Friday, January 3, 2014

Easily Upgrade your BlackBerry 10 Devices to Natively Install and Run Android Apps

For you BlackBerry power users (I'm a Q10 user) looking to run Android apps, this is how to do it (there was a single app I wanted which is a train commuter scheduler [RailBandit]). The newest leaked Blackberry OS includes Android runtime 4.2.1 and allows ability to natively load Android apps (yes - you load apps right from your BB - AWESOME!). Sadly, Verizon hasn't launched the next OS (10.2 even though it's been out for MONTHS), so you can do it yourself. I've been running this for 12 hrs, and so far I like it. It's super easy as well. This is to run the brand new leaked 10.2.1.1925 (radio 1899) less than a week old. What's cool about BB10 is you can upgrade the radio code separately from the general OS. Makes it easier for the carrier to test and release updates (or in theory should). The juicy details...

Use This to Download Your OS (Q10, Z10, Z30, etc)
http://forums.crackberry.com/bb10-leaked-beta-os-f395/lengend-presents-10-2-1-1925-all-q-z-887047/

Backup Source
http://www.bbin.in/en/2013/12/24/leaked-os-10-2-1-1925-for-all-blackberry-10-smartphones/

Here are the steps to install a leaked OS on your BlackBerry 10 device (most popular desktop OS required):

Download and install BlackBerry Link (latest is 1.2.2.13 b122) direct from BB.
Backup your BB, just in case and to downgrade if you need to.
Download correct OS from CB URL link above (don't worry about the term "radio" - from the one that says "10.2.1.1925").
Switch off your BlackBerry 10 device
Run the AutoLoader File
Connect your BlackBerry 10 Device to your PC via USB
Quickly Turn on your BlackBerry 10 device
The AutoLoader will detect your device and starts the installation
Please hold till the AutoLoader reaches to 100% and CLOSES automatically
Disconnect your BlackBerry 10 device and wait till it starts again
Security wipe before start using/restoring your data (I didn't do this, but the instructions suggest it)
Manual Setup your config, apps, etc
Enable the install apps functionality from 3rd parties. The first time you download and run an app, the OS will prompt you to enable this feature. Thanks BlackBerry!

Bonus: 2 good sources for loading Android apps is Amazon Apps and 1mobile.com. Load both App Store Apps and you can load your new Android apps easily.

Screenshots of the goodness (note: no BES required, but I run one since I roll like that)....

Before

 After - 10.2.1.1925 (yeah baby)






To a Happy, Healthy, Productive, and Efficient 2014!
-Ben

Monday, November 18, 2013

Network Solutions = AOL Email. If you want to be respected in the 21st century switch to another provider.


Worked on a server environment migration to a datacenter yesterday. Everything went smoothly except for DNS was not working for the client. I spent an extra 2 hours troubleshooting DNS. I repeatedly attempted to update DNS in the Network Solutions webpage, and it would not show the updated entries. Tried with IE, Chrome, and multiple OSes. Nada. Turns out it was a bug in the NetSol system. A call to support indicated that. So, I was assured it would be resolved on Sunday, almost 24 hrs later on Monday, still not working. DNS A records are showing up web page with one entry, and the result is not showing up on the NetSol NS query responses. So, if you updated with 1.1.1.1 and do a DNS query the original IP pre-Sunday.

Just to be CLEAR.... if I query ns57.worldnic.com & ns58.worldnic.com which are the client's NS entries PER Network Solutions, they respond with the wrong entries. How nice. Call to support, and the script reading call rep, didn't understand the issue and kept repeating it takes 24 hours to propagate. Another favorite is you delete or change an entry on the NetSol "advanced DNS" page and the changes aren't displayed. Logout and log back in, same info. This happens on the main webpage and DNS as well. What a joke of a system. I tried to switch to a 3rd party DNS system, and the NetSol NS are not following the DNS spec for NS lookups at point of entry (I added my NS entries ns10.operationdns.com, etc). NetSol claimed they cant' be found, but even the native Windows DNS finds them. Sigh.... So sad the founding internet's domain name provider has failed so badly similar to AOL.

DNS Tool I like since it allows me to query against any NS and for any record
http://centralops.net/co/


-Ben


Wednesday, February 27, 2013

BES 5 & BES 10 Server Consolidation Coming...

