<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The ProStructure Blog</title>
	<atom:link href="http://www.prostructure.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.prostructure.com/blog</link>
	<description>A blog about high-end IT Infrastructure and Security</description>
	<lastBuildDate>Thu, 22 Sep 2011 19:41:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.3</generator>
		<item>
		<title>Limitations of UAG 2010 for Publishing Public Websites</title>
		<link>http://www.prostructure.com/blog/2011/09/22/limitations-of-uag-2010-for-publishing-public-websites/</link>
		<comments>http://www.prostructure.com/blog/2011/09/22/limitations-of-uag-2010-for-publishing-public-websites/#comments</comments>
		<pubDate>Thu, 22 Sep 2011 19:41:01 +0000</pubDate>
		<dc:creator>Amber Pham</dc:creator>
				<category><![CDATA[Enterprise IT]]></category>
		<category><![CDATA[Web Operations]]></category>
		<category><![CDATA[ForeFront]]></category>
		<category><![CDATA[UAG 2010]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=158</guid>
		<description><![CDATA[While UAG 2010 does work as a reverse proxy that can protect your web servers from many attacks, there are several limitations of which you should be aware before deciding to use UAG for all your reverse proxy needs. UAG 2010 excels at providing authenticated remote access to internal applications. It can even be used [...]]]></description>
			<content:encoded><![CDATA[<p>While UAG 2010 does work as a reverse proxy that can protect your web servers from many attacks, there are several limitations of which you should be aware before deciding to use UAG for all your reverse proxy needs.</p>
<p>UAG 2010 excels at providing authenticated remote access to internal applications.  It can even be used to add authentication to internal applications.  Where you will run into limitations is when you have public web properties being published through it.</p>
<p>Consider this scenario: You have two websites you want to publish: www.mysite.com and www.myothersite.com.  The first thing you will notice when publishing www.mysite.com is that you can only publish three part names.  If you want users to be able to reach your site by going to http://mysite.com, UAG will not be listening for that.  You cannot create a host header on the UAG because every time you change the UAG configuration and save it, your IIS site will be overwritten.  In order to allow people to type in alternate names in their browsers, you will need to run a separate web server that hosts redirect sites.</p>
<p>Another interesting thing happens when you decide to publish www.myothersite.com.  Since it doesn&#8217;t share the last two parts of the name with your other site, you&#8217;ll need another trunk.  This will need another IP address. If you want that load balanced, you&#8217;ll need another VIP.</p>
<p>I&#8217;m not saying UAG shouldn&#8217;t be used as a reverse proxy for public websites, but you should be aware of these limitations before you get started.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2011/09/22/limitations-of-uag-2010-for-publishing-public-websites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>One Policy to Enforce for Android Phones Connecting to Your Corporate Wifi</title>
		<link>http://www.prostructure.com/blog/2011/06/23/one-policy-to-enforce-for-android-phones-connecting-to-your-corporate-wifi/</link>
		<comments>http://www.prostructure.com/blog/2011/06/23/one-policy-to-enforce-for-android-phones-connecting-to-your-corporate-wifi/#comments</comments>
		<pubDate>Thu, 23 Jun 2011 19:41:14 +0000</pubDate>
		<dc:creator>Amber Pham</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Enterprise IT]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Wifi]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=153</guid>
		<description><![CDATA[As reported by blogger Donovan Colbert on TechRepublic, Android devices automatically synchronize settings from your phone to Google servers so that when you log in from other devices, your settings travel with you.  This is very convenient for users, but if those users have signed into your corporate wifi, the synchronized data may include your [...]]]></description>
			<content:encoded><![CDATA[<p>As reported by blogger <a href="http://tek.io/mCn3II" target="_blank">Donovan Colbert on TechRepublic</a>, Android devices automatically synchronize settings from your phone to Google servers so that when you log in from other devices, your settings travel with you.  This is very convenient for users, but if those users have signed into your corporate wifi, the synchronized data may include your corporate WPA2 key.  This is an obvious risk to the privacy of your corporate wifi network.</p>
