724 KiB
Windows Server Hacks Team DDU - By Mitch Tulloch
• Table of Contents • Index • Reviews • Reader Reviews • Errata • Academic Windows Server Hacks By Mitch Tulloch Publisher: O'Reilly Pub Date : March 2004 ISBN: 0-596-00647-0 Pages : 384
The tools, or hacks in this book reveal techniques that go well beyond basic management tasks found in most handbooks. Hacks range from those that deal with general administration to more esoteric hacks in the areas of network deployment, patch management, performance, security, and backup and recovery. No matter which Windows Server you use--NT, IIS, 2000, or 2003--Windows Server Hacks will put the knowledge and expertise of veteran system administrators to work for you.
• Table of Contents • Index • Reviews • Reader Reviews • Errata • Academic Windows Server Hacks By Mitch Tulloch Publisher: O'Reilly Pub Date : March 2004 ISBN: 0-596-00647-0 Pages : 384
Copyright Credits About the Author Contributors Acknowledgments Foreword: I'm a Sci-Fi freak Preface Why Windows Server Hacks? Getting and Using the Scripts How to Use This Book How This Book Is Organized Conventions Used in This Book Using Code Examples How to Contact Us Got a Hack? Chapter 1. General Administration Hacks #1-16 Section 1. Use Run As to Perform Administrative Tasks
Section 2. Drag and Drop to the Run Menu Section 3. Find and Replace Registry Keys from a Command Line Section 4. Automatically Log On After Booting Section 5. Wait for and Optionally Terminate a Process Section 6. Shut Down a Remote Computer Section 7. Rename Mapped Drives Section 8. Execute a Command on Each Computer in a Domain Section 9. Add, Remove, or Retrieve Environment Variables Section 10. Extend Group Policy Section 11. Disable EFS Section 12. Get Event Log Information Section 13. Shortcut to Remote Assistance Section 14. Desktop Checker Section 15. Top Five Tools Section 16. myITforum.com Chapter 2. Active Directory Hacks #17-24 Section 17. Retrieve the List of Old Domain Computer Accounts Section 18. Automate Creation of OU Structure Section 19. Modify All Objects in the OU Section 20. Delegate Control of an OU to a User
Section 21. Send OU Information in Active Directory to an HTML Page Section 22. Display Active Directory Information Section 23. Store and Display Contact Information in Active Directory Section 24. Restore the Active Directory Icon in Windows XP Chapter 3. User Management Hacks #25-35 Section 25. Search for Domain Users Section 26. Manage User Accounts in Active Directory Section 27. Get a List of Disabled Accounts Section 28. Get User Account Information Section 29. Check for Passwords that Never Expire Section 30. Enumerate Group Membership to a CSV File Section 31. Modify User Properties for All Users in a Particular OU Section 32. Check Group Membership and Map Drives in a Logon Script Section 33. Script Creation of a User's Home Directory and Permissions Section 34. Prevent Ordinary Users from Creating Local Accounts Section 35. Put a Logoff Icon on the Desktop Chapter 4. Networking Services Hacks #36-47 Section 36. Manage Services on Remote Machines
Section 37. Simplify DNS Aging and Scavenging Section 38. Troubleshoot DNS Section 39. Manually Recreate a Damaged WINS Database Section 40. Change WINS for All Enabled Adapters Section 41. Ensure DHCP Server Availability Section 42. Change a Network Adapter's IP Info Section 43. Change from Static IP to DHCP Section 44. Release and Renew IP Addresses Section 45. Use netsh to Change Configuration Settings Section 46. Remove Orphaned Network Cards Section 47. Implement Windows 2000 Network Load Balancing Chapter 5. File and Print Hacks #48-53 Section 48. Map Network Drives Section 49. Determine Who Has A Particular File Open on the Network Section 50. Display a Directory Tree Section 51. Automate Printer Management Section 52. Set the Default Printer Based on Location Section 53. Add Printers Based on Name of Computer Chapter 6. IIS Hacks #54-61
Section 54. Back Up the Metabase Section 55. Restore the Metabase Section 56. Map the Metabase Section 57. Metabase Hacks Section 58. Hide the Metabase Section 59. IIS Administration Scripts Section 60. Run Other Web Servers Section 61. IISFAQ Chapter 7. Deployment Hacks #62-68 Section 62. Get Started with RIS Section 63. Customize RIS Section 64. Tune RIS Section 65. Customize SysPrep Section 66. Remove Windows Components from the Command Line Section 67. Unattended Installation of Windows Components Section 68. Easily Create a Network Boot Disk Chapter 8. Security Hacks #69-78 Section 69. Fundamentals of a Virus-Free Network Section 70. Antivirus FAQ
Section 71. Rename the Administrator and Guest Accounts Section 72. Get a List of Local Administrators Section 73. Find All Computers that Are Running a Service Section 74. Grant Administrative Access to a Domain Controller Section 75. Secure Backups Section 76. Find Computers with Automatic logon Enabled Section 77. Security FAQ Section 78. Microsoft Security Tools Chapter 9. Patch Management Hacks #79-89 Section 79. Best Practices for Patch Management Section 80. Beginners Guide to Enterprise Patch Management Section 81. Patch-Management FAQ Section 82. Enumerate Installed Hotfixes Section 83. Apply Patches in the Correct Order Section 84. Windows Update FAQ Section 85. Obtain Updates via the Windows Update Catalog Section 86. Use Automatic Updates Effectively Section 87. Use Group Policy to Configure Automatic Updates Section 88. Automatic Updates FAQ Section 89. Software Update Services FAQ
Chapter 10. Backup and Recovery Hacks #90-100 Section 90. Collect Disaster Recovery Files Section 91. Back Up Individual Files from the Command Line Section 92. Back Up System State on Remote Machines Section 93. Back Up and Restore a Certificate Authority Section 94. Back Up EFS Section 95. Work with Shadow Copies Section 96. Back Up and Clear the Event Logs Section 97. Back Up the DFS Namespace Section 98. Recover with Automated System Recovery Section 99. Recovery Roadmap Section 100. Data Recovery of Last Resort Colophon Index
Copyright © 2004 O'Reilly Media, Inc. Printed in the United States of America. Published by O'Reilly Media, Inc., 1005 Gravenstein Highway North, Sebastopol, CA 95472. O'Reilly & Associates books may be purchased for educational, business, or sales promotional use. Online editions are also available for most titles (http://safari.oreilly.com). For more information, contact our corporate/institutional sales department: (800) 998-9938 or corporate@oreilly.com. Nutshell Handbook, the Nutshell Handbook logo, and the O'Reilly logo are registered trademarks of O'Reilly Media, Inc. The Hacks series designations, Windows Server Hacks, the image of a squeegee, 'Hacks 100 Industrial-Strength Tips and Tricks,' and related trade dress are trademarks of O'Reilly Media, Inc. Many of the designations used by manufacturers and sellers to distinguish their products are claimed as trademarks. Where those designations appear in this book, and O'Reilly Media, Inc. was aware of a trademark claim, the designations have been printed in caps or initial caps. While every precaution has been taken in the preparation of this book, the publisher and authors assume no responsibility for errors or omissions, or for damages resulting from the use of the information contained herein.
Credits About the Author Contributors Acknowledgments
About the Author Mitch Tulloch is the author of over a dozen computer books, including three Nutshells for O'Reilly & Associates, Inc. (Microsoft Exchange Server in a Nutshell, Windows 2000 Administration in a Nutshell, and Windows Server 2003 in a Nutshell), two encyclopedias for Microsoft Press (the Microsoft Encyclopedia of Networking, currently in its second edition, and the Microsoft Encyclopedia of Security), and a string of titles for system administrators from Osborne/McGraw-Hill. Mitch has also written feature articles for industry magazines such as NetworkWorld and Microsoft Certified Professional Magazine, has developed university-level courses in Windows system administration, and provides training and consulting in Microsoft platforms and products. Mitch is based in Winnipeg, Canada, and you can contact him through his web site (http://www.mtit.com).
Contributors The following people contributed their hacks, writing, and inspiration to this book: Dennis Abbott is a columnist on myITforum.com (http://www.myitforum.com) and has been working in the high tech industry for eight years. He has worked with Microsoft Systems Management Server since Version 1.1 and with Windows NT Server since Version 3.51. Dennis discovered the power of Microsoft scripting while building in-house solutions for software distribution that required industry-standard infrastructure and a minimum amount of code. He has coded numerous scripts that combine Windows Management Instrumentation, Active Directory Service Interfaces, and Windows Scripting Host to create simple solutions to complex problems. He currently works for Schneider National in Green Bay, WI, where he bicycles to work through rain, sleet, or snow. Previous employers include Dell Computers and Advanced Micro Devices. He can be reached at speckled_trout@hotmail.com. Sean Ademy is a columnist on myITforum.com (http://www.myitforum.com) and has been in the IT industry for eight years. He is thankful to be lucky enough to be able to turn a hobby into a career. He is a lifelong resident of St. Petersburg, FL, where he currently resides with his wife, Wendy, and son, Kyle. In his spare time, you can usually find Sean cheering for his
hometown Tampa Bay Buccaneers, playing one of his guitars, or fishing the waters of Tampa Bay with Wendy. You can reach Sean at seanademy@yahoo.com. Michael Brainard is a columnist on myITforum.com (http://www.myitforum.com) and has worked in the computer industry for the past 10 years. He has worked in Tennessee, Georgia, and Florida. During that time he has worked for companies such as Eastman Chemical Company, Cox Communications, MCI, and Motorola. He currently runs his own business, Computing Xperts (CX) (http://www.computingxperts.com), in the South Florida area. He has spent 6 of his 10 years in the computer industry administrating Systems Management Server (SMS), package automation, and scripting, and he spent the other 4 years offering automated solutions utilizing Active Directory and Group Policy. In his current assignment, he is working as a consultant for Mortgage Systems International to design an SMS 2003 hierarchy for an international mortgage company. Chris Crowe works as a Database Administrator for Trimble in Christchurch, New Zealand. He has a MCP, MCP+I, MCSA, and MCSE, and he has been a Microsoft MVP since 1997, specializing in Internet Information Server (IIS). In early 2000, Chris started a web site called IISFAQ (http://www.IISFAQ.com) as a resource to help him maintain a set of answers to frequently asked questions on the microsoft.public.inetserver.iis newsgroup on msnews.microsoft.com. IISFAQ has since grown to be the premier independent IIS resource on the Internet. Chris can be reached via IISFAQ or via email at chris@iisfaq.com.
Matthew Goedtel is a columnist on myITforum.com (http://www.myitforum.com) and is President and CEO of IT Centric Inc. (http://www.itcentric.biz), an IT solutions and consulting company that offers professional services and technology solutions. Matthew founded IT Centric in 2002, with the vision of forming a leading- edge solutions firm, creating innovative solutions while ensuring cost effectiveness. Prior to IT Centric, he was Senior Systems Architect with National Life of Vermont, where he led the design and migration to Windows 2000, evaluated and redefined single vendor solution for data center server and storage solutions, assisted with the design and implementation of a SAN and enterprise backup solution, and much more. Prior to National Life, he held a Systems Engineer position at Merrill Lynch, developing change and configuration management solutions and assisting in the development and support of a global Windows NT 4.0 infrastructure. Matthew has also worked as a consultant for many leading financial and retail companies throughout his career, providing similar responsibilities. John Gormly is a columnist on myITforum.com (http://www.myitforum.com) and has worked for a leading public accounting firm for the last 15 years. He earned his bachelor's degree in Accounting and Finance from the University of Cincinnati. He began his career as an auditor and made the transition in to IT nine years ago, when he was asked to head the IT department for the firm's Cincinnati location. He is now a Regional Technology Director and is responsible for all aspects of technology, including PC support, LAN/WAN infrastructure, telecommunications, project
management, training, IT deployments, and personnel management. John has written many training courses for end users, technical articles for newsletters, and presentations specifically for the IT community. He specializes in all Microsoft operating systems and all versions of Microsoft Office. He also maintains certifications in Novell Netware (CNE3, 4, and 5) and is an A+ Certified Technician. John lives in Lebanon, OH, with his wife, Cynthia, and three young sonsJohn, Jacob, and Joshua. John can be reached at jgormlyjr@yahoo.com. Harvey Hendricks is a columnist on myITforum.com (http://www.myitforum.com) and started working with computers as a hobby that later became an occupation. He bought his first computer in 1982 and taught himself to write basic language programs. Writing programs soon went from being a hobby to an obsession, and when a career change became desirable he returned to college after an 18-year hiatus. There he became a member of a national honor society and earned a degree in Computer Science in 1993. He is employed at a great company in Houston, Texas, where his responsibilities include Microsoft Systems Management Server, Network Associates Inc. Total Virus Defense, IBM Tivoli Storage Manager, Microsoft Software Update Server, RSA SecurID, and SecurPBX. He holds the following certifications: TIAComp A+, Microsoft Certified Professional, and Microsoft Certified Systems Engineer. He is active in the martial arts, holding a second degree black belt in Tae Kwon Do and a first degree black belt in Torite-jutsu, and he is a member in good standing of Dragon Society International. He rides his Harley Davidson motorcycle every chance he gets and in his
spare time also likes riding his dirt bikes, scuba diving, camping, hunting, fishing, and snow skiing. Don Hite is a columnist on myITforum.com (http://www.myitforum.com). The eldest of four children, he was born to American parents in the Army hospital at Wurzburg Germany in November 1957. After living in Bad Kissingen, Germany, for the first few years of his life, the Hite family moved back to the United States when Don was still in khaki army diapers. Educated by trade as a commercial maintenance electrician and holding a master electrician's license, Don made the career change from terminating copper conductor cable to terminating Ethernet cable in the early 1990s. Don lives in Raymore, MO, with his wife, Ginny. He has a son, Lee, a stepdaughter, Lisa, and a grandson named Blake. David Jaffe is a columnist on myITforum.com (http://www.myitforum.com) and has been in IT for over six years. He has worked with a wide variety of applications specializing in system management. Dave is the co-owner of SMSExpert.com (http://www.smsexpert.com), the largest provider of SMS third-party tools. Janis Keim is a columnist on myITforum.com (http://www.myitforum.com) and is the PC Technical Support Supervisor for State Street, a mutual funds company in Kansas City, MO, and has over 15 years of experience in computer technology. As the SMS administrator for approximately 1,700 workstations, her responsibilities include software packaging, testing, and deployment. She is also responsible for image build
creation from start to finish, deployment of new PCs, ePO administration, security-related patch deployment for all workstations, maintenance of the company's entire fire call password process, and management of six support personnel. She is also cofounder of the Kansas City Regional SMS User Group (KCRSMSUG). Tim Kelly is a columnist on myITforum.com (http://www.myitforum.com) and is Technology Leader for TSYS (http://www.tsys.com), the world's largest credit card processing company. Tim leads the implementation of Microsoft.NET-based web services and applications. He worked for three years at Microsoft (1998-2001) during the time of the Windows 2000 rollout and assisted multiple enterprise customers with Active Directory implementations. He has worked extensively in e-commerce and the highly available web applications space during the last five years and counts as specialties IIS, MSCS, MS SQL high availability and management, Active Directory, and core network technologies. He is a graduate of the University of Idaho and received a Master's degree in Business from Auburn University. Tim enjoys his familyLynn, Russell, and Jacksonwhen he's not jumping out of perfectly good airplanes. His web site is http://www.skydiveopelika.net. Thomas Lee (http://www.psp.co.uk/tfl/tfl.htm) is Chief Technologist at QA, the UK's largest independent training firm, and has worked with Windows since it was first released. He graduated from Carnegie Mellon University and subsequently worked on two successful operating system projects (Comshare's Commander II and ICL's VME) before joining Andersen Consulting in 1981, where he was a manager in the London office. He
was an independent consultant from 1987 until he joined QA in 2003, where he now lectures, consults, and owns QA's technical portfolio. Thomas is a Microsoft Certified Systems Engineer (MCSE), Microsoft Certified Trainer (MCT), Microsoft Valued Professional (MVP) and Microsoft Regional Director (Europe). Thomas lives in a cottage in the English countryside with his wife, Susan, and daughter, Rebecca. Tim Mintner is a columnist on myITforum.com (http://www.myitforum.com) and is President and a Systems Architect Consultant for MMH Services (http://www.mmhservices.com). Tim has worked in the IT industry for over 10 years and has designed Microsoft networks for over 50 companies in the Midwest. Tim specializes in Microsoft Infrastructure technologies and has a deep background in Active Directory, SMS, SQL Server, MOM, Exchange, and ISA server. Tim is based in St. Louis, MO, where he runs the Microsoft Infrastructure Professional Users Group (http://www.mipug.org). Tim can often be found answering questions in the forums at myITforum.com. You can reach Tim by emailing him at tmintner@mmhservices.com. Chris Mosby is a columnist on myITforum.com (http://www.myitforum.com) and worked for three years at Bechtel Hanford Inc. (BHI) as a full-time SMS/Virus Protection Administrator. During his tenure at that company, Chris turned SMS into an essential management tool for BHI. His complete redesign of BHI's antivirus system and antivirus policy led to the elimination of 7,356 viruses and to zero network downtime due to virus infection from January 2000 until
he left employment at BHI in June 2003. At last report, this antivirus system is still protecting the BHI network and was able to fend off thousands of additional virus infections during the global outbreaks of Blaster, Mimail, Welchia, and Swen viruses during the period of August and September 2003. His other accomplishments include beta-testing the current version of SMS Installer for Microsoft, designing and implementing the initial SMS 2.0 system of Bechtel National's Waste Treatment Plant Project, obtaining his Symantec Product Specialist Certification in Norton AntiVirus Corporate Edition 7.5/7.6, and coauthoring Configuring Symantec AntiVirus Corporate Edition (Syngress). Chris is also the creator of SMS Admin gear (http://www.cafeshops.com/smsadmin). Chris now works as the SMS Administrator for a large regional bank and lives in Tupelo, MS, with the love of his life, his wife Debbie. He can be contacted at mozbe@yahoo.com. Marcus Oh is a team leader for the Windows Core Technologies Group at Cox Communications, Inc. (http://www.cox.com), specializing in Systems Management. He lives happily with his wife, Joanna, in Alpharetta, GA. In his spare time, Marcus writes articles for myITforum.com (http://www.myitforum.com), maintains geek status by reading a mound of technical articles and white papers, and helps his wife with her web site (http://www.webcritter.net). He can be reached at marcus@webcritter.net. Rob Olson is a columnist on myITforum.com (http://www.myitforum.com) and is the founder of DudeWorks Software (http://www.dudeworks.com), which develops add-on solutions for SMS and many other
Windows systems-management tools and solutions and provides custom systems-management programming solutions. Rob also serves as a senior software distribution engineer for a major financial company in the United States, supporting over 50,000 (and growing) SMS clients. He can be reached at rob@dudeworks.com. Marcin Policht has been contributing to a number of popular technology web sites, such as myITforum.com (http://www.myitforum.com), ServerWatch (http://www.ServerWatch.com), and Database Journal (http://databasejournal.com) for several years. While he focuses on engineering and administration of large Windows deployments (primarily in financial institutions) involving a variety of Windows-based products, such as SMS, SQL, IIS, Exchange, and Citrix, he is also interested in programming and scripting topics. This interest is best exemplified by his book WMI Essentials for Automating Windows Management (SAMS), published in 2001. He also cowrote Windows 2003 Server Bible (Wiley) and Mastering Active Directory for Windows Server 2003 (Sybex). Marcin has also been actively involved as a technical trainer in the field of certifications. One of the first recipients of Windows 2000 and Windows 2003 MCSE and MCSA, he has also worked with Microsoft on setting criteria for Windows 2000 Clustering exam. Brian Rogers is a columnist on myITforum.com (http://www.myitforum.com) and is currently a consultant with Collective Technologies Inc. (http://www.colltech.com), providing SMS 2.0 and 2003 analysis, proof of concepts, implementations, and upgrades, with focus on patch management. His previous experience includes over five years with
Systems Management Server, beginning with SMS 1.2 and continuing through to SMS 2003; over two years as an MCT, teaching SMS 1.2 and 2.0; and over three years as an SMS 2.0 Administrator. Janet Ryding is a columnist on myITforum.com (http://www.myitforum.com), based in the UK, and has more than 10 years of experience in the IT industry. Working mainly with Windows NT/2000, Citrix, and the standard BackOffice products, she provides network consultation to a variety of large multinational organizations and has worked in the past for Ford Motor Company, the Ministry of Defense, and the National Health Service. Janet holds an MCSE in NT4 and 2000, the Citrix CCA and CCSP certifications, and Cisco's CCNA. Janet is currently working on a variety of projects and is looking to move into more project management roles. She can be reached at pn1995@yahoo.co.uk. Peter Rysavy is a columnist on myITforum.com (http://www.myitforum.com) and is currently the webmaster and network administrator at a small private business college. He spends his day taking care of the academic network and labs, administering an Exchange email system and the college intranet, supporting the campus-wide wireless network, and maintaining the college web site. In his spare time, Peter is actively involved in the Tablet PC community, evangelizing the platform, contributing news stories, interacting with users, and writing about Tablet PCs on his web site, Tabula PC (http://www.kstati.com/tabula).
Hans Schefske is a columnist on myITforum.com (http://www.myitforum.com) and has over eight years experience engineering and designing the architecture and implementation of Microsoft client/server-based network solutions. Consulting and leading projects in the IT industry, he has provided technical expertise in the areas of designing and implementing infrastructures for large enterprise-level companies such as Nabisco, Prudential, AIG, Simpson, Thatcher and Bartlett, Novartis, and Hoffman LaRoche Pharmaceuticals. In 2003, Hans was awarded a Microsoft Most Valuable Professional (MVP) Award for SMS for his outstanding technical skills and willingness to share knowledge with his peers. As a technical author at myITforum.com, he provides technical information, tools, scripts, and utilities for IT professionals and administrators to better assist them in managing their Microsoft-based solutions. Hans is currently a Senior Active Directory and SMS consultant at a large telecommunications company based in Atlanta, GA. Pat Sklodowski is a contributor to myITforum.com.com (http://www.myitforum.com) and a Microsoft Certified Systems Engineer with over eight years of industry experience. His specialties include Windows NT/2000, Active Directory, SMS, Exchange, and scripting. Pat is currently working as a Senior Engineer with a global provider of engineering solutions and specialized staffing. He is responsible for developing new initiatives, architectural solutions, technical project-management, and ongoing support. Pat can be reached at psklodow@yahoo.com.
Donnie Taylor is a columnist for several web sites, including myITforum.com (http://www.myitforum.com), and is currently the Systems Management Administrator for Central Technology Services. His duties include the installation, maintenance, and administration of SMS, MOM, SQL, and various management applications. He has been with Central Technology Services for four years. Donnie lives with his wife and two daughters in Jefferson City, MO. He met his wife while attending Southwest Missouri State University, where he pursued degrees in CIS/MIS, English, and Anthropology. Donnie enjoys PC and console gaming, exploring his Cherokee heritage, and spending time with his family. Dan Thomson is a columnist on myITforum.com (http://www.myitforum.com) and an influential member of the IT staff at a local college, where he assists with many aspects of supporting the computing systems. Some of Dan's responsibilities include maintaining antivirus software, OS imaging, group policies, software deployments, and SMS. Dan is always happy to share whenever he can and can be found participating in many online forums and newsgroups. Dan enjoys spending time with his wife and 10-month-old daughter. Richard Threlkeld is a columnist on myITforum.com (http://www.myitforum.com) and was employed as a contractor for Motorola, where he eventually worked his way up to manage the SMS infrastructure for all of Motorola's Boynton Beach facilities, including packaging, software deployments, site maintenance, client support, and reporting. Along with his local SMS responsibilities, Richard also helped develop packages
for Motorola's Global Packaging Team which distributed software and security updates to workstations and servers worldwide. In late 2002, Richard moved to San Diego, CA, to work for QUALCOMM Inc. (http://www.qualcomm.com). Richard currently heads the SMS Infrastructure for the QUALCOMM CDMA Technologies division, which spans locations worldwide, and deals with other Active Directory and engineering issues. Outside of work, Richard takes part in different SMS forums and user communities, where he is regularly found assisting other administrators with issues in their environments. Richard is also a Microsoft MVP for SMS because of his community involvement. Rod Trent, manager of myITforum.com (http://www.myitforum.com), is the leading expert on Microsoft Systems Management Server. He has over 18 years of IT experience, 8 of which have been dedicated to SMS. He is the author of such books as Microsoft SMS Installer, Admin911:SMS, and IIS 5.0: A Beginner's Guide and has written thousands of articles on technology topics. myITforum.com is the central location for third- party SMS support, as well as the online gathering place for IT professionals and the IT community. Rod speaks at least three times a year at various conferences and is a principal in NetImpress, Inc. (http://www.netimpress.com). Chuck Young is a columnist on myITforum.com (http://www.myitforum.com) and began his IT career during his time in the Air National Guard, when he converted an old Banyan Vines network to an NT environment. After pursuing a degree in Computer Science and holding several jobs in the computer
industry, Chuck now finds himself working almost exclusively with Microsoft Systems Management Server (SMS). Often mistaken for SMSMAN, Chuck is just a dedicated perfectionist that will not settle for less than 80%; his philosophy is "Why give 100% at anything? It doesn't leave anything for the fun stuff!" Chuck can be reached at chuck.young@acs-inc.com. Oren Zippori is a columnist on myITforum.com (http://www.myitforum.com) and is currently working for Team Computers, a gold-certified Support Center for Microsoft. Oren specializes in system-management products and has also been involved in Windows 2000 and Exchange 2000 migrations. Oren also manages an open forum for Microsoft in Israel that supports SMS and MOM products. Oren spends his free time scuba diving, mountain climbing, and playing snooker. He knows how to enjoy a good fiction book and likes to write short stories for fun. You can reach him at orenzp@hotmail.com
Acknowledgments Talk about a book being a cooperative venture; this one was definitely so, for without the time, expertise, and content contributed by so many other IT professionalsmany of them columnists on myITforum.com (http://www.myitforum.com)this book wouldn't be the valuable resource to Windows system administrators that it is. So, a big thanks to everyone who contributed hacks to this book. You deserve it first, so thanks! And thanks especially to Rod Trent, CEO of myITforum.com, for his friendship and supportthanks, man! Second comes my thanks to Rael Dornfest, my editor at O'Reilly, who has been great fun to work with and whose gentle prodding has helped keep me focused on the task at handmaking this book as good as possible. Thanks, Rael! Third in line for thanks is my agent, Neil Salkind of Studio B (http://www.studiob.com), for his friendship and support in writing this, my 14th book. Thanks, Neil! Fourth, thanks to MTS Communications Inc. (http://www.mts.ca) for providing Internet services and web hosting for my web site (http://www.mtit.com), with special thanks to Dinis Prazeres there at MTS. Thanks! Last but not least, thanks to my wife and business partner, Ingrid, coauthor of the Microsoft Encyclopedia of Networking, 2nd Edition and consultant for our company MTIT Enterprises. (http://www.mtit.com). Thanks, Schatz!
Foreword: I'm a Sci-Fi freak Just because I work in the computer technology field, you might automatically assume that I'm also an avid science fiction reader. And, while there are many IT professionals who have never spoken a single word of Klingon or adeptly wielded a light saber made of paper towel rolls, if you point your finger at me, you can rest assured that your accusation is spot on. To be fair, my love of Science Fiction began years before I had my hands on a computer keyboard. I was practicing the Vulcan hand greeting long before I was potty trained, and I was mind-melding with my favorite pet before I knew how to feed myself. You can imagine my parents' joy. When Mitch Tulloch approached me about helping out with Windows Server Hacks, there was no hesitation in my response. Even though I've known Mitch for years and his work is always top-notch, Mitch has an unfair advantage when it comes to making Windows Server Hacks successfulhe actually carried the nickname of "The Vulcan" during his university days. So, using a kind of mind-meld, Mitch pieced together a culmination of the most powerful solutions on Earth to load Windows Server Hacks with tricks, tips, scripts, tools, and workarounds to help systems administrators manage their Windows-based networks. We've all bought books and ended up skipping pages or chapters because the information provided simply does not apply to our specific situation. But because the information in Windows Server Hacks comes from real world experience based on tried-and-true solutions, you'll probably use more of this book than any other in your tech library. In addition to working with Mitch, I was also excited that Windows Server Hacks would include many solutions from the myITforum.com community. Among the myITforum.com
membership, you'll find some of the smartest individuals in the industry who are willing to share their solutions to help make the IT world a better place. This fact becomes clearly evident as you read and implement the solutions in this book. And, when you're ready to find more solutions like those represented in Windows Server Hacks, you can stop by myITforum.com and experience the community. As many of you know, Vulcans show no emotion. So, I guess I may have ultimately tipped my hat when I was doubly excited that Windows Server Hacks was an O'Reilly project. O'Reilly is one of the top publishers in the world, spreading high-quality information to IT workers everywhere. For that, I am honored for the opportunity to introduce this book. I know you'll find it as useful as I do. To all those that contributed to this book, I salute you. Of course, that salute comes in the form of a perfectly crafted Vulcan hand greetingMitch would know. Rod Trent Live long and prosper, Rod. Mitch :-)
Preface For some time now, Microsoft Windows (in all its incarnations) has been the dominant desktop operating system for businesses small and large. But in recent years, the platform has also made significant inroads into the server side of the equation. In the late 1990s, for example, the now-legacy Windows NT 4.0 Server platform became popular for running web servers using IIS and largely displaced Novell NetWare in the file/print server arena. Other server applications that ran on top of NT, such as Microsoft Exchange and Microsoft SQL Server, also made Windows a top platform for messaging/collaboration and database servers. Windows 2000 Server built upon the success of NT by adding increased stability, reliability, and a new feature called Active Directory that quickly overtook Novell Directory Services (NDS) as the dominant enterprise-level directory service product. And Windows Server 2003, the latest incarnation of server-side Windows, is likely to further cement Microsoft's dominant position in the enterprise, despite the serious challenges arising from Linux and other open source software. Why has Microsoft made such rapid gains in the server market? The answer is found in the simplicity of administering the platforms. An easy-to-use GUI, a consistent set of tools, wizards that walk you through performing complex taskssuch features make it possible to learn how to install, configure, and maintain Windows servers in weeks, without any knowledge of a programming or scripting language or learning a lot of complicated command-line syntax. In fact, you can probably accomplish about 90% of all Windows administration without ever opening a command prompt or running a script.
But it's that other 10% that can really matter sometimes, and that's what this book is mainly about.
Why Windows Server Hacks? While most common, day-to-day tasks of Windows administration can be performed from the GUI, it's not always the best way, especially with complex or repetitive tasks. Scripts and command-line tools often provide a faster and more flexible approach, and Windows has grown more powerful in this area with the progressive addition of VBScript, Active Directory Services Interface (ADSI), Windows Management Instrumentation (WMI), and dozens of new commands to each new version of the platform. Unfortunately, learning to leverage the power of these different features takes timea precious commodity for today's busy system administrator. That's why a large portion of this book consists of scripts and other tools that can make your life much easier as an administrator. These tools, or hacksquick and dirty solutions to problems or clever ways of doing thingswere created by other professionals who have had to struggle to find solutions to administering their own Windows environments, and you can benefit from their expertise in two important ways. First, you can use their scripts, tools, tips, and advice to save valuable time as you manage your own Windows-based network. Second, by studying the scripts and learning a little VB/ADSI/WMI, you can easily customize these scripts to create even more powerful tools that meet your own specific needs.
Getting and Using the Scripts To save you the time and effort of typing long scripts by hand, all the scripts (except those that are only a few lines long) are available for download from the O'Reilly web site at http://www.oreilly.com/catalog/winsvrhks/. Before you use them in your own networking environment, however, make sure you have the latest scripting engines on the workstation from which you run the scripts. You can download the latest scripting engines from the Microsoft Scripting home page (http://msdn.microsoft.com/scripting/). Also note that, when working with the Active Directory Services Interface (ADSI), you must have the same applicable rights you need to use the built-in administrative tools. See Microsoft's ADSI web page (http://www.microsoft.com/windows2000/techinfo/howitworks/activedirectory/adsilinks.asp for more information. Furthermore, for VB scripts that interact with WMI, apply the most current version of the WMI agents, which are downloadable from the MSDN WMI SDK (http://msdn.microsoft.com/library/default.asp?url=/library/en- us/wmisdk/wmi/wmi_start_page.asp). This information is important enough that we mention it again several times at the beginning of the first few chapters. Finally, please note that while every all of the scripts, tools, procedures, and resources described and contained in this book have been tested, both the author and those experts who contributed them make no guarantee or warranty that they will work as intended in your own networking environment, nor do we assume any liability or responsibility for any loss or damage
arising from their use. In other words, the information provided in this book is presented on an as is basis, and we strongly recommend that you try out a hack in a test environment first before using it in your company's production environment.
How to Use This Book Although this book is divided into chapters, as described in the following section, you can use it in a variety of different ways. One approach is to think of the book as a toolbox and start by becoming familiar with the tools in each chapter. Then, when a need arises or a problem occurs, you can simply use the right tool for the job. Or, you might decide to browse or read the book from cover to cover, studying the procedures and scripts to learn more about power administration of Windows systems. Some of the hacks are helpful in this area, because they contain tutorials about complex subjects or well-documented scripts. You might also pick one chapter and see what you find useful to your current situation or might find helpful in the future.
How This Book Is Organized Whichever way you choose to use this book, you will probably first want to familiarize yourself with the contents, so here's a brief synopsis of each chapter and what you'll find: Chapter 1, General Administration Think of this chapter as the removable top drawer of your toolboxusually cluttered, but containing your favorite, indispensable tools. The topics in this chapter include ways of hacking the Run As command, collecting event log information, running commands, extending your environment, shutting down processes, renaming mapped drives, and more. You'll also learn how to disable file encryption if you don't need or want it, collect configuration settings from remote machines, use automatic logon where it's safe to do so, and make it easier for users to access Remote Assistance when they need to. We'll also list some of our favorite third- party tools and a terrific online resource for Microsoft management technologies. Chapter 2, Active Directory Most of the time, when you're administering Active Directory, you'll find the GUI tools are easy to use but ill suited for complex or repetitive tasks. That's where scripts come in, and this chapter includes scripts that leverage ADSI and WMI to make your life easier. These
scripts can be used to perform tasks such as searching for old computer accounts, creating organizational units (OUs), delegating authority over OUs, and displaying information about objects stored in Active Directory. Chapter 3, User Management A large part of day-to-day administration of an Active Directory environment is managing users and their accounts. The usual way of doing this is by using the GUI, but when it comes to organizations with hundreds or even thousands of users, this approach can be frustrating. This chapter is mostly about alternativesways of doing things faster using scripts. You'll find scripts for displaying information about users, finding specific users on your network, changing user passwords, unlocking user accounts, getting a list of disabled accounts, displaying which groups a user belongs to, and more. If you're familiar with VBScript, you can also customize these scripts further to meet the specific needs of your own networking environment. Chapter 4, Networking Services Under the hood of Windows are the core networking services and components that enable systems to communicate across a network. These components include services such as Dynamic Host Configuration Protocol (DHCP), Domain Name System (DNS), Windows Internet Name Service (WINS), and other services that run on top of TCP/IP. Configuring these services can be complex, and it can be hard to pinpoint the problem when things go wrong. This chapter is about
managing such services and other networking components. You'll learn how to use a script to manage services on remote computers, how to ensure DHCP server availability so your clients can communicate, how DNS aging and scavenging work and can be configured, how to troubleshoot common DNS problems when Active Directory is deployed, how to perform complicated network configuration tasks using scripts and from the command line, and several other important tasks. Chapter 5, File and Print File and print is the traditional bread and butter of networking, and while it's gradually being overtaken by more advanced document-management solutions, not many companies are planning on retiring their file servers anytime soon. Managing shared folders and printers also makes up a major component of an administrator's daily routine, and a high proportion of calls to help desk as well. So it's worth examining some new ways of doing old tasks, such as mapping drives or configuring default printers, as well as some ways to perform tasks that are not easy using standard Windows tools, including mapping the structure of a directory or determining who has a certain file open on the network. That's what this chapter is aboutdoing old tasks in new ways and making complex tasks simple. Chapter 6, IIS Internet Information Services (IIS) is one of the more popular features of Windows server platforms. Whether you're running IIS 5 (Windows 2000 Server) or IIS 6
(Windows Server 2003), the ability to hack the metabase (the place where IIS stores its configuration settings) lets you do things that are impossible to do using the standard GUI tool for managing IISnamely, Internet Services Manager. Before you start hacking the metabase, however, you better be sure you've backed it up properly and know your way around inside it. Several hacks in this chapter deal with these topics, including how to restore the metabase when you have no working backup. Also included are tips on hiding the metabase from attackers to make it more secure, managing different aspects of IIS by using scripts, and allowing other HTTP services, such as the Apache web server, to run on Windows and coexist with IIS. Chapter 7, Deployment Administering Windows-based networks begins with deployment, and the focus of this chapter is on how to manage the installation (and uninstallation) of Windows 2000/XP/2003 and its individual components. In particular, the first several articles deal with Remote Installation Services (RIS) and Sysprep, two powerful but complex tools for installing Windows images on large numbers of machines. Other articles deal with removing unneeded components manually from the command line and during unattended setup, and creating a network boot disk for unattended installation of Windows. These tips and tools are designed to make the job of deploying Windows easier, so you can get on with the day-to-day job of configuring, maintaining, and troubleshooting systems on your network.
Chapter 8, Security Probably no aspect of the system administrator's job is more important these days than security, and this is especially so with systems running Windows. The ever- increasing threats of viruses, worms, Trojans, and other exploits means administrators have to spend time and energy learning how to protect their company's networks against the wiles of malicious hackers on the Internet. This chapter looks at some of the ways you can protect your network from these threats. It includes coverage of best practices in virus protection, protecting Administrator accounts, securing backups, protecting domain controllers, and finding machines with automatic logon enabled. A security FAQ and a review of security tools you can download from Microsoft's web site round out this chapter and help you build an arsenal of best practices and tools that can help keep your network secure. Chapter 9, Patch Management Patch management is a way of life for system administrators nowadays. With the proliferation of Internet worms and other threats, new patches are being released for Windows platforms on an almost weekly basis. It takes time and energy to test these patches and deploy them on production systems, and occasionally something goes wrong and a patch designed to correct one problem actually creates another. The first key to effective patch management is proper business practices: test, deploy, and verify. The second key is proper tools; Windows platforms come with several built-in tools, while others can be obtained
from Microsoft's web site and third-party vendors. The third key is knowledgeknowing how patch-management tools work and how to troubleshoot them when things go wrong. The hacks in this chapter touch on all three keys to effective patch management and help enlarge your understanding and skills in this crucial area of a system administrator's job description. Chapter 10, Backup and Recovery Finally, this chapter looks at the backup process and examines how to back up specific entities, such as your System State, certificate authority (CA) information, Encrypting File System (EFS) keys, and Distributed File System (DFS) namespace. We also look at how to back up something as simple as an individual file from the command line, to something as complicated as an entire system using the new Automated System Recover (ASR) feature of Windows Server 2003. Also included is a script that can be used to collect disaster recovery files and event logs from remote Windows 2000 servers. We also map out procedures you can try to recover a failed system, short of restoring everything from backup, navigating through a maze of options like Safe Mode, Emergency Repair, Last Known Good Configuration, and the Recovery Console. Finally, we mention a few services you can call on when your worst nightmare happens and you need to recover your business data from a failed disk that has no backup.
