Posts

Using ffmpeg to split MOD movie files.

Image
My wife and I recently purchased a Panasonic SDR-H40 for capturing video of our son and daughter, after our Canon MiniDV crapped out last year. It was disappointing when the Canon failed again...TWO times this thing decides to get tape debris caught in the heads. This was the most delicate camera ever owned, and captured excellent quality footage, but I will NEVER buy another tape-based machine. The Panasonic falls short in the quality department as compared to the Canon, and we knew that going in. The maximum video quality is 10mbps, which seems to be pretty good quality on a laptop. I haven't tried it on a analog TV yet. Image via CrunchBase I needed to post these clips on YouTube for family and friends located in various parts of the planet, and rapidly discovered that the MOD files stored on the SDR-H40 can be accessed easily as plugging in the USB card, and waiting for udev to automatically mount it on my shiny new installation of Ubuntu. I discovered that t...

GFI LANguard 9 Review

Image
As a consultant, I used GFI LANguard (7?...it was at least 2 years ago) as a tool, in conjunction with nmap and some others, to perform security audits for our clients. Now I've an opportunity to use it again, and agreed to give it a review. Environment Dell Dimension 5150 P4 3ghz, 2gb Ram SLED 10.1, running VMWare Server 1.x 768mb allocated for XP SP2 Instance LAN, 2003 Domain in mixed mode The download from GFI's website was surprisingly small; only 50mb. The installation was straight forward, with only two questions; installation location, and initial credentials to use for scanning your domain. The UI is no different, very intuitive. I'd expect nothing else from GFI, since most of their products are the same way. The product is broken up into four components: Management Console - the central location for launching scans, view saved scans, configure options, and use specialized network security tools. Attendant Service - runs scheduled scans and patch deploymen...

Chucky Cheese

Yesterday, attended a birthday party for our friends 2 year old at Chucky Cheese. My first thought was that this was going to be fun for our young son, who's not had this kind of experience before. We try to expose him to as many things (read: safe, reasonable. i.e. Not bungee jumping. Yet.) as we can. What we encountered can only be described as what we used to call in the Army, as a "cluster f$%k". It was 20 degrees outside. There were at least 30 people waiting to enter, most for parties. We were all freezing our asses off, half inside the building, half outside. Would that be "half-assed"? I digress. The young man checking guests in, appeared new, because he was not bothering to check if some of us were attending parties, or just looking for somewhere to drink while our kids spread our particular variety of bactiria and virus around. So we waited. And waited. And waited. Finally the manager comes over to do her job, and find out why we are all standing aroun...

Symantec Endpoint Protection and Outlook's 0x800CCC0F Error

After upgrading from SEP 11 MR2 to MR3, my users 0x800CCC0F Outlook error stopped....for one day, then re-appeared. This issue ONLY occurred during his mail retrieval process. During my troubleshooting, I had initially opened a command prompt, and issued the command: telnet pop.myserver.com 110 And received an inline PGP reply, that it was proxying the connection. That prompted me to do a little Googling, but revealed nothing. I found a MS Kb article that pointed to some troubleshooting steps, but they didn't help at all, and neither did Symantec's kb or forums Much to my surprise and glee, he started to experiment with his POP settings. After setting his POP connection to SSL, his problems went away!

Symantec Endpoint Protection MR2 to MR3 Upgrade

Not much to mention...it_just_works. THIS TIME. Steps for upgrading: Download MR3 Stop all SEPM services. Run installer over the top of previous installation. Interestingly, researching an Outlook error 0x800CCC0F while POP'ing email down from our mail host, I found this article about how much better MR3 will perform, even over the likes of v10. Hopefully my test client will not experience any issues, as the SEPM surely didn't.

Redeploy Symantec Endpoint Security Client

I need a method to reinstall a SEP client package. Unfortunately, SEPM doesn't have a method in their GUI to do this...*nudgenudgewinkwink*, you must use the Migration and Deployment Wizard, and choose the default option Deploy the Client , and then Select and Existing Package to Deploy . I found a clue in a thread at Symantec's forums where one can use the %PROGRAMFILES%\Symantec\Symantec Endpoint Protection Manager\tomcat\bin\ClientRemote.exe utility, which is usually only revealed when you use the wizard, or initially install the product. You'll find your repository of packages you created in said installation at %PROGRAMFILES%\Symantec\Symantec Endpoint Protection Manager\Inetpub\ClientPackages, one folder for each package represented in SEPM, with a sub-folder called full. Unfortunately the folder names are named using the package checksum number, and I can't immediately tell by looking at the GUI which one is which. Fortunately for me, I only created two packa...

The Sinowal Trojan Steals You Blind

This morning, home sick, reading /. I find this story about the Sinowal Trojan . Evidently, starting in 2006, this Trojan has been stealing sensitive data from thousands of Internet users across the globe, except for those in Russia. Seems even the Russian mob has a heart. This all raises a question I've often asked myself. I've been managing enterprise environments for years now, using a variety of methods to protect the sheep, in hopes that the worst is avoided; a full network infection. It's happened to me once, when I worked for the Racine Art Museum. I'd been hired to oversee the IT side of a new museum we were raising capitol for. The environment was rather new at the time; NT Back Office server, 2000 clients, Trend AV suite. Unfortunately, as in some environments like this, there are applications that require elevated privileges to run. I suspect that this may have had something to do with the rapid spread of this virus. The signs were odd; in each network ...