<p>Businesses with wifi networks should have policies in place that state under what conditions, if any, smart phones are allowed to connect to its network.  It would be wise to include a specific reference to disabling the &#8220;Backup my data&#8221; setting, usually found in the Settings/Privacy menu on Android phones.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2011/06/23/one-policy-to-enforce-for-android-phones-connecting-to-your-corporate-wifi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Configuring My Sites for SharePoint 2010 &#8211; Tips and Tricks</title>
		<link>http://www.prostructure.com/blog/2011/05/25/configuring-my-sites-for-sharepoint-2010-tips-and-tricks/</link>
		<comments>http://www.prostructure.com/blog/2011/05/25/configuring-my-sites-for-sharepoint-2010-tips-and-tricks/#comments</comments>
		<pubDate>Wed, 25 May 2011 19:50:17 +0000</pubDate>
		<dc:creator>Amber Pham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[My Sites]]></category>
		<category><![CDATA[Sharepoint 2010]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=149</guid>
		<description><![CDATA[A colleague of mine just successfully configured My Sites in SharePoint 2010 and found that there were a few steps that weren&#8217;t well documented.  I&#8217;m sharing the directions here with his hints. After following the basic configuration instructions, he was seeing the following error when trying to create a personal site: “Your personal site cannot [...]]]></description>
			<content:encoded><![CDATA[<p>A colleague of mine just successfully configured My Sites in SharePoint 2010 and found that there were a few steps that weren&#8217;t well documented.  I&#8217;m sharing the directions here with his hints.</p>
<p>After following the basic configuration instructions, he was seeing the following error when trying to create a personal site:</p>
<p>“Your personal site cannot be created. Contact your site administrator for more information”</p>
<p>(These steps assume you&#8217;ve configured Profile Synchronization.  Setting up user profile synchronization has several steps that are outlined here: http://technet.microsoft.com/en-us/library/ee721049.aspx.  This blog article has a friendlier version of how to accomplish this (with screenshots): http://sharepointgeorge.com/2010/configuring-the-user-profile-service-in-sharepoint-2010/)</p>
<p>Configuration Settings:<br />
Database:  MySite_ContentDB<br />
Web Application:  your.host.here:80<br />
Managed Paths:  my (explicit inclusion); personal (wildcard inclusion)<br />
My Site Host location:  http://your.host.here/my/<br />
Personal Site location:  personal (<strong>do NOT enter the full URL here!</strong>)</p>
<p>Procedure<br />
1.       Create a MySites database for separation:  MySite_ContentDB<br />
2.       Create a new Web Application connected to the database:  your.host.here:80<br />
3.       Delete the existing Managed Paths for the newly created Web App<br />
4.       Add three Managed Path entries the Web Application to be used for configuring My Sites<br />
a.       “my” – explicit inclusion<br />
b.      “personal” – wildcard inclusion<br />
c.       / &#8211; (root) explicit inclusion<br />
5.       Create a new site collection at http://your.host.here/my/ choosing the My Site Host template from the Enterprise templates<br />
6.       Create a new blank site collection at the root location http://your.host.here (this is to allow enabling of Self-Service Site Creation)<br />
7.       Select the MySite Web application and click Self-Service Site Creation to turn the feature on<br />
8.       Finish configuring My Sites:<br />
a.       Go to Application Management &gt; Manage Service Applications<br />
b.      Select the User Profiles Service Application (not the proxy) &gt; Click Manage<br />
c.       Click Setup My Sites<br />
Note:  The information in the two fields My Site Host and Personal Site Location must follow these rules:<br />
i.   The My Site Host Location must be the location where you installed the My Site collection above:  http://your.host.here/my<br />
ii.  The Personal Site Location must be the wildcard inclusion managed path created above:  personal (<strong>do NOT use the full URL here!</strong>)<br />
iii.  Make sure the Preferred Search Center is a valid path</p>
<p>To test, click your user name in the top right corner of the window, click My Site.<br />
Your My Site will be created on the first visit to the site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2011/05/25/configuring-my-sites-for-sharepoint-2010-tips-and-tricks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HP System Management Homepage Security Advisory</title>
		<link>http://www.prostructure.com/blog/2011/05/05/hp-system-management-homepage-security-advisory/</link>
		<comments>http://www.prostructure.com/blog/2011/05/05/hp-system-management-homepage-security-advisory/#comments</comments>
		<pubDate>Thu, 05 May 2011 17:58:18 +0000</pubDate>