Currently, users running BB 4-7 need BES 5 and BB 10 requires BES 10. So, you need to run 2 separate servers for BES 5 & BES 10. This will be changing once an update is released to BES 10 (ETA is May 2013). This update will be "managed using a single fully featured management console". Then BES 10 & BES 5.0.3+ will be able to run on the same server. Very helpful.

-Ben

Exchange 2010 & 2013 Compatible Not There Yet...


With the recent release of Service Pack 3 for Exchange Server 2010 compatibility with Exchange Server 2013, we are getting closer, but NOT yet. Now Exchange Server 2013 needs an update. The update is tentatively called Exchange Server 2013 CU1. That will then allow integration between 2010 & 2013. ETA should be available "shortly". I would guess March or April of 2013.

-Ben

Wednesday, February 13, 2013

Apple Screws Up iOS EAS Implementation AGAIN! - Exchange Suffers


Has your Exchange 2010 CAS recently started experiencing heavy CPU, insane transaction logs growth (aka DoS), Apple might be the cause. Apple released iOS 6.1 last week (beginning of Feb) and it has a "slight" EAS bug in it. ;-) Another bonus... it drained iOS batteries and wasted data bandwidth. So bad... Vodafone txted all iPhone users to NOT upgrade to 6.1. Oops.... and 6.1.1 doesn't fix it...

You would think a large company (aka Apple) that prides itself on releasing "amazing products" would not repeat their mistakes in the past (iOS 4), but sadly history is repeating itself. iOS 6.1.1 fixed another problem. This is why I am not a fan of EAS. It's buggy since vendors don't have a real incentive or pressure to make sure EAS works well. Sure, Microsoft releases "guidelines" and crosses it's fingers vendors follow, but it's a frequent problem. I know, since I see the EAS connections logs and the Exchange problems they cause. I'll post in the future, how to look this up in your Exchange logs. I'm leaving EAS soon enough... I'll be happy to return to the BlackBerry ecosystem when the Q10 is released. That's another post...

See the Microsoft KB article, but to summarize, there are is a quick fix:

- delete the Exchange account from the iOS device and re-add

iOS 6.1 EAS Bug - Workarounds

iOS 4 EAS Bug (walk down memory lane)

-Ben

Monday, June 25, 2012

Exchange Book Review - iPhone and Exchange Server 2010


Hello All,

I was asked to review an Exchange book with a focus on iOS by Steven Goodman. Overall good Exchange Server book with decent amount of iPhone documentation. But there is a lot of non-relevant (non-iOS) content to call it an iPhone & Exchange book. I would refer to it as an Exchange Server Setup with a focus on iOS functionality.

There's a lot of content, which isn't relevant to experienced admins looking to brush up on iOS functionality/capabilities. For example, who needs to know how to run the "setup.exe" on Exchange (w/screen shots), design planning, HA, etc. Come on! Focus on iPhone integration. So, skip to the chapters you want to read, and don't attempt to read this cover to cover. The book lacks some important information about iOS devices such as throttling policies for iOS/ActiveSync devices, reviewing logs to determine performance usage (1/2 page on analyzing reports isn't adequate), etc. Don't get me wrong, the book is a good Exchange 2010 book with touches of iOS knowledge. But, if you run into Exchange performance issues with iOS/ActiveSync devices, you'll need more technical knowledge than this book offers.

-Ben

P.S. I agreed with the other review that the author is jumping on the "Apple bandwagon" by titling it as an iPhone Exchange Server book.

Friday, March 16, 2012

Our missing email admin friend called telnet!

Want a free tool to quickly test your email server is responding to port 25 and is acceptable mail. Use the native tool available in Windows. Sadly, it's not installed by default, so you'll need to add it as a "Feature". And then you can do things like telneting to port 25 and see your email server respond.

See this easy to follow Microsoft article to walk you through the telnet process to send email. I use this often. You can easily find it by googling "telnet port 25" and then bang, you have access to it wherever you are. No need to memorize the steps. http://support.microsoft.com/kb/153119

-Ben

NYExUG 3/12 Meeting Follow-up - Troubleshooting Tips

We had an excellent Exchange User Group meeting this past Tuesday about Troubleshooting Tips. Even though we ran later than we had in a while, we could not cover everything. I've highlighted comments and feedback received during the meeting and after. Thank you to everyone for your feedback. This is what makes us a community.