Conventions Used in This Book The following typographical conventions are used in this book: Italic Indicates new terms, URLs, email addresses, filenames, file extensions, pathnames, directories, and Unix utilities. Constant width Indicates commands, options, switches, variables, attributes, keys, functions, types, classes, namespaces, methods, modules, properties, parameters, values, objects, events, event handlers, XML tags, HTML tags, macros, the contents of files, or the output from commands. Constant width bold Used in examples and tables to show commands or other text that should be typed literally by the user. Constant width italic Used in examples, tables, and commands to show text
that should be replaced with user-supplied values. Color The second color is used to indicate a cross-reference within the text. This icon signifies a tip, suggestion, or general note. This icon indicates a warning or caution. The thermometer icons, found next to each hack, indicate the relative complexity of the hack:
beginner moderate expert
Using Code Examples This book is here to help you get your job done. In general, you may use the code in this book in your programs and documentation. You do not need to contact us for permission unless you're reproducing a significant portion of the code. For example, writing a program that uses several chunks of code from this book does not require permission. Selling or distributing a CD-ROM of examples from O'Reilly books does require permission. Answering a question by citing this book and quoting example code does not require permission. Incorporating a significant amount of example code from this book into your product's documentation does require permission. O'Reilly & Associates and the author both appreciate, but do not require, attribution. An attribution usually includes the title, author, publisher, and ISBN. For example: "Windows Server Hacks, by Mitch Tulloch. Copyright 2004 O'Reilly & Associates, Inc., ISBN 0-596-00647-0." If you feel your use of code examples falls outside fair use or the permission given above, feel free to contact us at permissions@oreilly.com.
How to Contact Us We have tested and verified the information in this book to the best of our ability, but you may find that features have changed (or even that we have made mistakes!). As a reader of this book, you can help us to improve future editions by sending us your feedback. Please let us know about any errors, inaccuracies, bugs, misleading or confusing statements, and typos that you find anywhere in this book. Please also let us know what we can do to make this book more useful to you. We take your comments seriously and will try to incorporate reasonable suggestions into future editions. You can write to us at: O'Reilly & Associates, Inc. 1005 Gravenstein Hwy N. Sebastopol, CA 95472 (800) 998-9938 (in the U.S. or Canada) (707) 829-0515 (international/local) (707) 829-0104 (fax) To ask technical questions or to comment on the book, send email to: bookquestions@oreilly.com For more information about this book and others, see the O'Reilly web site: http://www.oreilly.com For details about Windows Server Hacks, including examples, errata, reviews, and plans for future editions, go to:
http://www.oreilly.com/catalog/winsvrhks/ For code examples, additions and corrections, and other related miscellany: http://www.oreilly.com/catalog/winsvrhks/
Got a Hack? To explore Hacks books online or to contribute a hack for future titles, visit: http://hacks.oreilly.com
Chapter 1. General Administration Hacks #1-16 Section 1. Use Run As to Perform Administrative Tasks Section 2. Drag and Drop to the Run Menu Section 3. Find and Replace Registry Keys from a Command Line Section 4. Automatically Log On After Booting Section 5. Wait for and Optionally Terminate a Process Section 6. Shut Down a Remote Computer Section 7. Rename Mapped Drives Section 8. Execute a Command on Each Computer in a Domain Section 9. Add, Remove, or Retrieve Environment Variables Section 10. Extend Group Policy Section 11. Disable EFS Section 12. Get Event Log Information Section 13. Shortcut to Remote Assistance Section 14. Desktop Checker
Section 15. Top Five Tools Section 16. myITforum.com
Hacks #1-16 We'll begin with a catchall chapter of tips and tools that cover a wide range of general Windows system administration topics. Think of this chapter as the removable top drawer of your toolboxusually cluttered, but containing your favorite, indispensable tools. The topics in this chapter include ways of hacking the Run As command, collecting event log information, running commands, extending your environment, shutting down processes, renaming mapped drives, and more. You'll also learn how to disable file encryption if you don't need or want it, collect configuration settings from remote machines, use automatic logon where it's safe to do so, and make it easier for users to access Remote Assistance when they need it. We'll also list some of our favorite third-party tools and a terrific online resource for Microsoft management technologies. A number of the hacks in this chapter include scripts. To ensure these scripts run properly on your systems, make sure you download the latest scripting engines on the workstation from which you run the scripts. You can get these scripting engines from the Microsoft Scripting home page at http://msdn.microsoft.com/scripting/. Also, when working with the Active Directory Services Interface (ADSI), you must have the same applicable rights you need to use the built-in administrative tools, which basically means that you need administrator credentials to run the scripts.
Hack 1 Use Run As to Perform Administrative Tasks Use Run As to protect your administrator workstation from Trojans and other nasties. If you're lazy, like I am, you probably use the default administrator account on your desktop workstation for browsing the Web, checking your email, and managing the servers on your company's network. Not a good idea. What if you unknowingly visited a web page that executed a script that downloaded a Trojan to your machine? Your administrator account would be compromised, and the attacker would have total access to your workstation and possibly to your whole network! To avoid such dangers, administrators should always have two user accounts: a regular (user-level) account for ordinary activities, such as web browsing and messaging, and an administrator-level account, used only for performing administrative tasks. This way, when you are reading your email and suddenly remember you have to reschedule a backup, you can simply log off, log back on using your administrator account, perform the task, log off again, and log on again as a regular user. Who am I kidding? That's too much to expect of a lazy system administrator.
How Run As Works The Run As service (called Secondary Logon service in Windows Server 2003 and Windows XP) is a hack designed to enable you to run programs by using alternate credentials while you're logged on using another account. For example, if you are an administrator and are logged on to your desktop using your regular user account, you won't be able to run administrative tools such as Computer Management, because they require administrator credentials to run properly. (Actually, you can open Computer Management as an ordinary user; you just can't do much with it.) Using Run As, however, you can run Computer Management as an administrator while remaining logged on as an ordinary user. There are two ways to use Run As: using the GUI or from the command line. To use the GUI method, first find the program you want to run in Windows Explorer or My Computer. Then, for executables (.exe files), hold down the Shift key, right-click the program's icon, and select Run to open the Run As Other User dialog box shown in Figure 1-1. For MMC consoles (.msc files) and Control Panel utilities (*.cpl files), you do the same thing but don't need to hold down the Shift key. Figure 1-1. Using Run As to run a program using administrator credentials
Once you specify the appropriate alternate credentials and click OK, the program you selected runs in the security context of those alternate credentials until you close or terminate the program. If you prefer, the alternative credentials can also be entered as domain\user or user@domain, which in Figure 1-1 would be MTIT\Administrator or Administrator@mtit.com for an example domain named mtit.com (replace these credentials with the name of your own domain). The advantage of doing it the way shown in Figure 1-1 is that, if your computer is a member server, you can specify a local user account by entering the name of the computer in the Domain field. Using Run As from the command line is just as easy, but you need to know the path to the program (unless the program file is located within the system path). For example, the Computer
Management console file compmgmt.msc is located in the \system32 directory. To run it as Administrator in the MTIT domain, simply type the following at a command prompt: runas /user:MTIT\Administrator "mmc %windir\system32\compmgnt.msc" You'll be prompted for a password for the account, after which Computer Management will open. Note that you can also type this command directly into the Run box (accessed by Start Run). Limitations of Run As While Run As is useful, it has some limitations. First, the alternate credentials you specify must have the Log On Locally user right on the computer. Since Run As is usually used with administrator credentials (which have that right by default), this is usually an issue only in certain circumstances. For example, say you grant a few knowledgeable users a second user account that belongs to the Power Users group, to allow them to update device drivers and perform other minor maintenance on their desktop computers. If you try to reduce the attack surface of your network by removing the right to Log On Locally from the Power Users group using Group Policy, then these users won't be able to perform such tasks. Also, there are certain tasks you can't perform directly using Run As, such as opening the Printers folder to administer a printer that is connected to your machine. The reason for this is that the special folders such as Printers and Network and Dial- up Connections are opened indirectly by the operating system, not by a command. You also can't use Run As to open Windows Explorer and access the filesystem on your computer as
administrator, because the Windows shell explorer.exe is already running as your current desktop environment and Windows allows only one GUI shell to run at a time. Finally, Run As also might not work if the program you are trying to run is located on a network share, because the credentials used to access the share might be different than the credentials used to run the program. Most limitations have workarounds of some sort, if you try hard enough to find them. So, let's see if we can figure out ways to get around these limitations (except for the Log On Locally limitation, which is absolute). Running programs without an executable Say you want to change some settings for the Local Area Connection in the Network and Dial-up Connections folder. If you try doing this as an ordinary user, you'll get a message saying "The controls on this properties sheet are disabled because you do not have sufficient privileges to access them." Here's how to access these settings as an administrator without logging out of your regular account. Right-click on the task bar and open Task Manager. Then, switch to the Processes tab, select explorer.exe, and click End Process to kill the desktop but leave Task Manager running. Now, switch to the Applications tab, click New Task, type runas /user:MTIT\Administrator explorer.exe to run the Windows Explorer shell in an administrator context, and click OK. Finally, move Task Manager out of the way and type your password into the command-prompt window.
A new desktop will now appear, running in the security context of your administrator account. You can now change the settings of your Local Area Connection, modify the properties of a printer in the Printers folder, browse the filesystem, or do anything you want to do as administrator. But be sure to leave Task Manager running, because it is your only connection to your original desktop! You can minimize it so it won't be in the way. Once you're finished performing your administrative tasks, you can return to your original desktop (the one running under the security context of your regular account) as follows. Maximize Task Manager so that you'll have access to it when your desktop disappears again. Then, to log off of your administrator session, click Start Shut Down and select Log Off. Do not try to log off by pressing Ctrl-Alt- Del and clicking Log Off, because this will log off the session for your regular user account. Your administrator desktop has now disappeared, but Task Manager is still running (in the security context of your regular account), so switch to the Applications tab, click New Task, type runas /user:MTIT\Administrator explorer.exe, and click OK. Your desktop has returned. At this point, you might ask, "Why should I go to all that trouble? It would be faster just to log off as a regular user and log on as an administrator." True, but any applications you have
running as a regular user would then have to be terminated. Doing it the way shown here, however, leaves all your desktop applications running in the background. Running programs from network shares Here's how to get around the limitation of running programs from network shares with appropriate credentials. To run a program named test.exe found in the TOOLS share on server SRV230, use Start Run to open a command-prompt window as administrator, type runas /user:MTIT\Administrator cmd to open a command shell in administrator context, and then map a drive to the shared folder by typing net use Z:\SRV230\TOOLS. Now, switch to the Z: drive and run the program as desired. This lets you connect to the shared folder using domain administrator credentials and run the program under the same credentials. This approach is also useful for installing applications from a network distribution point. Run As Shortcuts To make your life easier, instead of having to type stuff at the command line, you can use Run As to create a shortcut that will run a program under alternate credentials. For example, to run the Computer Management console from a Run As shortcut, right-click on your desktop, select New Shortcut, and type %windir%\system32\compmgmt.msc as the command string. Name
your shortcut Computer Management and click OK. Then, right-
click on the shortcut, select Properties to open its properties
sheet, and on the Shortcut tab select the checkbox labeled "Run
program as other user" (on Windows Server 2003, click the
Advanced button on the Shortcut tab to configure this). Now,
whenever you double-click on the shortcut to run Computer
Management, the Run As Other User dialog box (see Figure 1-1)
will appear. Just type in your administrator password to run
Computer Management in administrator context.
There's another way to create Run As shortcuts that you might
find even easier to use. Just right-click on your desktop, select
New Shortcut, and type the following command string:
%windir%\system32\runas.exe /user:MTIT\Administrator "mmc %windir%\system32\compmgmt.msc"
Save the shortcut with the name Computer Management. Now,
when you double-click the shortcut, a command-prompt window
opens, prompting you for the password for the
MTIT\Administrator account. Type the password, press Enter, and
Computer Management starts in administrator context.
What if you get tired of typing your administrator password each
time you want to run a Run As shortcut? On Windows Server
2003, there's a way to get around that. Just create a new
shortcut with this command string:
%windir%\system32\runas.exe /user:MTIT\Administrator /savecred "mmc %windir%
system32\compmgmt.msc"
Notice the /savecred switch in this string. This option first
appeared in Windows XP. The first time you double-click on the
shortcut, a command-prompt window opens to prompt you for the
password for the alternate credentials, just like before. The next
time you double-click on the shortcut, however, you are not
prompted for the password; it was stored on your machine the first time you ran the shortcut. Now you no longer have to type a password each time you use your Run As shortcut. Time-saver, right? Yes, but it's also a possible security hole: once the credentials for your administrator account are stored locally on the machine, they can be used to run any command-line program using administrator credentials. Here's a scenario to illustrate what I mean. Let's say you need to run an administrative tool on a user's desktop machine without logging the user off the machine. You ask the user to take a coffee break. Then, you open a command-prompt window and use runas with /savecred to start the tool (you use /savecred because you might have to run several administrative tools and you don't want to have to type your complex 24-character password repeatedly). When you're finished, you close all the tools you started and walk away. When the user returns to her desktop, she opens a command prompt and types runas /user:MTIT\Administrator /savecred cmd. A command-prompt window opens, displaying administrator credentials in the title bar. The user now knows that she can use this approach to run any program on her machine using administrator credentials. What did you do wrong as administrator in this scenario? Two things: you used /savecred on a user's desktop machine, which saved your administrator password locally on the machine, and you haven't renamed the default administrator account. If you had changed the name of this account to something complex and unknown to ordinary users, the runas /user:MTIT\Administrator /savecred cmd command the user typed wouldn't work. What do you do if you have used /savecred on an unsecured machine without thinking about the consequences? Just delete your stored credentials on the machine by opening Stored User Names and Passwords in the Control Panel.
Hack 2 Drag and Drop to the Run Menu If you're tired of having to drop out to a command prompt and navigate through folders to run an executable that requires switches, try this. The following easy-to-use steps can be used to run the program of your choice from the Run menu with any command-line switches you need to include. This is much handier than opening a command prompt and changing to the directory where the executable is located, especially if long filenames are involved, which requires you to enclose your path in double quotes. First, navigate in Windows Explorer to the executable you want to launch (Figure 1-2). Figure 1-2. Selecting the executable to run in Explorer
Next, use Start Run to invoke the Run menu (Figure 1-3). Figure 1-3. Opening the Run menu Then, drag and drop your executable to the Run menu (Figure 1- 4). Make sure the Open box is empty before you perform this step, or unexpected results might occur.
Figure 1-4. Dragging and dropping the executable into the Run menu Now, simply add your switches and click OK to launch your application (Figure 1-5). Figure 1-5. Adding switches as needed
You'll want to keep in mind that any filenames or paths that don't follow the old 8.3 naming convention should be within quotation marks to run properly (Figure 1-6). Figure 1-6. Using quotation marks for long filenames/paths Note that your switches and arguments can reside outside of the quotation marks. Sean Ademy
Hack 3 Find and Replace Registry Keys from a Command Line Using the Regfind utility, you can easily search the Registry for a value, regardless of the key, and replace it. Regfind (from the Windows 2000 Server Resource Kit) can be an invaluable tool when you need change a Registry key that you know the value for but when do not necessarily know the full path. Recently tasked with changing the hardcoded DNS server IP on all the servers in our organization, I was pleasantly surprised when I located this gem. The problem with trying to change the DNS server entry in the Registry is that all the IP parameters are broken up by a hashed ID. The ID references several things, but most of them have to do with the network card. Regfind allows you to search a set of subkeys in the Registry for a specific value and, when found, replace it. Another real beauty of this program is that it will work remotely; all you need to do is supply it with a list of machines and let it go. Using a list of computer names (generated from SMS, Server Manager, or AD Users and Computers), combined with two batch files, you can make sweeping changes in a dynamic environment. The Code Here's an example of how to change the DNS server entry on all
servers in your organization. First, create a batch file called Regchange2.bat with the following syntax: regfind -m \%1 -p HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\parameters " You will obviously want to replace OLDIP with the old DNS server IP and replace NEWIP with the new DNS server IP. Now, create a second batch file called regchange1.bat with the following syntax: for /F %%A in (servers.txt) do (call regchange2.bat %%A) This searches the servers.txt file for computer names and passes them to the regchange2.bat file as a command-line argument. Now you need to create a list file for your batch files to use. Create a listing of servers that need to have their DNS IP's changed and save that list as servers.txt. An SMS report or a copy/paste from the server manager will suffice, or you can create the file manually if you like. Running the Hack Now, simply run the regchange1.bat batch file by calling it from a logon script and watch all your servers have their IP settings changed! This is just one simple example of how to use Regfind. There are many command-line arguments, so please examine those to meet your needs. Donnie Taylor
Hack 4 Automatically Log On After Booting It's sometimes convenient to configure machines to log on automatically when booted. Here are three ways to do this. In all versions of Windows that are based on Windows NT (including Windows 2000, Windows XP, and Windows Server 2003), a user is required to log on before he can use the system interactively. This is usually done by pressing Ctrl-Alt-Del and typing the user's credentials. Automatic logon is an option you can set to enable Windows to log on automatically using credentials that are stored in the Registry. To invoke automatic logon, you set Registry entries that define the user ID, the password, and the domain to be used to log on. Why use this feature? There are a number of reasons. As an IT professional, I have several of my home systems set up to do this, and it makes life simpler. Test systems in a lab might be another place to use this feature. I also use it all the time on virtual machine images I have running on my laptop. Automatic login makes things simpler, but it creates a security hole. First, the credentials are stored in clear text in the Registry. Thus, anyone with remote Registry privileges can see the clear text user ID and password. Also, if you have automatic logon set on a laptop, anyone who turns on the laptop is automatically logged in as you. So use this feature carefully!
Manual Configuration You can configure automatic logon manually by adding the following four key Registry entries: AutoAdminLogon, DefaultDomainName, DefaultUserName, and DefaultPassword. These entries inform Windows whether to attempt automatic logon and provide the credentials (username, password, and domain). Start Registry Editor (Start Run regedit) and find the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, which is where the Registry values you set to control automatic logon are located. Two of these values, DefaultDomainName and DefaultUserName, already exist. DefaultDomainName is a string that holds the domain (or workstation) name where the user ID exists, and DefaultUserName is the user ID that Winlogon will attempt to use to log on. This username is authenticated against the domain (or workstation) name set in the DefaultDomainName setting. Now, create two new values by right-clicking on Winlogon and selecting New String Value, which will create new values of type REG_SZ. Name the first value AutoAdminLogon, and specify a value data of 1 to instruct Winlogon to attempt to use automatic logon. Name the second value DefaultPassword; this value specifies the password for the user set in the DefaultUserName setting. The result will looking like Figure 1-7. Figure 1-7. Enabling automatic logon by editing the Registry
Script Method An easier way to configure automatic logon on your machines is to use two VBScript scripts, one to enable automatic logon and the other to disable it. Here's the script for enabling it: ' Script to turn on automatic logon
' (c) Thomas Lee 2002 ' Freely distributed! Dim Prompt, oWSH,UserName, UserPass, UserDomain set oWSH = WScript.CreateObject("WScript.Shell") ' get user name Prompt = "Enter the autologon user name" UserName = InputBox(Prompt, Title, "") ' get password Prompt = "Enter the autologon user password for " & UserName UserPass = InputBox(Prompt, Title, "") ' get domain Prompt = "Enter the autologon user domain for " & UserName Userdomain = InputBox(Prompt, Title, "") ' now set these in the Registry
oWSH.RegWrite "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoAdminLogon",
"1","REG_SZ"
oWSH.RegWrite "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
DefaultDomainName", UserDomain, "REG_SZ"
oWSH.RegWrite "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
DefaultUserName", UserName, "REG_SZ"
oWSH.RegWrite "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
DefaultPassword", UserPass, "REG_SZ"
' ensure the change is persistent!
oWSH.RegWrite "HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\ForceAutoLogon",
"1", "REG_SZ"
' All done
And here's the script for disabling automatic logon:
' Script to remove autoadmin logon
' (c) Thomas Lee 2002
' Freely distributed!
Option Explicit
On Error Resume Next
'Declare variables
Dim Prompt, oWSH
'Set the Windows Script Host Shell
set oWSH = WScript.CreateObject("WScript.Shell")
' delete the relevant keys
oWSH.RegDelete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
AutoAdminLogon"
oWSH.RegDelete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
DefaultDomainName"
oWSH.RegDelete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
DefaultUserName"
oWSH.RegDelete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
DefaultPassword" ' All done - say goodbye! Legend = "Autoadmin removed - have a nice day!" MyBox = MsgBox (legend, 4096, "We're Done") You can use Notepad to type these scripts and save them with a .vbs file extension, or download autoadminlogon.vbs and noautoadminlogon.vbs from http://www.oreilly.com/catalog/winsvrhks/. Sysinternals Tool Finally, here's one more way to configure automatic logon on machines. Mark Russinovich, of Sysinternals fame, also wrote a simple program to do this. You can download the program and the source from http://www.sysinternals.com/ntw2k/source/misc.shtml#AutoLogon where you can find lots of other great tools. Thomas Lee
Hack 5 Wait for and Optionally Terminate a Process If you've wondered how to write code that waits for a process to finish before terminating it, here's the answer. I have seen a number of discussions regarding the need for a VB script that waits for a process to finish. The script in this hack does this and more: it waits for a process to finish and optionally terminates the process if it has not finished within a specified amount of time. This code is a modified form of what I use to control my software deployments, and it has two purposes. First, the code is designed to be certain that the deployment script waits until the initiated software setup executable is fully finished before proceeding. Even though the majority of recent software releases do not require this functionality when being deployed, it is still required for some legacy installations. Second, the code can perform a forceful termination of an application if this functionality is required. This script accepts three arguments: the name of the executable to wait for or terminate, the amount of time to wait before terminating the specified executable, and (optionally) a switch specifying that the script should run silently. Note that the script uses Windows Management Instrumentation (WMI) for the process-management tasks, so make sure you're running the latest WMI version on your machine.
The Code The script consists of several sections, which are described inline in the following sections. Main routine First, command-line switches are read in the main body area: Option Explicit ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' File: vbsWaitForProcess.vbs ' Updated: Nov 2002 ' Version: 1.0 ' Author: Dan Thomson, myITforum.com columnist ' I can be contacted at dethomson@hotmail.com ' ' Usage: The command processor version must be run using cscript ' cscript vbsWaitForProcess.vbs notepad.exe 60 S
' or ' The IE and Popup versions can be run with cscript or wscript ' wscript vbsWaitForProcess.vbs notepad.exe -1 ' ' Input: Name of executable (ex: notepad.exe) ' Time to wait in seconds before terminating the executable ' -1 waits indefinitely for the process to finish ' 0 terminates the process imediately ' Any value > 0 will cause the script to wait the specified ' amount of time in seconds before terminating the process ' Silent mode (S) ' ' Notes: ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' On Error Resume Next
'Define some variables Dim strProcess Dim intWaitTime Dim strSilent 'Get the command line arguments strProcess = Wscript.Arguments.Item(0) intWaitTime = CInt(Wscript.Arguments.Item(1)) strSilent = Wscript.Arguments.Item(2) Call WaitForProcess (strProcess, intWaitTime, strSilent) Check if process is running Next, the ProcessIsRunning function determines if a process is running: ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' '
' Function: ProcessIsRunning ' ' Purpose: Determine if a process is running ' ' Input: Name of process ' ' Output: True or False depending on if the process is running ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Private Function ProcessIsRunning( strProcess ) Dim colProcessList Set colProcessList = Getobject("Winmgmts:").Execquery _ ("Select * from Win32_Process Where Name ='" & strProcess & "'") If colProcessList.Count > 0 Then ProcessIsRunning = True Else ProcessIsRunning = False
End If Set colProcessList = Nothing End Function Terminate the process In the next section, the ProcessTerminate function terminates a process: ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' Function: TerminateProcess ' ' Purpose: Terminates a process ' ' Input: Name of process ' ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
Private Function ProcessTerminate( strProcess ) Dim colProcessList, objProcess Set colProcessList = GetObject("Winmgmts:").ExecQuery _ ("Select * from Win32_Process Where Name ='" & strProcess & "'") For Each objProcess in colProcessList objProcess.Terminate( ) Next Set colProcessList = Nothing End Function Wait for process to terminate Finally, in the WaitForProcess subroutine, the user interface is set up, the script waits while the process is active, and the process termination is initiated. I created three versions of the subroutine in an effort to demonstrate a few methods for displaying status messages. For example, here's how to display these messages using the command console: '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
' ' Sub: WaitForProcess ' ' Purpose: Waits for a process ' ' Input: Name of process ' Wait time in seconds before termination. ' -1 will cause the script to wait indefinitely ' 0 terminates the process imediately ' Any value > 0 will cause the script to wait the specified ' amount of time in seconds before terminating the process ' Display mode. ' Passing S will run the script silent and not show any prompts ' ' Output: On screen status ' ' Notes: The version echos user messages in the command window via StdOut
' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Private Sub WaitForProcess( strProcess, intWaitTime, strMode ) If ProcessIsRunning(strProcess) Then Dim StdOut Dim w : w = 0 Dim strPrompt Dim intPause : intPause = 1 If UCase(strMode) <> "S" Then strPrompt = "Waiting for " & strProcess & " to finish." Set StdOut = WScript.StdOut StdOut.WriteLine "" StdOut.Write strPrompt End If 'Loop while the process is running Do While ProcessIsRunning(strProcess)
'Check to see if specified # of seconds have passed before terminating 'the process. If yes, then terminate the process If w >= intWaitTime AND intWaitTime >= 0 Then Call ProcessTerminate(strProcess) Exit Do End If 'If not running silent, post user messages If UCase(strMode) <> "S" Then _ StdOut.Write "." 'Increment the seconds counter w = w + intPause 'Pause Wscript.Sleep(intPause * 1000) Loop If UCase(strMode) <> "S" Then StdOut.WriteLine "" Set StdOut = Nothing
End If End If End Sub The result is shown in Figure 1-8. Figure 1-8. Status message displayed in command console Alternatively, here's some code for displaying status messages in Internet Explorer: ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' Sub: WaitForProcess ' ' Purpose: Waits for a process
' ' Input: Name of process ' Wait time in seconds before termination. ' -1 will cause the script to wait indefinitely ' 0 terminates the process imediately ' Any value > 0 will cause the script to wait the specified ' amount of time in seconds before terminating the process ' Display mode. ' Passing S will run the script silent and not show any prompts ' ' Output: On screen status ' ' Notes: This version uses Internet Explorer for user messages ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Private Sub WaitForProcess( strProcess, intWaitTime, strMode ) If ProcessIsRunning(strProcess) Then
Dim objIntExplorer Dim c : c = 0 Dim w : w = 0 Dim strPrompt Dim intPause : intPause = 1 strPrompt = "Waiting for " & strProcess & " to finish." 'If not running silent, create reference to objIntExplorer 'This will be used for the user messages. Also set IE display attributes If UCase(strMode) <> "S" Then Set objIntExplorer = Wscript._ CreateObject("InternetExplorer.Application") With objIntExplorer .Navigate "about:blank" .ToolBar = 0 .Menubar = 0 ' no menu
.StatusBar = 0 .Width=400 .Height = 80 .Left = 100 .Top = 100 .Document.Title = "WaitForProcess" End With 'Wait for IE to finish Do While (objIntExplorer.Busy) Wscript.Sleep 200 Loop 'Show IE objIntExplorer.Visible = 1 End If Do While ProcessIsRunning(strProcess) 'Check to see if specified # of seconds have passed before terminating 'the process. If yes, then terminate the process If w >= intWaitTime AND intWaitTime >= 0 Then
Call ProcessTerminate(strProcess) Exit Do End If If UCase(strMode) <> "S" Then objIntExplorer.Document.Body.InnerHTML = strPrompt & String(c, ".") 'Increment the counter. 'Reset the counter indicator if it's > 25 because 'we don't want it taking up a lot of screen space. If c > 25 Then c = 1 Else c = c + 1 'Increment the seconds counter w = w + intPause End If 'Pause Wscript.Sleep(intPause * 1000) Loop objIntExplorer.Quit( ) ' close Internet Explorer Set objIntExplorer = Nothing ' release object reference
End If End Sub The resulting status message is shown in Figure 1-9. Figure 1-9. Displaying status messages in Internet Explorer Finally, here's code that uses the Popup method of Windows Scripting Host for displaying status messages: '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' Sub: WaitForProcess ' ' Purpose: Waits for a process ' ' Input: Name of process
' Wait time in seconds before termination. ' -1 will cause the script to wait indefinitely ' 0 terminates the process imediately ' Any value > 0 will cause the script to wait the specified ' ' amount of time in seconds before terminating the process ' Display mode. ' Passing S will run the script silent and not show any prompts ' ' Output: On screen status ' ' Notes: This version uses WshShell.Popup for user messages ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Private Sub WaitForProcess( strProcess, intWaitTime, strMode ) If ProcessIsRunning(strProcess) Then Dim objWshShell Dim c : c = 0
Dim w : w = 0 Dim strPrompt Dim intPopupTimer : intPopupTimer = 2 Dim intPause : intPause = 1 strPrompt = "Waiting for " & strProcess & " to finish." 'If not running silent, create reference to objWshShell 'This will be used for the user messages If UCase(strMode) <> "S" Then _ Set objWshShell = CreateObject("WScript.Shell") 'Loop while the process is running Do While ProcessIsRunning(strProcess) 'Check to see if specified # of seconds have passed before terminating 'the process. If yes, then terminate the process If w >= intWaitTime AND intWaitTime >= 0 Then Call ProcessTerminate(strProcess)
Exit Do End If 'If not running silent, post user prompt If UCase(strMode) <> "S" Then objWshShell.Popup strPrompt & String(c, "."), intPopupTimer, _ "WaitForProcess", 64 'Increment the counter. 'Reset the counter indicator if it's > 25 because 'we don't want it taking up a lot of screen space. If c > 25 Then c = 1 Else c = c + 1 End If 'Increment the seconds counter w = w + intPause + intPopupTimer 'Pause Wscript.Sleep(intPause * 1000) Loop Set objWshShell = Nothing End If
End Sub The resulting dialog box is shown in Figure 1-10. Figure 1-10. Displaying status messages in a dialog box Note that if you are assembling a standalone script, it should contain sections 1, 2, 3, and one option from section 4. If you would rather incorporate this code into your existing script, you need only sections 2, 3, and one option from section 4. You'll also need to add the call statement that is at the end of the main routine section. All the code sections are self-contained, which makes them easy to import into existing scripts. Running the Hack To use this hack, type the code into Notepad (with Word Wrap disabled) and save it with a .vbs extension as WaitForProcess.vbs. Or, if you don't want to tire your fingers out, download it from the O'Reilly web site instead.
Here are a few sample command-line examples. This will wait indefinitely until Notepad is closed: cscript WaitForProcess.vbs notepad.exe -1 This will wait silently and indefinitely until Notepad is closed: cscript WaitForProcess.vbs notepad.exe -1 S And this will wait 10 seconds before Notepad is forcefully closed: cscript WaitForProcess.vbs notepad.exe 10 Dan Thomson
Hack 6 Shut Down a Remote Computer Here's a nifty way to use a script to shut down remote machines. Sometimes, you need to be able to shut down a server remotely. This script pings the computer in question prior to sending the Win32Shutdown method. It operates on remote PCs and has been tested on systems running Windows 2000. It will probably work on NT4 systems with the proper WHS/WMI/VB scripting, though it has not been tested on such systems. Using the Win32Shutdown method, the script provides you with the option of logging off the current user of the machine, powering the machine down, or rebooting it. In addition, each of these options can be forced so that the action occurs even if applications are running. Use this option carefully, though, because it might cause the logged-on user to lose his work if he has open files. Note that forced log off/power down/reboot will not work if the screen saver is password-protected and is currently active. The Code Make sure you have the latest scripting engines on the workstation you run this script from. You can download the latest scripting engines at the Microsoft Scripting home page
(http://msdn.microsoft.com/library/default.asp? url=/nhp/default.asp?contentid=28001169). Note that, when working with the Active Directory Services Interface (ADSI), you must have the same applicable rights as you need to use the built-in administrative tools. Also, for VB scripts that interact with Windows Management Instrumentation (WMI), apply the most current version of the WMI agents. Type the following code into a text editor such as Notepad (making sure to have Word Wrap disabled) and save it with a .vbs extension. Alternatively, you can download the RemoteShutdown.vbs script from the O'Reilly web site at http://www.oreilly.com/catalog/winsvrhks/. '/'|| RemoteShutdown.vbs '|| '|| Created by Harvey Hendricks, MCP, MCSE, A+ '|| March 2001 '|| email: Harvey.Hendricks@aramcoservices.com '|| '|| '|| Based on techniques and ideas from: '|| SMS admin, SMS Installer, & WMI forums -> '|| http://www.myITforum.com/forums '|| Win32 Scripting -> http://cwashington.netreach.net/
'|| Microsoft Windows Script Technologies -> '|| http://msdn.microsoft.com/scripting '|| Microsoft Online Library -> '|| http://msdn.microsoft.com/library/default.asp '|| Microsoft VBScript 5.5 documentation and Microsoft WMI SDK '|| '||~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ '|| SCRIPT LOGIC FLOW: '|| Collects computername from user, calls function to ping the computername '|| to determine if it is accessible, if not then display message and exit '|| otherwise continue. '|| Collects desired action to perform from the user, does error checking on '|| the input to determine if it is acceptable, if not then display message '|| and exit otherwise continue. '|| Set variables and output messages based on the action chosen. Calls '|| Win32Shutdown with the appropriate variable. Displays success message '|| and exits '||
'|| Uses WMI Win32Shutdown method from the Win32_OperatingSystem class '|| to perform different logoff / powerdown / reboot functions '|| '|| Testing found the following values to be effective on Win32Shutdown: '|| Action decimal binary '|| Logoff 0 0000 '|| Force Logoff 4 0100 '|| Reboot 2 0010 '|| Force Reboot 6 0110 '|| Powerdown 8 1000 '|| Force Powerdown 12 1100 '|| '|| Notice that the third bit from the right appears to be the "FORCE" bit. '|| '|| A value of 1 will do a shutdown, ending at the "It is safe to turn '|| off your computer" screen. I have no use for this and did not test it. '||
'|| '||NOTES: - tested under Windows 2000 Pro. with ACPI compliant systems - '|| SHOULD work under Windows NT4 without modification IF the '|| system has compatible versions of WSH / WMI / VBscripting '|| '||Logoff / Powerdown / Reboot: '|| Does not work if a password protected screen saver is active or '|| there is data to save. Either way the system waits for user input. '|| '||Force Logoff / Force Powerdown / Force Reboot: '|| Does not work if a password protected screen saver is active, will wait '|| for user input. Otherwise will close open applications without saving '|| data. '|| '/~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ '//////////////\ start function function Ping(byval strName)
dim objFSO, objShell, objTempFile, objTS dim sCommand, sReadLine dim bReturn set objShell = WScript.CreateObject("Wscript.Shell") set objFSO = CreateObject("Scripting.FileSystemObject") 'Set default return value bReturn = false 'Create command line to ping and save results to a temp file sCommand = "cmd /c ping.exe -n 3 -w 1000 " & strName & " > C:\temp.txt" 'Execute the command objShell.run sCommand, 0, true 'Get the temp file
set objTempFile = objFSO.GetFile("C:\temp.txt") set objTS = objTempFile.OpenAsTextStream(1) 'Loop through the temp file to see if "reply from" is found, 'if it is then the ping was successful do while objTs.AtEndOfStream <> true sReadLine = objTs.ReadLine if instr(lcase(sReadLine), "reply from") > 0 then bReturn = true exit do end if loop 'Close temp file and release objects objTS.close objTempFile.delete set objTS = nothing set objTempFile = nothing
set objShell = nothing set objFSO = nothing 'Return value Ping = bReturn end function '//////////////\ end function '///////////\ Start Main body of script 'Get computer name to operate on ComputerName=InputBox("Enter the Machine name of the computer" & vbCRLF _ & "you wish to Shutdown / Reboot / Logoff", _ "Remote Shutdown / Reboot / Logoff", _ "ComputerName") 'if Cancel selected - exit If (ComputerName = "") Then Wscript.Quit
'change the name to uppercase ComputerName=UCase(ComputerName) 'ping the computername to see if it is accessible bPingtest = ping(Computername) If bPingtest = FALSE Then y = msgbox ("'" & ComputerName & "' is not accessible!" & vbCRLF _ & "It may be offline or turned off." & vbCRLF _ & "Check the name for a typo." & vbCRLF, _ vbCritical, ComputerName & " NOT RESPONDING") Wscript.Quit end IF 'Get the action desired Action=InputBox( _ "Select Action to perform on " & ComputerName & vbCRLF & vbCRLF _
& " 1 - Logoff" & vbCRLF _ & " 2 - Force Logoff ( NO SAVE )" & vbCRLF _ & " 3 - Powerdown" & vbCRLF _ & " 4 - Force Powerdown ( NO SAVE )" & vbCRLF _ & " 5 - Reboot" & vbCRLF _ & " 6 - Force Reboot ( NO SAVE )" & vbCRLF & vbCRLF _ & "NOTE:" & vbCRLF _ & " Using Force will close windows" & vbCRLF _ & " without saving changes!", _ "Select action to perform on " & ComputerName, "") 'if Cancel selected - exit If (Action = "") Then Wscript.Quit 'error check input If (INSTR("1234567",Action)=0) OR (Len(Action)>1) then y = msgbox("Unacceptable input passed -- '" & Action & "'", _
vbOKOnly + vbCritical, "That was SOME bad input!") Wscript.Quit end if 'set flag to disallow action unless proper input achieved, 1 => go 0 => nogo flag = 0 'set variables according to computername and action Select Case Action Case 1 'Logoff x = 0 strAction = "Logoff sent to " & ComputerName flag = 1 Case 2 'Force Logoff x = 4 strAction = "Force Logoff sent to " & ComputerName flag = 1 Case 3 'Powerdown
x = 8 strAction = "Powerdown sent to " & ComputerName flag = 1 Case 4 'Force Powerdown x = 12 strAction = "Force Powerdown sent to " & ComputerName flag = 1 Case 5 'Reboot x = 2 strAction = "Reboot sent to " & ComputerName flag = 1 Case 6 'Force Reboot x = 6 strAction = "Force Reboot sent to " & ComputerName flag = 1 Case 7 'Test dialog boxes y = msgbox("Test complete", vbOKOnly + vbInformation, "Dialog Box Test Complete")
flag = 0 Case Else 'Default -- should never happen y = msgbox("Error occurred in passing parameters." _ & vbCRLF & " Passed '" & Action & "'", _ vbOKOnly + vbCritical, "PARAMETER ERROR") flag = 0 End Select 'check flag ' if equal 1 (TRUE) then perform Win32Shutdown action on remote PC ' and display a confirmation message ' if not equal 1 (FALSE) then skip the action and script ends if flag then Set OpSysSet=GetObject("winmgmts:{(Debug,RemoteShutdown)}//" _ & ComputerName & "/root/cimv2").ExecQuery( _ "Select * from Win32_OperatingSystem where Primary=true") for each OpSys in OpSysSet OpSys.Win32Shutdown(x)
y = msgbox(strAction,vbOKOnly + vbInformation,"Mission Accomplished") next end If 'Release objects set OpSys = nothing set OpSysSet = nothing Running the Hack To run the hack, simply double-click on the RemoteShutdown.vbs file in Windows Explorer (or a shortcut to this file on your desktop) and type the name of the remote computer you want to log off from, power down, or reboot. This name can be the NetBIOS name, DNS name, or IP address of the remote machine. You will then be presented with an input box that displays a menu of options: 1 - Logoff 2 - Force Logoff 3 - Powerdown 4 - Force Powerdown 5 - Reboot 6 - Force Reboot Simply type the number for the action you want to perform and press Enter.
Harvey Hendricks
Hack 7 Rename Mapped Drives Renaming drive mappings can be done in several ways, but automating the process is most efficient using a script. Occasionally, an administrator might need to change drive- mapping names to hide share paths or to make the drive name user-friendly. This is an easy operation when done manually through a console, but when you try to automate this task, it becomes a little more difficult. Because mapped drives are not partitions on the local hard disk, common DOS commands, such as label, can't be used. Most drive-mapping commands, such as net use, don't have a way to customize the name of the mapped drive either. One common way to perform this task is to hack the following Registry key and add the _LabelFromReg string value: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2%key% Here, the %key% variable is the drive letter to be changed. There is a whole host of ways to make this method work, either by editing the Registry directly, via script, or by importing a .reg file using regedit /c. All of these methods require many steps and some require external files, so they might not fit into every administrative scheme. But there's an easier approach.