		<dc:creator>Amber Pham</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Enterprise IT]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[HP System Management Homepage]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[SMH]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=145</guid>
		<description><![CDATA[NIST has announced a highly exploitable flaw in the HP System Management Homepage (SMH) that can allow unauthenticated users to attack the web application over the network to ultimately execute arbitrary code on the server. The flaw has been rated with a CVSS Base Score of 10, which means it is highly exploitable and has [...]]]></description>
			<content:encoded><![CDATA[<p>NIST has <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1541" target="_blank">announced</a> a highly exploitable flaw in the HP System Management Homepage (SMH) that can allow unauthenticated users to attack the web application over the network to ultimately execute arbitrary code on the server.  The flaw has been rated with a CVSS Base Score of 10, which means it is highly exploitable and has a potentially severe impact if exploited.</p>
<p>All administrators using this tool to manage HP hardware over the network should upgrade HP SMH to the <a href="http://h18013.www1.hp.com/products/servers/management/agents/index.html" target="_blank">latest version</a> in which the flaw has been resolved.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2011/05/05/hp-system-management-homepage-security-advisory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SharePoint 2010 Managed Accounts Automatic Password Change Results in Access Denied</title>
		<link>http://www.prostructure.com/blog/2011/03/29/sharepoint-2010-managed-accounts-automatic-password-change-results-in-access-denied/</link>
		<comments>http://www.prostructure.com/blog/2011/03/29/sharepoint-2010-managed-accounts-automatic-password-change-results-in-access-denied/#comments</comments>
		<pubDate>Tue, 29 Mar 2011 22:50:43 +0000</pubDate>
		<dc:creator>Amber Pham</dc:creator>
				<category><![CDATA[Enterprise IT]]></category>
		<category><![CDATA[Web Operations]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[Managed Accounts]]></category>
		<category><![CDATA[SharePoint]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=130</guid>
		<description><![CDATA[The Managed Accounts feature in SharePoint 2010 allows administrators to hand control of service account passwords over to SharePoint, reducing the need to manually track and change passwords.  This is a major advance in security because administrators now have a tool to change those service accounts that are rarely changed otherwise. In two independent SharePoint [...]]]></description>
			<content:encoded><![CDATA[<p>The Managed Accounts feature in SharePoint 2010 allows administrators to hand control of service account passwords over to SharePoint, reducing the need to manually track and change passwords.  This is a major advance in security because administrators now have a tool to change those service accounts that are rarely changed otherwise.</p>
<p>In two independent SharePoint 2010 farms, I&#8217;ve encountered errors after changing passwords via the Managed Account functionality.  The symptom is that after the change, services will fail to start due to invalid credentials, and you may see errors in the Windows Application Event Log indicating access denied failures.</p>
<p>Each time I&#8217;ve seen this problem, there were Windows Services that were set to run as the login with the recently changed password, but at least one of those services was stopped.  The solution is that when you are preparing to automate the password change for a service account, ensure that only those services intended to be running are set to run as the managed login, and ensure that those services are in a started state at all times.  Your alerting and monitoring system should be configured to watch these services and ensure they are restarted if they stop.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2011/03/29/sharepoint-2010-managed-accounts-automatic-password-change-results-in-access-denied/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Automate your SharePoint 2010 Installation with PowerShell</title>
		<link>http://www.prostructure.com/blog/2011/02/28/automate-sharepoint-2010-installation/</link>
		<comments>http://www.prostructure.com/blog/2011/02/28/automate-sharepoint-2010-installation/#comments</comments>
		<pubDate>Mon, 28 Feb 2011 20:34:31 +0000</pubDate>
		<dc:creator>Amber Pham</dc:creator>
				<category><![CDATA[Enterprise IT]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[automate]]></category>
		<category><![CDATA[CodePlex]]></category>
		<category><![CDATA[Install]]></category>
		<category><![CDATA[PowerShell]]></category>
		<category><![CDATA[SharePoint]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=125</guid>
		<description><![CDATA[Using PowerShell to install SharePoint 2010 is reliable and repeatable.  The Codeplex AutoSPInstaller project has made this very easy.]]></description>