NYExUG Exchange Troubleshooting and Tips Presentation

Correction: the Exchange Server User Monitor (ExMon) tool does not list ActiveSync versions, but other AS performance stats.

Dirt cheap $60 UCC/SAN (5 names) certificate I recommend is https://certificatesforexchange.com/ which is backended via GoDaddy.

RDP Manager I use is called RoyalTS ($35) which has a lot of flexibility, functionality, stability, and works on XP and above. http://www.code4ward.net/main/

Website tool highlights from my presentation





Attendees Feedback (thank you)

  • The website designed to check your TLS configuration. http://www.checktls.com
  • "Out of control transaction logs. On a number of occasions we have had the transaction logs grow significantly (one every second or so). This can be caused by a rogue application sending emails via your HT or a bad out of  office configuration. We have experienced both.  The last one was a user's out of office settings. They had used the rules section in the out of office. Viewing the transaction log showed the user forwarding the same email every second or so. Turning of the out of office resolved the issue."
  • Exchange environment summary report based (# of Exchange Servers & mailboxes, DB sizes, DAG status, etc.  http://www.stevieg.org/2011/06/exchange-environment-report
  • Post on troubleshooting ActiveSync issues from the Exchange Team Blog.  http://blogs.technet.com/b/exchange/archive/2012/01/31/a-script-to-troubleshoot-issues-with-exchange-activesync.aspx
  • Tony Redmond wrote an excellent article about ActiveSync not working as a result of 2010 user being a member of the priv’ group on his blog site. If he’s truly 2003 user, then the only thing I can think of is setting up similar profile on a different iphone. If that stil doesn’t work then it’s the account & he may need to look into deleting the EAS association via adsiedit & redo the EAS profile on the device. An Exchange MVP (Michael B Smith) has commented several times in the past on the MSExchange forum re: the ills people have been experiencing with iphones – in our own environment we’ve seen disappearing emails/corrupted calendars/and all sorts of wackiness. I can forward forum posts if people are interested but my desktop team has been beaten into submission about what to do/not to do when it comes to syncing EAS devices with Exchange.  http://thoughtsofanidlemind.wordpress.com/2010/10/08/ex2010-insufficient-access/
  • Free Microsoft RDP manager mentioned was Remote Desktop Connection Manager (I didn't like the last version, so I know nothing about this one -Ben)  http://www.microsoft.com/download/en/details.aspx?id=21101


Any comments, post them or email me. Thanks.
-Ben

Sunday, February 12, 2012

HP SAN vs "Dividing by Zero". 0-1. SAN hardware crashes.

Hello All,

Never, ever, ever, ever divide by zero otherwise very bad things can happen. A client's less than 1 year old HP SAN environment crashed last week thanks to a SAN firmware bug (dividing by zero) which caused a kernel panic. And of course this only happened when uptime hit 208.5 days. Hence, HP calls it the "208 Day" bug. I call it poor software development.

Absolutely ridicuous. I have never really liked the HP SAN hardware which was brought over from Lefthand Networks. For mission critical environments, I'm a believer in proper SAN hardware such as the Dell EqualLogic line. REEF has deployed HP and Dell SAN hardware, and without a doubt, the Dell SAN hardware is better. Even the HP software has problems with Hyper-V and running under Windows Core. Disappointing. The Dell SAN hardware is better built and cheaper, and this is why REEF Solutions' is a Dell Premier Partner.


HP bug which causes reboots after 208.5 days


-Ben

P.S. The IT Director of the client who experienced the problem at least has a good sense of humor. This "dividing by zero" programming mistake is clearly a common issue. Enjoy the image below.

Preparing for D Day for Me...

