<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Phocean.net &#187; Windows</title>
	<atom:link href="http://www.phocean.net/category/administration-systeme/windows/feed" rel="self" type="application/rss+xml" />
	<link>http://www.phocean.net</link>
	<description>Crusing for Knowledge, Drifting towards Security</description>
	<lastBuildDate>Thu, 02 Sep 2010 13:57:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>ARPFreeze</title>
		<link>http://www.phocean.net/2009/06/08/arpfreeze.html</link>
		<comments>http://www.phocean.net/2009/06/08/arpfreeze.html#comments</comments>
		<pubDate>Mon, 08 Jun 2009 06:32:34 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Defense]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[System]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[arp]]></category>
		<category><![CDATA[flooding]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=381</guid>
		<description><![CDATA[ARPFreeze is a nice GUI for Windows that allows to configure static ARP entries very easily, and makes these changes persistent after reboot. Thus does it protect the client machine against ARP flooding. It works for both Windows Vista and prior versions (support of arp -s and netsh).]]></description>
			<content:encoded><![CDATA[<p><a title="ARPFreeze" href="http://www.irongeek.com/i.php?page=security/arpfreeze-static-arp-poisoning" target="_blank">ARPFreeze</a> is a nice GUI for Windows that allows to configure static ARP entries very easily, and makes these changes persistent after reboot.<br />
Thus does it protect the client machine against ARP flooding.</p>
<p>It works for both Windows Vista and prior versions (support of arp -s and netsh).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2009/06/08/arpfreeze.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows 7 UAC security design flaw</title>
		<link>http://www.phocean.net/2009/05/15/363.html</link>
		<comments>http://www.phocean.net/2009/05/15/363.html#comments</comments>
		<pubDate>Fri, 15 May 2009 14:48:02 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[System]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[UAC]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=363</guid>
		<description><![CDATA[Video of a dummy vulnerability on Windows 7 . More info there. It is incredible that Microsoft invests so much money in its security and that there are still such a bad security design for programs that in no way should be granted any administrator access (calc.exe or notepad.exe). Also, I can&#8217;t imagine that no [...]]]></description>
			<content:encoded><![CDATA[<p><a title="WIndows 7 vulnerability" href="http://leo.lss.com.au/W7E_VID_INT/W7E_VID_INT.htm">Video of a dummy vulnerability</a> on Windows 7 . More <a title="Windows 7 UAC vulnerability" href="http://www.pretentiousname.com/misc/win7_uac_whitelist2.html" target="_blank">info there</a>.</p>
<p>It is incredible that Microsoft invests so much money in its security and that there are still such a bad security design for programs that in no way should be granted any administrator access (calc.exe or notepad.exe).</p>
<p>Also, I can&#8217;t imagine that no one could detect it in their teams during the quality process and security audit.</p>
<p>What the hell are they doing ?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2009/05/15/363.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMWare Workstation 6.5</title>
		<link>http://www.phocean.net/2008/10/05/vmware-workstation-65.html</link>
		<comments>http://www.phocean.net/2008/10/05/vmware-workstation-65.html#comments</comments>
		<pubDate>Sun, 05 Oct 2008 16:46:40 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Desktop]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[System]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[Gnome]]></category>
		<category><![CDATA[kernel 2.6.26]]></category>
		<category><![CDATA[Unity]]></category>
		<category><![CDATA[VMWare]]></category>
		<category><![CDATA[vmware-any-any]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=249</guid>
		<description><![CDATA[I have just upgraded WMWare from version 6.04 to 6.5, and I have to say that it has very nice new features. The first surprising thing was the file I downloaded. It is now not anymore a tar.gz archive but a .bundle file. After downloading, as root, just make it executable or start it with [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;">I have just upgraded WMWare from version 6.04 to 6.5, and I have to say that it has very nice new features.</p>
<p style="text-align: left;">The first surprising thing was the file I downloaded. It is now not anymore a tar.gz archive but a .bundle file.</p>
<p style="text-align: left;">After downloading, as root, just make it executable or start it with sh :</p>
<pre class="brush: plain;">% sh VMware-Workstation-6.5.0-118166.x86_64.bundle</pre>
<p style="text-align: left;">It now starts a graphic installer, that takes care of everything. All the compilation process is now hidden to the user.</p>
<p style="text-align: left;">I was expecting the compilation to fail and that I would have to look for a patch to run on my edge Linux kernel. Indeed, I just compiled 2.6.26 kernel (64 bits) a few days ago.</p>
<p style="text-align: left;">But nothing like that. the process went smoothly.</p>
