[Tool] xsyslogd

From xcorp. He released a syslog daemon on Windows 2000/XP (and possibly Server 2003 or NT4...)

xsyslogd

The source code is published as well as the binary.

posted @ 6:56 PM | Feedback (0)

[Snort] IDS Policy Manager

Also from seculogger's blog.

IDS Policy Manager

It would be useful when we deploy snort on multiple nodes.

Interesting, so I will evaluate this in future. I decided that I add this in the task list at my JP site... ;-)

posted @ 6:42 PM | Feedback (0)

Honeynet Security Console

From seculogger's blog.

Honeynet Security Console

It seems very neat. I decided that I should evaluate this, with sebek!

posted @ 6:36 PM | Feedback (0)

Monday, May 10, 2004 #

Microsoft Support Webcast: Microsoft Windows XP: Exploring Boot Options and Recovery Console June 25, 2002

This webcast covers topics around "how to use the recovery console" and more about troubleshooting the boot phase. It is a must thing, you know, as we engineers handle issues around servers. ;-)

Microsoft Support Webcast: Microsoft Windows XP: Exploring Boot Options and Recovery Console June 25, 2002

posted @ 10:16 AM | Feedback (0)

Sunday, May 09, 2004 #

Note: [IIS] How to have NNTP Feed?

From Bernard's article.
Errors in IIS 6.0 Documentation

I have once tested this NNTP Feed feature of IIS 6.0, with Shavlik's news server.
It seems I have to dig more on this.;-)

Thanks, Bernard!

posted @ 5:01 PM | Feedback (0)

JAPAN: Personal and private information in danger?

From seculogger, another Japanese MVP.
http://www.7th-angel.net/seculog/item/550.html

According to NHK, a leading broadcasting company in Japan, about 38% of market-leading companies in Tokyo Stock Exchange Market stated that they do not and will not have|prepare rules to prevent the outflow of private information.
Src (Pls use babelfish to have them translated):
http://www3.nhk.or.jp/news/2004/05/09/k20040508000025.html
http://www.asahi.com/national/update/0508/012.html

* Babelfish:
http://babelfish.altavista.digital.com/babelfish/tr

I do not understand what these companies have in mind, as the privacy law will be enforced in the next year. This means all the companies should be careful and does have responsibility enough to prevent such a thing, otherwise it is each of these companies' fault. I wonder where people in this country are heading for...?

posted @ 4:54 PM | Feedback (0)

[Tool] Quest Software Quest Central (Freeware)

From SQLJunkies.

Quest Software Quest Central for SQL SERVER - FREEWARE Now Available
http://www.quest.com/quest_central/sql_server/freeware/

It features things like this:

  • Database Administration
  • Space Management
  • 24x7 Monitoring
  • Performance Diagnostics with Spotlight
  • Database Analysis
  • Load Testing and Data Generation

Hmm, sounds not too bad, you know.

posted @ 4:36 PM | Feedback (0)

[Tool] Syslog Turbo, etc.

Softwares from Weird-Solution.

http://www.weird-solutions.com/download/demo.html

As for Syslog Turbo there are things that would be cooler if implemented. We can manipulate it with a sql-like dialect, which may be useful if you are familiar with SQL.

posted @ 2:48 PM | Feedback (0)

Note: added some maps of links.

I added the clickable maps of ISC and its Internet Traffic Report site.

The TrendMicro's stuff have to stay on top as otherwise I cannot show other news.

I hope in some near future we Japanese can have fully localized items of them. That way we can show our fellow people more precisely what is going on and what should be done aroud each of them... (sigh)

posted @ 2:26 PM | Feedback (0)

[Tool] ieSpell

A spell checker for IE. I found it when I did some spell-checks on the previous article. This tool is for English only, it seems. Still, it is very cozy.

ieSpell - A Spell Checker for Internet Explorer

posted @ 3:25 AM | Feedback (0)

Saturday, May 08, 2004 #

Just a note of log consolidation issues.

There are numbers of tasks around sysadmins and security engineers at the data centers, which include log management and monitoring the servers/clients to check if there is an unusual thing happening/ongoing.