Hello All,

I've been doing a lot of "house keeping" lately before "D" Day. "D" day being delivery day. My wife is due with our 3rd child. While my wife is nesting, I'm doing the equivalent for an IT person. We had a false alarm when we thought it was happening, so now I feel like I'm living on borrowed time and have all this "extra" time. In the last week I've done the following:
  • getting our REEF NY & TX SonicWall firewalls updated to the latest code (VPN tunnel speed to my TX off-site environment doubled in speed)
  • rolling out a SonicWall based network bandwidth and auditing solution (we currently monitor it using another solution) for REEF's networks.
  • NY based on-site servers replication operating system re-installed (for REEF environment, the on-site server is 2008 R2 based. The replication data was not touched, since it is iSCSI based.)
  • NY based on-site servers replication software upgraded (to improve performance, noticeable positive difference between AppAssure Replay 4.6.1,31257 and 4.7.2.40512 [found a bug in the replication UI and alerted AppAssure about it and received a support response in 5 minutes. Impressive. I wish all AppAssure support techs responded so quickly]). For REEF environment. Enjoy the image below.
  • TX based off-site servers replication upgraded (same AppAssure Replay versions upgraded)
  • rolled out my digital photo album solution based on a BlackBerry PlayBook. Considered an iPad, but security, performance, and low cost of the 64GB PlayBook ($300) made it the better solution.
  • NY on-site server operating system re-installed (for clients environment, the server environment is Windows 2003 x86 based. Currently using a stable release of Ahsay. Planning to upgrade to latest stable version shortly.
  • working on deploying a new wireless SonicWall based solution so guests at home will be on a separate VLAN based network. In preparation for all those home visitors.
Notice the replication speed showing “10.22MBit/sec”. It should be “Mb”, not MB. A capital “B” is BYTES, while a lower case “b” is bits. This is on the latest version 4.7.2.40512. Dev has been alerted per support's response.



Back to spending time with the existing kids and wife,
-Ben

Saturday, December 24, 2011

Recommended Exchange Deployments are Multi-role Now

At the last free "Tech Ed style" event in NYC held at the Microsoft Offices, we had Ross Smith IV present on

Exchange 2010 High Availability/Database Availability Groups. If you don't know Ross, he's a VERY senior Microsoft employee who wrote the Exchange Storage and Server Role Calculator. He knows Exchange, period. End of story. So, when he said that everyone should deploy Exchange 2010 in a multi-role configuration to improve performance and not break apart the roles, you need to take his recommendation seriously. This was the 1st time I had heard this. I had a long conversation with him about this in NYC, and he explained that for performance and the ability for leveraging failover capacity it is better to keep all the roles together. In theory, you could deploy less. Since if you were going to deploy 2 CAS and 2 Mailbox, you could in theory just deploy 3 consolidated roles. Well, Microsoft TechNet finally released some guidance on this. That only took 6 months. Don't forget to use a hardware/VM load balancer when deploy your multi-role Exchange Servers.


TechNet article title: Understanding Multiple Server Role Configurations in Capacity Planning
http://technet.microsoft.com/en-us/library/dd298121.aspx

-Ben

Hackers & Malware - Dangers Everywhere - Not Just Scare Tactics

Hackers and malware were busy this week at clients of REEF Solutions.

Good news first, we identified a serious denial of service vulnerability during a network infrastructure review for a financial firm. So bad, a simple command would reboot a core network device. That was a highlight of the review. And this was not even a security audit, I am sure it'll be only worse.

Bad news now
  • A client's system was infected with TDSS, one of the nasty [known] malware products  (think encryption, p2p command and control, http/https tunneling, malware competition removal, and MBR infection). Malware vendors even offer a Firefox plug-in to allow paying customers to surf via infected machines to provide anonymous cover. To summarize, TDSS is extremely dangerous. More technical details here. As of now, the only tool that can remove it or most of it is Kaspersky. Ideally, we should have wiped the system, but the client would not permit this.
  • A hacker attacked via RDP and compromised a system. We detected the compromise and took immediate action to isolate and remediate the attack. If we had not caught it faster, this could have been a serious issue. The key is to have an Intrusion Detection System in place, even if it's just a firewall based solution. You need to be aware of what is happening on your network. I recommend additional policies such as resetting all administrator passwords, not permitting  "administrator" usernames, requiring 15+ characters passwords, email alerting w/3rd party logging tool on administrator level logins, and layered security products (firewall based scanning, servers based, proxy based, DNS scanning, etc).

Sadly, malware and attackers are not sitting idly by. There are some real threats out there. Stay safe...