			<content:encoded><![CDATA[<p><img src="///Users/amber/Library/Caches/TemporaryItems/moz-screenshot-13.png" alt="" /><img src="///Users/amber/Library/Caches/TemporaryItems/moz-screenshot-14.png" alt="" /></p>
<p>Installing SharePoint 2010 from the GUI installer off the CD is fine if you will only be doing it once and if you don&#8217;t need to be able to replicate the settings precisely later.  If you will potentially need to replicate the exact same farm settings a second time, you should automate the installation with PowerShell.  CodePlex has created an automated installation script that requires you to gather all the necessary information up front, create all the accounts you will need, and create at least one web application.  While this requires more up-front organization, it pays off in the long run.</p>
<p>The CodePlex project is called AutoSPInstaller: http://autospinstaller.codeplex.com/<br />
The Version 2 beta is being updated regularly.  It worked for a basic two-server farm (WFE + separate SQL backend).</p>
<p>The set of scripts works great, but there are very few instructions for the beginner, so I have compiled some here.</p>
<p>Before you run the scripts:</p>
<p>1. Create domain accounts and configure the WFE and the SQL server per this article: http://technet.microsoft.com/en-us/library/cc678863.aspx<br />
2. You will also most likely want to create the object cache user accounts: http://technet.microsoft.com/en-us/library/ff758656.aspx<br />
3. Ensure PowerShell v2 is installed.  It is included with Windows Server 2008 R2.<br />
4. Edit the xml file(s) being read by the script.<br />
- Config.xml needs to be updated with the product ID (license key).<br />
- The AutoSPInstallerInput.xml file (that is its name as of build 67032) needs to be updated with all the actual account names and other settings you would like to use.<br />
5. Make sure that if you decide to create the initial portal web app, use the application pool account you defined within managed accounts.<br />
6. Determine whether you want Claims (Kerberos) or Classic authentication and specify that when creating the first web application: http://technet.microsoft.com/en-us/library/cc262350.aspx. The script defaults to claims.  To use classic/NTLM, change useClaims to False.</p>
<p>&lt;WebApplication type=&#8221;Portal&#8221;<br />
name=&#8221;Portal Home&#8221;<br />
applicationPool=&#8221;PortalHome&#8221;<br />
applicationPoolAccount=&#8221;DOMAIN\portalacc&#8221;<br />
url=&#8221;http://localhost&#8221;<br />
port=&#8221;80&#8243;<br />
databaseName=&#8221;PortalHome_Content&#8221;<br />
useClaims=&#8221;False&#8221;&gt;</p>
<p>When you are ready to run the installer:</p>
<p>1. Temporarily disable UAC.<br />
2. Disable any anti-virus active scanner.<br />
3. Run PowerShell as Administrator then run the following commands<br />
- Set-ExecutionPolicy -executionpolicy unrestricted for scopes: LocalMachine, Process, and CurrentUser.<br />
- &#8220;Add-PSSnapin Microsoft.SharePoint.PowerShell&#8221;<br />
4. Use the FolderStructure.txt as a guide to where to put the installer files and the scripts.  Basically, you should put all the installer files (usually extracted from a CD or ISO) into a folder called SP2010.  Inside that folder at the top level, drop the AutoSPInstaller script folder with its files.<br />
5. Create the accounts that you configure as managed accounts in the xml file.  Every service you tell it to create (such as the Managed MetaData) needs a managed account, or you will get an error and will have to create the service later.<br />
6. If you are working with a virtual machine, take a snapshot at this point before you kick off the Launch.bat.<br />
7. Log in as the setup user (local admin), and kick off the batch.<br />
8. By default the log will be placed on the logged in user&#8217;s desktop.  This will have any errors that scrolled by on the screen.  If there is an error, the log will show the line number in the script that produced it.  Fix the error and run the script again &#8211; it will just skip the parts that are already done.</p>
<p>After the installation completes:<br />
1. You will need to change the <a href="http://support.microsoft.com/kb/896861" target="_blank">loopback check setting</a>.<br />
2. Install the <a href="http://technet.microsoft.com/en-us/library/ff686815.aspx" target="_blank">patch</a> mentioned in the log if you will be using claims based (Kerberos) authentication.<br />
3. Watch the application and system error logs for at least 24 hours and resolve any issues you find there.<br />
4. Complete <a href="http://technet.microsoft.com/en-us/library/cc262849.aspx" target="_blank">security hardening steps</a> for the farm servers.</p>