The Code As it turns out, our old friend VBScript can be used to make this task a little more seamless. This simple script can be used on mapped drives as well as local partitions: mDrive = "drive letter" Set oShell = CreateObject("Shell.Application") oShell.NameSpace(mDrive).Self.Name = "AnyName" Running the Hack To use this hack, simply edit the script to change the drive letter and drive name as desired. For example, if E: is a mapped drive that has the label Budgets on 172.16.33.14, and you want to change the label on the mapped drive to simply Budgets, change this line: mDrive = "drive letter" to this: mDrive = "e:" Then, change this line: oShell.NameSpace(mDrive).Self.Name = "AnyName" to this: oShell.NameSpace(mDrive).Self.Name = "Budgets"
Finally, run the script by creating a shortcut to it and double- clicking on the shortcut, by calling it from a logon script, or by any other method suitable for your environment. Michael Brainard
Hack 8 Execute a Command on Each Computer in a Domain This handy script lets you easily run any command on a specified subset of computers in your domain. Running the same command on multiple computers in your domain can be tedious indeed, but such a scenario is common in an administrator's life. I've written this hack to make this chore easier. The script traverses member systems of a domain, executing a command against each system that has a name that matches a particular specification you specify in the command line. Note that regular expressions are legal in this script, which makes it a powerful and flexible addition to the administrator's toolkit. The Code To use this script, type it into a text editor such as Notepad (make sure Word Wrap is disabled) and save it with a .vbs extension as ExecuteAll.vbs. Alternatively, if you don't want to wear your fingers out, you can download the script from the O'Reilly web site. 'Script Name: ExecuteAll.vbs
Option Explicit Dim oDomain, oService, oItem, oShell Dim strDomain, strSpec, strCommand, intButton Dim oArgs, strFinalCommand, oRegEx, boolConfirm ' Prepare to execute commands & do popups Set oShell = CreateObject("WScript.Shell") GetArguments ' Access the domain so we can traverse objects WScript.Echo "Accessing NT Domain " & strDomain Set oDomain = GetObject("WinNT://" & strDomain) ' Initiate our regular expression support Set oRegEx = New RegExp
oRegEx.Pattern = strSpec oRegEx.IgnoreCase = True ' Traverse each computer (WinNT) object in the domain WScript.Echo "Searching for " & strSpec oDomain.Filter = Array("Computer") ' only look at computers For Each oItem In oDomain If oRegEx.Test(oItem.Name) Then WScript.Echo " Matched " & oItem.Name strFinalCommand = Replace(strCommand, "$n", oItem.Name) intButton = vbNo If boolConfirm Then intButton = oShell.Popup("Execute " & strFinalCommand & "?",,_ "System " & oItem.Name, vbYesno + vbQuestion) End If If (boolConfirm = False) Or (intButton = vbYes) Then
WScript.Echo " Executing: " & strFinalCommand execute strFinalCommand End If End If Next ' All done; clean up Set oItem = Nothing Set oRegEx = Nothing Set oDomain = Nothing Set oShell = Nothing Set oArgs = Nothing ' ' Glean the arguments for our run from the command line, if provided. ' If any are missing, prompt for input. A blank input signals an abort. ' ' /Y is an optional last argument
Sub GetArguments Dim i, strConfirm, intButton Set oArgs = WScript.Arguments boolConfirm = True ' assume always confirm strDomain = "" ' domain to be traversed strSpec = "" ' name specification to be matched strCommand = "" ' command to be executed on each match strConfirm = "" ' track prompting for confirmation setting ' Look for our optional 4th argument If oArgs.Length = 4 Then If UCase(oArgs.Item(3)) = "/Y" Then boolConfirm = False strConfirm = "/Y" ' don't prompt below End If End If
' Look for any specified arguments, in order If oArgs.Length >= 1 Then strDomain = oArgs(0) If oArgs.Length >= 2 Then strSpec = oArgs(1) If oArgs.Length >= 3 Then strCommand = oArgs(2) ' Prompt for any arguments not specified on the command line If strDomain = "" Then strDomain = InputBox _ ("Enter the name of the NT Domain to be traversed", _ "NT Domain") End If If strDomain = "" Then WScript.Quit strDomain = UCase(strDomain) If strSpec = "" Then strSpec = InputBox _ ("Enter your name specification for the computer(s) " & _
"that will be matched within the " & strDomain & " Domain." & _ vbCrlf & "Regular Expressions are acceptable.", _ "Name Specification") End If If strSpec = "" Then WScript.Quit If strCommand = "" Then strCommand = InputBox _ ("Enter the command to be executed on each computer matching " & _ strSpec & " within the " & strDomain & " Domain." & _ vbCrlf & "$n will be substituted for the computer name.", _ "Command to Execute") End If If strCommand = "" Then WScript.Quit If strConfirm = "" Then intButton = oShell.Popup("Confirm each command prior to execution?",,_
"Confirm?", vbYesNo + vbQuestion) If intButton = vbNo Then boolConfirm = False End If End If End Sub ' Execute a command. Each is always run under a new instance of the command ' processor. This allows the use of built-in commands and I/O redirection. ' ' We won't wait for command completion. Sub Execute(strCommand) Dim RetVal strCommand = "%COMSPEC% /c " & strCommand RetVal = oShell.Run(strCommand, 1, False) End Sub
Running the Hack Here is the syntax for running the script: ExexcuteAll.vbs [/Y] When the script runs, the matched system's name will be substituted for the occurrence of $n in the command to be performed. By default, each command instance is confirmed before it is executed, but you can specify /Y to always answer Yes instead. Here's an example of how to run the script: ExexcuteAll.vbs MYDOMAIN WKSATL* "del \$n\admin$\activitylog.txt" This example traverses the MYDOMAIN domain, looking for computer names that start with WKSATL* (note the wildcard) and deletes the activitylog.txt file from the C:\Winnt folder. Hans Schefske
Hack 9 Add, Remove, or Retrieve Environment Variables Environment variables can easily be added, removed, or retrieved using the script in this hack. Using VBScript to work with the Windows system environment can be pretty simple. This hack shows how to use a script to read variables, add new variables, remove variables, and recurse through all of them. Just take a look through the script and read the comments to see how to perform each task. Note that there are four types of values in the Windows Script Host (WSH) environmentSystem, User, Volatile, and Processand the script uses all of them. By the way, this script is provided by Dudeworks (http://www.dudeworks.net). For additional resources on Windows scripting and working with the environment, see http://msdn.microsoft.com/library/default.asp?url=/library/en- us/script56/html/wsProEnvironment.asp. The Code Type the following script into Notepad (with Word Wrap disabled) and save it with a .vbs extension as GetEnvVars.vbs: '~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Created by: Rob Olson - Dudeworks 'Created on: 10/17/2001 'Purpose: Get Environment Variables. '~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ wscript.echo "Working with the Environment: Provided by www.dudeworks.net"&vbcrlf&vbcrlf&strval '// Create an instance of the wshShell object set WshShell = CreateObject("WScript.Shell") 'Use the methods of the object wscript.echo "Environment.item: "& WshShell.Environment.item("WINDIR") wscript.echo "ExpandEnvironmentStrings: "& WshShell.ExpandEnvironmentStrings("%windir%") '// add and remove environment variables '// Specify the environment type ( System, User, Volatile, or Process ) set oEnv=WshShell.Environment("System")
wscript.echo "Adding ( TestVar=Windows Script Host ) to the System " _ & "type environment" ' add a var oEnv("TestVar") = "Windows Script Host" wscript.echo "removing ( TestVar=Windows Script Host ) from the System " _ & "type environment" ' remove a var oEnv.Remove "TestVar" '// List all vars in all environment types '//System Type set oEnv=WshShell.Environment("System") for each sitem in oEnv strval=strval & sItem &vbcrlf next
wscript.echo "System Environment:"&vbcrlf&vbcrlf&strval strval="" '//Process Type set oEnv=WshShell.Environment("Process") for each sitem in oEnv strval=strval & sItem &vbcrlf next wscript.echo "Process Environment:"&vbcrlf&vbcrlf&strval strval="" '//User Type set oEnv=WshShell.Environment("User") for each sitem in oEnv strval=strval & sItem &vbcrlf next wscript.echo "User Environment:"&vbcrlf&vbcrlf&strval
strval="" '//Volatile Type set oEnv=WshShell.Environment("Volatile") for each sitem in oEnv strval=strval & sItem &vbcrlf next wscript.echo "Volatile Environment:"&vbcrlf&vbcrlf&strval strval="" Running the Hack To run the script, open a command prompt, change to the directory where the script is saved, and type cscript.exe GetEnvVars.vbs. Here is an example of typical output from the script on a Windows 2000 machine: Microsoft (R) Windows Script Host Version 5.6 Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.
Working with the Environment: Provided by www.dudeworks.net Environment.item: %SystemRoot% ExpandEnvironmentStrings: C:\WINNT Adding ( TestVar=Windows Script Host ) to the System type environment removing ( TestVar=Windows Script Host ) from the System type environment System Environment: ComSpec=%SystemRoot%\system32\cmd.exe Os2LibPath=%SystemRoot%\system32\os2\dll; Path=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem windir=%SystemRoot% OS=Windows_NT PROCESSOR_ARCHITECTURE=x86 PROCESSOR_LEVEL=6 PROCESSOR_IDENTIFIER=x86 Family 6 Model 5 Stepping 2, GenuineIntel PROCESSOR_REVISION=0502 NUMBER_OF_PROCESSORS=1
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
TEMP=%SystemRoot%\TEMP
TMP=%SystemRoot%\TEMP
Process Environment:
=C:=C:
=ExitCode=00000000
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Administrator\Application Data
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=SNOOPY
ComSpec=C:\WINNT\system32\cmd.exe
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Administrator
LOGONSERVER=\SNOOPY
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Os2LibPath=C:\WINNT\system32\os2\dll;
Path=C:\WINNT\system32;C:\WINNT;C:\WINNT\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 5 Stepping 2, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0502
ProgramFiles=C:\Program Files
PROMPT=$P$G
SystemDrive=C:
SystemRoot=C:\WINNT
TEMP=C:\DOCUME1\ADMINI1\LOCALS1\Temp
TMP=C:\DOCUME1\ADMINI1\LOCALS1\Temp
USERDOMAIN=SNOOPY
USERNAME=Administrator
USERPROFILE=C:\Documents and Settings\Administrator
windir=C:\WINNT
User Environment: TEMP=%USERPROFILE%\Local Settings\Temp TMP=%USERPROFILE%\Local Settings\Temp Volatile Environment: LOGONSERVER=\SNOOPY APPDATA=C:\Documents and Settings\Administrator\Application Data By the way, if you add a new variable via the command prompt, you will not see it when you try to read it via the script. You can read only the new values created via the same scripting type you used to create them. Although I've tested this only to a limited extent, it seems to be true. Try it for yourself; just open a command prompt, type Set DUDE=Dudeworks, and press Enter to set the new environment variable. Now, when you execute GetEnvVars.vbs, and you'll notice that it does not list that new variable. However, if you type SET at the command prompt, you will see it. Rob Olson
Hack 10 Extend Group Policy Group Policy is a powerful tool for managing Windows systems, but by configuring ADM files you can extend its capabilities even further. One day, one of my customers gave me a phone call to say that "the Group Policy Plan we made was pretty nice, but there's something missing, and if we had this we could really impress our boss." From that day on, my life wasn't the same, because this comment led to me discover the true power of Group Policy through customizing ADM files. But first you need to understand the basics of ADM files. ADM Files An ADM file is an ASCII file that defines the Group Policy settings; every checkbox, drop-down menu, and folder in the Group Policy window is defined in this file. The ADM file can also be hacked with any text editor to extend the built-in settings of Group Policy, or you could even build a custom ADM to import to your own Group Policies files. This customization feature makes Group Policy a more powerful tool to manage computers. The default Group Policy Object (GPO) created in Active Directory is composed of three ADM files: conf.adm, inetres.adm,
and system.adm. The conf.adm file holds all the policy settings for Microsoft NetMeeting. The inetres.adm file holds some of the settings for the Windows Components section under both Computer and User Configuration portions of Group Policy. Finally, the system.adm file has additional settings for the Windows Components and System sections under Administrative Template in both the Computer and User Configuration portions of the Group Policy. These ADM files are located in the %winnt%\inf folder, and every other ADM file that is installed on your machine will be put into that location as well. Also, many products that Microsoft has released for Windows 2000/XP have their own ADM files. For example, the Microsoft Office XP Resource Kit has a corresponding ADM file for each product of the Office suite. For instance, an ADM file called word10.adm adds policy settings that affect Word XP on clients computers. Hacking ADM Files How do you to find the policy you want to edit? And how do you change it? In the following example, I want to find and edit the "Save Word files as" policy in the word10.adm file. This policy defines the way a file is saved by default in Word XP. I usually add the option to save the Word file in a format that appears in a local version of Word but doesn't appear in the ADM. Figure 1-11 shows what the policy looks like. Figure 1-11. Editing a policy setting
As you can see, the policy setting is found in the Save folder and its name is "Save Word files as." Now, if I want to find this policy in the appropriate ADM file, I simply need to look for "Save Word files as." To do this, just open the correct ADM file (which in this case is word10.adm) and do a text search for the string "Save Word files as". You'll find the following section of the ADM file: POLICY "Save Word files as"
KEYNAME Software\Policies\Microsoft\Office\10.0\Word\Options PART "Save Word files as" DROPDOWNLIST VALUENAME DefaultFormat ITEMLIST NAME "Word document (.doc)" VALUE "DEFAULT" NAME "Web Page (.htm; .html)" VALUE "HTML" NAME "Word 6.0/95 (.doc)" VALUE "MSWord6Exp" NAME "Word 6.0/95 - Japanese (.doc)" VALUE"MSWord6JExp" NAME "Word 6.0/95 - Korean (.doc)" VALUE "MSWord95KExp" NAME "Word 97-2002 & 6.0/95 - RTF" VALUE "MSWord6RTFExp" NAME "Works 4.0 for Windows (.wps)" VALUE "MSWorksWin4" NAME "Works 3.0 for Windows (.wps)" VALUE "MSWorksWin3" END ITEMLIST NOSORT END PART END POLICY As you can see, the first line, Policy "Save Word files as", defines the name of the policy as it appears in Figure 1-11, while
everything under that line defines the policy settings until the last line, END POLICY, closes the policy. Looking at this further, KEYNAME defines the path to the affected key in the Registry, PART defines the way the policy box will appear in the GUI (in this case, a drop-down menu list), VALUENAME defines the name of the affected value in the Registry, NAME defines the name of each option as it appears in the drop-down list, and VALUE specifies the actual data that will be inserted into the affected value that is defined by VALUENAME. So, if I want to add another option to be displayed in the drop- down list of this policy, all I need to do is add the following line wherever I want (within the section bounded by ITEMLIST and END ITEMLIST): NAME "Word 97-2002 & 6.0/95 Hebrew Converter\doc" VALUE "MSWord6HBRExp" Figure 1-12 shows the result of what will be added to the policy drop-down list in the GUI. Figure 1-12. Adding an option to a drop-down list
Easy, isn't it? With this method, you can manipulate virtually any Registry key that is in the HKEY_LOCAL_MACHINE and HKEY_CURRENT_USER hives to extend Group Policy. If you'd like to learn more about hacking ADM files, see http://www.microsoft.com/windows2000/en/server/help/sag_spconcepts_34.htm from the Windows 2000 Server online documentation. Note that occasionally you might not see the results of your hack; see article 228723 in the Knowledge Base on TechNet for more information (http://support.microsoft.com/default.aspx? scid=kb;en-us;228723). Oren Zippori
Hack 11 Disable EFS While the Encrypted File System of Windows 2000/XP can be useful for protecting data, your best approach might actually be to disable it. The Encrypted File System (EFS) feature was first introduced in Windows 2000 and is also available in Windows XP Professional. EFS provides a much higher level of security than the one offered by NTFS alone, which can be circumvented without much effort as long as physical access to the computer is allowed. EFS is extremely easy to use and is available without any special configuration because it is enabled by default. Even though it seems that with all these advantages EFS should quickly find its place in everyone's environment, implementating it properly is a fairly complex task. The Problem Your two primary concerns are the ability to recover encrypted files and the protection of private keys used for encryption, which are associated with each user's account and the recovery agent's account. Recovery of encrypted files might be a fairly common occurrence. Because the private keys necessary for decryption are stored in the user's profile, if the profile gets deleted or corrupted, the user can no longer access their encrypted files. The process of recovery involves simply logging
on as an account that is designated as a data recovery agent. By default, this account is a local administrator on a standalone computer and a domain administrator in a domain environment. Because the private keys for data recovery agents are also stored as part of their profiles, it is recommended that private keys for data recovery agents should be exported from the computer that contains them and stored in a secure place until a recovery needs to be performed. Currently, without using any custom solution, backup and storage of a user's private keys (without backing up the entire profile) tends to be a time-consuming process. In addition, using nondefault recovery agents (which is the recommended procedure) requires installation of the Certificate Authority feature, which also needs to be managed properly. If you are not ready to handle all these additional tasks, your best bet might simply be to temporarily disable EFS on users' machines. The Solution In the Windows 2000 domain environment, launch the Group Policy MMC snap-in and select the Group Policy Object (GPO) linked to your domain. Then, drill down to Computer Configuration Windows Settings Security Settings Public Key Policies Encrypted Data Recovery Agents, right- click on the folder labeled Encrypted Data Recovery Agents, and select Delete Policy to delete the default recovery policy. Then, right-click on Encrypted Data Recovery Agents again and select Initialize Empty Policy. This will remove users' ability to use EFS on any Windows 2000 system that belongs to the domain. In absence of EFS recovery agent, Windows 2000 clients will refuse to encrypt any files or folders.
However, you might be in for a surprise if you try to use the same approach in Windows XP, because Microsoft changed the default EFS behavior to allow a Windows XP client to use encryption even if no Data Recovery Agent is available (the same is true for Windows Server 2003). Fortunately, there are several new ways of preventing this, which we'll look at now. Disabling EFS for a file Windows XP offers greater flexibility in configuring the scope of reach of EFS. If your intention is to disable EFS for a single file, you can simply assign the system attribute to the file. Although this is not the most elegant solution, it does provide a quick workaround. In order to apply the system attribute to a file, use the attrib command with +s parameter. For example, to apply the system attribute to the info1.txt file, type the following at the command prompt: attrib +s info1.txt Disabling EFS for a folder If you instead want to prevent EFS on the folder level, you can create a desktop.ini file in the folder. The desktop.ini file should contain the following two lines: [Encryption] Disable=1
This will affect the folder itself and all of its files. However, it does not have any impact on its subfolders and their content. Disabling EFS for a system Finally, if you prefer, you can disable EFS on the system level. This can be accomplished by editing the Registry. Set the following entry of DWORD type to the value 1: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EFS\EfsConfiguration It is easier, however, to use Group Policy for this purpose. Start by launching Local Security Policy from the Administrative Tools menu. Next, double-click on the Public Key Policies folder. You will see a subfolder named Encrypting File System. Right-click on it and select Properties from the context-sensitive menu. You will notice a checkbox labeled "Allow users to encrypt files using Encrypting File System (EFS)," as shown in Figure 1-13. Figure 1-13. Disabling EFS in Windows XP/2003
Unchecking this box will disable EFS altogether on the system. Note that this setting can be also used to together with Group Policy to disable EFS for all computers residing in any of Active Directory containerssites, domains, or organizational units. Marcin Policht
Hack 12 Get Event Log Information Need to check on the size and configuration settings of your event logs? Use this script instead of the GUI; it's faster! Monitoring event logs is an essential part of an administrator's job. Unfortunately, viewing event log settings and log file sizes from the GUI is cumbersome, and it would be useful to have an easier way to obtain this information. That's exactly what this hack is all about. You can run the script on Windows NT/2000 and later to obtain the current file size, maximum file size, and number of records, and you can overwrite settings on the Application, System, and Security logs. The Code Type the following script into Notepad (make sure Word Wrap is disabled) and save it with a .vbs extension as loginfo.vbs. Or, if you like, you can download the script from the O'Reilly web site. Option Explicit On Error Resume Next Dim strMoniker
Dim refWMI Dim colEventLogs Dim refEventLog Dim strSource 'moniker string stub - security privilege needed to get 'numrecords for Security log strMoniker = "winMgmts:{(Security)}!" 'append to moniker string if a machine name has been given If WScript.Arguments.Count = 1 Then _ strMoniker = strMoniker & "\" & WScript.Arguments(0) & ":" 'attempt to connect to WMI Set refWMI = GetObject(strMoniker) If Err <> 0 Then WScript.Echo "Could not connect to the WMI service." WScript.Quit
End If 'get a collection of Win32_NTEventLogFile objects Set colEventLogs = refWMI.InstancesOf("Win32_NTEventLogFile") If Err <> 0 Then WScript.Echo "Could not retrieve Event Log objects" WScript.Quit End If 'iterate through each log and output information For Each refEventLog In colEventLogs WScript.Echo "Information for the " & _ refEventLog.LogfileName & _ " log:" WScript.Echo " Current file size: " & refEventLog.FileSize WScript.Echo " Maximum file size: " & refEventLog.MaxFileSize WScript.Echo " The Log currently contains " & _
refEventLog.NumberOfRecords & " records" 'output policy info in a friendly format using OverwriteOutDated, 'as OverWritePolicy is utterly pointless. 'note "-1" is the signed interpretation of 4294967295 Select Case refEventLog.OverwriteOutDated Case 0 WScript.Echo _ " Log entries may be overwritten as required" Case -1 WScript.Echo _ " Log entries may NEVER be overwritten" Case Else WScript.Echo _ " Log entries may be overwritten after " & _ refEventLog.OverwriteOutDated & " days" WScript.Echo End Select Next Set refEventLog = Nothing
Set colEventLogs = Nothing Set refWMI = Nothing Running the Hack To run the script, use Cscript.exe, the command-line version of the Windows Script Host (WSH). Simply type cscript loginfo.vbs at a command prompt from the directory in which the script resides. Here is a sample of typical output when the script runs on a Windows 2000 machine: C:>cscript loginfo.vbs Microsoft (R) Windows Script Host Version 5.6 Copyright (C) Microsoft Corporation 1996-2001. All rights reserved. Information for the Security log: Current file size: 65536 Maximum file size: 524288 The Log currently contains 166 records Log entries may be overwritten after 7 days
Information for the Application log: Current file size: 524288 Maximum file size: 524288 The Log currently contains 2648 records Log entries may be overwritten as required Information for the System log: Current file size: 524288 Maximum file size: 524288 The Log currently contains 2648 records Log entries may be overwritten after 7 days Note that when you run this script on a domain controller it displays information concerning the Directory Service, File Replication Service, and DNS logs as well. Rod Trent
Hack 13 Shortcut to Remote Assistance Remote Assistance is a helpful feature for troubleshooting Windows XP systems, but it's a pain for ordinary users to use. This hack creates a helpful shortcut to this feature. Windows XP provides a Remote Assistance feature, but you have to walk through several screens to get to it. This can be a problem for users who are not technically savvy, and you might find yourself spending a lot of time explaining to them how to use the feature. However, there's a really cool workaround. Place a shortcut to this feature on users' desktops. This will provide them with quicker access to the screen where they can type in the remote computer's IP address to ask for remote assistance. This approach will make life easier for both you and your users. First, right-click on the desktop and choose New Shortcut. Then, in the Create Shortcut box, type the following URL into the Location Box: hcp://CN=Microsoft%20Corporation,L=Redmond,S=Washington,C=US/Remote%20Assistance/ Escalation/Unsolicited/unsolicitedrcui.htm as shown in Figure 1-14. Figure 1-14. Creating a shortcut to the Remote Assistance feature
Click Next and name the shortcut something descriptive, like "Remote Assistance" (Figure 1-15). Figure 1-15. Naming the shortcut
When the shortcut creation is finished, you'll have an icon on your desktop for Remote Assistance (Figure 1-16). Figure 1-16. Desktop icon for Remote Assistance
When you double-click on this icon, you'll be whisked away to the Remote Assistance feature, as shown in Figure 1-17. Simply type the computer name or IP address of the computer you want to connect to for remote assistance. Figure 1-17. Remote Assistance window Pretty handy, eh?
Rod Trent
Hack 14 Desktop Checker Here's a useful script to quickly display the configuration of a remote system for troubleshooting or inventory purposes. This handy script will attempt to gather various Windows NT/2000/XP/2003 operating-system attributes and display them in a coherent way to assist in troubleshooting. I highly suggest modifying the customization variables located within the script. To edit this text file, just open it with Notepad (leave Word Wrap turned off). Even if you have no experience with VBScript, you should find the changes quite easy to make. Please read the comments for different sections to make the tool viable for your organization. This tool was intended to use only standard API calls and nothing from third-party COM objects. This keeps the tool lightweight and portable as only a text file. I suggest putting the tool into a local directory by itself so that the HTML pages it creates don't get out of hand. If a machine does not have WMI 1.5, then a lot of info might be missing. You will get similar results if you don't have administrator rights on the remote box. This script will not work on any Windows 9x operating systems. The Code You can download this script as DesktopChecker.vbs from the
O'Reilly web site at http://www.oreilly.com/catalog/winsvrhks/: '************************************************************** '* * '* Desktop Checker - This script will ATTEMPT to gather * '* various OS attributes and diplay them in a coherent * '* way to assist in troubleshooting. I highly suggest * '* modifying the customization variables located 2 sections * '* below. Please read the comments for different sections * '* to make the tool viable for your organization. This * '* tool was intended to use only standard API calls and * '* nothing from 3rd party COM objects. This keeps the * '* tool lightwieght and portable as only a text file. * '* I suggest putting the tool into a directory by itself * '* so that the HTML pages it creates don't get out of hand. * '* If a machine does not have WMI 1.5 then lots of info may * '* be missing. * '* * '* Dennis Abbott *
'* speckled_trout@hotmail.com * '* * '************************************************************** On Error Resume Next Dim WshShell,WshFso,WshNet,WshSysEnv,IE,wmi,ADSIobj,OutPutFile,DumpFile Dim PathToScript,ComSpec,Cnt,CompName,Company,Title,LogoLink,SelectServices, _ Domain,Progress,Instance,CurLine Set WshShell = CreateObject("Wscript.Shell") Set WshFso = CreateObject("Scripting.FileSystemObject") Set WshNet = CreateObject("Wscript.Network") Set WshSysEnv = WshShell.Environment("SYSTEM") PathToScript = Left(WScript.ScriptFullName,(Len(WScript.ScriptFullName) - _ (Len(WScript.ScriptName) + 1))) ComSpec = WshSysEnv("COMSPEC") Cnt = 0 ' grab contents of clipboard ' This allows you to work a LIST of boxes by cut-n-paste
Set IE = CreateObject("InternetExplorer.Application") IE.Navigate("about:<script language=" & Chr(34) & "vbscr" & "ipt" & Chr(34) & ">function go( ):document.all.it2.select" & "( ):document.execCommand " & Chr(34) & "Paste" & Chr(34) & ":en" & "d function</script><body onload=go( )> <input type=t" & "ext value=" & Chr(34) & "start" & Chr(34) & " id=it2>") While IE.ReadyState <> 4:Wend CompName = IE.document.all.it2.value IE.quit( ) Set IE = Nothing ' SET CUSTOMIZATION VARIABLES Company = "myITforum" Title = Company & " - Helpdesk Diagnostic Tool" LogoLink = "http://www.myitforum.com/img/logo_final.gif"
' The next line alows you to query a variety of NT services of your choosing ' Make sure you enter the service NAME not the DISPLAY NAME, they can be different names SelectServices = Array("WinMgmt","Norton Antivirus Server","DefWatch","clisvc","Dhcp") Domain = "amd" 'Your NT domain Progress = True 'causes pop-up boxes when set to True it is silent when set to False CompName = InputBox("Enter the name of the remote computer",Title,CompName) If CompName = "" Then MsgBox "No machine name was entered.....goodbye" : _ Wscript.Quit(0) Set wmi = GetObject("winmgmts:{impersonationLevel=impersonate}!//" & _ CompName) Set ADSIobj = GetObject("WinNT://" & CompName & ",Computer") Call PrepHTML(CompName) 'create an HTML file If Progress Then WshShell.Popup "Getting OS information",2,Title, vbokonly + _ vbsystemmodal
End If Call GetOS(CompName) If Progress Then WshShell.Popup "Getting NT administrators",2,Title, vbokonly + _ vbsystemmodal End If Call GetAdmins(CompName) If Progress Then WshShell.Popup "Checking Vital Services",2,Title, vbokonly + _ vbsystemmodal End If Call Services(CompName,SelectServices) If Progress Then WshShell.Popup "Checking Admin shares",2,Title, vbokonly + vbsystemmodal End If Call AdminShares(CompName) If Progress Then
WshShell.Popup "Getting date/time stamp",2,Title, vbokonly + _ vbsystemmodal End If Call GetTime(CompName) If Progress Then WshShell.Popup "Getting NetBIOS information",2,Title, vbokonly + _ vbsystemmodal End If Call GetNBTstat(CompName) If Progress Then WshShell.Popup "Pinging computer",2,Title, vbokonly + vbsystemmodal End If Call Ping(CompName) If Progress Then WshShell.Popup "Getting Registry Quota",2,Title, vbokonly + _ vbsystemmodal End If Call GetRegQuota(CompName)
If Progress Then WshShell.Popup "Getting Hardware information",2,Title, vbokonly + _ vbsystemmodal End If Call GetHW(CompName) If Progress Then WshShell.Popup "Getting Network Card information",2,Title, vbokonly + _ vbsystemmodal End If Call GetNIC(CompName) If Progress Then WshShell.Popup "Getting Software information",2,Title, vbokonly + _ vbsystemmodal End If Call GetSW(CompName) If Progress Then WshShell.Popup "Getting Critical NT Events",2,Title, vbokonly + _
vbsystemmodal End If Call GetEvents(CompName) Call ExitScript Function PrepHTML(CompName) Set OutPutFile = WshFso.CreateTextFile(PathToScript & "" & CompName _ & ".html") OutPutFile.WriteLine "" OutPutFile.WriteLine "
" & Title & "
" OutPutFile.WriteLine "<IMG SRC=" & Chr(34) & LogoLink & Chr(34) _ & "
" OutPutFile.WriteLine "" & "Account running this script is " _ & WshNet.UserDomain & "" & WshNet.UserName & " @ " _ & Now & " from workstation " & WshNet.ComputerName & "
" OutPutFile.WriteLine "Information on remote machine \" _ & UCase(CompName) & "
" OutPutFile.WriteLine "To see information as it " _
loads hit the REFRESH button on your web browser.
" OutPutFile.WriteLine "" WshShell.Run PathToScript & "" & CompName & ".html" End Function Function GetOS(CompName) OutPutFile.WriteLine "
1 - Operating System
" OutPutFile.WriteLine "Operating System Version = " _ & ADSIobj.OperatingSystem & " " & ADSIobj.OperatingSystemVersion & "" For Each Instance in wmi.ExecQuery("Select * From Win32_OperatingSystem") OutPutFile.WriteLine "Operating System Caption = " _ & Instance.Caption & "
" OutPutFile.WriteLine "Operating System Service Pack = " _ & Instance.CSDVersion & "
" OutPutFile.WriteLine "Operating System LastBootUpTime = " _ & StrDateTime(Instance.LastBootUpTime) & "
" OutPutFile.WriteLine "Operating System Directory = " _
& Instance.WindowsDirectory & "
"
Next
OutPutFile.WriteLine "
" End Function Function GetAdmins(CompName) Dim Admins,Admin Dim AdsInfo Set Admins = GetObject("WinNT://" & CompName & "/Administrators") OutPutFile.WriteLine "
2 - Members of the local " _ & "administrators group
" OutPutFile.WriteLine "" For Each Admin in Admins.Members Set AdsInfo = GetObject(Admin.adspath) OutPutFile.WriteLine ""Next OutPutFile.WriteLine "
| Name</ b> | Type | Description |
| " & AdsInfo.Name & " | " _ & AdsInfo.Class & " | " & AdsInfo.Description & " |
" End Function Function Services(CompName,SelectServices) Dim Service,srvc,State,Strg OutPutFile.WriteLine "
3 - Status of vital services
" OutPutFile.WriteLine "" For Each Service in SelectServices Strg = "" ADSIobj.Filter = Array("Service") For Each srvc in ADSIobjSelect Case srvc.Status Case 1 State = "STOPPED" Case 2 State = "START_PENDING" Case 3 State = "STOP_PENDING" Case 4 State = "RUNNING" Case 5 State = "CONTINUE_PENDING" Case 6 State = "PAUSE_PENDING" Case 7 State = "PAUSED" Case Else State = "ERROR" End Select If LCase(srvc.Name) = LCase(Service) Then Strg = _ "
" Next OutPutFile.WriteLine Strg Next OutPutFile.WriteLine "| Service Name | Display Name | Status |
| " & Service & " | </ td> | NOT PRESENT</ td> |
| " & srvc.Name & " | " & srvc.DisplayName _ & " | " & State & " |
OutPutFile.WriteLine "
" End Function Function AdminShares(CompName) Dim Shares OutPutFile.WriteLine "
4 - Status of administrative shares
" Shares = True If WshFso.FolderExists("\" & CompName & "\c$") = True Then OutPutFile.WriteLine "C$ share exists" Else Shares = False OutPutFile.WriteLine "C$ share is not " _ & "accessible
" End If If WshFso.FolderExists("\" & CompName & "\admin$") = True Then OutPutFile.WriteLine "admin$ share exists
" Else
Shares = False
OutPutFile.WriteLine "admin$ share is not " _
& "accessible
"
End If
If Shares = False Then
OutPutFile.WriteLine "
"
OutPutFile.WriteLine "Shares made not be " _
& "accessible due to the folowing reasons:
"
OutPutFile.WriteLine "a - You do not have " _
& "admin rights on this box
"
OutPutFile.WriteLine "b - box is offline
"
OutPutFile.WriteLine "c - Server service is not " _
& "running
"
OutPutFile.WriteLine "d - Shares have been " _
& "disabled
"
OutPutFile.WriteLine "e - remote machine's " _
& "operating system is not NT-based
"
End If
OutPutFile.WriteLine "
" End Function Function GetTime(CompName) OutPutFile.WriteLine "
5 - Current date and time
" OutPutFile.WriteLine "Current date and time of a domain controller" WshShell.Run ComSpec & " /c net time /DOMAIN:" & Domain & " >" _ & PathToScript & "\time.txt",6,True Set DumpFile = WshFso.OpenTextFile(PathToScript & "\time.txt", 1, True) Do While DumpFile.AtEndOfStream <> True CurLine = DumpFile.ReadLine If InStr(CurLine,"Current") <> 0 Then OutPutFile.WriteLine CurLine & "
" End If Loop DumpFile.Close OutPutFile.WriteLine "Current date and time of computer you are " _
& "troubleshooting
"
WshShell.Run ComSpec & " /c net time \" & CompName " _
& " >" & PathToScript & "\time.txt",6,True
Set DumpFile = WshFso.OpenTextFile(PathToScript & "\time.txt", 1, True)
Do While DumpFile.AtEndOfStream <> True
CurLine = DumpFile.ReadLine
If InStr(CurLine,"Current") <> 0 Then
OutPutFile.WriteLine CurLine & "
"
End If
Loop
DumpFile.Close
OutPutFile.WriteLine "
" End Function Function Ping(CompName) OutPutFile.WriteLine "
7 - Ping test (DNS name resolution)
" OutPutFile.WriteLine "If you get no reply on the ping yet other data is retrieved on this page then there is most likely a problem with a static DNS entry.
This needs to be fixed before anything else. You MUST VERIFY the machine is running DHCP before you modify the static DNS entry!!!!
" WshShell.Run ComSpec & " /c ping " & CompName & " >" & PathToScript & _ "\ping.txt",6,True Set DumpFile = WshFso.OpenTextFile(PathToScript & "\ping.txt", 1, True) Do While DumpFile.AtEndOfStream <> True OutPutFile.WriteLine DumpFile.ReadLine & "" Loop Set DumpFile = Nothing OutPutFile.WriteLine "
" End Function Function GetNBTstat(CompName) Dim User User = "Nobody Logged On"
WshShell.Run ComSpec & " /c nbtstat -a " & CompName & " >" & PathToScript & "\nbt.txt",6,True Set DumpFile = WshFso.OpenTextFile(PathToScript & "\nbt.txt", 1, True) Do While DumpFile.AtEndOfStream <> True CurLine = DumpFile.ReadLine If InStr(CurLine,"---") <> 0 Then CurLine = DumpFile.ReadLine CompName = Trim(Left(CurLine,InStr(CurLine,"<")-1)) End If If InStr(CurLine,"<03>") <> 0 Then If Trim(Left(CurLine,InStr(CurLine,"<03>")-1)) <> _ UCase(CompName) and _ Trim(Left(CurLine,InStr(CurLine,"<03>")-1)) <> _ UCase(CompName) & "$" Then User = Trim(Left(CurLine,InStr(CurLine,"<03>")-1)) End If End If If InStr(CurLine,"<1E>") <> 0 Then
If Trim(Left(CurLine,InStr(CurLine,"<1E>")-1)) <> UCase(CompName) and Trim(Left(CurLine,InStr(CurLine,"<1E>")-1)) <> UCase(CompName) & "$" Then Domain = Trim(Left(CurLine,InStr(CurLine,"<1E>")-1)) End If End If Loop OutPutFile.WriteLine "
6 - NetBIOS Info
" OutPutFile.WriteLine "Current User Logged on = " & User & " (this value may not be accurate, it depends on the box's messenger service)" OutPutFile.WriteLine "Domain machine is joined to = " & Domain & "
" DumpFile.Close OutPutFile.WriteLine "
" End Function Function GetNIC(CompName) OutPutFile.WriteLine "
9 - Network Card Configuration
"For Each Instance in wmi.ExecQuery("Select * From Win32_" & _ "NetworkAdapterConfiguration Where IPenabled = 'True'") OutPutFile.WriteLine "" OutPutFile.WriteLine "" OutPutFile.WriteLine "" OutPutFile.WriteLine "" OutPutFile.WriteLine "" OutPutFile.WriteLine "" OutPutFile.WriteLine "" OutPutFile.WriteLine "" OutPutFile.WriteLine "" OutPutFile.WriteLine "" OutPutFile.WriteLine "
| " & _ "Attribute | Value |
| Name of card | " _ & Instance.Caption & " |
| DHCP Enabled | " _ & Instance.DhcpEnabled & " |
| IP address | " _ & Instance.IPAddress(0) & " |
| Subnet Mask | " _ & Instance.IPSubnet(0) & " |
| MAC Address | " _ & Instance.MACAddress & " |
| DNS HostName | " _ & Instance.DNSHostname & " |
| DNS Servers(in order) | " _
& Instance.DNSServerSearchOrder(0) & " : " _
& Instance.DNSServerSearchOrder(1) & " |
| Primary WINS | " _ & Instance.WINSPrimaryServer & " |
| Secondary WINS | " _ & Instance.WINSSecondaryServer & " |
" End Function Function GetRegQuota(CompName) OutPutFile.WriteLine "
8 - Registry size information
" For each Instance in wmi.InstancesOf("Win32_Registry") OutPutFile.WriteLine "Current Registry size is " _ & Instance.CurrentSize & " MB's." OutPutFile.WriteLine "Maximum Registry size is " _ & Instance.MaximumSize & " MB's.
"
If Instance.MaximumSize - Instance.CurrentSize < 8 Then
OutPutFile.WriteLine "The Registry quota on " _
& CompName & " may need to be increased!!!