-Ben

Friday, August 12, 2011

Sprint 4G appears to be hacked at DEFCON

Hello All,

It appears there could have been a successful man in the middle attack (MiTM) on Sprint 4G at DEFCON. Numerous Android devices were attacked during this period. I hope Android users didn’t "upgrade" or re-enter "their passwords" during the multiple day event. Dangerous, but there is a solution that the carriers and handheld manufacturers could implement to protect against this (see solution below).

News from:
http://www.extremetech.com/computing/92370-4g-and-cdma-reportedly-hacked-at-def-con
http://seclists.org/fulldisclosure/2011/Aug/76

A friend and I were discussing this and this what his response was:

 
I'm betting that they did it one of two ways on 802.16/ClearWire/Sprint4G.



They gained physical access to the local tower, and did MiTM from the tower.  WiMax is Mobile IP from the tower to the provider edge.  It would be a lot easier to do MiTM on at a Mobile IP tower, rather than a LTE network.



The other way is, someone in the group worked for / had access to enough of the parts to make a fake WiMax base station.  Based on the signal strength reports, and slow speeds, this is what I bet they did.  WiMax uses either EAP-TLS or EAP-TTLS.  I'm guessing either they had access to the certs to appear valid, or the end devices did not properly implement EAP-TLS and EAP-TTLS, and just accepted any certificate


A pretty cool hack if they did.  Hopefully it can be shown, and the 4G devices can implement proper security.

Update to above.....

After further research, it definitely looks like the latter method (fake WiMax Base station).  They talk about signal strength and upload speeds.  Those wouldn't be affected by the first method (getting into a valid tower).


Unfortunately the supplicate (client) is probably just configured to accept any client.  
For example in the Cradlepoint, you just specify the carrier / realm, but that's it.  No username, etc.   No certs.  No other options.


Another example, the Sprint SmartView client, it doesn't have the ability to specify anywhere anything related to authentication and certificates.


One would need a fake WiMax base station (that can do 2.6ghz) in order to test to see if the supplicate takes any certificate.



Side note: certain applications offer the ability to register against a specific TLS certificate serial number such as Apple Mail.  I hope other devices/applications allow this in the future.


The MiTM Attack Solution
If phones only accepted carrier based certs and had a proper implementation of EAP-TLS or EAP-TTLS this would protect against this sort of attack. 

Sadly, the solution is going to take a bit of work and time. So, don't automatically "trust" voice over data. Protect your data and it can be more secure than your data.

 

-Ben

Thursday, April 28, 2011

New Microsoft ActiveSync Compatibilty Program fails on helpfulness

Ehlo All,

Curious about knowing...
  • what ActiveSync functionality is available with which version of Exchange?
  • which mobile devices have higher Active Functionality?

Well, this new Microsoft ActiveSync compatibility program for OEMs won't help, but read on about it.
Microsoft recently announced the Exchange ActiveSync (EAS) Logo Program for OEMs (think HTC, Google, Apple, Motorola, Microsoft, etc) which should have been used to identify and bring clarify to the level of EAS support a mobile device included. Sadly, it does not do this since there is 1 level for EAS Logo Program and it includes very basic functionality. So, if the device says "ActiveSync", this is pretty much equal to the EAS Logo Program. BK (author of post below) had it right that there should be multiple levels. For example, "basic", "enhanced", "ultimate". So, if an ActiveSync device said "Ultimate", you would know it supports every feature under the sun for EAS against Exchange 2010. Oh well, maybe version 2 of the program will get this improvement.

Windows IT Pro Post about new EAS Logo Program by BK Winstead

-Ben

Monday, April 25, 2011

Message Dehydration isn't a good thing for Exchange!

Ehlo All,


Quote of the week: "limit is 94% before message dehydration occurs."

A normally very stable client's Exchange Server 2007 stopped processing inbound emails and this was the issue above. Client reported all internal email was working though. I logged into their Exchange Server and reviewed the normal issues inside the Exchange Management Console and nothing jumped out (e.g. databases mounted, 3GB free space on C, 700GB+ free space on database partition (D), no quota limits, receive connectors present/enabled, etc). Strange. I decided to check the email filtering solution in front of the Exchange Server. Since I always recommend clients use my company's email filtering service (SpamCop - I'll discuss this is another post) since it allows me to quickly troubleshoot issues and provide very secure email service. Reviewing SpamCop outbound queue to the client's Exchange Server illuminated the error:


Deferred: : host 55.55.55.55 said: 452 4.3.1 Insufficient system resources (in reply to...