I have begun to think of this one year ago when around me there were many of "untouched" or unmanaged as for the system environment. With such a server, when a trouble happens there is no one who could trace what is wrong or what should be done, or worse, when the box downs. It is not cool....

So, to trace the anomalies I am now heading in log consolidation/management to have evidence enough for troubleshooting and detection of problems.

What I have completed:

  1. consolidating logs and alerts of network appliances, routers, (managed) switches, firewalls.
    This means I have to collect both syslog messages and SNMP traps.

    To do this I am using WinSyslog from Adiscon as a central location for storing syslog messages and Kiwi Syslog Daemon to collect SNMP Traps. From Kiwi SNMP traps are translated into syslog and be poured in the syslog storage.
  2. consolidating Event log entries from Windows Machines.
    For this I am using NTSyslog I got from SourceForge. I am still in a half way as it cannot handle multi-byte languages properly, especially around  (what do you say in English? We say this "kaigyo code" in Japanese) and Chinese characters.

    Another point here is the future possibilities of using of Log Parser, which is written by a guy in Microsoft.
    We can handle eventlog messages in multi-byte languages without a fear with the current versions of the tools released, as it handles those characters as Unicode.
    We engineers in regions with multi-byte languages welcome this tool very much as we do not have to think about "how to localize this cozy tool?", etc, etc.

    I am not yet planning utilizing this very kewl and cozy tool in my framework because I want to design "effortless and yet cohered" design, though.
    I emphasize here that I am planning to improve/change the whole design so there is such a high possibility that I will be using this tool.

    In the MVP Summit 2004 some of us Japanese MVPs had a chance to discuss on the tool with the author, in which we have heard there will be much improvements in severals of the coming versions. I promise he is so dedicated and is so enthusiastic. ;-)
  3. Choosing the base platform.
    I chose the following stuffs for this system:
    A. Log consolidation
    Windows 2000 Server/Server 2003
    IIS 5.0 and later
    Active Server Pages
    Microsoft SQL Server 2000
    Adiscon WinSyslog 4.2 or later
    Kiwi Syslog Daemon (to just translate SNMP Traps into syslog messages, without an effort.)
    Softether (as providing the VPN way to collect logs of servers in several segments of different locations on the Internet.)

    B. MRTG and some other system monitors
    For this I am using several up to now, and I am planning to consolidate the monitors in just a few nodes, as I want to include links for the graphs of MRTG in the system A. above. I intentionally have several nodes, as in such a way I can troubleshoot more precisely where the bottle neck/system down occurs.

What I am not yet doing:

  1. Consolidating logs scattered around the system and messages written in other forms
    As for these logs I am imagining api.log, setup.log, and so on which are written in the text format and scattered around the whole system for Windows OSes.
  2. Consolidating Backup and Task Scheduling logs of Windows NT-Based OSes
  3. Consolidating HFNETCHK/MBSA resultant texts.
  4. Consolidating MRTG results
  5. Consolidating results from tools for penetration testings like NIKTO, Syhunt, N-Stealth, Nessus, and so on.
  6. Merging and consolidating /var/log/messages and so on in Unix platforms including FreeBSD and Linux.
  7. Merging the logs of crond and the texts of logwatch from Unix platforms.
  8. Consolidating results of system monitoring softwares like those released from Dell, HP, and so on.
  9. Visualize the results to make it easier to confirm what is going on.
  10. Issuing alerts via e-mail and web monitor pages.
  11. The site design as a whole. (I am using IIS as a web server to show the results.)
  12. Designing a fault-tolerant system for both SoftEther and the server.

posted @ 11:13 PM | Feedback (0)

Beware of the computer name...

From vbNullString's VBASPCODER's blog:
Beware of your computer name

I just remembered a hard time I experienced during a migration project from NT Domain to Active Directory, in an international company.(sigh)

Sometimes the naming rules of computers in the company matters, especially those rules that require us to use underscore or some other characters which are not conforming to the design of some functions/components of products or the RFC itself.