"
End If
Next
OutPutFile.WriteLine "
" End Function Function GetHW(CompName) Dim stuff OutPutFile.WriteLine "
10 - Hardware Information
" For Each Instance in wmi.ExecQuery("Select * From Win32_" & _ "LogicalDisk Where DeviceID = 'C:'") OutPutFile.WriteLine "Total Drive space available on C: is " & Left(Instance. FreeSpace/1000000,InStr(Instance.FreeSpace/1000000, ".")-1) & " Megabytes." stuff = ((Instance.Size - Instance.FreeSpace)/Instance.Size)*100 OutPutFile.WriteLine "The C: drive is " _ & Left(stuff,InStr(stuff, ".")-1) & "% full.
"
Next
For Each Instance in wmi.ExecQuery("Select * From Win32_ComputerSystem")
OutPutFile.WriteLine "Computer Manufacturer = " _
& Instance.Manufacturer & "
"
OutPutFile.WriteLine "Computer Model = " & Instance.Model & "
"
OutPutFile.WriteLine "Total Physical Memory = " & Left
(Instance.TotalPhysicalMemory/1000000,InStr(Instance.TotalPhysicalMemory/1000000,".")-1)
& " MB's" & "
"
Next
For Each Instance in wmi.ExecQuery("Select * From Win32_" & _
"SystemEnclosure")
OutPutFile.WriteLine "Asset Tag = " & Instance.SMBIOSassettag " _
& "
"
OutPutFile.WriteLine "Serial Number = " & Instance.serialnumber " _
& "
"
Next
For Each Instance in wmi.ExecQuery("Select * From Win32_Processor")
OutPutFile.WriteLine "Processor Name = " & Instance.Name & "
"
OutPutFile.WriteLine "Processor Clock Speed = " _
& Instance.CurrentClockSpeed & " MHz
"
OutPutFile.WriteLine "Processor Voltage = " _
& Instance.CurrentVoltage & " Volts
"
OutPutFile.WriteLine "Current Processor Load = " _
& Instance.LoadPercentage & "%
"
Next
OutPutFile.WriteLine "
" End Function Function GetSW(CompName) Dim oReg Dim NavParent,PatternDate,NavDir,NavVer,IEVersion,program,installed, Version,ProgramName OutPutFile.WriteLine "
11 - Software Information
" Set oReg=GetObject("winmgmts:{impersonationLevel=impersonate}!//" _ & CompName & "/root/default:StdRegProv")oReg.getstringvalue 2147483650,"SOFTWARE\INTEL\LANDesk\VirusProtect6\CurrentVersion",
"Parent",NavParent
oReg.getstringvalue 2147483650,"SOFTWARE\Symantec\SharedDefs", _
& "NAVCORP_70",PatternDate
oReg.getstringvalue 2147483650,"SOFTWARE\Symantec\InstalledApps" & _
","NAV",NavDir
If UCase(Left(NavDir,1)) = "C" Then
NavVer = WshFso.GetFileVersion("\" & CompName & "\c$" _
& Right(NavDir,Len(NavDir)-3) & "\vpc32.exe")
OutPutFile.WriteLine "Norton Antivirus Version = " & NavVer _
& "
"
End If
PatternDate = Right(PatternDate,12)
OutPutFile.WriteLine "Norton Antivirus Parent Server = " & NavParent _
& "
"
OutPutFile.WriteLine "Norton Antivirus Definition Date = " _
& Mid(PatternDate,5,2) & "/" & Mid(PatternDate,7,2) & "/" &
Mid(PatternDate,1,4) & " Revision " & Right(PatternDate,3) & "
"
oReg.getstringvalue 2147483650,"SOFTWARE\Microsoft\Internet Explorer" & _
","Version",IEVersion
OutPutFile.WriteLine "
Internet Explorer Version = " & IEVersion OutPutFile.WriteLine "
Installed Programs(from Add/Remove Programs applet)</ p>" OutPutFile.WriteLine "</ tr>" oReg.EnumKey 2147483650, "SOFTWARE\Microsoft\Windows\CurrentVersion" & _ "Uninstall", installed For each program in installed oReg.getstringvalue 2147483650,"SOFTWARE\Microsoft\Windows" & _ "CurrentVersion\Uninstall" & program & "","DisplayName",ProgramName oReg.getstringvalue 2147483650,"SOFTWARE\Microsoft\Windows" & _ "CurrentVersion\Uninstall" & program & "","DisplayVersion",Version If ProgramName <> "" Then OutPutFile.WriteLine "" End If Next OutPutFile.WriteLine "
| Program Name | Version(if available) |
| " & ProgramName & "</
td> | " & Version & " |
" End Function Function GetEvents(CompName) OutPutFile.WriteLine "
12 - First 25 Errors from the system event log
" OutPutFile.WriteLine "" For Each Instance in wmi.ExecQuery("Select * From Win32_NTLogEvent Where Type = 'Error' and LogFile = 'System'") Cnt = Cnt + 1 If Cnt = 25 Then Exit For OutPutFile.WriteLine "" Next OutPutFile.WriteLine "| DateTimeStamp | EventSource | Message |
| " & Mid(Instance.TimeGenerated,5,2) " _
& "-" & Mid(Instance.TimeGenerated,7,2) & "-" _ & Left(Instance.TimeGenerated,4) & " | " _ & Instance.SourceName & " | " & Instance.Message & " |
Function ExitScript OutPutFile.WriteLine "" OutPutFile.Close WshShell.Run PathToScript & "" & CompName & ".html" If Progress Then MsgBox "The " & Title & " script is done.",vbokonly + _ vbsystemmodal,Title End If Set WshShell = Nothing Set WshFso = Nothing Set WshNet = Nothing Set OutPutFile = Nothing Wscript.Quit(0) End Function Running the Hack To run this hack, simply double-click on the DesktopChecker.vbs file in Windows Explorer (or on a shortcut to the file on your
desktop). Then, type the name of the remote computer you want to query using either its NetBIOS name, DNS name, or IP address. At this point, Internet Explorer will open and display a page titled "myITforum Helpdesk Diagnostic Tool," followed by a series of dialog boxes that show the progress of the script (you don't need to click OK to close these dialog boxes, because they close automatically). Once the final dialog box appears"The myITforum Helpdesk Diagnostic Tool script is done"click OK and refresh the web page to view the information. Here's some sample output generated when the script was run on a workstation using Domain Admin credentials. The target machine is a Windows Server 2003 machine named SRV230. The output of the script is in the form of an HTML page named srv230.htm, which is created in the same directory where the script itself resides, but the output has been reformatted here as text to make it easier to include in this book. myITforum - Helpdesk Diagnostic Tool Account running this script is MTIT2\administrator @ 12/3/2003 11:40:37 AM from workstation SRV235 Information on remote machine \SRV230 To see information as it loads hit the REFRESH button on your web browser.
1 - Operating System Operating System Version = Windows NT 5.2
Operating System Caption = Microsoft(R) Windows(R) Server 2003, Enterprise Edition Operating System Service Pack = Operating System LastBootUpTime = 12/3/2003 11:26:42 AM Operating System Directory = C:\WINDOWS
2 - Members of the local administrators group Name Type Description Administrator User Built-in account for administering the computer/domain Enterprise Admins Group Designated administrators of the enterprise Domain Admins Group Designated administrators of the domain
3 - Status of vital services Service Name Display Name Status winmgmt Windows Management Instrumentation RUNNING Norton Antivirus Server NOT PRESENT DefWatch NOT PRESENT clisvc NOT PRESENT Dhcp DHCP Client RUNNING
4 - Status of administrative shares C$ share exists admin$ share exists
5 - Current date and time Current date and time of a domain controller Current date and time of computer you are troubleshooting
6 - NetBIOS Info Current User Logged on = Nobody Logged On (this value may not be accurate, it depends on the box's messenger service) Domain machine is joined to = amd
7 - Ping test (DNS name resolution) If you get no reply on the ping yet other data is retrieved on this page then there is most likely a problem with a static DNS entry. This needs to be fixed before anything
else. You MUST VERIFY the machine is running DHCP before you modify the static DNS entry!!!!
8 - Registry size information Current Registry size is 1 MB's. Maximum Registry size is 88 MB's.
10 - Hardware Information Total Drive space available on C: is 1776 Megabytes. The C: drive is 58% full. Computer Manufacturer = System Manufacturer Computer Model = System Name Total Physical Memory = 536 MB's Asset Tag = Asset-1234567890 Serial Number = Chassis Serial Number Processor Name = Intel(R) Pentium(R) III processor Processor Clock Speed = 501 MHz Processor Voltage = 29 Volts
Current Processor Load = 2%
9 - Network Card Configuration Attribute Value Name of card [00000001] 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX) DHCP Enabled False IP address 172.16.11.230 Subnet Mask 255.255.255.0 MAC Address 00:01:02:FC:92:FC DNS HostName srv230 DNS Servers(in order) 172.16.11.230 : Primary WINS Secondary WINS
11 - Software Information Norton Antivirus Parent Server =
Norton Antivirus Definition Date = // Revision Internet Explorer Version = 6.0.3790.0 Installed Programs(from Add/Remove Programs applet) Program Name Version(if available) FullShot V6 Windows Media Player Hotfix [See wm819639 for more information] Remote Administration Tools 5.2.3790.0
12 - First 25 Errors from the system event log DateTimeStamp EventSource Message 11-21-2003 W32Time The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time. 11-13-2003 DCOM The server {A9E69610-B80D-11D0-B9B9-00A0C922E750} did not register with DCOM within the required timeout. etc...
Dennis Abbott
Hack 15 Top Five Tools Here's one IT professional's take on five third-party tools for Windows 2000 every system administrator should have. There can be no doubt that with every release of Microsoft's operating system the need for third-party utilities becomes less and less. One major complaint about NT was its lack of disk quotas, something Unix has included since day one. A number of companies noticed this oversight and produced a product that did the trick. The release of Windows 2000 saw disk quotas become part of the OS, thus making the need to purchase this type of software an irrelevance for the majority of companies. Whether you agree with Microsoft's policy of continually adding features to its products that were once available only from other sources is one for debate. But in my role as a network administrator, I still find a need to seek out additional software to help make my job a lot easier. I'm sure everyone has their favorite must-have utilities, but these are my top five must-have add-on products for Windows 2000. Server Monitor Lite Server Monitor Lite is an invaluable monitoring product that allows you to monitor your servers centrally and get notified if a problem occurs. I use this utility to ping all my servers
periodically, watch for low disk space, keep an eye on critical services, and make sure the company intranet is still accessible for my users. For more information, see http://www.purenetworking.net/Products/ServerMonitor/ServerMonitor.htm Lost Password Recovery Have you inherited systems for which nobody knows the local administrator password, or do you have users that need access to Word, Excel, or Access documents that are password- protected and nobody knows the password? Well, this handy little product will save the day. It lets you reset the password on a huge array of systems. For more information, see http://www.lostpassword.com. Data Replicator Do you need to copy files from one system to another on a regular basis? Data Replicator makes this job much easierit allows you to watch files or folders for changes, and then replicate them to another location. You can copy files across a LAN, WAN, or via FTP, which makes Data Replicator a great alternative to traditional backup software. For more information, see http://www.purenetworking.net/Products/DataReplicator/DataReplicator.htm Virtual Network Computing (VNC) Take control of your remote servers from the comfort of your
desk. VNC lets you control Windows, Unix, and Mac machines. For more information, see http://www.realvnc.com. Network View With this handy tool, you'll never need to draw out your network. It automatically generates a network diagram for you within minutes. For more information, see http://www.networkview.com. Janet Ryding
Hack 16 myITforum.com One of the best resources around for administrators who deploy and manage Windows-based networks, myITforum.com is best described by its CEO and founder, Rod Trent. myITforum.com (http://www.myitforum.com) is the leading systems administration web site and community. It was created to be the Internet's premiere knowledge and information forum for IT professionals. The web site provides IT administrators the opportunity to gain better insight about what they do by learning/sharing from other IT experts throughout the world. Through the web site, myITforum.com users give tips, share insight, and download utilities and tools to assist them in managing their IT enterprises. Whether you oversee 10 nodes or 100,000 nodes, myITforum.com can help you manage your environment. myITforum.com is managed by Rod Trent (myself!), a Microsoft MVP and author of the best-selling books Microsoft SMS Installer, Admin911: SMS, and IIS 5.0: A Beginner's Guide. Rod Trent is the leading authority on Microsoft SMS and an annual presenter and keynote presenter at the annual Microsoft Management Summit (http://www.microsoft.com/management/training/mms.mspx). He has over 18 years of IT experience, 8 of which have been dedicated to SMS. In addition to his best-selling books, Rod has written thousands of articles on technology topics in many publications, on the Web, and in the form of Microsoft white
papers, case studies, and technical guides. Rod is also a principal in NetImpress, Inc. (http://www.netimpress.com), a technology publishing company. History myITforum.com's roots lead back to the now defunct Swynk.com web site. Swynk.com was founded and operated by Stephen Wynkoop until 1999. Stephen had developed a web site that allowed administrators all over the world to gain support for their everyday IT tasks. myITforum.com was built on the success of the Systems Management Server (SMS) section of Swynk.com. The success of the SMS section led to an urgency to keep the ever-growing community alive when it was evident that the parent company of Swynk.com was not going to support it. Swynk.com had become much more than simply content and articles, and it became evident that the web site had outgrown its electronic boundaries. It had become a live community that was represented both on the Web and in the real IT world. So, the SMS community from Swynk.com migrated to its web site location: http://www.myitforum.com. Since the move, myITforum.com has grown by leaps and bounds, primarily due to the opportunities it presents to administrators all over the world to interact with their fellow administrators and peers. The members of the myITforum.com community are the most caring folks found in any corner of the Internet. They give their time, experience, and knowledge selflessly to help create a brain trust of smarter administrators who become efficient and proficient IT professionals. Scope
While myITforum.com was based on Microsoft Systems Management Server, it has grown far beyond this one topic. To be an SMS administrator, an IT professional must be proficient in far more than just SMS. SMS administrators are required to support many different applications, operating systems, and technologies. Because of this requirement and myITforum.com's ability to grow quickly with the community needs, myITforum.com expanded its topic base to include many more areas in the IT world. myITforum.com supports Altiris products, Microsoft Operations Manager (MOM), VBScript, SMS 1.2/2.0/2003, Windows, SQL Server, Networking, Active Directory, security and patch management, antivirus technologies, Windows Mobile technologies, web technologies, and deployment technologies such as Windows Installer. MyITforum.com supports these many topics through articles, email discussion lists, and web-based forums Figure 1-18 shows the myITforum.com home page. The articles posted to the web site are quite a bit different than the articles you find in other publications. Instead of information from individuals you can't be sure have ever worked in IT, the myITforum.com articles are from real IT workers from real IT experiences. The premise is that if you are faced with a real-world situation, someone out there has probably already been through it and has the solution all wrapped up. By sharing their experiences through articles, the myITforum.com columnists provide a central location for IT administrators all of the world to get solutions to problems they might be facing, without having to spend days or weeks working through a tough situation. If it's a problem, someone has already faced it and succeeded, and the solution is probably outlined on myITforum.com. Figure 1-18. Home page of myITforum.com
In addition to providing these web resources for the myITforum.com community, myITforum.com has transcended the confines of the Internet. Because real IT professionals make up the myITforum.com community, myITforum.com has reached beyond the Web to aid real people in setting up real-world local communities. myITforum.com has been instrumental in setting up over 17 user groups all over the world. From the U.S. to Canada to Israel to Australia, myITforum.com has provided valuable time and resources to set up and manage some of the
most successful user group communities in the real world. myITforum.com provides many things to the user groups, including a free web site for the group's web presence, contacts with vendors for speaking services, and an intermediary link between Microsoft and the user group for planning, support, and meeting facilities. Over time, myITforum.com has also become a successful liaison between employers and prospective employees. Offered as a free service, myITforum.com has helped place hundreds of qualified employees into IT jobs. During the last few years, when the economy has caused layoffs and outsourcing, myITforum.com has stood as a central beacon for employers and employees to connect with each other. So, in addition to providing a central repository for connecting with peers, myITforum.com has become an informal meeting place, where workers find employment and employers locate the top candidates for open positions. It has been noted that if you attend any IT event, anywhere in the world, you will find at least one myITforum.com community member. myITforum.com's influence reaches into almost every nook of the IT world, primarily because it provides what IT professionals need to advance to a higher level in their profession, but also because it provides a level of sharing that can't be experienced anywhere else. myITforum.com is a real community comprised of real people with real personalities. Participating in myITforum.com is like meeting with friends. myITforum.com is an ever-evolving, ever-growing community meeting place that extends experience and knowledge that is more valuable than sitting through a weeklong training class. At the end of the day, myITforum.com is the one location for everything IT. Rod Trent
Chapter 2. Active Directory Hacks #17-24 Section 17. Retrieve the List of Old Domain Computer Accounts Section 18. Automate Creation of OU Structure Section 19. Modify All Objects in the OU Section 20. Delegate Control of an OU to a User Section 21. Send OU Information in Active Directory to an HTML Page Section 22. Display Active Directory Information Section 23. Store and Display Contact Information in Active Directory Section 24. Restore the Active Directory Icon in Windows XP
Hacks #17-24 Most of the time you're administering Active Directory, you're probably using the Active Directory Users and Computers console. Like most GUI tools, this console is easy to use but ill- suited for complex or repetitive tasks. That's where scripts come in, and this chapter includes a handful of VB scripts that leverage the Active Directory Services Interface (ADSI) and Windows Management Instrumentation (WMI) to make your life simple. These scripts can be used to perform tasks such as searching for old computer accounts, creating organizational units (OUs), delegating authority over OUs, and displaying information about objects stored in Active Directory. See Chapter 3 for additional scripts targeted mainly to administering users and groups with Active Directory. As with any custom scripts, be sure to try them in a test environment before using them on your production network. Also make sure that you have the latest scripting engines on the workstation or server from which you run these scripts. You can download the latest scripting engines from the Microsoft Scripting Home Page (http://msdn.microsoft.com/scripting/). Finally, note that when you work with ADSI you must have the same applicable rights you use for running the built-in administrative tools. Typically, what this means is that you need to be a member of either the Administrators group on the machine being targeted or the Domain Admins group in an Active Directory environment.
Hack 17 Retrieve the List of Old Domain Computer Accounts Finding inactive computer accounts in Active Directory is a choreunless, of course, you script it. If you need to quickly retrieve a list of old (inactive) computer accounts in the domain, VBScript is your utility of choice. The script in this hack first asks for the domain name (Figure 2-1), then prompts for the number of days for active computer accounts (Figure 2-2), and then, finally, displays the old computer accounts that are found in the domain. Figure 2-1. Specifying the name of your domain
Figure 2-2. Specifying number of days for cutoff The computer accounts shown have not been active during the days you specified. For example, when we run the script we can see that the computer account for the machine named SRV111 has a password whose age is beyond the cutoff, so the script recommends that you delete this account to be safe (Figure 2- 3). Figure 2-3. Recommending an account that should be deleted This is a great, quick way to find those computers that could be having trouble authenticating, or those that have been brought
down but remain in the domain's list. The Code Type the following code into Notepad (make sure Word Wrap is turned off), and save it with a .vbs extension as DeleteOldComputers.vbs: On Error Resume Next DomainString=Inputbox("Enter the domain name","Check Active Computers","DomainName") if DomainString="" then wscript.echo "No domain specified or script cancelled." wscript.quit end if numDays=InputBox("What is the number of days to use as a cutoff for" & _ "Active Computer Accounts?","Check Active Computers","XX") if numDays="" then
wscript.echo "No cutoff date specified or script cancelled." wscript.quit end if Set DomainObj = GetObject("WinNT://"&DomainString) if err.number<>0 then wscript.echo "Error connecting to " & DomainString wscript.quit end if DomainObj.Filter = Array("computer") Wscript.echo "Computer Accounts in " & DomainString & " older than " & _ numDays & " days." For each Computer in DomainObj Set Account = GetObject("WinNT://" & DomainString & "/" & Computer.Name & _ "$") RefreshTime = FormatNumber((Account.get("PasswordAge"))/86400,0) If CInt(RefreshTime) >= CInt(numDays) Then
wscript.echo "DELETE " & Computer.Name & " Password Age is " & _ RefreshTime & " days." End If Next set DomainObj=Nothing set Shell=Nothing Wscript.quit Running the Hack To run this script, use Cscript.exe, the command-line script engine for the Windows Script Host (WSH). Here's some sample output when the script is run to delete computer accounts older than 90 days in the MTIT domain: C:>cscript.exe DeleteOldComputers.vbs Microsoft (R) Windows Script Host Version 5.6 Copyright (C) Microsoft Corporation 1996-2001. All rights reserved. Computer Accounts in mtit older than 90 days. DELETE NEWTEST1 Password Age is 151 days.
DELETE QWER Password Age is 151 days. DELETE SRV211 Password Age is 97 days. DELETE SRV212 Password Age is 154 days. Rod Trent
Hack 18 Automate Creation of OU Structure Here's a snappy method for creating a standard hierarchy of organizational units (OUs) for a domain. If you manage deployment of Active Directory in a medium- sized or large organization, you probably are spending a significant amount of time trying to maintain consistency in the Active Directory hierarchy. Even within a single domain, it typically makes sense to keep your organizational units (OUs) structured according to some agreed-upon rules. Regardless of whether your top-tier OU design is based on functional, business, geographic, or some other criteria, you will likely benefit from keeping the lower tiers arranged in the same fashion. This way, for example, you can formulate standard operating procedures that will apply across the entire organization. You can also attempt to automate some of the common administrative tasks, such as user, group, or computer account creation; script delegations and permission assignments; and group policy object management on the OU level. One of the ways to make sure that the structure will remain consistent throughout Active Directory deployment is to script the OU-creation process. The script in this hack creates a sample OU hierarchy. The assumption is that the top-level OUs are created manually, while the lower layers are always the same. The structure follows Microsoft best practices and
includes two second-tier OUs: Accounts and Resources. The Accounts OU is further divided into Users, ServiceAccounts, Groups, and Admins. Resources consists of Workstations and Servers. It is fairly easy to extend this structure (for example, you could create separate OUs for different server types, such as File, Print, or TerminalServices, beneath the Servers OU). The script performs some error checking to verify that the respective organizational units haven't been created yet. The Code The following VBScript is a Windows script (*.wsf) file, a text document that contains Extensible Markup Language (XML) code. Using a text editor such as Notepad (with Word Wrap turned off) type the following code and save it as CreateOU.wsf:
<?xml version="1.0"?> <script language="VBscript"> '*** Accounts children OUs - Users, ServiceAccounts, Groups, Admins '*** Resources children OUs - Workstations, Servers '*** '*** To execute, run cscript.exe //nologo CreateOUs.wsf OUName '*** where OUName is the name of the top level OU Option Explicit Dim strOU1 'the first level OU Dim strOU2 'the second level OU Dim strOU3 'the third level OU Dim arrOUTier2 'array of the second level OUs Dim arrOUTier3a 'first array of the third level OUs Dim arrOUTier3b 'second array of the third level OUs Dim strDomainDN 'name of the domain Dim strADsPath 'ADsPath of the first level OU Dim strADsSubPath 'ADsPath of the second level OUDim adsRootDSE 'aDSRootDSE object Dim adsContainer, adsSubContainer, adsOU 'variables representing AD container objects '*************************************************************** '*** Connect to the current domain Set adsRootDSE = GetObject("LDAP://rootDSE") strDomainDN = adsRootDSE.Get("defaultNamingContext") '*************************************************************** '*** Connect to the top level OU strOU1 = WScript.Arguments(0) strADsPath = "LDAP://OU=" & strOU1 & "," & strDomainDN Set adsContainer = GetObject(strADsPath) On Error Resume Next
arrOUTier2 = Array("Accounts", "Resources") arrOUTier3a = Array("Users", "ServiceAccounts", "Groups", "Admins") arrOUTier3b = Array("Workstations", "Servers") '*************************************************************** '*** Populate the OU structure For Each strOU2 in arrOUTier2 Set adsOU = adsContainer.Create("OrganizationalUnit", "OU=" & strOU2) adsOU.SetInfo If ErrCheck(Err, strOU2) <> 2 Then strADsSubPath = "LDAP://OU=" & strOU2 & ",OU=" & strOU1 & "," & strDomainDN Set adsSubContainer = GetObject(strADsSubPath)
Select Case strOU2 Case "Accounts" For Each strOU3 in arrOUTier3a Set adsOU = adsSubContainer.Create("OrganizationalUnit", "OU=" & strOU3) adsOU.SetInfo Call ErrCheck(Err, strOU3) Next Case "Resources" For Each strOU3 in arrOUTier3b Set adsOU = adsSubContainer.Create("OrganizationalUnit", "OU=" & strOU3) adsOU.SetInfo Call ErrCheck(Err, strOU3) Next End Select End If Next
On Error GoTo 0 Set adsOU = Nothing Set adsContainer = Nothing '*************************************************************** '*** Error checking function Function ErrCheck(objErr, strObj) If objErr.Number <> 0 Then 'if the object already exists If objErr.Number = &H80071392 Then WScript.Echo "The OU " & strObj & " already exists" ErrCheck = 1 Else
WScript.Echo "Unexpected error " & objErr.Description ErrCheck = 2 End If Else ErrCheck = 0 End If objErr.Clear End Function ]]> </script>
Running the Hack To execute the script, open a command prompt, change to the directory in which CreateOUs.wsf resides, and type cscript.exe //nologo CreateOUs.wsf "OUName", where OUName is the name of the top-level OU. If OUName does not already exist, you'll get an error. To illustrate how this script works, I first created an OU named Boston in the mtit.com domain and then ran cscript.exe //nologo CreateOUs.wsf "Boston" from the command line. Figure 2-4 shows the result in Active Directory Users and Computers. Figure 2-4. OU hierarchy for Boston
Marcin Policht
Hack 19 Modify All Objects in the OU Use this script to quickly change specific properties of all objects within an organizational unit. Using GUI tools such as Active Directory Users and Computers to modify the properties of objects stored in Active Directory is a slow process. In Windows 2000, you have to open the properties sheet for each object, switch to the appropriate tab, and make the change; then, you must do it over and over again for other objects. In Windows Server 2003, you can open the properties of multiple objects simultaneously, but not all tabs are available when you do this and only a small number of settings can be modified in this way. It would be nice if there were a faster way of doing this. Using VBScript, this is indeed possible. The sample script in this hack shows how you can modify the properties of all objects in a specific OU. This particular script modifies the state, address, postal code, and city for all User objects in the Boston OU in the mtit.com domain, but it can easily be customized to modify other properties of objects. This script is particularly useful if you've planned your implementation of Active Directory so that users in the same OU have certain sets of similar properties, such as their business address information. The Code
Type the following script into Notepad (with Word Wrap disabled) and save it with a .vbs extension as ModifyUsers.vbs. Be sure to customize the second line to specify the OU and domain for your own environment, and customize the Put statements to use the address information appropriate for users in your OU. Dim oContainer Set oContainer=GetObject("LDAP://OU=Boston,DC=mtit,DC=com") ModifyUsers oContainer 'cleanup Set oContainer = Nothing WScript.Echo "Finished" Sub ModifyUsers(oObject) Dim oUser oObject.Filter = Array("user") For Each oUser in oObject
oUser.Put "st","Your State" oUser.Put "streetAddress","Your Address" oUser.Put "postalCode","Your Zip" oUser.Put "l","Your City" oUser.SetInfo Next End Sub Running the Hack To run the script, simply create a shortcut to it and double-click on the shortcut. A dialog box will appear, indicating that the script ran successfully. Figure 2-5 shows what the Address tab of the properties sheet for user Bob Smith (who is in the Boston OU) looks like after running the script. Figure 2-5. Result of running the ModifyUsers.vbs script
Rod Trent
Hack 20 Delegate Control of an OU to a User Rather than use the Delegation of Control Wizard, use this script to delegate authority over an organizational unit (OU) to a particular user. By delegating administrative responsibilities, you can eliminate the need for multiple administrative accounts that have broad authority (such as over an entire domain). Although you likely will still use the predefined Domain Admins group for administration of the entire domain, you can limit the accounts that are members of the Domain Admins group to highly trusted administrative users. Administrative control can be granted to a user or group by using the Delegation of Control wizard. The Delegation of Control wizard allows you to select the user or group to which you want to delegate control, the organizational units and objects you want to grant those users the right to control, and the permissions to access and modify objects. The Code While using the wizard to do this is straightforward, there is a quick and easy way to achieve the same effect through
VBScript. Just open a text editor such as Notepad (making sure that Word Wrap is disabled), type the following script, and save it with a .vbs extension as DelegateOU.vbs: Set ou = GetObject("LDAP://OU=Test,OU=Users,OU=Services,OU=Network,DC=MY,DC=Domain, DC=com") Set sec = ou.Get("ntSecurityDescriptor") Set acl = sec.DiscretionaryAcl Set ace = CreateObject("AccessControlEntry") ace.AceType = ADS_ACETYPE_ACCESS_ALLOWED_OBJECT ace.AccessMask = ADS_RIGHT_DS_CREATE_CHILD Or ADS_RIGHT_DS_DELETE_CHILD ace.ObjectType = "{BF967ABA-0DE6-11D0-A285-00AA003049E2}" 'User's GUID (schemaIDGuid) ace.AceFlags = ADS_ACEFLAG_INHERIT_ACE ace.Flags = ADS_FLAG_OBJECT_TYPE_PRESENT ace.Trustee = "MY\Jsmith" 'User to delegate to acl.AddAce ace sec.DiscretionaryAcl = acl ou.Put "ntSecurityDescriptor", Array(sec) ou.SetInfo
Set ace = Nothing Set acl = Nothing Set sec = Nothing When you run this script, the result is to delegate to the user the ability to create and delete users in the MY.DOMAIN.COM/NETWORK/SERVICES/USERS/TEST organizational unit. The first line you need to customize to make this work in your own environment is this one: Set ou = GetObject("LDAP://OU=Test,OU=Users,OU=Services,OU=Network," & _ DC=MY,DC=Domain,DC=com") You must insert the distinguished name (DN) of the OU to which you want to delegate this right in the LDAP URL section of the command line. For example, if you want the delegated user to be able to add and delete users in the OU called UR.DOMAINHERE.COM/HR/USERS, the line would need to look like this: Set ou = GetObject("LDAP:// OU=Users,OU=HR,DC=Ur,DC=Domainhere,DC=com") Here is another line you need to modify for your environment: ace.Trustee = "MY\Jsmith" User to delegate to In the section in double quotes ("MY\Jsmith"), you must insert the username for the user to whom you want to delegate the right to add and delete users. For example, if the user that you want to be able to ADD and DELETE users is called Janedoe, the line would look like this: ace.Trustee = "UR\Janedoe" 'Who is the beneficiary of this ace
Make sure you have the latest scripting engines on the workstation you run this script from; you can download current scripting engines from the Microsoft Scripting home page (http://msdn.microsoft.com/library/default.asp? url=/nhp/Default.asp?contentid=28001169). When working with the Active Directory Services Interface (ADSI), you must have the same applicable rights you need to use the built-in administrative tools. Running the Hack To run the script, simply create a shortcut to the script and double-click on the shortcut. The script itself does the rest. Hans Schefske
Hack 21 Send OU Information in Active Directory to an HTML Page Here's a terrific way to quickly display all the organizational units (OUs) in a domain. If your Active Directory (AD) domains have a lot of OUs in them, it's easy to lose track of them, especially if you have OUs nested within OUs. This handy script generates an HTML page of all OUs in your current AD domain showing their path, description, and creation date. This information not only tells you which OUs you have in your domain, it also tells you which OUs contain other OUs, so you can easily create a map of the OU structure of your domain. The Code Just open Notepad or some other text editor (with Word Wrap disabled), type the following script, and save it with a .vbs extension as OU2HTML.vbs: On Error Resume Next Dim Root,Domain,wshNetwork
Dim oFileSys,fh Set Root = GetObject("LDAP://RootDSE") DomainPath = Root.Get("DefaultNamingContext") Set Domain = GetObject("LDAP://" & DomainPath) set wshNetwork=CreateObject("Wscript.Network") myDomain=wshNetwork.UserDomain htmlfile=myDomain & "-OUs.htm" Set oFileSys=CreateObject("Scripting.FileSystemObject") Set fh=oFileSys.CreateTextFile(htmlfile) fh.WriteLine "<HTML>" fh.WriteLine "" & myDomain & " & _ "Organizational Units
"
fh.WriteLine "" fh.WriteLine "" fh.WriteLine "" fh.WriteLine "" fh.WriteLine "" wscript.echo "Getting OU information for " & mydomain & "..." & _ EnumOU Domain.ADSPath fh.WriteLine "
" & _ "OU | Description | " & _ "Path | " & _ "Created |
Set oFileSys=Nothing Set fh=Nothing Set domain=Nothing Set Root=Nothing Set wshNetwork=Nothing wscript.quit '***************************************** Sub EnumOU(objPath) 'On Error Resume Next Set objPath = GetObject(objPath) objPath.Filter=Array("organizationalUnit")
For Each item in objPath If item.Description="" Then ouDescription="N/A" Else ouDescription=item.Description End If fh.writeLine "" & MID(item.Name,4) & "" & ouDescription & _ "" & item.ADSPath & "" & GetCreated(item.ADSPath) & "" 'Uncomment next line for debugging purposes ' wscript.echo item.Name & vbTab & item.Description & vbTab & item.ADSPath 'Iterate through EnumOU item.ADSPath Next
Set objPath=Nothing End Sub '**************************** Function GetCreated(objPath) On Error Resume Next Set objDetail=GetObject(objPath) Set objSchema=GetObject(objDetail.Schema) For Each z in objSchema.OptionalProperties Set adsProperty = GetObject("LDAP://Schema/" & z) If z="whenCreated" Then strCreated = objDetail.Get(z) GetCreated=strCreated 'wscript.echo "Created " & strCreated
strValue="" End If Next End Function Running the Hack To run the script, simply create a shortcut to the script, double- click on the shortcut, and follow the prompts provided by the dialog boxes the script generates. When the script runs, it creates an HTML page in the same directory in which the script itself is located. The name of this HTML page is domain-OUs.htm, where domain is the name of your domain. Figure 2-6 shows a sample HTML page created for a test domain named mtit.com. Figure 2-6. OUs in the mtit.com domain
It's easy to see from the Path column in Figure 2-6 that the Local and National OUs are contained within the Sales OU. Hans Schefske
Hack 22 Display Active Directory Information Here are five sample scripts that can be used to display information about computers, domains, sites, and trusts in Active Directory. Scripts are a quick way to drill down into Active Directory to display information you'd otherwise have to hunt for using the GUI. These five sample scripts can be used by themselves or as starting points for developing more sophisticated scripts. Just type them into Notepad (with Word Wrap turned off) and save them with a .vbs extension. Then, type cscript.exe scriptname.vbs to run them from a command prompt. Enjoy! List All Computers in the Domain The following VBScript retrieves a list of all computers in a given domain (or Active Directory container). Modify the Domain to your company's NT/2000 domain name or Active Directory container, and the list of registered computers will display: Dim Container Dim ContainerName
Dim Computer
ContainerName = "Domain"
Set Container = GetObject("WinNT://" & ContainerName)
Container.Filter = Array("Computer")
For Each Computer in Container
Response.Write Computer.Name & "
"
Next
Get a List of All Domains
This VBScript enumerates and lists all domains:
Dim NameSpace
Dim Domain
Set NameSpace = GetObject("WinNT:")
For Each Domain in NameSpace
Response.Write Domain.Name & "
"
Next
Get AD Site
This VBScript retrieves the name of the site to which the computer is assigned: Set WshShell = Wscript.CreateObject("Wscript.Shell") On Error Resume Next Site = "Not Assigned" Site = WshShell.RegRead( "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet" & _ "Services\Netlogon\Parameters\SiteName" ) If Err.Number=-2147024894 Then Site = WshShell.RegRead( "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet" & _ "Services\Netlogon\Parameters\DynamicSiteName" ) End If If Site = "Not Assigned" Then WScript.Echo "This computer is not assigned to an Active Directory site." Else WScript.Echo "This computer is assigned to Active Directory site: " & site End If Find a DC in a Site
Use this VBScript to verify that a specific domain controller (DC) exists in a site. Just replace the items in double quotes in the first two lines with your values: strDcName = "DCName" strSiteName = "SiteName" Set objADSysInfo = CreateObject("ADSystemInfo") strDcSiteName = objADSysInfo.GetDCSiteName(strDcName) If UCase(strSiteName) = UCase(strDcSiteName) Then WScript.Echo "TRUE: " & strDcName & " is in site " & strSiteName Else WScript.Echo "FALSE: " & strDcName & " is NOT in site " & strSiteName End If List Trust Relationships Use this script to enumerate the trust relationships for your domain and display the results: strComputer = "." Set objWMIService = GetObject("winmgmts:" _
& "{impersonationLevel=impersonate}!\" & _ strComputer & "\root\MicrosoftActiveDirectory") Set colTrustList = objWMIService.ExecQuery _ ("Select * from Microsoft_DomainTrustStatus") For each objTrust in colTrustList Wscript.Echo objTrust.TrustedDomain Wscript.Echo objTrust.TrustDirection Wscript.Echo objTrust.TrustType Wscript.Echo objTrust.TrustAttributes Wscript.Echo objTrust.TrustedDCName Wscript.Echo objTrust.TrustStatus Wscript.Echo objTrust.TrustIsOK Next Rod Trent
Hack 23 Store and Display Contact Information in Active Directory Using a script and an Access database, you can store detailed contact information in Active Directory and display it as an HTML page. Would you like to store all your employee contact information in Active Directory and then be able to display that information on an intranet page? Where I work, there are a number of individuals maintaining lists of user information. The telecom person maintains an Excel spreadsheet of employee names, phone numbers, and office locations. The Web person maintains a similar list for the Internet page. There's another list of sorts in a public folder on our Exchange server. I thought there must be a better way to get this information out that doesn't require quite so many people doing similar tasks. Figure 2-7 shows my solution to this challenge. Figure 2-7. HTML interface for Access database
I created an Access database named EmployeeInfo.mdb, with fields for the information I'd like to make available. I then created a .vbs script named ExportAdUsers.vbs, which processes Active Directory user accounts that meet a specified criterion and exports the account information to the database. The information in the database is accessible via the Data Access Page shown in Figure 2-7. While developing this solution, I found that I needed to be able to list information for employees who might not have an Active Directory user account. The database is open, so a designated person can maintain information for such employees. Each time Active Directory account information is updated, the script should be run again to update the Access database. I added a field to the database that contains a value that differentiates records that were manually entered from records that were created by running the script. To be sure that no duplicates exist in the database, prior to performing each export, the script deletes all records that are indicated as being exported from Active Directory. The Code Type the following VBScript into Notepad (with Word Wrap turned off) and save it with a .vbs extension as ExportAdUsers.vbs: Option Explicit ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
' File: ExportADUsers.vbs ' Updated: Dec 2003 ' Version: 1.0 ' Author: Dan Thomson, myITforum.com columnist ' I can be contacted at dethomson@hotmail.com ' ' Usage: This script should be run using cscript. ' cscript ExportADUsers.vbs ' ' Input: None ' ' Notes: This script exports all users whose accounts are not disabled, ' not expired, or do not have NoExport in their Notes section. ' There is also a constant "Users2Skip" to which you should add ' any names which should not be exported. ' ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
On Error Resume Next ' The name of the Access database to use Const AccessDatabase = "EmployeeInfo.mdb" ' The name of the Access table to use Const AccessTable = "tblEmployeeInfo" ' List of users who should NOT be exported ' This list should contain the user's logon name ' Separate each name by a comma Const Users2Skip = "Guest" ' Constant for the account being disabled Const ADS_UF_ACCOUNTDISABLE = 2 ' Constant for the search to search subtrees Const ADS_SCOPE_SUBTREE = 2
Const adOpenStatic = 3 Const adLockOptimistic = 3 ' General variable declarations Dim objConnectionDB, objRecordsetDB Dim objConnectionAD, objCommandAD, objRecordsetAD Dim dtStart Dim strSQL Dim objRootDSE, strDNSDomain Dim strDN, intUAC, strSam, strDisplayName, strManagerDN, dtExpireDate Dim blnProcessUser Dim objUser, objManager ' Get the start time of the script dtStart = TimeValue(Now( )) 'Create and open ADO connection to the Access database Set objConnectionDB = CreateObject("ADODB.Connection")
Set objRecordsetDB = CreateObject("ADODB.Recordset") ' Open the database objConnectionDB.Open "Provider=Microsoft.Jet.OLEDB.4.0;" & _ "Data Source=" & AccessDatabase & ";" ' Open the recordset objRecordsetDB.Open AccessTable, objConnectionDB, adOpenStatic, adLockOptimistic ' Define the SQL statement used to clear out previous ' user info which was exported from AD strSQL = "DELETE FROM " & AccessTable & " WHERE ImportedFromAD = 'True'" Wscript.Echo "Removing previously exported records from the " & _ AccessDatabase & " database." objConnectionDB.Execute strSQL, , 129
' Determine the DNS domain from the RootDSE object. Set objRootDSE = GetObject("LDAP://RootDSE") strDNSDomain = objRootDSE.Get("defaultNamingContext") ' Create and open an ADO connection to AD Set objConnectionAD = CreateObject("ADODB.Connection") Set objCommandAD = CreateObject("ADODB.Command") objConnectionAD.Provider = "ADsDSOObject" objConnectionAD.Open "Active Directory Provider" ' Set connection properties With objCommandAD .ActiveConnection = objConnectionAD ' Use SQL syntax for the query ' This retrieves all values named in the SELECT section for ' user accounts which do not have the Notes section = NoExport.