<p>I welcome comments and suggestions about how to make this process even more complete.  The folks working on this CodePlex project are actively updating the scripts and taking suggestions to make it better, as well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2011/02/28/automate-sharepoint-2010-installation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Time for a Second Look at Two-Factor Authentication</title>
		<link>http://www.prostructure.com/blog/2011/01/31/time-for-a-second-look-at-two-factor-authentication/</link>
		<comments>http://www.prostructure.com/blog/2011/01/31/time-for-a-second-look-at-two-factor-authentication/#comments</comments>
		<pubDate>Tue, 01 Feb 2011 02:12:16 +0000</pubDate>
		<dc:creator>Amber Pham</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[2FA]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[TFA]]></category>
		<category><![CDATA[two-factor]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=123</guid>
		<description><![CDATA[With increased competition in the TFA market, we're seeing better options at lower costs.  As a result, implementing TFA to protect critical assets is becoming more feasible by the day.]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s becoming widely recognized that traditional username/password combinations (single-factor authentication) are weak and prone to many attacks.  As a result, two-factor authentication (TFA) is being required or recommended in an increasing number of regulations and guidelines, such as Federal Financial Institutions Examination Council&#8217;s (FFIEC), HIPAA, and PCI-DSS.</p>
<p>Many organizations have balked at implementing TFA due to the high cost and complexity, and the lack of flexibility of the solutions available.  The landscape is changing quickly &#8211; there are new vendors and a better array of options from vendors that have been in the space for ten or more years.</p>
<p>For many years, commercially available TFA solutions meant carrying around a token that displays a number, which is combined with a PIN to produce two factors (something you have: the token, and something you know: the PIN).  Many new, more flexible solutions are becoming available with the recent entry of new participants in the TFA market.  Credit card form factor tokens are easier for some to carry than a traditional key fob.  Grid cards remove the electronic components bringing the price down, and electronic format grids reduce the need for replacement.  Software tokens that uniquely identify a particular phone or computer remove the need to have a user-accessible token altogether.  Out-of-band one time password (OTP) delivery via email, voicemail, or SMS is one of the latest developments in this new move toward flexibility.  Many vendors even support multiple factor types across a single user base, such that one type of user could have hardware tokens, while another set uses grid cards.</p>
<p>Possibly more important to the slow adoption of TFA than lack of flexibility has been the expense of hardware tokens &#8211; up to $50 per user every three to five years &#8211; on top of the related software licensing costs.  Many TFA vendors have added lower cost options, such as grid cards, software tokens, and hardware tokens that cost less than $10.  There are even lower cost options if you get away from dedicated hardware tokens entirely, for instance, by using out-of-band solutions.</p>
<p>Some of these new solutions are also decreasing the complexity of rollout as well as the time required.  User self-service portals and simplified provisioning are making it a more reasonable proposition to get TFA rolled out to larger numbers of users.</p>
<p>With increased competition in the TFA market, we&#8217;re seeing better options at lower costs.  As a result, implementing TFA to protect critical assets is becoming more feasible by the day.</p>
<p>UPDATE 2-11-11:</p>
<p>With Google’s <a href="http://googleblog.blogspot.com/2011/02/advanced-sign-in-security-for-your.html" target="_blank">announcement </a>of the coming availability of second factor  authentication for its general population of users, it looks like  two-factor is hitting the mainstream.  Other vendors will have to follow  suit or be left behind.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2011/01/31/time-for-a-second-look-at-two-factor-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>No Root Site on SharePoint 2010 Causes Intermittent Explorer View Problems</title>
		<link>http://www.prostructure.com/blog/2010/09/17/no-root-site-on-sharepoint-2010-causes-intermittent-explorer-view-problems/</link>
		<comments>http://www.prostructure.com/blog/2010/09/17/no-root-site-on-sharepoint-2010-causes-intermittent-explorer-view-problems/#comments</comments>
		<pubDate>Fri, 17 Sep 2010 18:31:03 +0000</pubDate>
		<dc:creator>Amber Pham</dc:creator>
				<category><![CDATA[Enterprise IT]]></category>
		<category><![CDATA[Web Operations]]></category>
		<category><![CDATA[Explorer View]]></category>
		<category><![CDATA[Sharepoint 2010]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=113</guid>
