors or controls your computer use. It may be used to send you pop-up ads, redirect your computer to websites, monitor your Internet surfing, or record your keystrokes, which could lead to the theft of your personal information.

Q: How can I tell if my computer is infected with spyware?
A: Your computer may be infected with spyware if:
- - It slows down, malfunctions, or displays repeated error messages
- - It won't shut down or restart
- - It serves up a lot of pop-up ads, or displays them when you're not surfing the web
- - It displays web pages or programs you didn't intend to use, or sends emails you didn't write.
Other signs include:
- - Your browser takes you to sites other than those you type into the address box
- - Your home page changes suddenly or repeatedly
- - New and unexpected toolbars
- - New and unexpected icons in the system tray (at the lower right corner of your screen)
- - Keys don't work (for example, the "Tab" key that might not work when you try to move to the next field in a webform)
- - Random error messages

Q: What should I do if I think my computer is infected?
A: Stop shopping, banking, and other online activities that involve usernames, passwords, or other sensitive information. Spyware could be sending your personal information to identity thieves. Write down the model and serial number of your computer, the name of any software you've installed, and a short description of the problem. Your notes will help you give an accurate description to the technician. At the office, report the problem to your IT help desk, network administrator, or information security officer. At home, if your computer is covered by a warranty that offers technical support, contact the manufacturer, your Internet Service Provider (Comcast, AT&T, Time Warner, Verizon, Qwest, Earthlink, etc.), or a trusted computer consultant.

More information: http://www.onguardonline.gov/topics/computer-security.aspx

************************************************************************
2. Ten Do-It-Yourself Computer Security Tips

a. Treat your computer like a machine. Computers need regular maintenance. If you ignore problems or put off fixing them, you risk more than the smooth functioning of your system. You may be inviting Bad Guys to steal your information or take over your system and use it to attack other computers.
More information: http://www.microsoft.com/atwork/getstarted/maintain.mspx
http://helpdesk.coloradocollege.edu/index.php/tips-and-how-to/maintain-your-computer/maintain-your-macintosh-computer/

b. Use email wisely. Email is not private. Never send personal or sensitive information by email. Never view, open, or even click on email attachments unless you know who sent it, why they sent it, and what's in it. Even messages forwarded to you by friends might contain infected attachments and links that will shuttle you off to dangerous websites.

c. Don't assume your security software is working. Familiarize yourself with the security software installed on your computers. Do you have a complete suite of anti-virus, anti-spyware, and a two-way software firewall? Identify onscreen icons and messages that indicate your security software is enabled and working. If an icon is not there, if its color or shape has changed, or if you see a message that says your security software isn't working, is out of date, or needs attention, take action to correct the problem immediately.

d. Keep your software up-to-date. Many software products, including Windows and Mac OS X, have built-in automatic updaters. Make sure these are turned on. Some software products require manual updating. Know which are which on your computer. Not sure? Visit the website of the software manufacturer for tips on updating your software. Consider installing Secunia's free Personal Software Inspector, which provides extensive details on the software installed on your computer, and gives you direct links to update programs that are older and potentially not secure More information: http://www.microsoft.com/protect/videos/Updates/UpdatesHi.html
http://support.apple.com/kb/HT1338
http://www.download.com/Secunia-Personal-Software-Inspector/3000-2162_4-10717855.html

e. Regard the Internet as a bad neighborhood at 2:00 AM. In 2008 about
1.5 billion people were using the Internet worldwide, and the number of websites approached 200,000,000. With that many apples in the barrel, it's anybody's guess how many are rotten. The steady growth of Web commerce attracts not only ordinary scammers, pirates, and thieves, but also national and multi-national organized crime syndicates. Criminal activity for financial gain is the single largest driver of massive increases in Internet threats, and bringing Internet criminals to justice remains a challenging task. Practice online safety. Protect your privacy, your identity, and your money.
More information: http://www.microsoft.com/protect/videos/Phishing/PhishingMSHi.html & http://www.microsoft.com/protect/videos/Privacy/privacy-hi.html

f. Ratchet up your browser's security. Malicious hackers and virus writers can infect your computer by taking advantage of low security settings in your browser software and enticing you to visit a malicious website. You can help limit your chances of being attacked by increasing your security settings and conducting business or entering sensitive information only on secure websites. Look for addresses that begin with https:// and check for the yellow security lock icon at the bottom of your browser window.
More information: http://www.microsoft.com/protect/computer/advanced/browsing.mspx
http://news.cnet.com/8301-13880_3-9896427-68.html
http://www.microsoft.com/protect/yourself/phishing/spoof.mspx

g. Back up your data. Here is a simple, basic backup plan. Plug a good-sized, formatted, blank thumb drive (or "USB stick") into your computer. Double click on it and open a directory. As you work on your latest project and it comes time to take a break, save your work, close those crucial files, and drag copy them into the directory of the thumb drive. The more important your project is and the closer you get to the deadline, the more often you should pause to make a copy of your crucial files. The more often you backup, the less you stand you lose. After you've made a backup by whatever means, check to make sure that the copies are complete and that they work. At the office, check with IT about using a thumb drive. Some organizations do not allow them.