' The recordset is sorted ascending on the displayName value. .CommandText = _ "Select userAccountControl, distinguishedName," & _ " sAMAccountname, displayName" & _ " FROM 'LDAP://" & strDNSDomain & "'" & _ " WHERE objectCategory = 'person' AND" & _ " objectClass = 'user' AND info <> 'NoExport'" & _ " ORDER BY displayName" .Properties("Page Size") = 1000 .Properties("Timeout") = 30 .Properties("Searchscope") = ADS_SCOPE_SUBTREE .Properties("Cache Results") = False End With Wscript.Echo "Running the query to find users." Set objRecordSetAD = objCommandAD.Execute
' Move to the first record in the recordset objRecordSetAD.MoveFirst ' Loop until we reach the end of the recordset Do While NOT objRecordsetAD.EOF ' Blank out/reset a few variables..just in case. strDN = "" intUAC = "" strSam = "" strDisplayName = "" strManagerDN = "" dtExpireDate = "" blnProcessUser = True ' Get the userAccountControl value. This lets us, among other things, ' determine if the account is disabled. intUAC = objRecordsetAD.Fields("userAccountControl")
' Process user if account is not disabled. If (NOT intUAC AND ADS_UF_ACCOUNTDISABLE) Then ' Get the user's logon name strSam = objRecordsetAD.Fields("sAMAccountname") ' Determine if the user is included in the list of logon names to skip. If Instr(UCase(Users2Skip), UCase(strSam)) Then blnProcessUser = False ' Get the user's display name strDisplayName = objRecordsetAD.Fields("displayName") ' Set boolean value to skip this user if the user's display name is ' blank. If strDisplayName = "" Then blnProcessUser = False
' If our simple checks went ok, we can now process this user. If blnProcessUser = True Then ' Get the distinguished name of this user ' The syntax is something like: ' CN=Joe E. Law,OU=Sales,OU=US,DC=mydomain,DC=local strDN = objRecordsetAD.Fields("distinguishedName") ' Bind to the user object Set objUser = GetObject("LDAP://" & strDN & "") ' Process the user With objUser Wscript.Echo "Processing user: " & strDisplayName ' Get the user's account expiration date dtExpireDate = CDate(.AccountExpirationDate)
' Process the user if the user's account expiration date is not passed If (dtExpireDate = "") OR _ (dtExpireDate = CDate("01/01/1970")) OR _ (dtExpireDate >= Date( )) Then 'Add new record to the Access database objRecordsetDB.AddNew ' Get user data from AD and populate the new record in the ' Access database ' You can use the .Get("xxx") or .xxx formats to retrieve the data ' All fields on the left MUST exist in the Access table objRecordsetDB("FirstName") = .Get("givenName") objRecordsetDB("MiddleName") = .initials objRecordsetDB("LastName") = .sn objRecordsetDB("DisplayName") = .displayName
objRecordsetDB("Description") = .description objRecordsetDB("OfficeLocation") = .physicalDeliveryOfficeName objRecordsetDB("WorkPhone") = .telephoneNumber objRecordsetDB("Email") = .mail objRecordsetDB("WebPage") = .wwwHomePage objRecordsetDB("Street") = .streetAddress objRecordsetDB("POBox") = .postOfficeBox objRecordsetDB("City") = .l objRecordsetDB("StateOrProvince") = .st objRecordsetDB("PostalCode") = .postalCode objRecordsetDB("CountryOrRegion") = .co objRecordsetDB("HomePhone") = .homePhone objRecordsetDB("Pager") = .pager objRecordsetDB("MobilePhone") = .mobile objRecordsetDB("FaxNumber") = .facsimileTelephoneNumber objRecordsetDB("Notes") = .info objRecordsetDB("Title") = .title objRecordsetDB("Department") = .department
objRecordsetDB("CompanyName") = .company ' Get the distiguished name of the manager strManagerDN = .manager ' If manager value is not blank then process If strManagerDN <> "" Then ' Bind to manager's account Set objManager = GetObject("LDAP://" & strManagerDN & "") ' Populate the Access database with the display name of the manager objRecordsetDB("Manager") = objManager.displayName ' Release this object reference Set objManager = Nothing End If ' Define that this record was exported from AD objRecordsetDB("ImportedFromAD") = "True"
' Commit the record objRecordsetDB.Update ' Release this object reference Set objUser = Nothing End If End With End If End If ' Move to the next record in the AD recordset objRecordsetAD.MoveNext Loop ' Close the Access database recordset objRecordsetDB.Close ' Close the Access database connection
objConnectionDB.Close ' Release these object references Set objRecordsetDB = Nothing Set objConnectionDB = Nothing ' Close the AD recordset objRecordsetAD.Close ' Close the AD connection objConnectionAD.Close ' Release these object references Set objRecordsetAD = Nothing Set objConnectionAD = Nothing ' Let the user know how long this process took WScript.Echo "The script completed in approximately " & _
Second(TimeValue(now( )) - dtStart) & _ " seconds." ' That's all folks! Wscript.Quit Running the Hack This database and script version has been tested on various versions of Windows (the minimum requirements tested were Windows 2000 Service Pack 2 running Internet Explorer 5 with Microsoft Windows Script v5.5 participating in a small Active Directory domain). Though this solution works for me, your results may vary due to environmental differences. I saved these items in a directory named C:\EmployeeInfo. If you save them somewhere else on your system, you will need to modify the Data Access Page connection string in the EmployeeInfo.htm file. This can be done from within Access or by editing the .htm file directly. Also, the script and database should be in the same directory. If they are in different directories, you should edit the AccessDatabase constant in the script to point to the proper location where the database is saved. To run the script, simply type cscript ExportAdUsers.vbs from the command line from the current directory in which the script is found. The script, database, and HTML form page are all available from the O'Reilly web site. Figure 2-8 shows a sample session on running the script.
Figure 2-8. Output of running the ExportAdUsers.vbs script Dan Thomson
Hack 24 Restore the Active Directory Icon in Windows XP A useful feature in Windows 2000 that enables users to browse Active Directory is missing in Windows XP; here's how to get it back. In Windows 2000, when Active Directory is deployed, a user can easily browse Active Directory by double-clicking on My Network Places and then double-clicking on Entire Network. This displays the Directory icon (Figure 2-9), which represents Active Directory for the network. Figure 2-9. The Directory icon in Windows 2000
Successive double-clicking on this icon can then display information about which users, groups, printers, and other objects are listed for each domain. For each object selected, only a limited amount of information is displayed, but this can sometimes be handy for users who need to browse the directory for information. For example, a User object has a properties sheet with only three tabs on it: General, Address, and Business (see Figure 2-10), which is much less than the dozen or so tabs displayed when the properties sheet for the object is opened in Active Directory Users and Computers. Note that the user information is grayed out in the Figure 2-10; this is because the currently logged on user (James Brown) is an ordinary user and therefore can view selected information about other users but cannot change this information. Figure 2-10. Browsing the Directory icon for information about a user
Unfortunately, in Windows XP the directory icon is now gone, but if you want your users to have access to it, you can use this hack to add it back. If you have Windows 2000 computers running on your network (hopefully, with the latest service pack), the steps are simple. If not, you'll need the full instructions. The Easy Way
If you have a Windows 2000 computer handy, simply navigate to the C:\Windows\system32 directory of the Windows 2000 computer and find the dsfolder.dll file. Copy that file to the system32 directory of your Windows XP computer. Now click Start, and then click Run. In the Open box, type regsvr32 dsfolder.dll and then click OK. When you receive the message "DllRegisterServer in dsfolder.dll succeeded," click OK. The Hard Way If you don't have a Windows 2000 computer handy, do the following:
- Download the latest Microsoft Windows 2000 service pack from http://www.microsoft.com/windows2000/downloads/servicepacks/ Use an extract program (e.g., WinZip) to extract the files to a new folder. In the new folder, double-click i386. In the i386 folder, expand the compressed Dsfolder.dl file to Dsfolder.dll. To do so, first note the location of the folder where you extracted the files in step 2. For example, the i386 folder path might be C:\Documents and Settings\UserName\FolderName\i386 or something similar. Click Start, and then click Run. In the Open box, type a command that is similar to this: Expand "C:\Documents and Settings\UserName\FolderName\i386\Dsfolder.dl_"
"C:\Documents and Settings\UserName\FolderName\i386\Dsfolder.dll" In Windows Explorer, copy Dsfolder.dll from the i386 folder to the C:\Windows\System32 folder. Note that your Windows folder might be named something other than Windows, depending on whether you did a clean install or upgrade. Finally, click Start, and then click Run. In the Open box, type regsvr32 dsfolder.dll and then click OK. When you receive the message "DllRegisterServer in dsfolder.dll succeeded," click OK. The next time you view Network Neighborhood, you should have an Active Directory icon available. John Gormly
Chapter 3. User Management Hacks #25-35 Section 25. Search for Domain Users Section 26. Manage User Accounts in Active Directory Section 27. Get a List of Disabled Accounts Section 28. Get User Account Information Section 29. Check for Passwords that Never Expire Section 30. Enumerate Group Membership to a CSV File Section 31. Modify User Properties for All Users in a Particular OU Section 32. Check Group Membership and Map Drives in a Logon Script Section 33. Script Creation of a User's Home Directory and Permissions Section 34. Prevent Ordinary Users from Creating Local Accounts Section 35. Put a Logoff Icon on the Desktop
Hacks #25-35 A large part of day-to-day administration of an Active Directory environment is managing users and their accounts. The usual way of doing this is with the Active Directory Users and Computers (ADUC) console, but when it comes to organizations with thousands of users, this tool can be frustrating to use. This chapter is about alternatives to ADUCways of doing things faster using scripts. You'll find scripts to display information about users, find specific users on your network, change user passwords, unlock user accounts, get a list of disabled accounts, display which groups a user belongs to, and more. If you're familiar with VBScript, you can also customize these scripts further to meet the specific needs of your own networking environment. For all these scripts, make sure you have the latest scripting engines on the workstation from which you run the script. You can download the latest scripting engines from the Microsoft Scripting home page (http://msdn.microsoft.com/scripting/). Also, when working with the Active Directory Services Interface (ADSI), you must have the same applicable rights you need to use the built-in administrative tools. For more information, see Microsoft's ADSI web page (http://www.microsoft.com/windows2000/techinfo/howitworks/activedirectory/adsilinks.asp
Hack 25 Search for Domain Users Programmatically search for a user in a mixed Windows NT/2000 environment. If you are in the process of migrating from Windows NT to Windows 2000, you can certainly appreciate the search capabilities provided in Active Directory administrative tools. At the same time, more than ever, you suffer from its absence in the User Manager. This issue becomes especially acute in environments where there is no consistent naming convention or when the naming convention happened to change several times over years. The sorting feature might help, but only provided that a person responsible for creating accounts entered the full name correctly and in the same format. Misspellings or using diminutives and nicknames are other frequent causes of confusion. Your search becomes considerably more time consuming if you manage multiple domains with different naming conventions. To resolve a problem, you can employ a couple of approaches. The first one involves exporting a user list, along with each user's properties, into a comma-delimited file or a database (e.g., Access or SQL). The main drawback of this solution is the need for regular updates of the exported list. The second drawback, which eliminates the need for maintenance, is using an ADSI-based script. This approach is shown in the script that follows.
The Code The script allows searches against multiple domains. In order to accomplish this, you need to provide as the second input argument the list of domains (individual names need to be separated by semicolons). The first argument of the script is the part of the username (of any length) that you want to match against account names. Type the script into Notepad (with Word Wrap disabled) and save it with a .vbs extension as FindUser.vbs: '*************************************************************** '*** The script searches for a username in one on more domains by '*** looking for a match on the string of characters you specify. '*** '*** The syntax: '*** cscript //nologo FindUser.vbs string dom1[;dom2] '*** where string is used to match against the username '*** dom1;dom2 is the semicolon separated list of one or '*** more domains to search (no limit on number of entries) '*************************************************************** '*** variable declaration
Dim sName 'string to match against Dim sDom 'string storing list of domains Dim aDom 'array storing list of domains Dim iCount 'counter variable Dim oDomain 'object representing domain Dim oUser 'object representing user account Dim sLine 'string containing results of the search '*************************************************************** '*** variable initialization sName = Wscript.Arguments(0) sDom = Wscript.Arguments(1) aDom = Split(sDom, ";") '***************************************************************
'*** search for matches in the loop For iCount=0 To UBound(aDom) Set oDomain = GetObject("WinNT://" & aDom(iCount)) oDomain.Filter = Array("user") For Each oUser in oDomain If InStr(1, oUser.name, sName, 1) > 0 Then sLine = oDomain.Name & "" & oUser.Name & ";" SLine = sLine & oUser.Description & ";" SLine = sLine & OUser.FullName & ";" WScript.Echo sLine End If Next Next Running the Hack
When you run FindUser.vbs using Cscript.exe in a command- prompt window, you can easily find the full name and domain for a user, given his username. For example, when I search to see if the username bsmith is present in the MTIT domain, I find that user Bob Smith is assigned that username (Figure 3-1). Figure 3-1. Using FindUser.vbs to check whether username bsmith is already used Marcin Policht
Hack 26 Manage User Accounts in Active Directory Use these five handy scripts to easily manage domain user accounts. While the usual way of managing user accounts in Active Directory is to use the Active Directory Users and Computers (ADUC) console, that GUI approach to managing accounts can be tedious if your organization is large and you have many accounts to manage. This hack provides examples of scripts you can use to simplify things and speed up common administrative tasks, and I think you'll find them quite useful. You can even use some of them to delegate certain tasks to nonadministrators to save you time and trouble. To use one of these scripts, type it into Notepad (with Word Wrap turned off) and save it with a .vbs extension. Then, type cscript.exe scriptname.vbs from a command prompt, or create a shortcut to the script and double-click on the shortcut to run the script. Changing a User's Domain Password This simple script allows you to give others the ability to change end users' passwords without having to install the
administration tools. The script prompts for the domain, username, and new password, and notifies the user of whether the password change was successful: Dim UserName Dim UserDomain UserDomain = InputBox("Enter the user's domain:") UserName = InputBox("Enter the user's login name:") Set User = GetObject("WinNT://" & UserDomain & "/"& UserName &"",user) Dim NewPassword NewPassword = InputBox("Enter new password") Call User.SetPassword(NewPassword) If err.number = 0 Then Wscript.Echo "The password change was successful." Else Wscript.Echo "The password change failed!" End if
Changing User Account Names in Active Directory Using VBScript, changing a user's account name in the Active Directory is a quick process: Set oDomain = GetObject("WINNT:\domainname") Set oUser = oDomain.GetObject("originalusername") oDomain.MoveHere oUser.AdsPath, "newusername" You just need to connect to the specific domain (as indicated in the first line), set the original username (the second line), and then change the username using the MoveHere method (the third line). This is a much simpler process than opening up the MMC and either navigating to the username or searching the Active Directory for the account instances. A script like this is extremely useful for occasions when names change due to things like marriage, or when the user just can't stand the name they were given for logging in. Customize the script with the appropriate domain name (domainname), the user's old account name (originalusername), and the user's new account name (newusername). Unlocking a Windows 2000 Domain Account Need a quick and easy way to unlock a Windows 2000 domain
account? Use VBScript. The following script prompts for the username, then the user's domain, and unlocks the specified account: UserName = InputBox("Enter the user's login name that you want to unlock:") DomainName = InputBox("Enter the domain name in which the user account exists:") Set UserObj = GetObject("WinNT://"& DomainName &"/"& UserName &"") If UserObj.IsAccountLocked = -1 then UserObj.IsAccountLocked = 0 UserObj.SetInfo If err.number = 0 Then Wscript.Echo "The Account Unlock Failed. Check that the account is, " & _ "in fact, locked-out." Else Wscript.Echo "The Account Unlock was Successful" End if Disabling a Domain Account
Use this handy VBScript to quickly disable a user account in the specified domain. This script prompts for the username and domain and then disables the account you specify: Dim Username Dim UserDomain UserDomain = InputBox("Enter the user's domain:") UserName = InputBox("Enter the user's login name:") Set UserObj = GetObject("WinNT://" & UserDomain & "/" & Username &) UserObj.AccountDisabled = True UserObj.SetInfo Set UserObj = Nothing Setting the Account to Not Expire This handy script configures a user account to not expire. The script works by setting the expiration date attribute to a past date: Set objUser = GetObject _ ("LDAP://cn=yourcontainer,ou=yourOU,dc=yourDC,dc=com") objUser.AccountExpirationDate = "01/01/1970" objUser.SetInfo
To use the script, customize the second line as desired. For example, if the user account for user Bob Smith resides in the Sales OU in the mtit.com domain, this line should be changed to: ("LDAP://cn=Bob Smith,ou=Sales,dc=mtit,dc=com") Be judicious in deciding which accounts should be set to not expire, as such accounts could pose a security risk. See [Hack #29] for a quick way to search for such accounts on your network. Rod Trent
Hack 27 Get a List of Disabled Accounts Here's a fast way to determine any disabled user accounts in your Active Directory forest. Disabled accounts are accounts that still exist in Active Directory but cannot be used to log on to the network. For example, when an employee moves on to a different company, a common practice is to disable the individual's user account instead of deleting it. That way, the account can be reassigned to the individual's replacement, renamed, and used to access all the resources the previous employee had permission to access. Sometimes, though, you might forget which accounts have been disabled on your network, and it would be nice to have a way to find all disabled accounts. You can use this VBScript to do just thatlocate all of the disabled accounts in Active Directory. This is useful for inventory purpose but also for securityfor example, to verify that the Guest account and other vulnerable accounts are in fact still disabled on your network. The Code Simply type the script into Notepad (with Word Wrap turned off) and save it with a .vbs extension as DisabledAccounts.vbs:
Const ADS_UF_ACCOUNTDISABLE = 2 Set objConnection = CreateObject("ADODB.Connection") objConnection.Open "Provider=ADsDSOObject;" Set objCommand = CreateObject("ADODB.Command") objCommand.ActiveConnection = objConnection objCommand.CommandText = _ "GC://dc=rootdomain,dc=com;(objectCategory=User)" & _ ";userAccountControl,distinguishedName;subtree" Set objRecordSet = objCommand.Execute intCounter = 0 While Not objRecordset.EOF intUAC=objRecordset.Fields("userAccountControl") If intUAC AND ADS_UF_ACCOUNTDISABLE Then WScript.echo objRecordset.Fields("distinguishedName") & " is disabled" intCounter = intCounter + 1 End If
objRecordset.MoveNext Wend WScript.Echo VbCrLf & "A total of " & intCounter & " accounts are disabled." objConnection.Close Make sure you have the latest scripting engines on the workstation you run this script from. You can download the latest scripting engines from the Microsoft Scripting home page (http://msdn.microsoft.com/library/default.asp? url=/nhp/Default.asp?contentid=28001169). Also, when working with the Active Directory Services Interface (ADSI), you must have the same applicable rights you need to use the built-in administrative tools. Running the Hack To use the script, simply change this line to specify your own forest root domain: "GC://dc=fabrikam,dc=com;(objectCategory=User)" & _ For example, if your forest root domain is mtit.com, then the line should read: "GC://dc=mtit,dc=com;(objectCategory=User)" & _
Then, run the script by creating a shortcut to it and double- clicking on the shortcut. The output of the script is a series of dialog boxes, an example of which is shown in Figure 3-2. Figure 3-2. Displaying disabled domain user accounts Rod Trent
Hack 28 Get User Account Information Need to find information about user accounts on a machine? Use this handy script to do it fast. This script lets you quickly query a Windows 2000 (or later) machine to determine what user accounts are present, whether local accounts in the SAM database or domain accounts in Active Directory. It will output a list of accounts, giving the following information for each account: Username of user Full name of user Account lockout status Whether the user is allowed to change the password Whether the account is nonexpiring or not The Code
To use the script, simply type it into Notepad (with Word Wrap turned off) and save it with a .vbs extension as GetAccountInfo.vbs: ComputerName = localhost winmgmt1 = "winmgmts:{impersonationLevel=impersonate}!//"& ComputerName &"" Set UserSet = GetObject( winmgmt1 ).InstancesOf ("Win32_UserAccount") for each User in UserSet WScript.Echo "===============================================" WScript.Echo "Information for " & User.Name WScript.Echo "The full username for the specified computer is: " & _ User.FullName WScript.Echo "Account Locked? " & User.Lockout WScript.Echo "Password can be changed?: " & User.PasswordChangeable WScript.Echo "Password is expirable: " & User.PasswordExpires WScript.Echo "===============================================" Next
Running the Hack Here's some typical output when the script is run locally on a Windows 2000 domain controller. To avoid getting the series of dialog boxes that would appear if you ran the script using Wscript.exe, use Cscript.exe to run it from the command-line instead: C:>cscript.exe C:\MyScripts\GetAccountInfo.vbs Microsoft (R) Windows Script Host Version 5.6 Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.
Information for Administrator The full username for the specified computer is: Account Locked? False Password can be changed?: True Password is expirable: False
=============================================== Information for Guest
The full username for the specified computer is: Account Locked? False Password can be changed?: False Password is expirable: False
=============================================== Information for jsmith The full username for the specified computer is: Jane Smith Account Locked? False Password can be changed?: True Password is expirable: False
=============================================== Information for bsmith The full username for the specified computer is: Bob Smith Account Locked? False Password can be changed?: True Password is expirable: True
=============================================== The output continues for the remaining accounts on the system. Hacking the Hack You can easily modify the script to get user information from a remote computer instead of from the local computer on which the script is running. This is useful when you want to run the script from an administrator workstation instead of interactively on a domain controller. Simply change this line: ComputerName = localhost to this: ComputerName = InputBox("Enter the name of the computer you wish to query") The script will prompt you with a dialog box (see Figure 3-3) for the name of the remote computer whose accounts you want to query. You can specify the NetBIOS name, DNS name, or IP address of the remote machine, as long as your currently logged-on account has administrative privileges on the remote machine. Figure 3-3. Querying user account information on a remote computer
Rod Trent
Hack 29 Check for Passwords that Never Expire Here's a handy script that makes it simple to find user accounts with nonexpiring passwords. User accounts set to never expire are sometimes used for permanent employees of a company, while temporary employees are assigned accounts that expire after a specified period of time. Ever wish you could quickly and simply find out which user accounts have their passwords set to never expire, along with the dates the flags were set? Here is a sample script that accomplishes this and more. This script prompts for the desired domain, checks all user accounts in the domain to see if their passwords are set to never expire, and reports the date the flags were set. It then writes the output to a CSV file called PWDNeverExpired.csv, creating this file in the same directory where the script itself is located. If the password is not set to expire, the script instead records a No and the date the password will expire. The Code To use the script, type it into Notepad (with Word Wrap turned off) and save it with a .vbs extension as PWDNeverExpired.vbs:
' Set WshShell Set WshShell = WScript.CreateObject("WScript.Shell") strVer = "Ver 1.0 " Set FileSystem = WScript.CreateObject("Scripting.FileSystemObject") Set oFile = FileSystem.CreateTextFile("PWDNeverExpired.csv", true) ' Pull Environment variables for domain/user strDomain = WshShell.ExpandEnvironmentStrings("%USERDOMAIN%") strUserName = WshShell.ExpandEnvironmentStrings("%USERNAME%") strOS = WshShell.ExpandEnvironmentStrings("%OS%") strMessage = strMessage & "Hit Cancel or enter a blank to quit" strTitle = "Domain to Search" 'get resource domain name, domain default UserDomain = InputBox(strMessage, strTitle, strDomain) strMessage = "" strTitle = ""
'strMessage = "Please enter the USER Login ID" & vbCrLf & vbCrLf & _ '"Default is: " & strUserName & vbCrLf & vbCrLf 'strMessage = strMessage & "Hit Cancel or enter a blank to quit" 'strTitle = "USER Login ID" 'get resource domain name, domain default via input box 'objUserName = InputBox(strMessage, strTitle, strUserName) ' Display Just a minute! strMessage = "This may take a few seconds. . ." WshShell.Popup strMessage,2,"One moment please. . . " strMessage = "" Set ObjDomain = GetObject("WinNT://" & UserDomain) ObjDomain.Filter = Array("User") For Each ObjUser In ObjDomain 'Attempt to bind to the user
'Set objUser = GetObject("WinNT://"& UserDomain &"/"& objUser.Name, user) Set UserName = GetObject("WinNT://" & UserDomain & "/" & ObjUser.Name & _ ",User") ' Is password set to NEVER expire? objPwdExpires = UserName.Get("UserFlags") If (objPwdExpires And &H10000) <> 0 Then objPwdExpiresTrue = "Yes" strPwdExpires = "Date Set: " msgPwdExpires = "Password Set to Never Expire: " Else objPwdExpiresTrue = "No" strPwdExpires = "Password Expires: " msgPwdExpires = "Password Set to Never Expire: " End If oFile.WriteLine (UserName.fullname & "," & UserName.name & "," & _ msgPwdExpires & objPwdExpiresTrue & "," & strPwdExpires & _ objUser.PasswordExpirationDate) 'Wscript.Echo "Full Name: " & UserName.fullname & vbCrlf &_ '"Account Name: " & UserName.name & vbCrlf &_
'msgPwdExpires & objPwdExpiresTrue & vbCrlf &_ 'strPwdExpires & objUser.PasswordExpirationDate & vbCrlf Set UserName = Nothing Next Wscript.Echo "Done Cheking Accounts" Running the Hack To run this hack, simply create a shortcut to the script and double-click on the shortcut. Figure 3-4 shows a sample CSV output file for the script, viewed in Excel. Figure 3-4. Sample output from running PWDNeverExpired.vbs
Hans Schefske
Hack 30 Enumerate Group Membership to a CSV File Export a list of which users are in which groups to a comma- separated file that is suitable for opening in your favorite spreadsheet or database application. Finding out which users belong to which groups is not a trivial task from the GUI. Using Active Directory Users and Computers (ADUC), you can view the Member Of tab of a user's properties sheet to see which groups the user belongs to but not which users belong to which group. The properties sheet of a group is more informative and has two tabs: Members, which shows which users belong to the group, and Member Of, which tells you if the group itself belongs to any other groups. Opening these properties sheets is a time-consuming process and doesn't always give you quick insight into users and the groups to which they belong. But if you need a quick way of knowing what the members of different groups are, you can use VBScript. The script in this hack enumerates the groups in an Active Directory domain and places the information in a CSV file. The name of each group, the description of the group, the group's members (both full name and SAM account name), and whether that member is a user or group will all be placed into a CSV file called GroupMembers.csv, located in the directory in which the script is running. This script uses LDAP to query Active Directory. It won't run against an NT4 domain, although you should be able to run it from an NT4
workstation. If you are not running Windows 2000 Professional or later, this script requires ADSI 2.5. The Code To use this script, type it into Notepad (with Word Wrap disabled) and save it with a .vbs extension as GroupMembers.vbs: On Error Resume Next Set FileSystem = WScript.CreateObject("Scripting.FileSystemObject") Set oFile = FileSystem.CreateTextFile("GroupMemebrs.csv", True) CRLF=CHR(13)+CHR(10) strDC = "DC01GA.My.Domain.com" 'Substitute your AD domain server name strRoot = "My.Domain.Com" 'Substitute your company/domain name strDomain = "DC=MY,DC=DOMAIN,DC=COM" Set DomainObj = GetObject("LDAP://" & strDC&"/CN=Users," & strDomain) if Err.Number <0 then wscript.echo "Failed to connect to " & strADName
wscript.quit end if DomainObj.Filter = Array("group") For Each GroupObj In DomainObj If GroupObj.Class = "group" Then oFile.WriteLine ("Group Membership for: " & MID(GroupObj.Name & "," & _ "Description - " & GroupObj.Description,4)) wscript.echo ("Group Membership for: " & MID(GroupObj.Name & vbTab & _ CRLF & CRLF & _ ' "Description - " & GroupObj.Description,4)) set memberlist=GroupObj.Members For Each member In memberlist oFile.WriteLine MID(member.Name & "," & member.SAMAccountName & "," & _ member.Class,4) wscript.echo MID(Vbtab & member.Name & " (" & member.Class & ")",5) next
end if Next set DomainObj = Nothing set GroupObj = Nothing if err.number<>0 then wscript.echo CRLF wscript.echo ("ERROR: "&err.number&" "&err.description & " from "&err.source) wscript.echo CRLF end if Wscript.Echo "Done!!" wscript.quit Running the Hack Before you run the script, modify these three lines near the beginning:
strDC = "DC01GA.My.Domain.com" 'Substitute your AD domain server name strRoot = "My.Domain.Com" 'Substitute your company/domain name strDomain = "DC=MY,DC=DOMAIN,DC=COM" For example, to query a domain controller named srv210.mtit.com in the mtit.com domain, change these lines to: strDC = "srv210.mtit.com" 'Substitute your AD domain server name strRoot = "mtit.com" 'Substitute your company/domain name strDomain = "DC=MTIT,DC=COM" Also note that the script lists only groups located in the Users container. To query other containers or organizational units, modify the following line accordingly: Set DomainObj = GetObject("LDAP://" & strDC&"/CN=Users," & strDomain) To run the hack, simply create a shortcut to it and double-click on the shortcut. Figure 3-5 shows a sample of typical output for the script, with the CSV file imported into Excel to make it more readable. You can see that the Domain Admins group has members Bob Smith, Frank Jones, Jane Smith, and the default Administrator account. Figure 3-5. A portion of sample output from running the GroupMembers.vbs script
Hans Schefske
Hack 31 Modify User Properties for All Users in a Particular OU Changing the logon script for all users in an organizational unit (OU) is a chore if you're working from the GUI, so try this script instead. The ability to quickly change the logon script that members of a particular OU are running is quick and easy though VBScript. To change the properties of objects located in a specific OU, you must first bind to that OU using ADSI. To do this, you must list all the parent OUs of the OUs you are trying to bind to, as shown in the script in this hack. Then you must gather all the usernames in the OU you are modifying and check to make sure they are indeed just users and not some other object. If they are users, change the path of the logon script property in their account to Network/NewLogon.cmd and set the changes in place. Then notify the person running the script that the changes have been completed. This script comes in handy when you need to modify common properties of many user accounts in a particular OU all at once in an Active Directory domain. In Windows 2000, unlike in NT4, you cannot just highlight the users you want to change, click on Properties and change a common property (e.g., Logon Script) for the users you have selected.
The Code
To use this script, type it into Notepad (with Word Wrap disabled)
and save it with a .vbs extension as ModifyUsersOU.vbs:
'Comment
'Modify all users in a specific OU in Active Directory at once. This script
'will change the logon script path For all users of the
'"Network/Services/Users/Test" OU To "Network/newlogon.cmd".
'Script
'This is the actual LDAP. If the OU is a sub-OU, you must enter ALL of them.
Set OU = GetObject("LDAP://DCServerName.MY.Domain.COM/OU=Test,OU=Users,OU=Services,OU=
Network,DC=MY,DC=Domain,DC=com")
'Setup to get all the users in the specified OU from above.
'Gather each username.
For Each oUser In OU
'Make sure they are only USER class.
If oUser.Class = "user" Then
'Set the name of the login script itself here.
oUser.Put "scriptpath", "Network\newlogon.cmd"
'Set these settings. oUser.SetInfo End If Next Wscript.echo "The Network/Services/Users/Test OU has been updated!" Wscript.Quit Change the following line to specify the appropriate OU in your own network environment: Set OU = GetObject("LDAP://DCServerName.MY.Domain.COM/OU=Test,OU=Users,OU=Services, OU=Network,DC=MY,DC=Domain,DC=com") For example, if your OU is named Boston and your domain is mtit.com, then this line should be changed to: Set OU = GetObject("LDAP://DCServerName.MY.Domain.COM/OU=Boston, DC= Specify the new logon script, like so: oUser.Put "scriptpath", "Network\newlogon.cmd" Finally, specify the output for the ECHO by modifying this line as required: Wscript.echo "The Network/Services/Users/Test OU has been updated!" In our example, this line should be changed to: Wscript.echo "The Boston OU has been updated!"
Hacking the Hack This script can easily be modified to change any of the User Object properties in a particular OU, such as: Profile Path Home Directory Home Drive Letter Email Description The script can of course be customized to modify virtually any other displayed properties of user objects. Hans Schefske
Hack 32 Check Group Membership and Map Drives in a Logon Script Find out which group a user referenced within a logon script belongs to. Logon scripts are useful for mapping drives so that users can store their work files in standard locations on network file servers. It would be nice to be able to map drives based on a user's group membership, and that's what this hack is about. By placing a user's group membership information into a dictionary object, you can quickly find out if a user is a member of a group and then perform actions (such as mapping drives) if they are. The script in this hack allows you to accomplish this and more. This script quickly checks to see if a user is a member of a particular group. It reads the Member Of tab information for the user account and places it into a dictionary object, because a dictionary object offers fast and easy access to group membership information. If the user is a member of the group specified, a dialog box will tell you so. The Code To use this script, type it into Notepad (with Word Wrap disabled) and save it with a .vbs extension as CheckMembership.vbs.
Option Explicit ' Force explicit declarations ' ' Variables ' Dim WSHNetwork Dim FSO Dim strUserName ' Current user Dim strUserDomain ' Current User's domain name Dim ObjGroupDict ' Dictionary of groups to which the user belongs Set WSHNetwork = WScript.CreateObject("WScript.Network") Set FSO = CreateObject("Scripting.FileSystemObject") ' ' Wait until the user is really logged in... ' strUserName = "" While strUserName = "" WScript.Sleep 100 ' 1/10 th of a second
strUserName = WSHNetwork.UserName Wend strUserDomain = WSHNetwork.UserDomain ' Read the user's account "Member Of" tab info across the network ' once into a dictionary object. Set ObjGroupDict = CreateMemberOfObject(strUserDomain, strUserName) If MemberOf(ObjGroupDict, "Domain Admins") Then wscript.echo "Is a member of Domain Admins." 'REM this line to Map Network Drives 'Map network Drives here, UNREM the below lines: 'WSHNetwork.MapNetworkDrive "O:", "\server1\share" 'WSHNetwork.MapNetworkDrive "Q:", "\server2\share" Else
wscript.echo "Is NOT a member of Domain Admins" End If Function MemberOf(ObjDict, strKey) ' Given a Dictionary object containing groups to which the user ' is a member of and a group name, then returns True if the group ' is in the Dictionary else return False. ' ' Inputs: ' strDict - Input, Name of a Dictionary object ' strKey - Input, Value being searched for in ' the Dictionary object ' Sample Usage: ' ' If MemberOf(ObjGroupDict, "DOMAIN ADMINS") Then ' wscript.echo "Is a member of Domain Admins." ' End If '
' MemberOf = CBool(ObjGroupDict.Exists(strKey)) End Function Function CreateMemberOfObject(strDomain, strUserName) ' Given a domain name and username, returns a Dictionary ' object of groups to which the user is a member of. ' ' Inputs: ' ' strDomain - Input, NT Domain name ' strUserName - Input, NT username ' Dim objUser, objGroup
Set CreateMemberOfObject = CreateObject("Scripting.Dictionary") CreateMemberOfObject.CompareMode = vbTextCompare Set objUser = GetObject("WinNT://" _ & strDomain & "/" _ & strUserName & ",user") For Each objGroup In objUser.Groups CreateMemberOfObject.Add objGroup.Name, "-" Next Set objUser = Nothing End Function Running the Hack To map drives based on a different user group than Domain Admins modify this line as required: If MemberOf(ObjGroupDict, "Domain Admins") Then For example, if you want to map drives based on whether users are members of a global group named Sales use this line instead: If MemberOf(ObjGroupDict, "Sales") Then
To map drives instead of displaying a message box, comment out the following line: wscript.echo "Is a member of Domain Admins." 'REM this line to Map Network Drives and uncomment these lines: 'WSHNetwork.MapNetworkDrive "O:", "\server1\share" 'WSHNetwork.MapNetworkDrive "Q:", "\server2\share" specifying drive letters and UNC paths as appropriate depending on your own networking environment. For example, to map the drive letter K: to a shared folder named Reports on file server fs3.mtit.com use this line instead of the above: WSHNetwork.MapNetworkDrive "K:", "\fs3.mtit.com\Reports" Hans Schefske
Hack 33 Script Creation of a User's Home Directory and Permissions Configuring home directories for users is a slow process using the GUI. Here's a script that does it faster. Ever wish you could create a user and her home directory and set the necessary permissions on that directory all in one script? Here is a sample script that shows you how to accomplish this. If you know some VBScript, you can easily customize it further to meet your needs. This script creates a user, adds additional properties such as telephone number and title, sets the password, and enables the user's account. Then the script creates the user's home folder and sets the Administrators group to have Full Control permission on the folder and the user's account to have Change permission on the folder. This script can easily be modified to set the permissions to fit the requirements of any environment. All you have to do is review the command-line switches for the cacls command and make the appropriate changes in the script. The Code To use this script, type it into Notepad (with Word Wrap disabled) and save it with a .vbs extension as
CreateUserHomeDirectory.vbs. Option Explicit Const WAIT_ON_RETURN = True Const HIDE_WINDOW = 0 Const USER_ROOT_UNC = "\dc1\users" 'Set Home Folder Location Here Dim WshShell, WshNetwork, objFS, objServer, objShare Set WshShell = Wscript.CreateObject("Wscript.Shell") Set WshNetwork = WScript.CreateObject("WScript.Network") Set objFS = CreateObject("Scripting.FileSystemObject") Set ou = GetObject("LDAP://OU=Users,OU=Billing,OU=Network,DC=my,DC=domain,DC=com") 'Create the User Set usr = ou.Create("user", "CN=James Smith") usr.Put "samAccountName", "jsmith" usr.Put "sn", "Smith"
usr.Put "givenName", "James" usr.Put "userPrincipalName", "jsmith@my.domain.com" usr.Put "telephoneNumber", "(555) 555 0111" usr.Put "title", "Network Billing Dept" usr.SetInfo 'Now that the user is created, reset their password and enable the account. usr.SetPassword "secret***!" usr.AccountDisabled = False usr.SetInfo 'Now create the User's Home Folder and set permissions. strUser = usr.samAccountName Call objFS.CreateFolder(USER_ROOT_UNC & "" & strUser) Call WshShell.Run("cacls " & USER_ROOT_UNC & "" & strUser & _ " /e /g Administrators:F", HIDE_WINDOW, WAIT_ON_RETURN) Call WshShell.Run("cacls " & USER_ROOT_UNC & "" & strUser & _
" /e /g " & strUser & ":C", HIDE_WINDOW, WAIT_ON_RETURN) Running the Hack To run the script, modify the following line to set the home folder location: Const USER_ROOT_UNC = "\dc1\users" 'Set Home Folder Location Here Then modify the following line to specify the organizational unit (OU) in which you want to create the user: Set ou = GetObject("LDAP://OU=Users,OU=Billing,OU=Network,DC=my,DC=domain,DC=com") Finally, modify the following lines to specify the personal information for the user, as desired: Set usr = ou.Create("user", "CN=James Smith") usr.Put "samAccountName", "jsmith" usr.Put "sn", "Smith" usr.Put "givenName", "James" usr.Put "userPrincipalName", "jsmith@my.domain.com" usr.Put "telephoneNumber", "(555) 555 0111" usr.Put "title", "Network Billing Dept" Hans Schefske
Hack 34 Prevent Ordinary Users from Creating Local Accounts Here's a quick hack that will let you prevent users from creating new local user accounts on their desktop computers. By default, ordinary users on Windows 2000 Professional workstations can use Computer Management to create new local user accounts on their machines. All they need to do is right- click on My Computer, select Manage to open Computer Management, locate Local Users and Groups under System Tools, right-click on Users, and select New User. This procedure lets them create ordinary user accounts only, not administrator accounts, but it still represents an undesirable loophole for most administrators. After all, it's usually not a desirable feature for users to create additional accounts for themselves on their desktop machines. Here's a workaround to solve this problem. To disable a user's ability to create new local accounts on his machine, log on locally to his machine as a member of the Administrators group and open Computer Management. Select Groups under Local Users and Groups to display all local groups on the machine. Double-click on the Users group to display its members (see Figure 3-6), and you should see NT AUTHORITY\INTERACTIVE as a member of this group. Select this account and click Remove to remove it from the group (this doesn't delete the account; it only removes it from the group).