More details about this error can be found on this posting. Checking the client's Application Event Log for this error, I found it "The Microsoft Exchange Transport service is rejecting message submissions because the available disk space has dropped below the configured threshold.". Which was surprising since the C drive had a decent amount of space available (3GB+). What changed? Good old SBS's Windows Server Update Services had downloaded every update under the sun and the storage space threshold was passed and triggered back pressure. I uninstalled WSUS and that eliminated 10GB and back pressure was eased and email flow started. I plan to remove some other functionality as well and plan to do a scheduled reboot as well to free up more space. To sum up, SBS causes more problems than it's worth for Exchange deployments. I prefer clean Exchange installs over Exchange SBS installs.

-Ben

Sunday, April 24, 2011

Fixing ActiveSync on an Exchange 2007 Server

Ehlo All,


So, a client's iPhone with ActiveSync stopped working with their Exchange Server 2007. If rebooting and deleting and setting it back up doesn't fix it, confirm your server's AS is working. An good way to do this is to test with Microsoft Exchange test website found here. So after some investigating, it turned up that the IIS Virtual Directory for "ActiveSync" wasn't responding correctly. One can test this by "https://myservername/Microsoft-Server-ActiveSync" and make sure it prompts for a username and pwd. My client's server didn't do that. It reported 501 service unavailable error. I therefore deleted the ActiveSync virtual directory and re-created it and it fixed the issue. A great blog posting to explain this can be found here. To clarify, the "XXXXX" in his example for normal Exchange installs is "Default Web Site".


Handy URLs:
Detailed instructions on deleting and recreating virtual directories for Exchange 2007
http://my.opera.com/RavenOverride/blog/2009/06/17/how-to-recreate-all-virtual-directories-for-exchange-2007

Microsoft's Test Website for Exchange/ActiveSync/Outlook/SMTP
https://www.testexchangeconnectivity.com

-Ben

Thursday, March 10, 2011

Techstravaganza Event with amazing Exchange Speakers (free)


Ehlo All,

           My user group (NYExUG) and 4 other UGs are organizing an amazing event that is a free Tech-Ed type event which has 5 tracks (Exchange, SharePoint, PowerShell, Server/Office, Ask the Experts) and 5 sessions in each.
           For those who attended this past week’s NYExUG meeting, I mentioned that at the upcoming Techstravaganza event we might have an Exchange Superstar presenting. Well, that has happened! Ross Smith (Microsoft) will be presenting (thanks to Bob Hunt). You do NOT want to miss this event! Just to give you an idea, this guy frequently presents at major conferences and even runs a session called “Stump the Experts”. With “Stump the Experts”, if you’re able to ask an Exchange question that Ross can’t answer, you win an Xbox. He’s never given away an Xbox. This guy knows Exchange. Period. Learn from a superstar. He’ll be presenting on Exchange 2010 High Availability / DAGs.

Techstravaganza
Held at Microsoft’s NY office
Friday, March 18 (8am-5pm).
This event will have 5 tracks of Exchange, PowerShell, SharePoint, Windows/Client Server, and Ask The Experts.

Register asap since spots are limited

Main Website

Hope to see you at the event...
-Ben

Tuesday, January 18, 2011

1st Known Spamming from the "Cloud"

Ehlo All,

This is my 1st confirmed spam (mid 2010) I have ever seen come from the "Cloud". The "winner" of this honor goes to Amazon. Congratulations (sarcasm). According to my latest research Amazon still does not allow PTR (rDNS) records which is typically required/strongly recommend to avoid outbound email being labeled as spam. How do the many mail servers running on Amazon's Cloud handle it? They relay their email from Amazon's environment onto another host (e.g. authsmtp, google "smtp relay service", etc) and then the other service forwards.