<p style="text-align: left;">However, I was still prudent. Even after a compiling, previous versions almost always required some patch to get full networking to work.</p>
<p style="text-align: left;">So I gave a try and launch one of my virtual machines. Surprise : all worked out of the box !</p>
<p style="text-align: left;">For the first time, I even did not need any vmware-any-any patch or any network patched vmmon and vmnet modules to get wifi networking operational.</p>
<p style="text-align: left;">I also quickly noticed some very nice and fancy features :</p>
<ul style="text-align: left;">
<li><strong>3D graphics support</strong></li>
<li><strong>more</strong> <strong>devices supported</strong> : fingerprint reader device, audio driver for Vista, &#8230;</li>
<li>a <strong>graphical virtual network settings</strong> editor : this utility had been for ages on the Windows version and finally will make your easier on Linux</li>
</ul>
<p style="text-align: left;">At last, but not least, the <strong>Unity</strong> display mode.</p>
<p style="text-align: left;">Though I am not a Mac user, I believe this can be compared to VMWare Fusion. Anyway, it allows you to display the virtual machines programs within your X session.</p>
<p style="text-align: left;">Look at this screenshot :</p>
<p style="text-align: center;"><a href="http://www.phocean.net/wp-content/uploads/2008/10/capture-11.png"><img class="size-medium wp-image-255" title="VMWare Workstation 6.5 and Unity" src="http://www.phocean.net/wp-content/uploads/2008/10/capture-11-300x187.png" alt="VMWare Workstation 6.5 and Unity" width="300" height="187" /></a></p>
<p style="text-align: left;">The result is quite spectacular. On my Gnome desktop, I am now able to display some windows from Windows XP and Windows Vista.</p>
<p style="text-align: left;">Well, this is not yet perfectly smooth or artifact free, but this is already really usable and responsive enough to be used intensively.</p>
<p style="text-align: left;">Another limit is the operating system support. So far, among my virtual machines, I was able to do it with Windows systems but not Open Solaris for instance.</p>
<p style="text-align: left;">There must have been more improvements, more or less visible, that I am not aware of. I won&#8217;t go for a full review.</p>
<p style="text-align: left;">I just wanted to insist that if you are a VMWare user,  you really should consider to upgrade for the <strong>complete support of the latest kernel</strong> and the <strong>Unity</strong> feature.</p>
<p style="text-align: left;">It seems that VMWare has listened to the Linux users, or at least is taking it more seriously. Not that they are nice, but the competitors are close (Virtual box, KVM, Xen&#8230;) !</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2008/10/05/vmware-workstation-65.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>DecaffenatID : a little ARP IDS for Windows</title>
		<link>http://www.phocean.net/2008/08/27/decaffenatid-a-little-arp-ids-for-windows.html</link>
		<comments>http://www.phocean.net/2008/08/27/decaffenatid-a-little-arp-ids-for-windows.html#comments</comments>
		<pubDate>Wed, 27 Aug 2008 12:49:17 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[IDS / IPS]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[arp]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[spoofing]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=115</guid>
		<description><![CDATA[DecaffeinatID is a tool for Windows that can be very useful against ARP attacks.]]></description>
			<content:encoded><![CDATA[<p><a title="DecaffeinatID" href="http://www.irongeek.com/i.php?page=security/decaffeinatid-simple-ids-arpwatch-for-windows">DecaffeinatID</a> is a tool for Windows that can be very useful against ARP attacks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2008/08/27/decaffenatid-a-little-arp-ids-for-windows.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Vista memory protection : defeated ?</title>
		<link>http://www.phocean.net/2008/08/08/windows-vista-memory-protection-defeated.html</link>
		<comments>http://www.phocean.net/2008/08/08/windows-vista-memory-protection-defeated.html#comments</comments>
		<pubDate>Fri, 08 Aug 2008 15:44:45 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[memory injection]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=218</guid>
		<description><![CDATA[It seems, at least according to some researchers showed it at the Black Hat conference. Mark Dowd (IBM) and Alexander Sotirov (VMWare) found a way to bypass  the memory protection implemented in Vista to inject malicious instructions within Internet Explorer. They were able to copy any content wherever they wished on the disk. Especially, this [...]]]></description>
			<content:encoded><![CDATA[<p>It seems, at least according to <a href="http://taossa.com/index.php/2008/08/07/impressing-girls-with-vista-memory-protection-bypasses/" target="_blank">some researchers showed it at the Black Hat conference</a>.</p>
<p>Mark Dowd (IBM) and Alexander Sotirov (VMWare) found a way to bypass  the memory protection implemented in Vista to inject malicious instructions within Internet Explorer. They were able to copy any content wherever they wished on the disk.</p>