Figure 3-6. Removing the INTERACTIVE special identity from the Users group This action removes the ability for logged-on users to create new local accounts on their systems. If you don't want to log on interactively to user's machines using your Administrator account, you can use the runas command instead. While the user is logged on to her machine using her ordinary user account, open a command line and type: runas /user:MyAdminAcct@MyDomain.com cmd
Type your password when prompted (make sure the user is not looking at the screen). This opens a new command-prompt window, running under your Administrator credentials. Now type the following command into the new window: net localgroup users "NT AUTHORITY\INTERACTIVE" /DELETE This removes the INTERACTIVE special identity from the Users group. Rod Trent
Hack 35 Put a Logoff Icon on the Desktop Here's a script that will enable users to safely reboot their machines when necessary. Occasionally, users need a way to reboot their machines when applications hang or updates have been installed. Rather than give users instructions about how to do this properly, it would be nice if a user could instead simply click on an icon that would log them off properly and reboot their machine in a way that does not endanger their work. That's what this script is aboutallowing your users to safely reboot their machines from an icon on their desktops. This VBScript prompts the user to make sure he has saved his data, then logs the user off and automatically reboots. This is quite handy when you push updates via SMS but suppress the reboot. The Code Just type the following script into Notepad (with Word Wrap disabled) and save it with a .vbs extension as LogoffIcon.vbs: Set OpSysSet = GetObject("winmgmts:{impersonationLevel=impersonate,(Shutdown)}" & _ "//./root/cimv2").ExecQuery("SELECT * FROM " & _
"Win32_OperatingSystem WHERE Primary = true") ianswer = MsgBox("Did you save your data first?"+vbLf++vbLf+ " LOGOFF?", _ vbCritical + vbYesNo, _ "Logoff?") If ianswer = vbYes Then 'If OK, shut down For Each OpSys In OpSysSet outParam = OpSys.Reboot If err.number <> 0 Then WScript.echo "Error number: " & Err.Number & _ vbNewLine & _ "Description: " & Err.Description End If
Next Else ' user selected cancel MsgBox "Logoff Aborted", , "Logoff Aborted" End If Copy the script to a folder on the user's machine and create a shortcut to the folder on his desktop. Then, when the user needs to reboot his machine, he can double-click on the shortcut and a dialog box (see Figure 3-7) will suggest that he save his work before logging off. Figure 3-7. Logging off and rebooting Once he saves his work and clicks OK, he is logged off and his computer shuts down and restarts. Chuck Young
Chapter 4. Networking Services Hacks #36-47 Section 36. Manage Services on Remote Machines Section 37. Simplify DNS Aging and Scavenging Section 38. Troubleshoot DNS Section 39. Manually Recreate a Damaged WINS Database Section 40. Change WINS for All Enabled Adapters Section 41. Ensure DHCP Server Availability Section 42. Change a Network Adapter's IP Info Section 43. Change from Static IP to DHCP Section 44. Release and Renew IP Addresses Section 45. Use netsh to Change Configuration Settings Section 46. Remove Orphaned Network Cards Section 47. Implement Windows 2000 Network Load Balancing
Hacks #36-47 Under the hood of Windows 2000 Server and Windows Server 2003 are the core networking services and components that enable systems to communicate across a network. This includes services such as Dynamic Host Configuration Protocol (DHCP), Domain Name System (DNS), Windows Internet Name Service (WINS), and other services that run on top of TCP/IP. Configuring these services can be complex, and it can be hard to pinpoint the problem when things go wrong. This chapter is about managing key services and other networking components. You'll learn how to use a script to manage services on remote computers, how to ensure DHCP server availability so your clients can communicate, how DNS aging and scavenging work and can be configured, how to troubleshoot common DNS problems when Active Directory is deployed, how to perform complicated network configuration tasks using scripts and from the command line, and several other important tasks. When running VB scripts for system administration, remember to ensure that you have the latest scripting engines on the workstation from which you run the scripts. Download the latest scripting engines from the Microsoft Scripting home page (http://msdn.microsoft.com/scripting/). Also, when working with the Active Directory Services Interface (ADSI), you must have the same applicable rights you need to use the built-in administrative tools. In other words, you should use an administrator account to run these scripts.
Hack 36 Manage Services on Remote Machines Here are three handy scripts for managing network services that run on remote machines. While the Services node in Computer Management can be used to manage services on remote machines, using a script is easier if you have many systems to manage. This hack offers three VB scripts you can use to display the services that run on a remote computer, change the start mode for a service, and change the password for the account used by a service. Enjoy! Getting Remote Computer Service Information If you want to check services on a remote computer, VBScript can help. Using the WMI repository and ADSI, you can easily retrieve information on stopped or started services. The script prompts for the NetBIOS name of the remote computer. Alternatively, you can get the service information for the local computer by typing in the local name as localhost. The script responds by displaying complete information for the services that are registered on the specified computer.
The code Type the following script into Notepad (with Word Wrap disabled) and save it with a .vbs extension: ComputerName = InputBox("Enter the name of the computer for which you " & _ "want service information") winmgmt1 = "winmgmts:{impersonationLevel=impersonate}!//"& ComputerName &"" Set ServSet = GetObject( winmgmt1 ).InstancesOf ("Win32_service") for each Serv in ServSet GetObject("winmgmts:").InstancesOf ("win32_service") WScript.Echo "" WScript.Echo Serv.Description WScript.Echo " Executable: ", Serv.PathName WScript.Echo " Status: ", Serv.Status WScript.Echo " State: ", Serv.State WScript.Echo " Start Mode: ", Serv.StartMode
Wscript.Echo " Start Name: ", Serv.StartName next Running the hack To run the script, open a command prompt, switch to the directory where the script is located, and type the following: cscript.exe GetRemoteServices.vbs > services.txt The reason for redirecting output to a text file is because the script generates a lot of output. A dialog box appears (see Figure 4-1), requesting the name of the remote machine. The machine name can be a FQDN, NetBIOS name, or IP address, as desired. Figure 4-1. Getting information about services running on a remote machine
Here's a sample of what the output of the script might look like if the target machine is running Windows Server 2003: Microsoft (R) Windows Script Host Version 5.6 Copyright (C) Microsoft Corporation 1996-2001. All rights reserved. Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start. Executable: C:\WINDOWS\system32\svchost.exe -k LocalService Status: OK State: Stopped Start Mode: Disabled
Start Name: NT AUTHORITY\LocalService Provides support for application level protocol plug-ins and enables network/protocol connectivity. If this service is disabled, any services that explicitly depend on it will fail to start. Executable: C:\WINDOWS\System32\alg.exe Status: OK State: Stopped Start Mode: Manual Start Name: NT AUTHORITY\LocalService Processes installation, removal, and enumeration requests for Active Directory IntelliMirror group policy programs. If the service is disabled, users will be unable to install, remove, or enumerate any IntelliMirror programs. If this service is disabled, any services that explicitly depend on it will fail to start. Executable: C:\WINDOWS\system32\svchost.exe -k netsvcs Status: OK
State: Stopped Start Mode: Manual Start Name: LocalSystem Note that you can easily determine the start mode, service account, and state of each service from this output. Changing the Start Mode for a Service This VBScript changes the Server service start mode to Automatic and works remotely. This can be a big help to sites where the security folks have gone nuts and disabled the Server service or set it to Manual start mode. In its current form, the script prompts for a remote computer name, connects, and changes the Server service's start mode. The script could also be edited to run on the local computer and placed in a login script to hit a large number of computers at once. The code Type the following script into Notepad (with Word Wrap disabled) and save it with a .vbs extension: strComputer = InputBox("Enter the name of the computer for which " & _ "you want to change the Start Mode for the Server service")
Set objWMIService = GetObject("winmgmts:" _ & "{impersonationLevel=impersonate}!\" & strComputer & "\root\cimv2") Set colService = objWMIService.ExecQuery _ ("Select * from Win32_Service where DisplayName = 'Server'") For Each objService in colService errReturnCode = objService.Change( , , , , "Automatic") Next Running the hack To run this script, simply create a shortcut to it and double-click on the shortcut. To change the start mode of another service, simply change the DisplayName to the service you want to modify. For example, to change the start mode for the World Wide Web Publishing Service, you'd alter the select statement to read: ("Select * from Win32_Service where DisplayName = 'w3svc'"). And, of course, you can also use "Manual" or "Disabled" instead of "Automatic" in the second-to-last line. Changing a Service Password
Services always run within the context of some user account. Usually, this account is built in, such as LocalSystem or NetworkService, but some services, such as IIS and those for Exchange, use special accounts called service accounts. To ensure these accounts are secure, you can change the password used by these accounts, which this script will allow you to do. The code Type the following script into Notepad (with Word Wrap disabled) and save it with a .vbs extension: Dim Computer Dim ComputerName Dim ComputerDomain Dim Service Dim TargetService Dim NewPassword TargetService = "YourServicename" ComputerDomain = "YourDomain" ComputerName = "YourComputerName" NewPassword = "YourPassword"
Set Computer = GetObject("WinNT://" & ComputerDomain & "/" & ComputerName & _ ",computer" Set Service = Computer.GetObject("service", TargetService) Service.SetPassword(NewPassword) Service.SetInfo Running the hack Just replace the items in the following lines with your own information: TargetService = "YourServicename" ComputerDomain = "YourDomain" ComputerName = "YourComputerName" NewPassword = "YourPassword" For example: TargetService = "Network Agent" ComputerDomain = "MTIT" ComputerName = "SRV14" NewPassword = "Pa$$w0rd" Rod Trent
Hack 37 Simplify DNS Aging and Scavenging Understanding the mysteries of how DNS aging/scavenging works can save you time and effort troubleshooting DNS name- resolution problems. Dynamic DNS (DDNS, introduced in Windows 2000) brought with it a process called DNS scavenging, the automatic removal of stale DNS information. In a perfect world, DNS scavenging would not be necessary, but who lives in a perfect world? So, before you spend time reading the rest of this hack, let's see if it applies to you. Have you pinged a machine before by name and gotten a reply, but when you attempt to connect to it, you connect to a different machine name or cannot connect at all? If you just shook your head in agreement, nodded, or mumbled something about this happening to you, then this hack might shed some light. Still reading? Good. First, let me establish my bias: all of this information pertains to Active Directory Integrated Zones. That said, let's establish some definitions before we continue: A This record maps the name of the machine (host) to the IP address.
PTR This record maps the IP address to the hostname. Why Scavenge? There are two parts of DDNS that you need to understand before we answer the question of when scavenging is necessary: DNS and DHCP. DHCP process Wait a second. I thought we were talking about DNS? Before we go on about DNS, we first have to understand how DDNS works and why DHCP is important in this process. Dynamic DNS registration happens at two places: either the DHCP client or the DHCP server. It all depends on configuration and client type. For the most part, Windows 2000 clients and above handle their own hostnameregistrations, while the DHCP server handles the PTR registration (except in the case of statically assigned IP addresses, in which case the client will handle both the hostnameand PTR registrations). In other configurations, the DHCP server can be made to handle the host and PTR registrations. Other, down-level clients (NT4, 9x, etc.), do not interact with the DDNS registration process. However, the DHCP server can be set to handle registration for these clients as well.
Okay, now we have an idea of how these records are getting in DDNS. Unfortunately, how the records go in is much more efficient than how the records come out. Read Larry Duncan's excellent article, "DNS for Active Directory: A 10 Minute Primer" (http://www.myitforum.com/articles/16/view.asp? id=3907), to understand when clients likes to refresh their DNS records. DDNS process There's nothing to stop two records from holding the same IP address or the same host name. This scenario is problematic for image-based workstation/laptop deployments. During a portion of the image process, the client will register as WIN2KIMAGE in DNS (for example), before having the machine name changed later in the process. Another image is started and WIN2KIMAGE is added again with a different IP address. Sooner or later, you'll end up with 50 PTR records pointing to the same name, WIN2KIMAGE. This same process happens under different situations, in which a machine will establish a different dynamic IP address, but for some reason, the old reverse-lookup record is not removed. Generally, the DHCP client and server helps clean up these records. In some configurations, the DHCP
server does it all. However, real-world experience might tell you that this is not getting done effectively. When this clean-up process does not occur properly, stale records reside in DNS. This is where scavenging comes in. Scavenging deletes stale records if they're beyond a set age. All records have an age. However, the age of a record is not considered until scavenging is turned on. Once scavenging is turned on, DNS does not calculate how old the record was prior to when scavenging was enabled. For more information on various triggers of the StartScavenging time frame, refer to the Microsoft DNS white paper at http://www.microsoft.com/technet/treeview/default.asp? url=/TechNet/prodtechnol/windows2000serv/plan/w2kdns2.asp How to Use Scavenging There are three intervals you need to understand before you set up scavenging: Scavenging Period, No-refresh Interval, and Refresh Interval. These intervals are described in the DNS GUI. Just right-click on an Active Directory Integrated zone, select Properties, choose the General tab, and click the Aging button to see the screen shown in Figure 4-2. Figure 4-2. Configuring DNS scavenging options
If you're like me, your brain is twitching from the complex wording of the definitions. In order to understand this a little better (without needing the mental capacity to solve a Rubik's Cube in two minutes), let's break down what the definitions really mean: Scavenging Period This is easy enough to understand. This interval simply tells your DNS server how often to check the zones for stale records. You can only get as granular as telling
DNS to check every x number of hours or x number of days. By the way, this setting applies only to the DNS server, not the zones. No-refresh Interval This a mechanism by which DDNS suppresses reregistration attempts. This helps keep replication of record information to a minimum. For example, using the default of seven days, after the DNS client registers with DDNS, all attempts to reregister for a period of seven days will be ignored. Refresh Interval This definition took awhile for me to grasp. It basically means the number of days after the No-refresh Interval expires that DDNS will wait for the client to refresh its record before the record becomes stale. Again, by default, this setting is also seven days. Now, we'll put this all together in an example that makes sense. In this scenario, the DNS client does not reregister during the Refresh Interval period. Keep in mind, we are using the default of seven days:
- DNS client registers with DDNS. No-refresh Interval starts (seven days). DDNS server will not accept reregistration attempts from
this client for seven days. No-refresh Interval expires. Refresh Interval starts (seven days). DNS client has seven days to refresh its records before the record is considered stale. Refresh Interval expires. Scavenging process removes record. If the client had registered its record again, the No-refresh Interval would have started all over again. In the previous scenario, with the default settings of seven days, a record would have to be greater than 14 days old before DDNS would scavenge it. This might work if your DHCP lease times are eight days (the default). Otherwise, you might need to set the intervals closer to your DHCP lease times. Also, keep in mind the Scavenging Period runs only on the interval specified, which is also seven days by default. Scavenging jobs will use processor time. However, the scavenging process is a low-priority thread of the DNS service. This ensures that scavenging does not use all the processing capacity, but it's horrible if your DNS servers are used heavily. As a low-priority thread on a highly used DNS server, there's a probability that the scavenging thread might never run. Also, if the server attempts to run the scavenging process during a time when the DNS server is highly used, it will miss the scheduled
interval. It will not attempt to start running over and over but instead will wait until the next scheduled interval (remember the default of seven days). At the time of this writing, I haven't found a setting that can be adjusted to change which hour the scavenging process starts. For the Advanced Pack Rat As I mentioned earlier, the Scavenging Period setting applies only to an individual DNS server. Unlike the other settings, which are replicated by Active Directory, this setting is specific to the DNS server in question. With this in mind, not enabling this setting means that no servers are scavenging records. Aging of records is taking place (No-refresh, Refresh), but nothing else is going on. This is good for a variety of reasons. First, you don't necessarily want all of your DNS servers to scavenge. You need only one server to scavenge. It'll replicate the record deletes to the other DNS servers. This also allows for some other configuration options: Small environment Turn Scavenging Period on. This should be ample for you. Larger environment Leave the Scavenging Period setting off. In other words, you don't want DNS servers scavenging records for you. Instead, use the dnscmd command (found in the Support
Tools folder on your product CD) with the /StartScavenging option and schedule it on a recurring basis, at the time frame you're looking for. It's probably reasonable to suggest that nighttime hours have little DNS registrations or queries going on. Enterprise environment Designate a DNS server to handle all scavenging and nothing else. This can be established by placing the DNS server in its own site so that clients do not refer to it for lookups or any Active Directory functions. If that sounds like too much work, the SRV records for this DNS server can be stripped from DNS to achieve the same effect. See Also DNS Scavenging on Windows 2000 Server (http://www.microsoft.com/windows2000/en/server/help/default.asp? url=/WINDOWS2000/en/server/help/sag_DNS_imp_ManageAgingScavenging.htm Enable Aging and Scavenging for DNS (http://www.microsoft.com/technet/treeview/default.asp? url=/technet/prodtechnol/windowsserver2003/proddocs/deployguide/dssbm_drd_dvwv.asp Scavenging Stale DNS Records (http://www.winnetmag.com/Articles/Index.cfm? ArticleID=19897)
Set Aging/Scavenging Properties for the DNS Server (http://www.microsoft.com/technet/treeview/default.asp? url=/technet/prodtechnol/windowsserver2003/proddocs/standard/sag_DNS_pro_SetAgeScavengeServer.asp How to Optimize the Location of a Domain Controller or Global Catalog (http://support.microsoft.com/? id=306602) Marcus Oh
Hack 38 Troubleshoot DNS Here are some tips, tools, and resources to help you troubleshoot DNS problems on Windows 2000/2003-based networks. DNS troubleshooting is usually straightforward, because most errors tend to be simple configuration or setup errors. To troubleshoot DNS, you must have details of the configuration of any DNS resolvers and/or DNS servers and be able to use common DNS troubleshooting tools. This hack provides some details and links to tools you can use to troubleshoot DNS, as well as tips on how to overcome common DNS errors. DNS Troubleshooting Tools Here are a few useful web sites that offer tools for troubleshooting DNS: www.DNSreport.com (http://www.dnsreport.com) This site will check the DNS settings for an Internet zone and provide prescriptive guidance on optimizing the settings.
www.DNSstuff.com (http://www.dnsstuff.com) This site has a number of DNS tools that you can use to diagnose DNS issues. SamSpade.org (http://www.samspade.org) This site has some good tools for DNS troubleshooting. It promotes its tools and expertise as anti-spam utilities, as opposed to just DNS troubleshooting. The site's tools page (http://www.samspade.org/t/) provides tools similar to those at www.DNSstuff.com. I have the Sam Spade For Windows tool (http://www.samspade.org/ssw/) on my desktop and use it a great deal. AnalogX DNSDig (http://www.analogx.com/contents/dnsdig.htm) This page provides an online version of DIGa useful tool from the Unix world that is used to troubleshoot DNS issues. (Why can't Microsoft provide a port of DIG in Windows or the resource kit?) Squish.net DNS Checker (http://www.squish.net/dnscheck) Given a record name and a record type, this page will return a report that details all possible answers. DNS Dump (http://www.reskit.net/DNS/dnsdump.cm_)
This is a truly awesome script by Dean Wells that exports/imports DNS server configurations. Read carefully before using it, and make sure you change the extension before you run it! Troubleshooting Common DNS Issues Here is a list of common problems and solutions that have been discussed in online newsgroups: Running nslookup returns nonexistent domain If you run nslookup, you might see an error that looks like this: C:>nslookup *** Can't find server name for address 192.168.1.1: Non-existent domain *** Default servers are not available Default Server: UnKnown Address: 192.168.1.1 When nslookup starts, it attempts do a reverse lookup of the IP address of the DNS server. If the reverse lookup fails, nslookup returns the preceding error message, which is somewhat misleading. The solution is to either install a reverse lookup zone for your workstations or to ignore the message.
Netlogon Error 5774 - DNS Operation Refused This error is typically caused by the use of a DNS server that does not allow dynamic update or is set to refuse operations from your computer. Sometimes, this is due to a workstation that points to the ISP's DNS server instead of an internal DNS server. In general, all internal servers and workstations should point to one or more internal DNS servers that in turn point to a DNS server that forwards to the Internet. DNS Error 414 - The specified domain either does not exist or could not be contacted This error usually occurs when the computer is configured without a DNS domain name. If the computer is a DNS server that has only a single label name (e.g., kona2 versus kona2.reskit.net), any zone created will have the default SOA and NS records created using just a single label. This in turn will lead to invalid or failed referrals for the zone used to provide lookups for this zone. DNS Error 5504 - The DNS Server encountered an invalid domain name in a packet from X.X.X.X This error indicates that the DNS server has received a packet with an invalid domain name and the packet has been rejected. The most common cause of this is DNS cache pollution, as described in Knowledge Base (KB) article 241352
(http://support.microsoft.com/default.aspx?scid=kb;en- us;241352). Troubleshooting dynamic update problems Dynamic update is a DNS feature that enables hosts to update their DNS details at the DNS server. Although easy to set up, there are some ways in which DNS dynamic update can fail. See the KB article 287156 for more details (http://support.microsoft.com/default.aspx?scid=kb;en- us;287156) Windows Server 2003 cannot resolve addresses that Windows 2000 can In some cases, it appears that server is just not functioning and not resolving some names. The cause is that Extension Mechanisms for DNS (EDNS0) requests from the 2003 DNS server are not recognized by all other DNS servers. To resolve this, you should disable EDNS0 requests, using the DNScmd program from the Windows Server 2003 Support Tools folder and type dnscmd /config /enableednsprobes at a command prompt. DNS Newsgroups If the previous tips and tools do not help and you are using any version of Microsoft Windows (or DOS, for that matter), consider posting a query to the microsoft.public.win2000.dns newsgroup.
This newsgroup can be obtained from news://news.microsoft.com. If you do post, you will need to provide some details of your particular issue, including most of all of the following: Is the problem a client problem or a DNS server problem? What operating system are you running and with which service packs or other fixes? What is the client configuration? (ipconfig /all provides this!) What specific error, if any, are you seeing? What zones are configured on your DNS server, and what properties are set for those zones? Are your DNS zones configured to be updated dynamically? What sort of Internet connection do you have? Does your ISP allow you to run servers on your connection? Does your provided IP address vary, or is it fixed? DNS Books
Finally, here are two books you can use to learn more about troubleshooting DNS issues: DNS and BIND By Cricket Liu and Paul Ablitz (O'Reilly). This book is possibly the best introduction to DNS in existence. It's Unix-based, but it's still a good book. Windows 2000 DNS By Herman Knief, Roger Abell, Jeffery Graham, and Andrew Daniels (O'Reilly). This is a pretty good Windows 2000 DNS book. Thomas Lee
Hack 39 Manually Recreate a Damaged WINS Database A corrupt WINS database can spell a host of problems and must be repaired if your network is to function properly. This hack shows you how to recreate a damaged WINS database. If you're still using WINS on your networktypically in a mixed NT/2000 or NT/2003 environment while migration is underwayyou might occasionally experience corruption of the Windows Internet Name Service (WINS) database. If your WINS database becomes corrupted, you can experience all manner of problems with your workstations and serversmost notably, name-resolution problems for legacy Windows clients. You'll need to fix your WINS database if these clients are to communicate on the network. This hack recreates a damaged Windows NT 4.0 or Windows 2000 WINS database. Windows NT 4.0 To recreate a damaged WINS database on Windows NT, first go to Control Panel Services and stop the Windows Internet Name Service. Then, create a folder named WINS_OLD and move the contents of the %SystemRoot%\System32\WINS folder to WINS_OLD. Finally, restart the Windows Internet Name Service. When you are positive that the new WINS database is
functioning properly, delete the WINS_OLD directory. Windows Server 2000/2003 To recreate a damaged WINS database on Windows Sever 2000/2003, first go to Control Panel Administrative Tools Services and stop the Windows Internet Name Service. Then, create a folder named WINS_OLD and move the contents of the %SystemRoot%\System32\WINS folder to WINS_OLD. Finally, restart the Windows Internet Name Service. When you are positive that the new WINS database is functioning properly, delete the WINS_OLD directory. The only difference between Windows NT 4.0 and Windows 2000 for recreating a WINS database is the location for accessing the services. Again, when you are positive that the new WINS database is functioning properly, delete the WINS_OLD directory. Rod Trent
Hack 40 Change WINS for All Enabled Adapters Changing WINS settings on client machines can be a pain when you have to move your WINS servers. This hack makes it easier. If you are using WINS as a name-resolution method (typically in a mixed NT/2000 environment) and have to change your WINS serversfor example, when you install a new WINS serveryou have to reconfigure WINS settings on all your client computers. If you are using DHCP, you can configure the 044 WINS/NBNS Servers option on your DHCP servers to provide client computers with new WINS servers addresses, but this requires releasing and renewing DHCP leases on all your clients. Here's another approach you can use. The following script changes the WINS server settings on client machines and is useful when you install new WINS servers and need to change your WINS server settings on workstations across the board. Note that the script also works on multihomed machines (machines that have two or more network adapters). The Code Type the following code into Notepad (with Word Wrap disabled) and save it with a .vbs extension as ChangeWINS.vbs:
Option Explicit On Error Resume Next Dim objLocator, objService, NIC Dim strComputer, strUsername, strPassword Dim strWINS1, strWINS2 Dim intErr strComputer = "." strUsername = "" strPassword = "" strWINS1 = "172.16.1.122" strWINS2 = "172.16.1.132" Set objLocator = CreateObject("WbemScripting.SWbemLocator") Set objService = objLocator.ConnectServer(strComputer, "root/cimv2", & strUsername, strPassword)
objService.Security_.impersonationlevel = 3 For Each NIC In objService.ExecQuery("Select * from Win32_NetworkAdapterConfiguration Where IPEnabled=True") WScript.Echo "Nic Index: " & NIC.index WScript.Echo "Current Settings" WScript.Echo "Primary Wins Server: " & NIC.WINSPrimaryServer WScript.Echo "Secondary Wins Server: " & NIC.WINSSecondaryServer intErr = NIC.SetWinsServer(strWINS1, strWINS2) If intErr <> 0 Then Wscript.Echo "Error changing WINS" Next Set objService = Nothing Set objLocator = Nothing Running the Hack To run this hack, you first have to customize it. For example, if your primary WINS server is 10.0.0.15 and your secondary server is 10.0.0.16, change these lines:
strWINS1 = "172.16.1.122" strWINS2 = "172.16.1.132" to this: strWINS1 = "10.0.0.15" strWINS2 = "10.0.0.16" Then, create a shortcut to the script and double-click on the shortcut to run the script. This will refresh your computer's WINS settings. Rod Trent
Hack 41 Ensure DHCP Server Availability Making sure a DHCP server is always available is critical if your network uses dynamic TCP/IP addressing. Microsoft DHCP server became much more popular in Windows 2000 environments, where it became part of the overall strategy for managing IP addressing, host namespace, and name resolution (due to its close integration with Microsoft's implementation of DNS). Because of its significance, it is imperative to have a solid plan that allows you to quickly recover from DHCP server failures. Installing Redundant DHCP Servers One approach to ensuring DHCP server availability is to install multiple DHCP servers and divide the list of available IP addresses on each subnet into multiple ranges, one per server. In the simplest case of two DHCP servers, configure each with the scopes that have matching start and end address. Next, for each one create mutually exclusive exclusion lists. For example, if your network is using class C nonsubnetted network 192.168.168.0/24, then, on both servers, you should create the scope with the start IP address 192.168.0.1 and the end IP address 192.168.168.254. Your choice of exclusion lists depends on whether you want both servers to share the load equally or whether one of them will be a primary choice for your
DHCP clients. For example, to balance the load, you would configure the range 192.168.168.1-192.168.168.127 on the first server and 192.168.168.128-192.16.168.254 on the second. In order for this configuration to work, you have to ensure that broadcasts from DHCP clients will reach both servers. Typically, this is done either by installing DHCP relay agents on the servers that reside on clients subnet or by configuring routers as BOOTP Relay Agents. Backing Up the DHCP Database In addition to providing redundancy, you should also ensure regular backups of the DHCP database. Fortunately, the backup takes place automatically by default. Its behavior is determined by Registry entries that reside in the following key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DHCPServer\Parameters The Registry entries contain the following values: BackupDatabasePath Determines the location of the backup (set initially to %SystemRoot%\System32\DHCP\Backup). BackupInterval Determines the frequency of the automatic backup, in minutes (the default is 60).
RestoreFlag Can be used to force the restore by using the existing backup (by setting RestoreFlag to 1). Typically, the operating system does this automatically if it detects the DHCP database corruption. Windows also automatically backs up the content of the Registry key HKLM\SOFTWARE\Microsoft\DHCPServer\Configuration to the DHCPCFG file, which resides in the Backup folder. Recovering the Database Recovering the database involves restoring both the database files and the Registry settings. You should first stop the DHCP server and then copy the files and load the Registry hive (using REGEDT32.EXE) to their target location by overwriting the existing HKLM\SOFTWARE\Microsoft\DHCPServer\Configuration Registry key. After you have restored the database file, you should change the default of 0 conflict-detection attempts (from the Advanced tab of Server properties in the DHCP MMC console) to a nonzero value (5 is the maximum). Another option is to use the NETSH command-line utility to back up and restore configuration of the DHCP server database. NETSH's functionality is provided through a number of helper DLLs, each dealing with a particular type of Windows networking component. NETSH allows you to dump the configuration of the DHCP server (including all superscopes, scopes, exclusion ranges, and reservations) into a text file that later can be used to restore. Note, however, that NETSH does not back up
information about existing leases, which are stored in the DHCP database. To create the DHCP configuration dump file, execute the following command, where IPAddressOrName is the IP address or name of your DHCP server (note that this command can be executed remotely): NETSH DHCP SERVER IPAddressOrName DUMP > C:\DHCPCfg.txt To restore the DHCP server configuration settings using the same file, run this command: NETSH EXEC C:\DHCPCfg.txt Marcin Policht
Hack 42 Change a Network Adapter's IP Info Changing TCP/IP settings via the GUI is tedious at best. It's accomplished more easily with a little VB scripting magic. Changing a machine's TCP/IP settings from the GUI usually involves a number of steps. This becomes tedious if you have to do it oftenfor example, if the machine is part of a testbed network where you test different deployment scenarios. Using the VBScript in this hack, you can quickly and frequently modify the network adapter information on a computer. The Code To use this script, type it into Notepad (with Word Wrap turned off) and save it with a .vbs extension as ChangeIP.vbs: Option Explicit Dim NetworkAdapter, AdapterConfiguration 'Objects Dim IPAddress, SubnetMask, Gateway, DNS 'String Arrays
Dim RetVal 'Integers For Each NetworkAdapter In GetObject("winmgmts:").InstancesOf("Win32_NetworkAdapter") If NetworkAdapter.AdapterType = "Ethernet 802.3" Then For Each AdapterConfiguration In GetObject("winmgmts:").InstancesOf ("Win32_NetworkAdapterConfiguration") If UCase(AdapterConfiguration.ServiceName) = UCase(NetworkAdapter.ServiceName) Then IPAddress = Array("192.168.0.10") SubnetMask = Array("255.255.255.0") Gateway = Array("192.168.0.1") DNS = Array("35.8.2.41") RetVal = AdapterConfiguration.EnableStatic(IPAddress, SubnetMask) If Not RetVal = 0 Then WScript.Echo "Failure assigning IP/Subnetmask." End If RetVal = AdapterConfiguration.SetGateways(Gateway)
If Not RetVal = 0 Then WScript.Echo "Failure assigning Gateway." End If RetVal = AdapterConfiguration.SetDnsServerSearchOrder(DNS) If Not RetVal = 0 Then WScript.Echo "Failure assinging DNS search order." End If End If Next End If Next Running the Hack To run this hack, modify the IP information in the following lines, as required by your environment: IPAddress = Array("192.168.0.10") SubnetMask = Array("255.255.255.0") Gateway = Array("192.168.0.1")
DNS = Array("35.8.2.41") For example, to change the IP address of a machine to 172.16.44.3 with subnet mask 255.255.0.0 and default gateway 172.16.44.1, replace those lines with these: IPAddress = Array("172.16.44.3") SubnetMask = Array("255.255.0.0") Gateway = Array("172.16.44.1") Also, note this statement: If NetworkAdapter.AdapterType = "Ethernet 802.3" Then This is where the script checks the AdapterType, which in this script is listed as "Ethernet 802.3". You should modify this line if you have a different networking environment. Once these changes have been made to the script, create a shortcut to the script and double-click on the shortcut to run the script. Rod Trent
Hack 43 Change from Static IP to DHCP Reconfiguring a network from static IP addressing to DHCP is a chore no system administrator wants to do, but now there's help. Companies grow over time, and their networks have to grow along with them. This means that the static IP addressing that was used when the network was small will no longer practical once the systems number more than a few dozen. Unfortunately, changing machines from static to dynamic addressing usually means visiting each machine, logging on as a local administrator, and clicking through numerous properties sheets to reconfigure TCP/IP settings for network adapters. However, there's an easier way. The VBScript in this hack uses Registry writes to change the TCP/IP settings on a machine from static IP to DHCP. The Code Type the script into Notepad (with Word Wrap disabled) and save it with a .vbs extension as Static2DHCP.vbs: 'All variables declared Option Explicit
Dim oWSHShell Dim sNIC, sMan Dim iCount Set oWSHShell = WScript.CreateObject("WScript.Shell") ' Set the DCHP service to autostart oWSHShell.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\DHCP\Start", 2 ' Get Network card On Error Resume Next iCount = 1 Do sNIC = oWSHShell.RegRead("HKLM\SOFTWARE\Microsoft\Windows NT\ " & _ "CurrentVersion\NetworkCards" & iCount & "\ServiceName") sMan = oWSHShell.RegRead("HKLM\SOFTWARE\Microsoft\Windows NT\ " & _
"CurrentVersion\NetworkCards" & iCount & "\Manufacturer") ' Skip the Async and NDIS services If sMan <> "Microsoft" And Err.Number = 0 Then Call SetNIC End If iCount = iCount + 1 Loop Until Err.Number <> 0 ' Clear the error Err.Clear ' End of Script Sub SetNIC Dim iTest ' Set the NIC service to use DHCP
sNIC = "HKLM\SYSTEM\CurrentControlSet\Services" & sNIC &"\Parameters\TCPIP" iTest = oWSHShell.RegRead(sNIC & "EnableDHCP") If iTest = 0 Then oWSHShell.RegWrite sNIC & "EnableDHCP", 1, "REG_DWORD" oWSHShell.RegWrite sNIC & "IPAddress", "0.0.0.0", "REG_MULTI_SZ" oWSHShell.RegWrite sNIC & "SubnetMask", "0.0.0.0", "REG_MULTI_SZ" End If End Sub Running the Hack To run this hack, call the Static2DHCP.vbs script from a logon script and use Group Policy to assign this logon script to users' machines. When a user next logs on to his machine, the machine's TCP/IP settings will be changed from static to dynamic addressing. To lease an address from the DHCP server, the user's machine needs to be rebooted, so you could also send out a message asking all users to reboot their machines using the method in [Hack #35] or some other approach. If you like, the logon script could also be combined with the SU utility from the Windows 2000 Server Resource Kit to perform a hands-off migration from static to dynamic addressing. Rod Trent
Hack 44 Release and Renew IP Addresses Using this handy script, you can release and renew a dynamically assigned IP address with a click of the mousewell, two clicks, actually. Troubleshooting DHCP lease problems is frustrating when it involves users' desktop machines, because help desk personnel have to explain to users how to open a command prompt, use the ipconfig command, and interpret the output. It would be nice if there were a way to release and renew a machine's IP address without having to go through such techie steps. Well, it turns out there is such a way; just use this handy VBScript to release and renew IP addresses assigned through DHCP. The Code Type the script into Notepad (with Word Wrap disabled) and save it with a .vbs extension as ReleaseRenew.vbs: On Error Resume Next Dim AdapterConfig
Dim RetVal Set AdapterConfig = GetObject("winmgmts:Win32_NetworkAdapterConfiguration") 'WMI release IP Address for all installed network adapters RetVal = AdapterConfig.ReleaseDHCPLeaseAll 'if retval = 1 then display success. If 0 then failure If RetVal = 1 Then MsgBox "IP Address Release was successful." Else MsgBox "DHCP Release failed!" End If 'WMI renew ip for all network adapters RetVal = AdapterConfig.RenewDHCPLeaseAll 'if retval = 1 then display success. If 0 then failure If RetVal = 1 Then
MsgBox "IP Address Renew was successful." Else MsgBox "DHCP Renew failed!" End If Set AdapterConfig = Nothing Running the Hack Copy the script to users' machines and create a shortcut to the script on their desktops. Then, when a user has IP address problems and can't talk to the network, tell her to double-click on the shortcut to release and renew her address, and see if that fixes things. If not, escalate to the next level of troubleshooting! Rod Trent
Hack 45 Use netsh to Change Configuration Settings You can use the Windows 2000 Netshell (netsh) command to do some amazing things, including switching your machine between two different network configurations. If you move your machines around a lot, you know the pain of having to reconfigure their network settings so they can continue to talk on the network. This sort of thing is common in a testbed environment where you are building and testing different network-deployment scenarios prior to rolling out the real thing. You might also have to reconfigure network settings for your computers if you have a routed network with several subnets in one building and frequently move machines from one subnet to anothera common scenario in a physics lab or similar academic environment. Otherwise, if you have a laptop that you need to use at work, at home, and at the sites of several clients, being able to save and reload network configurations would be a real timesaver. There are a few utilities on the market that allow you to quickly switch between different network configurations. NetSwitcher (http://www.netswitcher.com) is one effective tool. But did you know you can do the same thing using the Windows 2000 Netshell (netsh) command?