h. Protect sensitive information, especially when you use a public computer. It's best to avoid typing your credit card number, or other financial or sensitive information into any public computer, but sometimes you can't avoid it. Don't save your logon information. Don't leave a public computer unattended with sensitive information on the screen. Web browsers keep a record of your passwords and every page you visit, even after you've closed them and logged out. Learn how to erase your tracks. Watch for over-the-shoulder snoops.
More information: http://www.microsoft.com/protect/yourself/mobile/publicpc.mspx
http://support.mozilla.com/en-US/kb/Clearing+Private+Data
http://www.usyd.edu.au/ict/switch/troubleshooting/cache.shtml#safari

i. Be careful with wireless networks. Secure your own wireless network by enabling and using wireless encryption that scrambles the data transmitted between your PC and your wireless router. Check your WAP (wireless access point) to find out what kinds of encryption it can provide. Out of the box, the encryption on most WAP's will be shut off. The most effective encryption is WPA2 (Wireless Protected Access version 2). Use a strong password for your WPA2 encryption key. Before you connect to someone else's wireless network, make sure it's a legitimate hotspot: Nefarious types have been known to set up pirate WAP's with familiar names like "wayport" or "t-mobile,"
and then use them to capture passwords and other private data. Verify that your two-way software firewall is turned on, and that filesharing is off. Always turn your Wi-Fi networking off when you're not at a hotspot.
More information: http://www.pcworld.com/article/130330/how_to_secure_your_wireless_network.html
http://arstechnica.com/guides/tweaks/wireless-security.ars

j. Know your limits, and when you reach them, get expert advice.
Not sure what the error message means? Don't know why you got that pop-up? Puzzled because a familiar website has asked you for a password or other sensitive information unexpectedly? Not sure whether or not you should allow that program to access the Internet? Ask before you do the wrong thing. Contact your network administrator, IT Help Desk, your computer manufacturer's technical support department, your Internet Service Provider (ISP), or a trusted computer consultant.

************************************************************************
3. Scams and Hoaxes
- - Nigerian "419" Scam Meets the FBI
Consumers continue to be inundated by emails purportedly from the FBI. Many of the emails currently in circulation claim to be an "official order" from the FBI's Anti-Terrorist and Monetary Crimes Division, from an alleged FBI unit in Nigeria, confirming an inheritance, or containing a lottery notification millions of dollars. Recipients are instructed to furnish personally identifiable information (PII) and are often threatened with some type of penalty, such as prosecution, if they fail to do so. But these emails are scams, are not from the FBI, nor does the FBI ever send unsolicited emails of this nature.
More information: http://www.fbi.gov/cyberinvest/escams.htm

- - Airline Ticket Scam
This email scam targets holiday travelers. Recipients get a .zip file attached to a message about an airline ticket and an ominous mention of a credit card balance. It appears to come from legitimate major airlines including Delta, JetBlue, Continental, American Airlines and Virgin America. This .zip attachment appears to contain a purchase invoice and flight ticket. But if you open the attachment, malicious code may be installed on your system.
More information: http://blogs.zdnet.com/security/?p=2299

- - IRS Phishing Scam Targets US Immigrants The Internal Revenue Service is warning taxpayers not to respond to a mass email phishing scam, which appears to target immigrants. The emails, purporting to come from "noreply@irs.gov," include attached fake forms that ask unwitting taxpayers to fax in personal bank account numbers. The e-mail may have a cover letter from a person identifying herself as IRS public relations employee Laura Stevens, who instructs recipients to fill out the attached W-4100B2 form. The attached form W-4100B2 does not exist but is similar to the IRS'
W8-BEN form. The form requests such information as the person's birth date, Social Security number, mailing address, bank account number and signature. The IRS never contacts taxpayers by email.
More information: http://www.zimbio.com/Exposing+Scams/articles/1020/IRS+Warns+Phishing+Scam+Targeting+Immigrants

************************************************************************
4. Microsoft and Apple Security Updates
Microsoft and Apple provide free security updates for their software products. Windows: Microsoft issues patches for all Microsoft products on the second Tuesday of each month as well as out-of-cycle patches on any day of the month. The next scheduled release date is January 13th. Check manually too, once every two weeks, to make sure all of the updates have been installed. More information:
http://www.microsoft.com/athome/security/default.mspx OS X: Updates are issued frequently, and their contents may differ depending on which processor is in your Mac (PPC or Intel).
More information: http://www.apple.com/support/downloads/
iPhones: Must be updated manually: http://docs.info.apple.com/article.html?artnum=305744

************************************************************************
Copyright 2009, SANS Institute (http://www.sans.org) Editorial Board: Bill Wyman, John York, Barbara Rietveld, Alan Reichert, Alan Paller.
Permission is hereby granted for any person to redistribute this in whole or in part to any other persons as long as the distribution is not being made as part of any commercial service or as part of a promotion or marketing effort for any commercial service or product. We request that redistributions include attribution for the source of the material. Readers are invited to subscribe for free at https://www.sans.org/newsletters/ouch.