An example of such trouble is the one described in the following KBs:
316112 PRB: Session Variables Do Not Persist Between Requests After You Install Internet Explorer Security Patch MS01-055

In such a case we have nothing to do, other than just rename the computer name. This may cause problems, one of which is like this:
234142 Updating IIS After You Change the Computer Name

Sure, as you may have seen in SQL6.5/7.0 migration, or migration projects from NT Domain to Active Directory, we sysadmins, designers, and the architects should carefully design so that the result of an operation is not so disasterous.

So, it is important to know there are risks to use characters not included in the alphabet or numbers, you know, especially for the server...

posted @ 10:07 PM | Feedback (0)

KB:314470 Definition of System Partition and Boot Partition

Sometime it is so confusing, you know. ;-)

314470 Definition of System Partition and Boot Partition

posted @ 9:49 PM | Feedback (0)

Tuesday, April 13, 2004 #

Misc: Moving contents from JP site to here.

Now, at first, I am moving some of the links, not all, to this site as my JP site contains somewhat too much of links, you know.

I am going to post things here more often, as in my JP site... Mainly English, and sometimes, French.

Cheers,

--kyamamoto

posted @ 11:34 PM | Feedback (0)

[Site] WMIex.MSFT.NET

The famous snmpboy site has evolved dramatically to handle WMI implementation!

http://wmiex.msft.net/

posted @ 11:00 PM | Feedback (0)

Tuesday, March 16, 2004 #

[Tool] Multiple tools for Logging sessions

As we know Windows generally does not log sessions on any level up to Layer 4 of OSI 7 layers model.

So there emerges the need for such a method or tool.

Currently there are multiple that enable logging sessions, so let's just note here.

1. Port Reporter (Microsoft)
A service tool which logs the session info (IP, port of both src and dst), PID, and the process that initiated the session.)
http://www.microsoft.com/downloads/details.aspx?familyid=69ba779b-bae9-4243-b9d6-63e62b4bcd2e&displaylang=en

2. Xlog (Freeware by xcorp)
This tool utilizes Winsock2. Created by xcorp, a Japanese programmer who makes useful tools for security and network management.
http://xcorp.saposen.com/toolz/xlog.html

3. Syunlog (Freeware by syun)
This tool utilizes library provided with WinPcap. Use with WinPcap. Created by syun.
http://www.baba-lab.com/syunlog/

4. monyolog (Freeware by monyo, or TAKAHASHI, Motonobu of the Samba team.)
This tool also utilizes WinSock2, especially RAW_SOCKETS of Winsock 2.2. The author is one of the Samba core team members, who is specialized in TCP/IP and Windows networking, and also I18N.
http://www.monyo.com/technical/products/monyolog/

posted @ 1:13 PM | Feedback (2)

Sunday, February 29, 2004 #

JAPANESE: 日本語テスト

(English follows after Japanese)

??????????????? MSDN ? ASP.NET ? Blog ??? Post ??????? Feedback ?????????????
????????????????????????

??????????????????? Workaround ? Tips ?????????? ???????????????????

?: ????????????????????????????????? Tips ??????????????????????????????????

This is a test for writing things in Japanese. As you can see, in blogs at MSDN or ASP.NET it is okay to write things in Japanese in the message body itself but not okay in the feedback fields.
Well, is it difficult to handle multi-byte languages (especially in .TEXT) ?

If you are familiar with these languages and have some tips on the workaround of this issue, pls let us know.

Note: I am not a developer, but I believe those developers who have seen this post can and will implement more excellent, cooler, and better things in the future.

posted @ 6:30 PM | Feedback (1)

Monday, February 09, 2004 #

[KB] 810639 FIX: FTP Passive Mode Support for Firewall Scenarios

This article describes how to put controll on the ports used with FTP PASSIVE mode with IIS 5.0.
SP4 is required to enable this.
http://support.microsoft.com/?kbid=810639

posted @ 6:06 PM | Feedback (7)

[Tool] IISecure

Un utilitaire pour fixer l'IIS
http://www.laboratoire-microsoft.org/cd/outils/iisecure/

posted @ 1:42 PM | Feedback (2)