		<description><![CDATA[Windows 7 clients require there to be a site at the root on SharePoint 2010 in order for Explorer View to work properly.  If there is no root site and some clients get errors when trying to open Explorer View, try creating a root site.]]></description>
			<content:encoded><![CDATA[<p>A client had a SharePoint 2010 issue in which Explorer View (which relies on WebDav) only worked some of the time for Windows 7 clients.  They found the answer, and I thought it was worth sharing.</p>
<p>Most of the time, Windows 7 client would get an error in SharePoint when opening Explorer View from a document library: &#8220;Your client does not support opening this list with windows explorer.&#8221;  Restarting the Web Client service on the Windows 7 computers temporarily resolved the issue but did not offer any explanation why it worked or any clues about what on the server was causing the incompatibility.</p>
<p>This week, the client got an answer to the &#8220;what&#8221; but not the &#8220;why.&#8221;  As it turns out, there must be a root site in order for Explorer View to work properly for all clients.  In this case, two sites had been set up at the default &#8220;/sites/&#8221; because no portal page was needed.  The client created a blank page at &#8220;/&#8221; to resolve the issue.  Why this works has not been clearly explained, but if you run into this scenario, where there is no root site and some clients get errors when trying to open Explorer View, try creating a root site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2010/09/17/no-root-site-on-sharepoint-2010-causes-intermittent-explorer-view-problems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The brute that is SSH Brute Force</title>
		<link>http://www.prostructure.com/blog/2010/07/12/the-brute-that-is-ssh-brute-force/</link>
		<comments>http://www.prostructure.com/blog/2010/07/12/the-brute-that-is-ssh-brute-force/#comments</comments>
		<pubDate>Mon, 12 Jul 2010 21:33:49 +0000</pubDate>
		<dc:creator>micah</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=105</guid>
		<description><![CDATA[The brute is back.  By the brute, I mean the SSH brute force attack.  In the last month we have noticed an upturn in SSH brute force traffic targeting hosts addressed in public IPv4 address space.  The highest ranking attack sources we have seen include address allocations in KRNIC, APNIC, and RIPE.  In the cases [...]]]></description>
			<content:encoded><![CDATA[<p>The brute is back.  By the brute, I mean the SSH brute force attack.  In the last month we have noticed an upturn in SSH brute force traffic targeting hosts addressed in public IPv4 address space.  The highest ranking attack sources we have seen include address allocations in KRNIC, APNIC, and RIPE.  In the cases we&#8217;ve encountered, the target user was either the root user or something out of a dictionary.  An SSH brute force attack challenges the complexity of the user generated password associated with a user account by iterating through a dictionary to guess user passwords.  Brute-force code will also generate attempts randomly.  The risk associated with the vulnerability exposed here is great, so its important that some action be taken by administrators to ensure a secure operating environment moving forward.</p>
<p>Does your organization currently employ a strong password policy?  Does your organization currently enforce this strong password policy? A strong password should be 14 characters long and should utilize numeric, upper and lower case alphabetical, and symbol characters such as &#8220;!@#$%^&amp;*()&#8221;.    Most every modern operating system or directory service (LDAP) implementation supports enforcement of strong password complexity.  Administrators should ensure they are utilizing the password history function of their directory service if available, to minimize the potential for password reuse by end users.  For Linux users not utilizing a directory, you can utilize the PAM module provided by the Openwall project, passwdqc, which provides password complexity enforcement.</p>
<p>If your environment allows, utilize password-less authentication using public key encryption provided by either the RSA or DSS.  Most SSH clients and servers support one or both of these methods.  Finally, Ensure that your SSH server does not allow root or Administrator logins.</p>
<p>If your environment already has a firewall in place to facilitate network access control, you should ensure that TCP port 22 is only available to those networks that need access.  If your environment does not have a firewall, OS level packet filtering is available in all modern operating systems.  When thinking about the SSH surface area in your environment, ensure you include devices that are manageable via SSH including routers, firewalls, switches, and other network appliances.</p>