Using netsh Here's how it works. First, you dump your network settings to a text file through the command line, as follows: netsh -c interface dump > NetworkSettings.txt This command stores your current network settings in a text file named NetworkSettings.txt. Now, let's say you have to reconfigure your machine's network settings to repurpose the machine or move it to a different part of the network. Then, later, if you need to restore your machine's original network settings, you can simply type the following command and load back in the previously dumped settings: netsh -f NetworkSettings.txt Note that the destination filename is not important, so you can effectively create multiple configuration files. You can create and name one for each network configuration you need. For example, you can use Work.txt for the office, Home.txt for your home configuration, and something like Client.txt to hold the values for a network you are temporarily visiting. Rod Trent
Hack 46 Remove Orphaned Network Cards Moving a network adapter card to a new PCI slot in Windows 2000/XP can sometimes cause unexpected results. If you swap out a network interface card (NIC) or move it into a different PCI slot but neglect to run the PnP Hardware Removal wizard or use Device Manager to do so, you might end up with an orphaned NIC. When you perform your hardware change with the card, power up the system, and log into Windows 2000/XP, the hardware wizard might display a message telling you that it detected a change. When you go to configure the network card's TCP/IP settings and try to save them, it will say "Hey, those settings are associated with this network card. Are you sure you want to use them for this one?" Then you'll realize the error you made. So, how do you remove the configuration settings for that orphaned NIC? To remove your orphaned NIC, you first need to know the Registry keys associated with it. This is the first such key: HKLM\Software\Microsoft\WindowsNT\CurrentVersion\NetworkCards You might see one or more subkeys numerically incremented. Selecting the subkey shows you two values: Description
This contains the displayed description of the network card. ServiceName This is the GUID of the network card that is referenced in the Services section of HKLM where the TCP/IP configuration information is maintained, and also under the Enum\PCI section where the configuration parameters of the network card are maintained. This is another important key: HKLM\System\CurrentControlSet\Services{GUID} Within this key, the Parameters\Tcpip subkey contains the TCP/IP configuration settings for the network card, including the DHCP server IP address, the lease information (if you're using DHCP), the subnet mask, and so on. Here is the third key: HKLM\System\CurrentControlSet\Services{ServiceName of Network Card This key represents certain driver parameters related to error control, path to the driver file, and so on. The Enum subkey also points to the PnP Instance ID of the device, if you want a shortcut to where in the HKLM\System\Enum section of the Registry the device is maintained. This is the fourth key: HKLM\System\CurrentControlSet\Control\Network{GUID} This key stores all information related to devices that serve as communications media to transmit/receive data between
devices, such as network cards, infrared ports, and so on. It also contains configuration information for the key Microsoft Network services, such as File & Printer Sharing, QoS, and so on. Each device/adapter has a GUID subkey under this section of the Registry, where you can find the information related to that device. For the network cards, find the appropriate GUID and under this fourth key is the Connection subkey that maintains information related to PnP and the name of the connection (as you see when you go to Start Settings Network & Dialup Connections). The PnpInstanceID value is what we are interested in, because it points to a section of the Registry that maintains configuration information for Plug and Play devices. Finally, this is the last key you need to know about: HKLM\Enum\PCI{PnPInstanceID} This key and its subkeys maintain information specific to the card, such as the PCI Bus it is installed in, driver information, and so forth. Once you find all this information, you can delete those keys related to the card that was once there in the system. Then, you will no longer have to worry about issues of conflicting TCP/IP information between the old card and the new one or orphaned information that may or may not cause conflicts later on. Use this hack at your own riskmaking any changes in the Registry could have dire consequences. Make a backup first and get comfortable with what you are modifying/removing before proceeding with the recommended steps in this hack.
Matt Goedtel
Hack 47 Implement Windows 2000 Network Load Balancing If you need network load balancing software on your network, why not try the NLB component that comes with Windows 2000 Advanced Server? Installing Windows Network Load Balancing (NLB) is often a terrific idea. Most network load balancing hardware devices today cost over $20,000. Thus, if your web application or content site is not necessarily going to support traffic as heavy as http://www.msn.com, NLB is a great choice. However, this mighty piece of web-balancing code from Microsoft has a few implementation gotchas that can crop up at any minute. Let's quickly review the basics, which most you probably already know. You can run NLB only on Windows 2000 Advanced Server, Windows 2000 Datacenter Server, or any edition of Windows Server 2003. NLB also has a role in Microsoft Application Center, but the concept is the same. The following tips provide successful techniques to use with NLB. Two NIC Environment Plan on a two-NIC environment. For instance, identify a private
network for Windows network activity, such as domain-level functions, file sharing, or name resolution. Identify the second NIC as the public- or client-facing connection. While NLB supports both unicast and multicast routing, using two NICS lets you avoid the complexities of using multicast mode. However, if you do want to use multicast mode with NLB, then either use a VLAN for all NLB NIC connections (which prevents saturating your Layer 2 network switches) or use a hub (that's right, a nonswitched hub) for all NLB NICs and allow the hub to make one connection to the Layer 2 switch front-ending your web farm. For security reasons, ensure also that the NLB NIC is stripped of all services, such as File and Print Sharing and the Microsoft network client. However, if you want to go home from work early, don't even try to run NLB on one NIC using multicast mode. The underlying technical challenge for Layer 2 switches and NLB is that the NLB-based NICs create a dummy MAC address and provide it to the MAC address table of the switch to which they are connected. NLB has to receive all traffic addresses to the NLB cluster for the software algorithm in use to make a decision on which node to send the traffic to. Some Layer 2 switches get confused at the same MAC address coming through different ports, and this can create the dreaded broadcast storm. Sample Environment The scenario shown in Figure 4-3 illustrates Microsoft Network Load Balancing in use in a standard Microsoft n-tier highly available Internet configuration. The three front-end IIS web servers (the dark shaded area in Figure 4-3) all are running Windows 2000 Advanced Server and illustrate the redundancy and load balancing archived with an NLB solution. Each web
server has its own internal or primary IP address of the form 10.0.0.x, which is a nonroutable address for security and management purposes, while the clustered or shared IP addresses are of the form 192.168.18.x. The firewall in front of the web farm is configured to perform a network translation of the actual hosted web site's DNS name and IP address to the listening IP address 192.168.18.158 of NLB. In this case, equal load balancing is used, such that each web server will carry 33% of the load so that NLB will load-balance traffic based on an equal distribution of the incoming traffic. If one server goes down, the load will be distributed to the remaining two servers. Figure 4-3. Using Network Load Balancing in an n-tier configuration
Other Microsoft high-availability technologies can also be seen in this examplefor example, the use of a SQL Server cluster (the light-shaded area in Figure 4-3) providing backend database services for this solution. This illustrates the relationship between Microsoft Clustering Services (MSCS) and Microsoft Network Load Balancing (NLB): generally, they secure different tiers of highly available Microsoft solutions. In this case, NLB is used for the web tier, while clustering is used for the database tier. These tips and the corresponding scenario should save you considerable time when implementing NLB web clusters using Windows 2000/2003. The main thing to remember, though, is to never fall for the one NIC multicast option when using Microsoft Network Load Balancing.
Chapter 5. File and Print Hacks #48-53 Section 48. Map Network Drives Section 49. Determine Who Has A Particular File Open on the Network Section 50. Display a Directory Tree Section 51. Automate Printer Management Section 52. Set the Default Printer Based on Location Section 53. Add Printers Based on Name of Computer
Hacks #48-53 File and print is the traditional bread and butter of networking, and while it's gradually being overtaken by more advanced document-management solutions, not may companies are planning on retiring their file servers soon. Managing shared folders and printers also makes up a major component of an administrator's daily routine, and a high proportion of calls to the help desk as well. So it's worth examining some new ways to do old tasks, such as mapping drives or configuring default printers, as well as some ways to perform tasks that are not easy using standard Windows tools, including mapping the structure of a directory or determining who has a certain file open on the network. That's what this chapter is aboutdoing old tasks in new ways and making complex tasks simple.
Hack 48 Map Network Drives This quick way to map a network drive can replace the traditional approach of using batch files. Using VBScript, you can easily map drive letters to shared folders on your network. This approach allows you to use VBScript to map and unmap network drivesfor example, in logon scripts. It also allows you greater flexibility in customizing scripts to perform actions across a network and doesn't require the net use command to work. Basically, the script creates the Network scripting object and then uses the MapNetworkDrive method to assign a drive letter to a network share. I've included examples of code for both mapping and unmapping network drives. The Code First, here's the code for mapping a network drive: Dim net Set net = CreateObject("WScript.Network") net.MapNetworkDrive "Z:", "\server\share"
And here's code for unmapping a network drive: Dim WshNetwork Set WshNetwork = WScript.CreateObject("WScript.Network") WshNetwork.RemoveNetworkDrive "Z:" Running the Hack To use the first snippet of code, type it into Notepad (with Word Wrap disabled) and save it with a .vbs extensionfor example, as map.vbs. Then modify this line to specify the drive letter and share you want to map: net.MapNetworkDrive "Z:", "\server\share" For example, to map the drive letter K: to the Sysback share on a file server with an IP address of 172.16.11.230, change the line to: net.MapNetworkDrive "K:", "\172.16.11.230\Sysback" Then, run the script either by creating a shortcut to it and double-clicking on the shortcut, by opening a command prompt and typing cscript.exe map.vbs, or by calling it from a batch file using a line like this (where path is the absolute path to where the script is located): cscript //nologo path\map.vbs To unmap this drive, type the second code snippet into Notepad, save it as unmap.vbs, and change this line: WshNetwork.RemoveNetworkDrive "Z:"
to this: WshNetwork.RemoveNetworkDrive "K:" Then, run the script using any of the methods described previously. Rod Trent
Hack 49 Determine Who Has A Particular File Open on the Network Using the Hyena utility, quickly find out which user on your network has a particular file open. One of the biggest problems for system administrators is dealing with help-desk or user requests that ask you to see who has a particular document open on the network. This can be most effectively completed using a utility called Hyena from SystemTools.com (http://www.systemtools.com). With this utility, you can even disconnect the user who has the open file or send her a message asking her to close the file in question. Here's a quick walkthrough on how to use the product, so you can see how easy it is to use. Start Hyena and begin by selecting the server name where the file is stored. Expand the + sign and the Shares leaf, and select the share you want to examine. Then, drill through the directories until you find the subdirectory you want, such as SqlDev in Figure 5-1. Figure 5-1. Finding open files in Hyena
Now, select the file you want (SMS_ABC_Database.mdb in our example) in the right pane to see who has it open. Right-click it, and from the context menu select More Functions and then Open By (Figure 5-2). Figure 5-2. Selecting an open file
Now, in the menu to the right, you will see who the user is by examining the User Name column, as shown in Figure 5-3. Figure 5-3. Viewing who has the file open
Now it is just a matter of either sending the user a message or, if he is unavailable, disconnecting him, by right-clicking on the file and choosing the appropriate menu option (Figure 5-4). If you opt for the latter, keep in mind that the file will be closed without giving the user the opportunity to make any final changes. Figure 5-4. Disconnecting the user
You can download a free, 30-day, fully functional, evaluation copy of this great tool from http://systemtools.com/hyena/download_frame.htm. Enjoy! Don Hite
Hack 50 Display a Directory Tree Using some simple coding, you can display a complete map of a directory structure from a command prompt. The Explorer interface makes it easy to browse directories on a Windows machine, but it doesn't provide a simple method to document the structure of directories and their subdirectories. For troubleshooting purposes, it's helpful to know the directory structure on file servers where users store their work. This VBScript simplifies the process of documenting a directory's structure by allowing you to view such structure from the command line. Alternatively, by redirecting the output of the command to a text file, you can print a permanent record of the structure of your directories. The Code Type the following code into Notepad (with Word Wrap turned off) and save the file with a .vbs extension as vbtree.vbs: ' Show simple directory tree Option Explicit
Dim sArg, oFSO Set oFSO = CreateObject("Scripting.FileSystemObject") ' Get folder (default is current directory) If Wscript.Arguments.Count > 0 Then sArg = Wscript.Arguments(0) Else sArg = "." End If sArg = oFSO.GetAbsolutePathName(sArg) ' Process entire tree (if valid folder) If oFSO.FolderExists(sArg) Then Wscript.Echo "Folder tree for:", sArg ShowTree "", oFSO.GetFolder(sArg) End If Set oFSO = Nothing
Wscript.Quit(0) Sub ShowTree(sIndent, oFolder) Dim oSubFolder, ix ix = 1 For Each oSubFolder In oFolder.SubFolders Wscript.Echo sIndent & "+--" & oSubFolder.Name If ix <> oFolder.SubFolders.Count Then ShowTree sIndent & "| ", oSubFolder Else ShowTree sIndent & " ", oSubFolder End If ix = ix + 1 Next End Sub Running the Hack
The script is hardcoded by design to display the structure of the current directory. Place the script into to directory whose structure you want to display, such as C:\data. Then, open a command prompt, change the current directory to C:\data, and type cscript vbtree.vbs to display the tree of subdirectories under the current directory (Figure 5-5). Alternatively, you can type cscript vbtree.vbs > tree.txt to redirect the output of the script to a text file for documentation purposes. Figure 5-5. Displaying the tree of subdirectories under C:\data Make sure you have the latest scripting engines on the workstation from which you run this script. You can download current scripting engines from the Microsoft Scripting home page (http://msdn.microsoft.com/scripting/). Rod Trent
Hack 51 Automate Printer Management Here are a couple nifty ways to manage printers from the command line instead of via the GUI. Managing printer mappings tends to be complicated task, especially in larger environments. Increased level of difficulty results from the fact that, in such situations, printers are shared (rather than used by individual users). Shared printer devices are typically network-attached (i.e., they either have internal network cards or are connected to external hardware-based print servers). This differs from a home/small office setup, where printing devices connect to individual workstations via parallel, USB, or infrared port. The way printer software is installed also varies by connection. Local printers are either autodetected (in Windows 2000 and XP) or installed via the Add Printer wizard. In the case of network-attached devices, printers are first installed with the Add Printer wizard on a network server. Next, users connect to these printers (either by double-clicking on the printers' icons in My Network Places/Network Neighborhood or by running the Add Printer wizard), which triggers automatic download of printer drivers and their configuration on the local workstations. The printer mappings are stored as part of a user's profile. Since the process of connecting to network printers is straightforward, you can leave this task to users. This is a viable solution, as long as printers are easy to find (e.g., by implementing a naming convention that clearly identifies the
printer's location). This, however, is not always the case. CON2PRT If you want to be able to manage printer mappings easily, you can use the CON2PRT command, which has been available since the release of the Zero Administration Kit for Windows NT 4.0. CON2PRT allows you to map network printers from the command line and is extremely easy to use. It works with Windows NT 4.0, 2000, and XP and can easily be included in a login script. Its only limitation is the fact that it cannot be used to force the installation of the locally attached printer, but this, fortunately, is rarely needed (since, with Windows 2000 and XP, local printers are usually autodetected). The CON2PRT command offers three functions: CON2PRT /f Deletes all existing printer mappings CON2PRT /c Creates a new printer mapping CON2PRT /cd Creates a new printer mapping and sets it as the default
For example, to set a default printer to the printer LJ4000_PS_01 on the server SERVER01, you would type in the following: CON2PRT /cd \SERVER01\LJ4000_PS_01 You can find the complete syntax of CON2PRT by typing the standard /? switch at the command prompt, and download CON2PRT.EXE (along with the rest of the Zero Administration Kit for Windows) from http://www.microsoft.com/ntworkstation/downloads/Recommended/Featured/NTZAK.asp RUNDLL32 While CON2PRT is easy to use, its capabilities are limited to removing all printer mappings and creating new ones (including setting the default printer). Though it seems that this might be all you need when dealing with printers, Windows offers much wider range of functionality. As you probably know, most of the features used by Windows in the traditional 32-bit Windows environment are implemented in the form of Dynamic Link Libraries (DLLs, files with the extension .dll). As the name indicates, DLLs are collections (libraries) of functions that can be used whenever they are needed (dynamically) by any process operating within Windows. Unfortunately, access to functions included in the DLL files, in general, is restricted primarily to programmers. However, there are exceptions to this rule. For example, you can take advantage of certain specifically designed DLLs by running the RUNDLL32 command that is included in every 32-bit version of Windows. Keep in mind, though, that the number of functions available with RUNDLL32 is fairly small (for example, it does not include any of the Win32 API calls exported from the system DLLs).
Printer-management functions used by RUNDLL32 are stored in the printui.dll file. To find out the collection of functions included in this file, you can run the following from the command prompt or Start Run box: rundll32 printui.dll,PrintUIEntry /? This will display a long list of options available to you. In general, you use the following syntax of commands (where options and commandfile parameters vary): rundll32 printui.dll,PrintUIEntry options commandfile Here are just a few of many possible uses of this command: Delete a local printer (called HP LaserJet 5) rundll32 printui.dll,PrintUIEntry /dl /n "HP LaserJet 5" Delete the local printer on the remote computer (called RemotePC01) rundll32 printui.dll,PrintUIEntry /dl /n "HP LaserJet 5" /c\RemotePC1 Delete a network printer rundll32 printui.dll,PrintUIEntry /dn /n "\SERVERNAME\PRINTERNAME"
Add a network printer rundll32 printui.dll,PrintUIEntry /in /n "\SERVERNAME\PRINTERNAME" Set a printer as the default rundll32 printui.dll,PrintUIEntry /y /n "\SERVERNAME\PRINTERNAME" Marcin Policht
Hack 52 Set the Default Printer Based on Location Using a combination of Group Policy and logon scripts, you can easily assign different default printers to different users. At the college, where I work, we use mandatory profiles for students, who log into Windows XP machines in three different computer labs in a Windows 2000 Active Directory environment. Each lab has its own networked printer, which should be used by students working in that lab. But the profile can have only one default printer set, which obviously wouldn't work, since students in two labs would default to a printer that wasn't in their room. The Code Here is the quick and dirty VBScript that solves the problem: set net = CreateObject("WScript.Network") workstation=net.computername location=left(workstation,2) printername=""
select case location case "L1" printername="L1 LaserJet" case "L2" printername="L2 LaserJet" case "L3" printername="L3 LaserJet" End Select if printername<>"" then net.SetDefaultPrinter(printername) set net = Nothing Running the Hack The script looks at the first two characters of the computer name (this specifies which lab the computer is located in) and then sets the default printer accordingly. If the student is logging on to a computer that's not in one of the labs, the default printer isn't changed. If you name printers differently in your own environment, you might have to customize the script further as needed. We run this script in our own environment by specifying it as a logon script using Group Policy (so legacy Windows 98 machines ignore it), because all our labs have Windows XP anyway. All our machines also have the necessary drivers installed and configured, and the printers have the same names, so we just have to change the default printer. Peter Rysavy
Hack 53 Add Printers Based on Name of Computer Here's a logon script you can use to solve a complicated problem in printer management: performing a logon task based on the name of the computer being logged into. In various forums, I have noticed questions regarding how to perform tasks at logon based on the name of the computer that the user is logging into. In my environment (a small community college), we thought we could have fewer servers and reduce network traffic by configuring all our computers to use TCP/IP printing. This worked out pretty well for a while, but we discovered a few drawbacks of using TCP/IP printing. For example, there is no control over excessive printing and it is not possible to track costs back to a user. Also, it is difficult to update systems when printers get replaced We soon split our thinking and were able to switch 99% of our student computers to print through a few servers. To assist us with our print-management needs, we purchased Print Manager Plus (http://www.printmanagerplus.com). Print Manager Plus has many benefits for my environment. We are an educational institution that has a number of open-use areas where students and the public can use our computers. We do not track printing costs back to users, and we were experiencing a rising cost of print supplies due to misuse of our printers. The implementation of Print Manager Plus allowed us to put controls in place that limit abuse in the following ways:
The user is able to print only 8 pages at a time. If the user's document is 10 pages long, he must print pages 1-8, then 9-10. There is a limit on the file size of the print job. The user is unable to print a document that is larger than 15MB when it arrives at the server. Print Manager Plus has the ability to inform the user when he exceeds the defined limits. I have customized the messages sent from Print Manager Plus to the user so that they present him with options on how to print the document in question. Server-based printers, however, created a few headaches of their own. In particular, any room is pretty much fair game for us to use when we provide training to not only our students, but also our faculty and staff. We needed a way to set the right printer on any given computer for any user who logs on. Also, we wanted to use one logon script for all users in any domain. We also had a Windows 2000 Terminal Server available but had not made good use of it until recently. The original thinking was to install a bunch of printers on it and trust users to select the appropriate printer before hitting the print button. We soon had calls asking, "What are all these documents coming out of my printer?" Anyway, I thought about this awhile and decided that the best approach would be to add the printers based on the name of the computer. We have a standard naming convention in use that made this task possible. This hack contains the code that I came up with. The code should be pretty readable by itself, but I'll spend some time
briefly discussing some of its more major parts. The Code To get the code for the script, I suggest downloading the Logon.vbs file from the O'Reilly web site (http://www.oreilly.com/catalog/winsvrhks/), because it's too long to type from scratch. This version of the script was tested on Windows 2000 Service Pack 2 running Internet Explorer 6 Service Pack 1 with Microsoft Windows Script v5.6. It was also tested on Windows XP Professional participating in a small Active Directory domain. I have had a variation of this script in production for a long time now with great success. But, as always, either the differences in your environment or something I missed in editing the script for this hack might cause things behave unexpectedly. Depending on your environment, the code requires: A recent version of Internet Explorer (http://www.microsoft.com/windows/ie/default.asp).
Windows Script 5.6 for Windows 98/ME/NT (http://www.microsoft.com/downloads/details.aspx? FamilyID=0a8a18f6-249c-4a72-bfcf-fc6af26dc390) Windows Script for 2000/XP (http://www.microsoft.com/downloads/details.aspx? FamilyID=c717d943-7e4b-4622-86eb- 95a22b832caa) Active Directory Client Extensions for Windows 9x, ME or NT4 (http://www.microsoft.com/windows2000/techinfo/howitworks/activedirectory/adsilinks.asp For more information on using Internet Explorer for status messages, see "Using an IE Window to Display Progress" (http://www.myitforum.com/articles/11/view.asp?id=3489), "VBScript Forms (Part 1): Using Internet Explorer for Data Input/Output Forms" (http://www.myitforum.com/articles/11/view.asp?id=4390), and "Using IE to Browse for Files" (http://www.myitforum.com/articles/11/view.asp?id=4229). Perform initial tasks This section sets up the basics of the script. In this script, I also call a few subroutines/functions (listed further in later sections) that either gather information or perform my required tasks. I like using subroutines and functions, because it makes my code reusable or easily stored in a code library for future
coding endeavors. This section accomplishes the following major tasks: Call a subroutine that gathers basic system information Exit the script if user is logged on locally to the server Call subroutines to gather group memberships The script also performs other tasks, as discussed in comments throughout the code. ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' File: Logon.vbs ' Updated: April 2003 ' Version: 2.1 ' Author: Dan Thomson, myITforum.com columnist ' I can be contacted at dethomson@hotmail.com ' ' Usage: ' This script can be directly assigned as a logon script for
' Windows 2000 or greater clients. For older systems, this ' script will need to be called from a logon batch file. ' ' Input: ' ' Requirements: ' Win 9x, ME or NT 4: ' - Active Directory Client Extensions ' http://www.microsoft.com/windows2000/techinfo/howitworks/ ' activedirectory/adsilinks.asp ' - Windows Script ' http://msdn.microsoft.com/library/default.asp?url=/downloads ' /list/webdev.asp ' - A recent version of Internet Explorer ' ' Notes: ' Tested on Windows 2000 Professional running Windows Script v5.6
' and participating in an AD domain ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' On Error Resume Next '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' Define Variables and Constants '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Dim objFileSys Dim objIntExplorer Dim objWshNetwork Dim objWshShell Dim strDomain 'Domain of the user Dim strHomePage 'Homepage to be set for user Dim strLogonPath 'Path to location from where the script is running Dim strOSProdType 'OS Product type (WinNT, LanmanNT, ServerNT)
Dim strWorkstation 'Local Computer Name Dim strUserGroups 'List of groups the user is a meber of Dim intCounter 'General counter Const UseNTServer = 0 'Sets whether this script runs when logging on locally 'to Windows Servers. 'Values are: 1 (Yes) OR 0 (No) 'Initialize common scripting objects Set objFileSys = CreateObject( "Scripting.FileSystemObject" ) Set objWshNetwork = CreateObject( "WScript.Network" ) Set objWshShell = CreateObject( "WScript.Shell" ) 'Pause script until user is fully logged on (applies only to Win 9x or ME) 'This will timeout after 10 seconds strUser = "" intCounter = 0
Do strUserID = objWshNetwork.Username intCounter = intCounter + 1 Wscript.Sleep 500 Loop Until strUserID <> "" OR intCounter > 20 'Check for error getting username If strUserID = "" Then objWshShell.Popup "Logon script failed - Contact the Helpdesk @ x 345", , _ "Logon script", 48 Call Cleanup End If 'Setup IE for use as a status message window Call SetupIE 'Display welcome message Call UserPrompt ("Welcome " & strUserID)
'Add horizontal line as a 'break' objIntExplorer.Document.WriteLn("<hr style=""width:100%"">") 'Gather some basic system info Call GetSystemInfo If IsTerminalServerSession <> True Then 'Exit if we are logging on locally to a server and the 'script is set to NOT run on servers IF UseNTServer = 0 AND (strOSProdType = "LanmanNT" OR strOSProdType = "ServerNT") Then objWshShell.Popup "Windows Server - Exiting Logon Script!", 10, _ "Logon to " & strDomain, 16 Call CleanUp End if End If
'Get group memberships strUserGroups = "" Call GetLocalGroupMembership Call GetGlobalGroupMembership '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' Map drives, add shared printers and set default homepage '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Determining workstation settings This section determines which settings should be applied to the workstation, based on the name of the workstation. Our environment has a nice naming convention: the building, room number, and station number are identified in the name. For example, the name Blg4Rm105-03 identifies a computer as being station 3, located in building 4, room 105. To determine which mappings get assigned to a computer, all I have to do is base my criteria on everything on the left of the dash (-). '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' '
' Part A ' This section performs actions based on computer name ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' 'The left side of the computer name contains building and room information If Instr( 1, strWorkstation, "-", 1) > 0 Then strWorkstation = _ Left( strWorkstation, ( Instr( 1, strWorkstation, "-", 1))) End If Select Case UCase( strWorkstation ) Case "BLD1RM101-" Call MapDrive ("U:", "MyShareSvr1", "MyShare1") Call AddPrinter ("Mydomain2", "MyPrtSvr2", "Bld1Rm101-HP4050") objWshNetwork.SetDefaultPrinter "\MyPrtSvr2\Bld1Rm101-HP4050"
strHomePage = "http://www.chesapeake.edu/academic_info/ " & _ "acad_computing.asp" Case "BLD1RM202-" Call MapDrive ("U:", "MyShareSvr2", "MyShare2") Call AddPrinter ("Mydomain1", "MyPrtSvr1", "Bld1Rm202-HP4000") objWshNetwork.SetDefaultPrinter "\MyPrtSvr1\Bld1Rm202-HP4000" strHomePage = "http://www.chesapeake.edu/library/default.asp" Case "BLD3RM104-" 'This room uses TCP/IP printing instead of a print server. 'Only set homepage strHomePage = "http://www.chesapeake.edu/writing/wchome.htm" Case Else End Select '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Adding mappings based on group membership
Adding mappings based upon the computer name is cool. However, there will always be a need to perform tasks based on specific group membership. This section takes care of such tasks. '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' Part B ' This section performs actions based on group membership ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' If InGroup( "ShareForStaff" ) Then Call MapDrive ("X:", "StaffSvr1", "StaffShare1") strHomePage = "http://www.chesapeake.edu/generalinfo/cambridge.asp" End If If InGroup( "ShareForStudents" ) Then Call MapDrive ("Y:", "StudentSvr1", "StudentShare1") strHomePage = "http://www.chesapeake.edu" End If
'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' End section '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Setting the IE home page and final message This section sets the IE home page (if specified), starts SMSls.bat, and posts a final message to the user. The script tests to determine if the user is a member of the Domain Admins or DoNotInstallSMS groups. If the user is a member of either of these groups, SMSls.bat is skipped. This is helpful if you want to get in quick to do a small task or to keep SMS off some of your more persnickety users' computers. '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' 'Set default homepage If strHomePage <> "" Then Err.Clear objWshShell.RegWrite _ "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", strHomePage
If Err = 0 Then Call UserPrompt ("Set Internet home page to " & strHomePage) End If 'Start SMSls.bat 'Do not run if a member of the Domain Administrators 'or in the global group DoNotInstallSMS If InGroup("Domain Admins") OR InGroup("DoNotInstallSMS") Then Call UserPrompt ("Skipping SMSLS.BAT") Else objWshShell.Run "%COMSPEC% /c " & strLogonPath & "\smsls.bat", 0, False End If 'Add horizontal line as a 'break' objIntExplorer.Document.WriteLn("<hr style=""width:100%"">") 'Inform user that logon process is done Call UserPrompt ("Finished network logon processes")
'Wait 10 seconds Wscript.Sleep (10000) 'Close Internet Explorer objIntExplorer.Quit( ) Call Cleanup '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' That's the end of the first major section of the script. The following subsections list and explain the various subroutines and functions. Connecting to a shared network printer The following routine is where the printer mapping occurs. It first verifies that the share is accessible and creates the mapping. If the share is not accessible or is not a valid print share, the user will be prompted with an error message that lets her know she should call the help desk. ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
' ' Sub: AddPrinter ' ' Purpose: Connect to shared network printer ' ' Input: ' strPrtServerDomain Domain in which print server is a member ' strPrtServer Name of print server ' strPrtShare Share name of printer ' ' Output: ' ' Usage: ' Call AddPrinter ("Mydomain2", "MyPrtSvr2", "Bld1Rm101-HP4050") ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Private Sub AddPrinter(strPrtServerDomain, strPrtServer, strPrtShare)
On Error Resume Next Dim strPrtPath 'Full path to printer share Dim objPrinter 'Object reference to printer Dim strMsg 'Message output to user Dim blnError 'True / False error condition blnError = False 'Build path to printer share strPrtPath = "\" & strPrtServer & "" & strPrtShare 'Test to see if shared printer exists. 'Proceed if yes, set error condition msg if no. Set objPrinter = GetObject _ ("WinNT://" & strPrtServerDomain & "/" & strPrtServer & "/" & _ strPrtShare)
If IsObject( objPrinter ) AND _ (objPrinter.Name <> "" AND objPrinter.Class = "PrintQueue") Then 'Different mapping techniques depending on OS version If objWshShell.ExpandEnvironmentStrings( "%OS%" ) = "Windows_NT" Then Err.Clear 'Map printer objWshNetwork.AddWindowsPrinterConnection strPrtPath Else 'Mapping printers for Win9x & ME is a pain and unreliable. End If Else blnError = True End IF 'Check error condition and output appropriate user message
If Err <> 0 OR blnError = True Then strMsg = "Unable to connect to network printer. " & vbCrLf & _ "Please contact the Helpdesk @ ext 345" & vbCrLf & _ "and ask them to check the " & strPrtServer & " server." & _ vbCrLf & vbCrLf & _ "Let them know that you are unable to connect to the '" _ & strPrtShare & "' printer" objWshShell.Popup strMsg,, "Logon Error !", 48 Else Call UserPrompt ("Successfully added printer connection to " & _ strPrtPath) End If Set objPrinter = Nothing End Sub ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
Mapping a drive to a shared folder This routine is where the drive mapping occurs. It first removes any preexisting drive mapping that might be using the designated drive letter. Then, it verifies that the share is accessible and creates the mapping. If the share is not accessible, the user will be prompted with an error message that lets him know he should call the help desk. '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' Sub: MapDrive ' ' Purpose: Map a drive to a shared folder ' ' Input: ' strDrive Drive letter to which share is mapped ' strServer Name of server that hosts the share ' strShare Share name ' ' Output:
' ' Usage: ' Call MapDrive ("X:", "StaffSvr1", "StaffShare1") ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Private Sub MapDrive( strDrive, strServer, strShare ) On Error Resume Next Dim strPath 'Full path to printer share Dim blnError 'True / False error condition blnError = False 'Disconnect Drive if drive letter is already mapped. 'This assures everyone has the same drive mappings
If objFileSys.DriveExists(strDrive) = True Then objWshNetwork.RemoveNetworkDrive strDrive, , True End If 'Build path to share strPath = "\" & strServer & "" & strShare 'Test to see if share exists. Proceed if yes, set error condition if no. If objFileSys.DriveExists(strPath) = True Then Err.Clear objWshNetwork.MapNetworkDrive strDrive, strPath Else blnError = True End If 'Check error condition and output appropriate user message If Err.Number <> 0 OR blnError = True Then 'Display message box informing user that the connection failed
strMsg = "Unable to connect to network share. " & vbCrLf & _ "Please contact the Helpdesk @ ext 345 and ask them " & _ "to check the " & strServer & " server." & vbCrLf & _ "Let them know that you are unable to connect to the " & _ "'" & strPath & "' share" objWshShell.Popup strMsg,, "Logon Error !", 48 Else Call UserPrompt ("Successfully added mapped drive connection to " & strPath) End If End Sub '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Gathering local group memberships This routine collects information about any local groups to which the user might belong. The names of these groups get placed into the strUserGroups variable for future reference. ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
' ' Sub: GetLocalGroupMembership ' ' Purpose: Gather all local groups to which the current user belongs ' ' Input: ' ' Output: Local group names are added to strUserGroups ' ' Usage: Call GetLocalGroupMembership ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Private Sub GetLocalGroupMembership On Error Resume Next Dim colGroups 'Collection of groups on the local system Dim objGroup 'Object reference to individual groups
Dim objUser 'Object reference to individual group member 'Verify system is not Windows 9x or ME If objWshShell.ExpandEnvironmentStrings( "%OS%" ) = "Windows_NT" Then 'Connect to local system Set colGroups = GetObject( "WinNT://" & strWorkstation ) colGroups.Filter = Array( "group" ) 'Process each group For Each objGroup In colGroups 'Process each user in group For Each objUser in objGroup.Members 'Check if current user belongs to group being processed If LCase( objUser.Name ) = LCase( strUserID ) Then 'Add group name to list strUserGroups = strUserGroups & objGroup.Name & "," End If Next
Next Set colGroups = Nothing End If End Sub '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Gathering global group memberships This routine is similar to the previous one, except it collects information about any global (rather than local) groups to which the user might belong. The names of the groups also get placed into the strUserGroups variable for future reference. Since some users might still be running Windows NT domains, I use the WinNT syntax instead of LDAP to perform the query, for cross- platform interoperability. This way is a little easier anyway. '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' Sub: GetGlobalGroupMembership '
' Purpose: Gather all global groups the current user belongs to ' ' Input: ' ' Output: Global group names are added to strUserGroups ' ' Usage: Call GetGlobalGroupMembership ' ' Notes: Use WinNT connection method to be backwards ' compatible with NT 4 domains ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Private Sub GetGlobalGroupMembership On Error Resume Next Dim objNameSpace Dim objUser
Const ADS_READONLY_SERVER = 4 Set objNameSpace = GetObject( "WinNT:" ) 'Use the OpenDSObject method with the ADS_READONLY_SERVER 'value to grab the "closest" domain controller 'Connect to user object in the domain Set objUser = objNameSpace.OpenDSObject( _ "WinNT://" & strDomain & "/" & strUserID, "", "", ADS_READONLY_SERVER) 'Process each group For Each objGroup In objUser.Groups 'Add group name to list strUserGroups = strUserGroups & objGroup.Name & "," Next Set objNameSpace = Nothing
End Sub '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Determining if user belongs to a specified group This simple routine searches the list of group names that is contained in the strUserGroups variable for the specified group and returns True if the group is found. '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' Function: InGroup ' ' Purpose: Determine if user belongs to specified group ' ' Input: Name of group to test for membership ' ' Output: True or False '
' Usage: If InGroup("Domain Admins") Then ' ' Requirements: ' strUserGroups must have been previously populated via ' GetLocalGroupMembership and/or GetGlobalGroupMembership ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Private Function InGroup(strGroup) On Error Resume Next InGroup = False 'Search strUserGroups for strGroup If Instr( 1, LCase( strUserGroups ), LCase( strGroup ), 1) Then InGroup = True End Function ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
Gathering basic information about the local system Here is another routine that gathers specific information about the local computer, such as the user domain, workstation name, product type, and the path to the location from which the script is running. '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' Sub: GetSystemInfo ' ' Purpose: Gather basic information about the local system ' ' Input: ' ' Output: strDomain, strOSProdType, strWorkstation, strLogonPath ' ' Usage: Call GetSystemInfo ' ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
Private Sub GetSystemInfo On Error Resume Next 'Get domain name If objWshShell.ExpandEnvironmentStrings( "%OS%" ) = "Windows_NT" Then strDomain = objWshNetwork.UserDomain Else strDomain = objWshShell.RegRead( "HKLM\System\CurrentControlSet" & _ "Services\MSNP32\NetWorkProvider\AuthenticatingAgent" ) End If 'Get Product Type from Registry (WinNT, LanmanNT, ServerNT) strOSProdType = objWshShell.RegRead( _ "HKLM\System\CurrentControlSet\Control\ProductOptions\ProductType") 'Get computer name
If IsTerminalServerSession = True Then 'Set strWorkstation to the real name and not the name of the server strWorkstation = objWshShell.ExpandEnvironmentStrings( "%CLIENTNAME%" ) Else strWorkstation = objWshNetwork.ComputerName End If 'Get the path to the location from where the script is running strLogonPath = Left( Wscript.ScriptFullName, _ ( InstrRev( Wscript.ScriptFullName, "") -1)) End Sub '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Determining if the script is running in a terminal server session The following routine identifies whether the user is logging on via
a Windows terminal session and returns True if this is the case. The determinant test criteria is whether the workstation has a valid %ClientName% environment variable set. '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' Function: IsTerminalServer ' ' Purpose: Determine if the script is running in a terminal server session ' ' Input: ' ' Output: ' True if running in a terminal server session ' False if not running in a terminal server session ' Usage: ' If IsTerminalServerSession = True Then ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Private Function IsTerminalServerSession
On Error Resume Next Dim strName 'Detect if this is a terminal server session 'If it is, set some names to the terminal server client name strName = objWshShell.ExpandEnvironmentStrings( "%CLIENTNAME%" ) If strName <> "%CLIENTNAME%" AND strName <> "" Then _ IsTerminalServerSession = True End Function '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Setting up IE for use as a status message window I like to use Internet Explorer as a general status message
screen for users. This routine gets Internet Explorer set up and ready for this purpose. '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' Sub: SetupIE ' ' Purpose: Set up Internet Explorer for use as a status message window ' ' Input: ' ' Output: ' ' Usage: Call SetupIE ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Private Sub SetupIE On Error Resume Next
Dim strTitle 'Title of IE window Dim intCount 'Counter used during AppActivate strTitle = "Logon script status" 'Create reference to objIntExplorer 'This will be used for the user messages. Also set IE display attributes Set objIntExplorer = Wscript.CreateObject("InternetExplorer.Application") With objIntExplorer .Navigate "about:blank" .ToolBar = 0 .Menubar = 0 .StatusBar = 0 .Width = 600 .Height = 350 .Left = 100 .Top = 100
End With 'Set some formating With objIntExplorer.Document .WriteLn ("<!doctype html public>") .WriteLn ("<head>") .WriteLn ("") .WriteLn ("<style type=""text/css"">") .WriteLn ("body {text-align: left; font-family: arial; _ font-size: 10pt}") .WriteLn ("</style>") .WriteLn ("</head>") End With 'Wait for IE to finish Do While (objIntExplorer.Busy) Wscript.Sleep 200 Loop
'Show IE objIntExplorer.Visible = 1 'Make IE the active window For intCount = 1 To 100 If objWshShell.AppActivate(strTitle) Then Exit For WScript.Sleep 50 Next End Sub '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Using IE as a status message window Finally, the last routine is just a little helper for the status message window. There's nothing fancy going on here. ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
'
' Sub: UserPrompt
'
' Purpose: Use Internet Explorer as a status message window
'
' Input: strPrompt
'
' Output: Output is sent to the open Internet Explorer window
'
' Usage:
'
''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
Private Sub UserPrompt( strPrompt )
On Error Resume Next
objIntExplorer.Document.WriteLn (strPrompt & "
")
End Sub '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' ' ' Sub: Cleanup ' ' Purpose: Release common objects and exit script ' ' Input: ' ' Output: ' ' Usage: Call Cleanup ' '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' Sub Cleanup
On Error Resume Next Set objFileSys = Nothing Set objWshNetwork = Nothing Set objWshShell = Nothing Set objIntExplorer = Nothing 'Exit script Wscript.Quit( ) End Sub Running the Hack Since I still have a few NT clients on my network, I place a batch file named logon.bat in the NETLOGON shares on my domain controllers. All users are then assigned this logon.bat file as their startup script. This logon.bat file verifies that the user is on a supported platform (NT, 2000, or XP) and then kicks in the logon.vbs script via a call like this (depending on the path to the script):
cscript //nologo %0..\logon.vbs To keep the user informed of the logon progress, status messages are posted to an Internet Explorer window. These are the three results of running the logon script: The user gets the appropriate printer added. The user gets mapped drives added where appropriate. The user's homepage is reset (depending on group membership and computer name). This sample logon script can prove useful for small organizations. However, storing all the mapping information in the script can soon become unwieldy. If you are in a large organization and want to perform tasks at logon based on computer names, it might be best to offload the mapping information to a network database that can be queried via the logon script. Dan Thomson
Chapter 6. IIS Hacks #54-61 Section 54. Back Up the Metabase Section 55. Restore the Metabase Section 56. Map the Metabase Section 57. Metabase Hacks Section 58. Hide the Metabase Section 59. IIS Administration Scripts Section 60. Run Other Web Servers Section 61. IISFAQ
Hacks #54-61 Internet Information Services (IIS) is one of the more popular features of Windows server platforms. Whether you're running IIS 5 (Windows 2000 Server) or IIS 6 (Windows Server 2003), the ability to hack the metabase (the place where IIS stores its configuration settings) lets you do things that are impossible to do using the standard GUI tool for managing IISnamely, Internet Services Manager. Before you start hacking the metabase, however, you'd better be sure you've backed it up properly and know your way around inside it. Several hacks in this chapter deal with these topics, including how to restore the metabase when you have no working backup. Also included are tips on how to hide the metabase from attackers to make it more secure, how to use scripts to manage different aspects of IIS, and how to allow other HTTP services, such as the Apache web server, to run on Windows and coexist with IIS.