[Tool] SyslogD de FPSOFT (Allemand)

Un utilitaire pour donner des possibilités de Windows de recevoir des messages de syslog. Il peut stocker toutes les données dans le serveur de MSDE/MSSQL. Essayez-vous, s'il vous plait.
http://www.syslogd.fpsoft.de/

posted @ 12:49 PM | Feedback (0)

[Tool] Pagedefrag de Sysinternals

Un utilitaire pour les dossiers defragment qui ne sont pas faits après bootup.
http://www.sysinternals.com/ntw2k/freeware/pagedefrag.shtml

posted @ 12:42 PM | Feedback (0)

Saturday, January 31, 2004 #

L'introduction à packetfiltering sur Windows (especialement 2000 et XP) <1er edition en Japonais>

Voici l'extrait de ma présentation en Japonaise à un événement.
http://www.forensic.jp/~yamaken/WinPacketFil.zip
Je veux transmettre les coups secs du "packet filtering" sur Windows à beaucoup de gens.

Regards,
--
Kenji Yamamoto, one of Japanese MVPs on Security

posted @ 12:29 AM | Feedback (0)

Thursday, January 29, 2004 #

Ev2T

It is a tool which converts event log messages to SNMP traps.
http://www.ncomtech.com/download.htm

As for multilbyte languages it may not be ready...
At least sending traps to Kiwi has been terrible when I used this tool with Japanese version of Windows Server 2003.
You may have to obtain a management app which is capable of handling multibyte messages like Japanese, Chinese, and Korean.
Anyway there seems no probs when used with English version of NT Kernel-based OSes.

posted @ 11:45 PM | Feedback (1)

Syslog management on Windows platforms.

Do you know WinSyslog from Adiscon? It is so cool a tool for us system operators/administrators.
Check it out at: http://www.adiscon.com/
(For Japanese: http://adiscon.port139.co.jp/)
This tool is so cool, as it allows you to consolidate all the standard error/log messages to one server. With MSSQL you can even display the messages via IIS 4/5. Merging Syslog, SNMP, and Windows Event logs are critical for system admins, to whom we can say this tool is the very solution for managing system health in general.
You can merge SNMP with syslog, using either the latest version of WinSyslog, or with Kiwi Syslog Daemon (http://www.kiwisyslog.com).
You can merge Windows event logs with the following tools:

1. Event Reporter from Adiscon

2. Event logs to syslog utility from Purdue University.

3. ntsyslog service tool from SourceForge

cf. I found a localised version of ntsyslog in Vector or Mado-no-mori, which uses EUC-JP for Japanese. If you have already deployed Linux- or *NIX-based solution for the consolidation of logs, this client is just-fit, it seems.

Note: there are other tools in the world to facilitate this function. According to Kawabata-san ( http://www.kawabata.com/), you can even write up the tool that just-fits to your need. ;-)

***System Requirements:

A. System: See the URLs above
B. Human:

B-1. Knowledge of syslog (unix and network devices you use.)

B-2. Ability or Experience of manually parsing eventlogs on Windows

B-3. Ability to configure network devices to emit logs, if you think you'd like to add the target of monitoring.

B-4. Ability to configure SNMP on servers and clients to enable them to emit SNMP messages.

B-5. Ability/experience to configure server management tools like Allied Telesyn SwimView, HP OpenView or Dell Server Administrator /IT assistant for PowerEdge Systems.

(It is okay to use other administrative tools according to the needs at your managed networks. Tools above are just as examples.)
Outputs are just like this.(Special thanks to lg_de_sucre, a cool guy working together.)


Howto: Manage logs (delete unwanted/needless log messages)?

-> Create jobs (using T-SQL) from SQL Server Enterprise Manager.

Howto: merge the route and simplify the system?

-> Use SoftEther or other VPN products.

Howto: merge outputs of Snort?

-> Consult with docs around Snort.

http://www.winsnort.com/ or http://www.snort.org/ are both good-starts.

Ah, it seems I am gonna miss the last train, so see ya later!
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 1
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值