<p>You should really ask yourself why your SSH service is available to the public if you aren&#8217;t explicitly providing a shell service to end users.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2010/07/12/the-brute-that-is-ssh-brute-force/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Offers Security Hardening Documentation for SharePoint 2010</title>
		<link>http://www.prostructure.com/blog/2010/06/07/microsoft-offers-security-hardening-documentation-for-sharepoint-2010/</link>
		<comments>http://www.prostructure.com/blog/2010/06/07/microsoft-offers-security-hardening-documentation-for-sharepoint-2010/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 16:25:55 +0000</pubDate>
		<dc:creator>Amber Pham</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=95</guid>
		<description><![CDATA[While there was some security documentation for SharePoint 2007, it was general in nature, and it required browsing around several different documents and pages.  Microsoft has done us a service with the SharePoint 2010 security hardening documentation that was released around the time the product hit RTM.  This documentation includes a secure server snapshot of [...]]]></description>
			<content:encoded><![CDATA[<p>While there was some security documentation for SharePoint 2007, it was general in nature, and it required browsing around several different documents and pages.  Microsoft has done us a service with the SharePoint 2010 security hardening documentation that was released around the time the product hit RTM.  This documentation includes a secure server snapshot of the services required, and it includes a definitive list of necessary ports for each component.  This is a big win for administrators who need to protect the SharePoint server(s) in an isolated network.</p>
<p>The documentation is divided into two parts, <a href="http://technet.microsoft.com/en-us/library/cc262849(office.14).aspx" target="_blank">web</a> and <a href="http://technet.microsoft.com/en-us/library/ff607733(office.14).aspx" target="_blank">SQL</a>, and together they provide the big picture for a secure environment.  I&#8217;ve recently used the documentation to design the security for a SharePoint farm that needs to provide access to multiple outside agencies/partners.  It was much easier to use this documentation than what was provided for the previous version.  I did find a few areas where the documentation could have been more clear, so I wanted to share my findings and see if anyone else has feedback to make the recommendations stronger.</p>
<p><strong>Web Front-End</strong></p>
<p>I found that in a standard Windows network, NetBIOS over TCP/IP could be disabled, according to Microsoft&#8217;s recommendation.  The article did not include instructions, but I did find a response on <a href="http://social.technet.microsoft.com/Forums/en/winservercore/thread/d18bd172-e1a0-4a61-ba52-0952a1e3cabc" target="_blank">TechNet</a> that describes how it&#8217;s done.</p>
<p>The web.config settings could have been described a little more clearly.</p>
<ul>
<li>The <img src="///Users/amber/Library/Caches/TemporaryItems/moz-screenshot-3.jpg" alt="" />PageParserPaths should be empty by default.</li>
<li>Remember that whenever you create a new web application, a new web.config file is created for it, so you will need to verify the settings are still secured.</li>
<li><img src="///Users/amber/Library/Caches/TemporaryItems/moz-screenshot-4.jpg" alt="" />I couldn&#8217;t find any information about this one, and I&#8217;d love it if someone who knows could share their thoughts on how to accomplish this suggestion: &#8220;Ensure that Web Part limits around maximum controls per zone is set low.&#8221;  Where is this set, and what would be considered low?</li>
</ul>
<p>I wish this documentation had listed the minimum required permissions for each service, as I&#8217;m having to discover these myself.  For instance, the web analytics service is the one that writes diagnostic logs, and that service account needs access to write to the diagnostic logs directory.  It would be great to see a definitive list beyond what was offered in the service accounts documentation.</p>
<p><strong>SQL Back-End</strong></p>
<p>Unless you are using named instances on SQL, it is safe to block access to port UDP/1434.  One measure that the documentation did not mention but is critical to protecting SQL servers in general is that the firewall rules should use a default deny for all inbound access to the SQL servers.  Only the application server(s), Domain Controllers, and the workstations of the DBAs should be able to reach the SQL servers at all.</p>
<p>Please share any other insights you might have or other resources that can help us secure our SharePoint environments better.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2010/06/07/microsoft-offers-security-hardening-documentation-for-sharepoint-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