Background on me
I see a LOT of spam since my firm handles filtering for most of our clients via our geographically diverse clustered anti-spam/virus/DoS solution. Our clients on an average day get a total of about 300-400k connections a day (spam/real). This provides me a lot of experience/exposure with spam filtering. If you are wondering why we run our own systems it is because it offers more flexibility, significantly lower latency for email messages (aka delay), and faster response than the big guys.


View from my Spam Filtering Solution which Quarantines Suspect Email Like This.

Spam Header Details
Received: from mm-notify-out-209-61.amazon.com (mm-notify-out-209-61.amazon.com [72.21.209.61])


by mail.rbkgroup.com with ESMTP id 67cz6639988tcu.19.20100625083501;

Fri, 25 Jun 2010 11:35:01 +0200

Date: Fri, 25 Jun 2010 11:35:01 +0200

X-Barracuda-BBL-IP: 72.21.209.61

X-Barracuda-RBL-IP: 72.21.209.61

From: "Buy.com"

Reply-To: Nobody

To:

Message-ID: <02630844.67618272250016768122.JavaMail.em-build@na-mm-relay.amazon.com>

Subject: Thanks for your order!

X-AMAZON-CLIENT-HOST: digital-docs-dope-5002.iad5.amazon.com

X-ASG-Orig-Subj: Thanks for your order!

Bounces-to: 20100625083501q4b3332ggg949lm9p0629fm7g208en6r@bounces.amazon.com

X-AMAZON-CLIENT-SENDTIME: Fri, 25 Jun 2010 11:35:01 +0200

X-AMAZON-MAIL-RELAY-TYPE: notification

X-AMAZON-RTE-VERSION: 2.0

MIME-Version: 1.0

Content-Type: text/html; charset=UTF-8

Content-Transfer-Encoding: 7bit


--------------------------------------------

Any questions, let me know.
-Ben

Saturday, January 15, 2011

DoS of DNS by an Exchange Focused Backup Software (AppAssure Replay)

 Ehlo All,

Imagine to my surprise that my favorite Exchange & Windows backup solution (AppAssure Replay 4.5.1.27532) was attempting to cause a denial of service (DoS). This version has a major problem with it's use of DNS lookups within the problem. Within 3 days, one Replay Server had performed over 450,000 queries of the hostname I used for Replay replication. This is almost 100 queries every minute 24 hours a day. That's what the product is doing. This is a serious issue. I've alerted the vendor, so I'm sure a fix will be included in a future release. In the mean-time, see below for the work-around until that happens.

The Issue
Inside AppAssure's Replay for replication, you specify a "Replication Target Host Name". This can be a hostname or IP address. See below for setting within Replay.




 This "Select Replication Target" configuration is per protected server (e.g. your Exchange Server, etc). I normally use a hostname for these types of settings since I'm a big fan of using DNS instead of IPs when possible (saves time when changing IPs & saves brain memory space for Exchange Server things). So, when you add your Replication Target hostname, the Replication target and source perform lookups more often than the snap-shot period (x min/hrs). In reality, Replay should only perform a DNS lookup when a replication needs to occur and NOT almost a 100 per minute.

AppAssure's Replay abusing DNS lookups. View from my Firewall hostname query  logs.









The Workaround Until a Permanent Fix is Released by AppAssure
If you use a hostname within the Replication option, make sure you add the corresponding information inside the hosts file (c:\windows\System32\drivers\etc\hosts - format is IP address space and hostname - use notepad to open the "hosts" file) on the source AND target Replay Replication Server. This avoids the use of an external DNS query and the query is handled by the operating system. So, this speeds up the process of performing a lookup and reduces your hostname's name server load. Otherwise prepare for your DNS to be attacked by your Replay environment.

Sadly, this isn't the first time I have seen a product mis-use DNS, but it's one of the worst in recent memory.

-Ben

Monday, December 27, 2010

Article - Constitution Finally is Defended over illegal email searches by US Government











 Hello All,

Glad to see someone cover this topic and that this "piece of paper" above means something. "This topic" is about defending our rights (4th Amendment which is unreasonable searches) from the US government illegal intrusions into email. US Dept of Justice illegally had an ISP copy someone's email and was slapped on the wrist, thank goodness for a Court of Appeals. See the Windows IT Pro article from Paul Robichaux discuss this. I hope this ISP get's sued as well now.

-Ben