<p>Especially, <a href="http://taossa.com/archive/bh08sotirovdowd.pdf" target="_blank">this paper</a> will be an interesting reading, even if it is not as simple as they say &#8211; at least for me.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2008/08/08/windows-vista-memory-protection-defeated.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Restoring a MSSQL 2000/2005 database while in production</title>
		<link>http://www.phocean.net/2007/03/03/restoring-a-mssql-20002005-database-while-in-production.html</link>
		<comments>http://www.phocean.net/2007/03/03/restoring-a-mssql-20002005-database-while-in-production.html#comments</comments>
		<pubDate>Sat, 03 Mar 2007 19:02:00 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[System]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[MSSQL]]></category>
		<category><![CDATA[SQL]]></category>

		<guid isPermaLink="false">http://192.168.1.10/wordpress/?p=23</guid>
		<description><![CDATA[<p>At my work, I had to overwrite a MSSQL database while in production. The goal was to replace the existing database by one with a new structure.</p> <p>I tried first the easy way, right clicking on it and trying to take it off line using the menu of Microsoft. </p> Unfortunately, that didn't do anything, complaining that several users were accessing it. Of course, trying to restore it directly gave the same message. <br /><br />I couldn't find a way to successfully force it through the interface.<br />]]></description>
			<content:encoded><![CDATA[<p>At my work, I had to overwrite a MSSQL database while in production. The goal was to replace the existing database by one with a new structure.</p>
<p>I tried first the easy way, right clicking on it and trying to take it off line using the menu of Microsoft.</p>
<p>Unfortunately, that didn&#8217;t do anything, complaining that several users were accessing it. Of course, trying to restore it directly gave the same message.</p>
<p>I couldn&#8217;t find a way to successfully force it through the interface.<br />
<span id="more-23"></span></p>
<p>It was, of course, a multiuser database on which always an user was working on, making it impossible to overwrite it.</p>
<p>So, at this point, I had to consider using the SQL query tool, to enjoy the power of a command line interface (you see what I mean).</p>
<p>Below is the kind of request I submited :</p>
<pre class="brush: sql;">use master;
alter database $your_database set single_user with rollback immediate;
backup database $your_database to disk = 'C:\$your_database.bak' with init,Name = 'backup';
restore database $your_database from disk = 'C:\path\to\your\DB\$your_new_database.bak' with replace,file=1,recovery
alter database Datasharing_Translation set multi_user with rollback immediate;</pre>
<p>It switches the database to the single user mode, make a backup of it (for safety), make the restoring operation, and finally switches it back to the multi user mode.</p>
<p><img src="http://www.phocean.net/wp-content/uploads/2007/05/public/mssql_query_tool.png" alt="" width="320" height="229" /><br />
Once again the day is saved by a command line tool !  <img src='http://www.phocean.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2007/03/03/restoring-a-mssql-20002005-database-while-in-production.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Solutions Linux 2007 : Tux vs Vista Car</title>
		<link>http://www.phocean.net/2007/02/01/solutions-linux-2007-tux-vs-vista-car.html</link>
		<comments>http://www.phocean.net/2007/02/01/solutions-linux-2007-tux-vs-vista-car.html#comments</comments>
		<pubDate>Thu, 01 Feb 2007 11:28:00 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Vista]]></category>

		<guid isPermaLink="false">http://192.168.1.10/wordpress/?p=19</guid>
		<description><![CDATA[<p>I couldn't have much free time this year, but I quickly stopped by the Solution Linux show of Paris, La Defense. It was the first time for me.</p>]]></description>
			<content:encoded><![CDATA[<p>I couldn&#8217;t have much free time this year, but I quickly stopped by the Solution Linux show of Paris, La Defense. It was the first time for me.</p>
<p><span id="more-19"></span></p>
<p>Unfortunately, I could not attend any conference, but I had a quick and nice view of the exhibition.  All the major actors were there and I had a good time talking with some people about the trends.</p>
<p><img style="margin: 0pt auto; display: block" src="http://www.phocean.net/wp-content/uploads/2007/05/public/solution%20linux/P1300004.JPG" alt="" width="240" height="320" /></p>
<p>It was fun to see that Microsoft was there in small stand. But more fun was that there were turning around in small cars, just in front of the building of Linux Solutions.</p>
<p>Here are the Vista vehicules :</p>
<p><img style="margin: 0pt auto; display: block" src="http://www.phocean.net/wp-content/uploads/2007/05/public/solution%20linux/P1300003.JPG" alt="" width="320" height="240" /></p>
<p>Beside that, it was great to learn the news that a french car makers, Peugeot, will swith 20 000 of its PC and 2500 of its server to the Novell Linux solution.</p>
<p>It seems that times are changing&#8230; and I am sure that shiny marketing won&#8217;t change anything !</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2007/02/01/solutions-linux-2007-tux-vs-vista-car.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