Labels: , , ,

Wednesday, December 31, 2008

WSUS 3.0 SP1 on SBS 2003

This post is going to address the Re-installation of WSUS 3.0 SP1 on an SBS 2003 R2 box. However, to set the stage, I need to go back to an earlier post that never actually got posted.

Earlier this month the server in question had some sort of "problem" that resulted in a corrupted file system. Some of you may recognize the following error that is prominently displayed immediately after POST, on boot-up.
Windows could not start because the following file is missing or corrupt C:\windows\system32\config\system You can attempt to repair this file by starting windows setup using the original setup CD-Rom. Select "r" at the first screen to start repair.?

This issue was resolved and if you are interested in the resolution (the post that never made it to press), let me know.

A day or two later we developed a problem with WSUS (Update Services) on the same box.
Event ID: 824
SQL Server detected a logical consistency-based I/O error: torn page
(expected signature: 0x0; actual signature: 0x48015c54). It occurred during a read of page (1:80447) in database ID 5 at offset 0x0000002747e000 in file 'H:\WsusDatabase\SUSDB.mdf'. Additional messages in the SQL Server error log or system event log may provide more detail. This is a severe error condition that threatens database integrity and must be corrected immediately. Complete a full database consistency check (DBCC CHECKDB). This error can be caused by many factors; for more information, see SQL Server Books Online.

Several attempts to resolve this problem were unsuccessful. Ultimately, WSUS 3.0 SP1 was "ripped and replaced" from the box. That involved stopping services, deleting files, removing registry entries and running the "Windows Install Clean Up" tool. Following all of those tasks, installation of WSUS was a fairly straightforward task. But wait... there's more...

WSUS installed correctly, it just wasn't working properly with the SBS 2003 R2 Server Management Console. We now had the dreaded "Blue Shield", you know, the one that says,
"Windows Small Business Server (Windows SBS) Update Services is not running because it automatically turns off if you customize Windows Server Update Services (WSUS). For a list of specific settings that cause Windows SBS Update
Services to turn off, see the Microsoft Website. Even if WSUS is managing updates for your network, the accuracy of the status in the Windows SBS monitoring report or on the Update Services home page cannot be guaranteed. To use Windows SBS Update Services, reverse the changes that you have made to WSUS or reinstall Windows SBS 2003 R2."

Back to the drawing board... I tried the obvious, ensuring that WSUS was configured in accordance with Software updates are not managed by Microsoft Windows Small Business Server 2003 Update Services. No Joy. The solution lies in a document call, Installing Microsoft Windows Server Update Services 3.0 on Windows Small Business Server 2003 but I still had a problem.

The procedure essentailly call for you to:
1. Uninstall WSUS 3.0.
2. Uninstall Windows SBS 2003 R2 components.
3. Reinstall Windows SBS 2003 R2 components in Maintenance Mode.
4. Upgrade WSUS 2.0 to WSUS 3.0.

1. Uninstall WSUS 3.0. << No Problem - this time. Unistalled from Control Panel\Add or Remove programs. See White Paper for additional instructions.
2. Uninstall Windows SBS 2003 R2 components. << No Problem. Unistalled from Control Panel\Add or Remove programs.
3. Reinstall Windows SBS 2003 R2 components. <<Problem>> First of all, the White Paper tells you to "Reinstall Windows SBS 2003 R2 components in Maintenance Mode." The point you to another URL which is essentially the release notes of the SBS R2 Technologies installation disc. It tells you to run Setup.exe, which is what I did... several times. Each time it would fail and point to a couple of log files that weren't terribly helpful. Eventually, I got to this, "Failed to install PSFSIP (Error 0x80004005: Unspecified error)". Here is where the rubber meets the road.

If you Google that phrase, you will find a number of article with a variety of "suggestions" none of which appeared to be a bona fide solution. I'll cut to the chase and identify the one that worked for me.

1. regsvr32 /u psfsip.dll
2. rename psfsip.dll in %windir%\system32 to OLD-psfsip.dll
3. try install again


It worked and we are back in the "Green Check" business.