Hack 54 Back Up the Metabase There's more than one reason for backing up the metabase, and there are different ways of doing it too. Instead of storing its configuration settings in the Windows Registry, like most other services store their configuration settings, IIS stores most of its settings in a file called the metabase. On Windows 2000 (IIS 5), the metabase is a binary file named MetaBase.bin, found in the %SystemRoot%\system32\inetsrv folder. Windows Server 2003 (IIS 6) uses XML as the format for its configuration information, rather than the proprietary binary format used by IIS 5. As a result, there are two metabase files in IIS 6: the metabase proper (MetaBase.xml), where configuration settings are stored, and an associated XML schema file (MBSchema.xml) that defines the XML syntax of the MetaBase.xml file. Because of the differences between these two platforms, we'll have to consider them separately when backing up IIS settings. Why Back Up the Metabase? Many IIS administrators don't realize that there are two reasons for backing up the metabase and each reason requires a different method for doing so. The most obvious reason is to prepare for the eventuality of a disaster. Note that I said eventuality instead of possibility, because wise system administrators know that it's
only a matter of time before something horrid happens. To prepare for such a disaster, you certainly want to back up the metabase on your IIS machines, but having a backup of the metabase alone isn't going to be much help if the hard drive containing your boot volume is toast; the proper functioning of the metabase depends on having access to some encryption keys that are part of the System State on your server. System State is a fancy phrase for a collection of important configuration information that lets you recover the predisaster state of your system after a massive failure renders it unbootable. You'll find more information about what's included in a server's System State in [Hack #92] in Chapter 10. So, here's the point: if you back up the IIS metabase without its associated System State, you won't be able to recover your web server after a disaster. Microsoft doesn't document clearly in either their Windows help files or on their web site that, by default, when you back up the System State information on a Windows 2000 or Windows Server 2003 machine, you also automatically back up the metabasethat is, if you've left your backup settings at their defaults. Let's dig a little deeper. Advanced Backup Settings Hidden away in the Windows Backup utility is a properties box called Advanced Backup Options (Figure 6-1). To access Advanced Backup Options, select the items you want to back up, click Start Backup, and then click Advanced. Figure 6-1. The Advanced Backup Options properties box in the Backup utility
When you choose to back up the server's System State, the setting "Automatically backup System Protected files with the System State" is selected by default. This setting actually backs up the entire contents of the %SystemRoot% folder and all its subfolders along with the rest of the System State information on the server. Of course, the inetsrv directory where the metabase is found is part of this directory hierarchy, so the metabase gets backed up along the way. So, if you want to back up the IIS metabase for comprehensive recovery from a disaster, simply back up the System State using Backup (or its command-line version, ntbackup). Since the "Automatically backup System Protected Files with the System State" checkbox automatically adds several hundred megabytes to the size of your System State backup, if you're the kind of person who likes living dangerously and you want to save on tape and
speed up your backup, you could deselect this checkbox. Naturally, it's usually best to avoid cutting corners like this and leave the setting checked. Quick Backups Preparing for that eventual disaster isn't the only reason for backing up the metabase. You should also make backup copies of the metabase if you plan on tinkering with it, either using MetaEdit (metaedit.exe)a tool in the Windows 2000 Server Resource Kit, used for editing the IIS 5 metabaseor a text editor such as Notepad, which you can use to edit the XML metabase of IIS 6 directly. The danger here is that indelicately laying hands on the metabase might break something and render your metabase unreadable to IIS, forcing you to restore before your WWW Publishing Service starts again and users can access your web sites. The syntax of the metabase is strict, and any untoward alterations could cause a service to behave unpredictably at best, or just fail altogether at worst. So, before you roll up your sleeves and start fiddling with your metabase, it behooves you to make a quick backup. You could back up the entire System State on your machine before touching the metabase, but that's overkill. You could use Backup to back up only the inetsrv directory on your server, but there are faster and simpler ways. IIS 5 You can back up the metabase from the GUI by using Internet
Services Manager, the MMC console used for configuring and managing IIS. Right-click on the node that represents your server and select Backup/Restore Configuration to open a dialog box of the same name, as shown in Figure 6-2. Click the "Create backup..." button, type a descriptive name for your backup, and click OK. Backups are stored in the %SystemRoot%\System32\InetSrv\MetaBack directory; to be extra careful, you can include this directory in your regular tape backups. Figure 6-2. Backing up the metabase Restoring the metabase is just as straightforward: select the metabase backup you want to restore and click Restore. If you're using MetaEdit to editing the IIS 5 metabase, you're in luck; conveniently enough, MetaEdit itself is capable of making
quick metabase backups. Before you start using MetaEdit, however, be sure to download the latest version of the tool from Microsoft's web site. Interestingly, when you search the Microsoft Download Center (http://www.microsoft.com/downloads/) for metaedit, you only get Version 2.0 of the tool, which is out of date. To obtain the latest version of the tool (MetaEdit 2.2), see Microsoft Knowledge Base article 232068 (http://support.microsoft.com/default.aspx?scid=kb;en- us;232068), which has a link to the installation package. Once you download and install the self-extracting file, you have two tools to play with: a Metabase Browser/Editor similar to Registry Editor and a Metabase Consistency Checker designed to ensure the syntax of the metabase remains consistent. Unfortunately, the Consistency Checker isn't too useful, because it won't repair certain types of mistakes you can make with the Browser/Editor, such as entering illegal values for metabase keys. So, just like when you edit the Registry directly, you're on your own and in dangerous territory. In fact, it's always a good idea to back up the metabase periodically, even if you make changes to your metabase only through the Internet Services Manager GUI. That way, if you make a lot of configuration changes to IIS and discover your web applications acting a mite odd, you can reverse those changes quickly and easily by restoring the metabase from recent backup. In fact, this might be the only way to return to a working IIS configuration if you can't remember all the changes you've made. So, regular metabase backups are a part of good housekeeping on your IIS machines. Backing up the metabase with MetaEdit is straightforward: simply open MetaEdit (it's installed by default under Administrative Tools) and select Metabase Backup/Restore
from the menu. This opens the same Configuration Backup/Restore dialog box (Figure 6-2) and saves backups in the same MetaBack directory as before. GUI- and MetaEdit-made backups are compatible, so you can back up using one way and restore using the other if you prefer. Remember that these quick backups of the metabase are designed only to recover from a corrupt metabase or to restore the metabase to an earlier working condition; you cannot use them to restore an IIS machine from scratch; use System State for that. Also, note that a metabase backup made on one machine cannot be restored to a different machine, due to the differences in System State information between the machines. There's a workaround for that too, though: export the metabase instead of backing it up. Exporting saves all or part of the metabase in a text file instead of in the proprietary binary format used for metabase backups. Note that exporting the metabase requires you use MetaEdit, because export functionality is not included in Internet Services Manager for IIS 5. Exporting the metabase is useful if you want to document the contents of your metabase by printing it out. It's also useful for copying web site configurations from one IIS machine to another. For example, if you want to mirror a site on two machines, simply export the metabase keys for the web site and then import the export file into the second machine. But don't forget to copy your site content as well; remember that the metabase contains only IIS configuration information, not the content of your web sites. IIS 6 Metabase backups are even easier in IIS 6, because the
functionality is built right into Internet Services Manager. In fact, in addition to allowing you to back up the metabase manually, IIS 6 also automatically backs up the metabase whenever configuration changes have been made. Let's look at these automatic backups first. IIS 6 automatically saves time-stamped (versioned) copies of the metabase; these copies are called history files and are saved in the %SystemRoot%\system32\intesrv\history folder. History files are identified by two numbers: major version and minor version. The major version number is incremented whenever you stop and start IIS using the GUI or net stop iisadmin on the command line, when IIS flushes the in-memory metabase to disk, or when you manually save the IIS configuration to disk. This provides a safety net, so you can recover an earlier configuration if you've made a series of changes and can't remember what they were, let alone how to undo them. When a new major version history file is saved, IIS includes a reference to this file in the MetaBase.xml file itself. Minor versions are somewhat different. IIS increments the minor version number if you have edit-while-running enabled and make modifications to the metabase while IIS is running. Edit-while- running is a new feature of IIS 6 that allows you to edit the metabase directly while Iisadmin and other IIS services are still running. Whenever the major version number is incremented, the minor version number is reset to 0. If you plan to use the new history feature of IIS 6it's enabled by defaultyou will probably want to modify the history settings to suit your needs. The default history settings save a maximum of 10 history files before overwriting the oldest file. This might not be enough history if you plan to edit the metabase extensively; you might want to increase this number to 20, 30, or even 100. Make sure you have sufficient disk space for all these files, however; if IIS can't create a new history file due to insufficient
disk space, it will automatically shut down without warning or explanation. To change the maximum number of history files IIS should save, you'll have to modify a metabase setting directly; there's no way to do it from the GUI. The property you need to change is called MaxHistoryFiles and it's located in the section (if you're navigating the metabase by its key hierarchy) or the LM location (if you're navigating by location hierarchy) of the XML code. The metabase can be a confusing place; you might take a gander at [Hack #56] for guidance. After you make changes to the metabase directly, check the history folder for any error files that might have been created. These error files are named in the form MetaBaseError_versionnumber.xml and are generated when metabase corruption has occurred after editing. If you see an error file, restore your metabase to the previous history version and try editing it again. IIS 6 also lets you manually back up the metabase and export portions to a text file, similar to what we did in IIS 5. The main difference is that in IIS 6 export functionality is built directly into the GUI, so you no longer need the old MetaEdit tool for exporting. In fact, you can't use MetaEdit with IIS 6 because of the metabase's format change from binary to XML.
GUI differences between IIS 5 and IIS 6 Backing up the metabase from the GUI is done the same way as it was in IIS 5, with a couple of important differences. First, an initial metabase backup is automatically performed once you install IIS on your machine (to reduce the attack surface of your machine, Windows Server 2003 no longer installs IIS by default). This initial backup consists of two backup files: an *.MD0 file that contains a backup of MetaBase.xml (the metabase proper) and an *.SC0 file that holds a backup of MBScehma.xml (the XML schema that defines the syntax of MetaBase.xml). Note that in IIS 5 the schema is included as part of the single metabase.bin file, though in MetaEdit the configuration (LM) and schema (Schema) portions of the metabase are displayed as two separate nodes. In other words, every time you back up the metabase in IIS 6, you back up both the configuration file and the schema. Here's another difference. In IIS 5, using Internet Services Manager, you right-click on the server node and select Backup/Restore Configuration. To do this in IIS 6, however, you right-click on the server node and select All Tasks Backup/Restore Configuration. This is just one example of the unnecessary, minor changes in Windows Server 2003 that cause frustration for administrators who are used to working with Windows 2000. You can also now use a password to encrypt metabase backups. An encrypted metabase backup can be restored to a different IIS machine, which gives you a way to clone the IIS configuration of one machine and copy it to another. This was not possible in IIS 5; you could restore a metabase backup only to
the same machine and only if you hadn't rebuilt the machine onto new hardware after a disaster. This is one of many good reasons to upgrade your web servers to Windows Server 2003, even if you choose to keep your domain controllers running Windows 2000. Just don't forget the password you use to encrypt your metabase or you won't be able to restore from the saved backup. Finally, IIS 6 also includes some scripts that can be used to back up and restore the metabase from the command line. For more information about these scripts and what they can and cannot do, see [Hack #59].
Hack 55 Restore the Metabase While it's simple to restore the metabase from a backup, what if you have no backup or can't open the GUI? Use this hack. In [Hack #54], we explored several ways of backing up the metabase, including backing up the machine's System State information using the Backup utility, saving the configuration in Internet Services Manager with MetaEdit (a downloadable tool for IIS 5), and using the history feature of IIS 6. Restoring the metabase from backup is equally straightforward. If you are recovering your machine from a disaster, the metabase is restored as part of the System State information you previously backed up, assuming you didn't change the default option of including System Protected Files in your backup. Alternately, if you're restoring the metabase on a working machine to recover a previous good IIS configuration, simply select the backup in the Configuration Backup/Restore dialog box and click Restore. Then, follow the prompts and wait as IIS stops, rebuilds, and restarts. Restoring the IIS 6 metabase from a history file is done in the same way: just select a history file in the Configuration Backup/Restore dialog box and click Restore. Notice that the dialog box (refer back to Figure 6-2) displays both metabase backups stored in %SystemRoot%\System32\inetsrv\MetaBack and history files stored in %SystemRoot%\System32\inetsrv\History in one combined list. You can tell the difference between a history file
and a backup file in this list by looking at the filenames: all history files are named Automatic Backup and are distinguished in the GUI only by their timestamp, while backup files you create are named whatever you decide to call them. It all seems so simple, but what if your metabase becomes corrupt and you need to restore it from backup? If you can start Internet Services Manager, you can use the Configuration Backup/Restore dialog box as described earlier. But if the metabase is corrupted beyond the ability of IIS to repair it, Internet Services Manager might not even start, and then you're stuck. What do you do? You could restore the entire System State of your machine from backup media. Unfortunately, that might have unpleasant side effects, especially if you're running IIS on a domain controller. For example, all those users and groups you created since the last backup will suddenly be gone (unless you have another domain controller to replicate the information). There might also be changes to the Registry that will be rolled back, and these changes might be harder to troubleshoot. But there's a better way. Manually Restoring a Backup in IIS 5 If you can't open Internet Services Manager, try replacing the metabase with its most recent backup. First, stop all IIS services by typing net stop iisadmin /y at the command prompt (or use iisreset /stop if you prefer). Then, find the metabase.bin file in %Systemroot%\System32\inetsrv and rename it metabase.bad (keep it in case you need it later). Copy your backup file (it probably has the extension .MD0) from
%Systemroot%\System32\inetsrv\MetaBack to %Systemroot%\System32\inetsrv and rename it metabase.bin. Now, restart the computer. You should once again have a working IIS configuration and be able to start Internet Services Manager. By the by, instead of rebooting your machine, you can try to restart IIS services by typing iisreset /start from the command line. But in my experience, it's better to reboot your machine, because IIS is sometimes a little flakey after a restore like this. Restoring without metabase backups What if you don't have any metabase backups in the inetsrv\MetaBack folder? Perhaps you deleted them all or you never created any in the first place. Hopefully, you do have a recent backup of your system driveon tape, perhaps? Use the Backup utility to restore the inetsrv folder from backup to a new location (C:\inetsrv2, for example) and repeat the previous process by copying C:\inetsrv2\metabase.bin over %Systemroot%\System32\inetsrv\metabase.bin. Be sure to stop the IIS services as before, and reboot the machine when you've finished. Restoring without a backup on tape But what if there are no metabase backups in your MetaBack
folder and you don't even have a working backup on tape? Here's a hack you can try that just might work: look in the inetsrv folder on your machine for files named metabase.bak or metabase.bin.bak. If you find one, you're in luck; this is a temporary metabase backup created by IIS when it has problems updating the metabase due to corruption. Normally, this temporary file is deleted once a successful metabase update is performed, but if your metabase corruption was caused by some interruption in the update process (a server glitch or hiccup), IIS might not yet have gotten around to deleting the temp file and you can use it to restore your configuration. Simply stop the services, rename metabase.bin to metabase.bad, rename metabase.bak to metabase.bin, and reboot the machine. Reinstalling IIS In the worst case scenario, you have no tape backup, nothing in the MetaBack directory, and no temporary .bak file in inetsrv. What do you do? Use Add/Remove Programs in the Control Panel to first uninstall IIS and then reinstall it. After you uninstall it, you should also check the %Systemroot%\System32\inetsrv folder (which is not deleted by the uninstall process) for a file named metabase.bin. If you find one, delete it before reinstalling IIS. Moral of the story? Sometimes a reinstall is the only way to recover. Manually Restoring a Backup in IIS 6
Remember that the metabase in IIS 6 is structured differently [Hack #54]; it consists of two files, MetaBase.xml and MBSchema.xml, instead of the single metabase.bin file used by IIS 5. Fortunately, you normally have to restore only the MetaBase.xml file, because it's highly unlikely that you would have made changes to the schema. The procedures to follow are identical to those described in the previous section, except you replace metabase.bin with MetaBase.xml in each step where metabase.bin occurs. I've also found that restarting IIS by using iisreset /start seems to work fine and you don't have to reboot. IIS in Windows Server 2003 does seem more robust than IIS in Windows 2000. See Also [Hack #59]
Hack 56 Map the Metabase Here are some helpful maps to help you navigate the complexities of the metabase. While basic IIS configuration can be done using Internet Services Manager, sometimes you need to roll up your sleeves and look under the hood. Under IIS's hood you'll find the metabase, the key repository of IIS configuration information. The metabase contains hundreds of settings, from how a web server performs to the format used for logging visits to sites. Both Windows 2000 and Windows Server 2003 let you edit the metabase directly, but the tools you use are different because the format of the metabase is different in each platform [Hack #54]. Before you start mucking about in your metabase, you need to know your way around, because its structure is quite complex. The goal of this hack is to give you a bird's-eye view of how the metabase is organized, so you can find things more quickly and avoid making mistakes that could confuse your server. Surprisingly enough, you won't find this information anywhere on Microsoft's web site, even though it is crucial to metabase exploration.
Once you know the lay of the land, you can start hacking the metabase [Hack #57] with a certain level of confidence. Logical Structure The logical structure is the easiest to consider first, because it's much the same for both IIS 5 and IIS 6. The important thing to keep in mind is that the metabase hierarchy reflects the way you manage IIS web sites, directories, and files using Internet Services Manger. For example, when you want to log visits to a site on your server, you can use Internet Services Manager to enable the Log Visits setting at the site level (for all web content on your site), at the virtual-directory level (for content stored in a single virtual directory), or at the page level (for monitoring traffic to individual pages). Most configuration settings can also be configured globally for the entire IIS machine. As a result, when you are navigating the properties sheets of Internet Services Manager, you'll see the following hierarchical progression: Server Site Directory File. The logical structure of the metabase is organized similarly and uses a location attribute to identify where a setting lies within the hierarchy. The top of this hierarchy is called LM, which stands for Local Machine (i.e., the server itself). Each metabase key then has a location attribute that identifies where the key resides. As a simple example, the Path key located at LM/W3SVC/1/ROOT contains the string value C:\Inetpub\wwwroot and identifies the location of the content for the Default Web Site. Figure 6-3 shows where this key is located in the IIS 5 metabase using MetaEdit, the tool used for editing the metabase on that
platform. Note that the metabase is organized hierarchically, using keys in a fashion similar to the way the Windows Registry is displayed in RegEdit. Figure 6-3. Path key for Default Web Site in the IIS 5 metabase To understand the location LM/W3SVC/1/ROOT, let's break it down: LM is the local machine itself, W3SVC means we're looking at web sites (not FTP, SMTP, or NNTP), 1 is the site ID for the Default Web Site, and ROOT contains configuration settings (keys) that apply to all virtual directories and files within the web site. The site ID is a number generated for each web site on the server to uniquely identify the site internally.
Location map for IIS 5 Now, here is the big picture of how the IIS 5 metabase is logically organized, omitting some of the deeper levels: LM LM/IISADMIN LM/IISADMIN/EXTENSIONS LM/IISADMIN/PROPERTYREGISTRATION LM/Logging LM/Logging/Custom Logging LM/Logging/Microsoft IIS Log File Format LM/Logging/NCSA Common Log File Format LM/Logging/ODBC Logging LM/Logging/W3C Extended Log File Format LM/MimeMap LM/W3SVC LM/W3SVC/1 LM/W3SVC/1/Filters LM/W3SVC/1/IIsCertMapper
LM/W3SVC/1/ROOT LM/W3SVC/2 LM/W3SVC/2/filters LM/W3SVC/2/root LM/W3SVC/Filters LM/W3SVC/Info Not so complicated after all, is it? The main locations under LM are pretty self-explanatory. For example, IISADMIN contains configuration settings for the IISAdmin service, Logging defines the settings for the different logging formats supported by IIS, and MimeMap has a copy of the MIME mappings that define how IIS responds to client requests for files with particular extensions. Everything under W3SVC relates to the World Wide Web Publishing Services on the machine, which you can see is hosting two web sites: the Default Web Site (site ID 1) and a custom web site (site ID 2). If your server is running additional services, such as FTP, you'll also find locations for those within the hierarchy. Of course, before you can successfully hack the metabase, you need to know how to find the site ID for a given web site and vice versa. In IIS 6, this is easily done. Select the Web Sites node in Internet Services Manager and look under the Identifier column in the pane on the right. This displays the site ID for each web site running on the server. Finding the site ID under IIS 5 is a little trickier. If you want to find the site ID for a particular site, open its properties sheet in
Internet Services Manager, choose the Web Site tab, and click the Properties button in the Logging section at the bottom. If you have W3C Extended Log File Format configured (the default), then the site ID is embedded in the name of the folder in which your IIS log files are saved. In our example, these folders are %SystemRoot%\System32\LogFiles\W3SVC1 for the Default Web Site and %SystemRoot%\System32\LogFiles\W3SVC2 for the custom web site. Figure 6-4 shows the Extended Logging Properties dialogue box for the custom web site. Figure 6-4. Finding the site ID for a web site in IIS 5
Of course, if you have dozens of web sites running on your machine, this is a rather slow approach. As a workaround you can use findweb.vbs, one of the sample administrator scripts included in the Inetpub\AdminSamples folder on IIS 5. Drop to a command prompt and type cscript findweb.vbs sitename, where sitename is the descriptive name of your site in Internet Services Manager. Be sure to use quotes if there are spaces in the site name. The output of the script will include the web site numberanother name for the site ID. For more information about
using scripts to administer IIS, see [Hack #59]. What about the reverse? Given a site ID within the metabase, how do you find the descriptive name of the web site as displayed in Internet Services Manager? One way is to use MetaEdit to view the contents of the ServerComment key in the location LM\W3SVC\n, where n is the site ID for the web site. The data value for this key is the descriptive name of the site in Internet Services Manager. Location map for IIS 6 IIS 6 is logically organized similarly to IIS 5, but with a few differences: . / /LM /LM/IISADMIN /LM/IISADMIN/EXTENSIONS /LM/IISADMIN/PROPERTYREGISTRATION /LM/Logging /LM/Logging/Custom Logging /LM/Logging/Microsoft IIS Log File Format
/LM/Logging/NCSA Common Log File Format /LM/Logging/ODBC Logging /LM/Logging/W3C Extended Log File Format /LM/MimeMap /LM/W3SVC /LM/W3SVC/1 /LM/W3SVC/1/Filters /LM/W3SVC/1/IIsCertMapper /LM/W3SVC/1/ROOT /LM/W3SVC/388907640 /LM/W3SVC/388907640/filters /LM/W3SVC/388907640/root /LM/W3SVC/AppPools /LM/W3SVC/AppPools/DefaultAppPool /LM/W3SVC/Filters /LM/W3SVC/Info Here, we see that LM is the third level instead of the root. The root level (.) contains keys for versioning (timestamp and
change number) and history major version number [Hack #54]. The next level (/) contains an AdminACL key used for protecting the metabase against unauthorized modification. Beyond that, everything under LM is pretty much the same as in IIS 5, with the obvious exception of /LM/W3SVC/AppPools and locations beneath it, which contain information about application pools when IIS 6 is running in worker process isolation mode. Another thing to notice is that the site ID for the custom web site is 388097640 instead of 2. While IIS 5 assigns site IDs to new web sites serially (1, 2, and so on), IIS 6 assigns what looks like a random number as a web site's site ID. Actually, it's not random at all; it's a pseudorandom number derived from scrambling the descriptive name of the web site. So, if you have two web servers, each with a custom site named My Company Site, they'll both be assigned the same site ID in IIS 6. The reason for doing it this way is to ensure that web farms with multiple IIS machines that host copies of sites have identical site IDs for mirrored sites. If you prefer, you can disable this feature via the Registry Editor; simply add a new REG_DWORD value to the HKLM\SOFTWARE\Microsoft\InetMgr\Parameters key, give the new value the name IncrementalSiteIDCreation, and assign it a value of 1. Restart IIS to jog the change into effect. This might be useful in a service provider environment, for example, if you have several IIS machines that host thousands of web sites and you don't want to worry about having two users create sites with the same descriptive name. Finally, be aware that while the basic logical structure of the metabase is almost identical in IIS 5 and IIS 6, there are many new metabase keys in IIS 6 that have no counterpart in IIS 5. Also, some IIS 5 keys have been retired or renamed in IIS 6. A full discussion of these items is obviously beyond the scope of this book; thankfully, I have another for you which does discuss this stuff at length: IIS 6 Administration (Osborne/McGraw-Hill).
Physical Structure On IIS 5, the physical structure of the metabase is hidden within the proprietary format of the binary metabase.bin file, so you need to know only the logical structure (location of keys) to find your way around the metabase using MetaEdit. Things are different in IIS 6, however, because here the metabase is a plain text file (MetaBase.xml) that is formatted in XML and adheres to strict constraints laid down by the schema (MBScehma.xml). In the XML syntax for the metabase, the location of a key is given by its location attribute within the XML tag for the key. For example, the Path key previously discussed for the Default Web Site in IIS 5 looks like this in the IIS 6 metabase: <IIsWebVirtualDir Location = "/LM/W3SVC/1/ROOT" Path = "c:\inetpub\wwwroot"
If you know a little XML, you can see that IIsWebVirtualDir is an element whose attributes include Location and Path, contained within a pair of opening and closing tags. To be accurate, IIsWebVirtualDir is itself a property called KeyType, and I've left out some other attributes to make the basic structure clear. Anyway, by editing this section of the MetaBase.xml file directly, using a text editor such as Notepad, you can easily change the default path for the home directory of the Default Web Site. XML map for IIS 6
So, now let's see the big picture of what the IIS 6 metabase looks like in terms of XML tags instead of location. This is important to know, because while the location map described earlier really defines the hierarchical structure of metabase keys, the actual physical metabase file is formatted in XML and that's what you have to look at when you edit it. Anyway, here's the XML for an IIS 6 machine configured with two web sites (keys that can be repeated are indicated with ellipses):
<?xml version ="1.0"?> IIS_Global IIS_ROOT IIsComputer IIsConfigObject... IIsLogModules IIsCustomLogModule... IIsLogModule... IIsMimeMap IIsWebService IIsWebServer IIsFiltersIIsCertMapper IIsWebVirtualDir IIsWebServer IIsFilters IIsWebVirtualDir IIsApplicationPools IIsApplicationPool IIsFilters IIsFilter IisCompressionScheme... IIsCompressionSchemes IIsWebInfo IIsConfigObject IIsWebServer IIsWebVirtualDir IIsWebServer IIsWebVirtualDir
As you can see from the duplicate sections beginning with IIsWebServer, two web sites are running on this machine. If you examine the details of these sections, you'll find they have identical KeyType attributes but different Location attributes. Also, note that unlike the location map, which accurately reflects the hierarchical structure of metabase keys, the XML map shows that the MetaBase.xml file is almost flat, with all KeyType attributes nested equally within tags, which themselves are nested within global tags. Of course, the metabase can get much more complicated if you have additional web sites, directories, and services installed. But now that you know the basic lay of the land, you should be able to find your way about. Just don't forget to back up the metabase before you start hacking away at it!Hack 57 Metabase Hacks Here are 10 things you might want to change with IIS, but you can do them only by editing the metabase. These are a few of my favorite IIS metabase hacks. You can find lots more informationtoo much, perhapsin the IIS SDK's IIS Metabase Properties Reference on MSDN (http://msdn.microsoft.com/library/en- us/iisref/htm/reference.asp). Most of the information there is pretty dry stufflists of different settings that provide little insight into what might be useful to tweakwhich is why I want to start you off with a few interesting hacks to inspire you. Still, it is a good idea to get familiar with how to read the Reference, because it details the allowable values for each property in the metabase. Except where stated otherwise, all of the following hacks work on both IIS 5 and IIS 6, though the effect in some cases might differ depending on the rest of your IIS configuration; I try to make note of such differences when appropriate. Also, most of these properties require IIS to be restarted before they take effectsomething that's usually a good idea anyway whenever you edit the metabase manually. Even on IIS 6, which lets you edit the metabase while IIS services are running, it's often a good idea to use the iisreset command to stop and start IIS after making metabase changes and see if there is any effect.
A Warning Before Hacking the Metabase Before you start hacking the metabase, remember that editing the metabase (like editing the Registry) shouldn't be done lightly; the preferred method is to configure IIS using the Internet Services Manager GUI tool. Unfortunately, a number of useful metabase settings are inaccessible from the GUI and you have to dig right into the metabase to change them. Also, before you edit the metabase make sure you back it up. That way, if you make a mistake and break IIS, you can restore the metabase from backup and get IIS working again. We looked at ways you can back up the metabase [Hack #54] earlier in this chapter, but it's also a good idea to make a copy of the metabase and edit the copy instead of editing the metabase itself. Then, when you've made your changes, you can stop IIS, rename metabase.bin to metabase.old, rename your copy of the metabase from whatever you called it to metabase.bin, and restart IIS. Should something go wrong, your original metabase is still there in the form of metabase.old and can be used to restore IIS to the configuration it had previously. That may sound like overkill, but you can never be too careful when it comes to manually editing critical configuration files. You should at least follow that procedure with IIS 5 (Windows 2000). With IIS 6 (Windows Server 2003), you can probably get by without following this approach, because the history feature saves a copy of the metabase every time you make a configuration change to it. You decide, though. Like most things in IT, it's a tradeoff, and in this case, the tradeoff is between
convenience and safety. Making backups of backups is not convenient, but it might help prevent you from burning your fingers. Also remember that MetaEdit (the downloadable tool for editing the IIS 5 metabase) doesn't check your modifications to ensure that the values you entered are within the allowable range for the properties you edit. Editing the IIS 6 metabase using Notepad or some other text editor is even more dangerous, because you could even assign a string value to a metabase property that should be numeric. So, before you change any metabase property manually, check the Reference to see which range of values is allowed. ServerListenBacklog Sometimes, IIS cracks under the weight of too many client requests, even though it still has lots of memory and CPU cycles to work with. Typically, clients start getting "Server too Busy" errors and have to click Refresh several times before they are able to see any content. At the server end, this might happen on only one IP address, and any others might behave as they should. With a packet-sniffing tool such as the Microsoft Systems Management Server's Network Monitor, you'll see TCP connections resetting almost as soon as they are established. The problem is that the application layer of the TCP/IP stack has run out of resources. To increase the resources available for
this layer, you can edit two metabase properties: ServerListenBacklog and MaxEndPointConnections (we will discuss the latter in the next section). The ServerListenBacklog property determines the maximum number of outstanding TCP socket connections that can be queued. By default, this property is set in the metabase schema and depends on how the Performance Tuning setting is configured on the Performance tab of your web server's properties sheet in the GUI. Specifically, ServerListenBacklog has defaults of 5, 40, or 100, depending on whether you tune the GUI to expect fewer than 10,000 hits per day, less than 100,000 hits per day, or more than 100,000 hits per day. You can override the schema defaults for this property by adding a ServerListenBacklog key at the web site's level (/LM/W3SVC) or at the level of an individual web site, such as the Default Web Site (/LM/W3SVC/1); assign the ServerListenBacklog key any value from 5 to 1000 (on IIS 5) or 500 (on IIS 6). More pending connections are queued as you increase the value for this key, but IIS will consume more memory resources. Experiment to find the best performance for your hardware. MaxEndPointConnections Another property you can tweak to improve performance under heavy load is MaxEndPointConnections, which indicates the maximum number of TCP sockets in a LISTENING state that can be allowed for a single IP address, network interface, or TCP port. By default, this property has the value 100 on IIS 5 and is also set in the schema, but you can add a key to set it at the /LM/W3SCV level or the /LM/W3SVC/n level, where n is the site ID of the web site that contains the application. To get better
performance under heavy load, try increasing this setting to 500 or even higher and evaluate the result from the client standpoint. On IIS 5, MaxEndPointConnections works in conjunction with ServerListenBacklog and IIS uses the property with the lower value by default. On IIS 6, however, MaxEndPointConnections is set to 4294967295 in the schema, which means unlimited connections and is usually best left as is. AspThreadGateEnabled Thread gating is a feature of IIS that is turned off by default, but if you turn it on, IIS dynamically adjusts the number of concurrent threads, depending on the load. If threads become blocked (for example, when an ASP application on IIS has to wait for a back-end SQL database to respond), then IIS starts more threads to handle client requests. If processor usage hits the wall, IIS begins decommissioning threads to reduce the amount of context switching going on. The lower- and upper- level CPU usages that start or kill threads are determined by two other metabase properties: AspThreadGateLoadLow and AspThreadGateLoadHigh. By default, these properties have values of 50 and 80 (percent), respectively, but you can change them to see if it improves performance. I've sometimes found that changing AspThreadGateEnabled from off (0) to on (1) can improve performance somewhat for web servers that host mainly static content. For servers that host ASP applications, use the Performance console first to check if ASP requests are becoming excessively queued. If so, try changing AspThreadGateEnabled to 1 and use Performance again to see if things improve. This key is already present in the metabase at the /LM/W3SCV
level, but you can also set it at the /LM/W3SVC/n level by creating the appropriate key. Note that this particular metabase property applies only to IIS 5, not IIS 6. AspProcessorThreadMax The AspProcessorThreadMax property determines the maximum number of worker threads IIS allows for handling ASP requests. The default value is 25 (threads per processor), and if you multiply the number of processors on your machine by the value of AspProcessorThreadMax, the product represents the maximum number of threads that can service a single ASP applicationregardless of how you have tweaked the previously described AspThreadGateLoadHigh property. In some cases, you might want to try increasing this valuefor example, when ASP requests are being blocked by slow response from a back-end database. In other cases, decreasing it to 15 or even 5 might improve performance by better utilizing available processor resources, especially under relatively light loads. Basically, just play with it and see what happens. This property is defined at the /LM/W3SCV level, but you can also set it at the /LM/W3SVC/n level. AspAllowSessionState The AspAllowSessionState property enables session state persistence for ASP applications and is set to 1 (on) by default. One way you can often improve ASP performance is to change this property to 0 (off) and then recode your applications to explicitly override session state persistence for pages that use session objects. Simply add the following statement to the top of
each ASP page as needed: <% @EnableSessionState=False %> This property is defined at the /LM/W3SCV level, but you can also set it at the /LM/W3SVC/n level. AspBufferingOn Big improvements in ASP performance can often be achieved by turning ASP buffering on using the AspBufferingOn property. This is because ASP buffering lets IIS collect the output of an ASP application in a buffer before flushing it to the client. Fortunately, this property is set to 1 (on) in IIS, provided you're working with a clean installation of Windows 2000 or Windows Server 2003. If you previously upgraded your web server from Windows NT 4.0, however, this property is set to 0 (off) and should generally be changed to 1, at least on all your production servers. However, while turning this property on increases ASP response times overall, from a user perspective it might actually seem to make sites less responsive. This is because instead of feeding the output of the ASP page to the user slowly, bit by bit, the entire output has to be generated and cached before any of it can be returned to the user. So, you'll have to play with this and see what how it feels from a client perspective, but in most cases it's best left turned on. You can also recode your ASP applications to make more use of the Response.Flush method to improve the performance from the user's point of view. This property is defined at the /LM/W3SCV level, but you can also set it at the /LM/W3SVC/n level.
AspQueueConnectionTestTime Ever tried to access a page that wouldn't load, so you kept refreshing impatiently? On the older IIS 4 platform, this had the unpleasant result of filling up the ASP request queue with multiple requests from the same user for the same page, which was quite annoying. Fortunately, in IIS 5 the AspQueueConnectionTestTime metabase property was added to foil this kind of unintentional denial-of-service attack on your web server. The default value for this key is 3 (seconds), but you can tweak it depending on how your ASP application is designed. For example, if you have an application in which the user usually just clicks through a number of pages without needing to fill in or read anything, you could add this key to the /LM/W3SVC/n level for that site and lower its value to 2 or even 1. That way, IIS will check more frequently to make sure the client is still connected before responding to another connection request from the same client. This property is defined at the /LM/W3SCV level, but you can also set it at the /LM/W3SVC/n level. AspScriptFileCacheSize The AspScriptFileCacheSize property determines how many precompiled script files or templates are cached in memory by IIS, in case they need to be reused. The default value for this setting is 250 (in IIS 5) or 500 (in IIS 6), but this can be increased to 1000 or more if needed. You can also set it to -1 (on IIS 5) or 4294967295 (on IIS 6) to allow unlimited caching of scripts. Unlimited caching is probably not a good idea unless you have unlimited RAM on your motherboard, but you definitely might consider increasing this setting to 1000 or higher if your
server is running applications that have many different ASP pages. This property is defined at the /LM/W3SCV level, but you can also set it at the /LM/W3SVC/n level. CacheISAPI The CacheISAPI property determines whether IIS caches ISAPI extensions (such as asp.dll) in memory or unloads them whenever they're no longer used. This is set to 1 (on) and should be left that way on production servers, unless you want your applications to run like molasses. However, if you need to debug a custom ISAPI extension you've written, set CacheISAPI to 0 (off); otherwise, you'll end up testing previous versions of your extension instead of testing the current one. This property is defined at the /LM/W3SCV level, but you can also set it at the /LM/W3SVC/n level. ID 36907 I'll end this list of hacks with something a little bit different. Until now, we've looked only at metabase properties for IIS proper. However, some other Microsoft products also use IIS; one of the most notable is Exchange 2000 Server. Every metabase property is uniquely identified by an internal ID number. For example, the CacheISAPI property has ID number 6034, which can easily be seen using MetaEdit (see Figure 6-5). Figure 6-5. Viewing the CacheISAPI property in MetaEdit
It's a little-known fact that these ID numbers are grouped into different ranges that depend on the IIS function to which they apply (IIS, ASP, or FrontPage) or the Microsoft server product to which they belong (such as Exchange Server or Application Center). Table 6-1 details the association between metabase Ids and their associated functions or products. Table 6-1. Metabase property ID ranges ID range Function/Product 1-32767 IIS 28672-32767 ASP (subset)
32768-36863 FrontPage Server Extensions 36864-40959 Exchange Server: SMTP 40960-45055 Exchange Server: POP3 45056-49151 Exchange Server: NNTP 49152-53247 Exchange Server: IMAP4 53248-57343 MSCS 57344-61439 Application Center Metabase property 36907 falls within the range of Exchange's SMTP Service and can be used to change the default SMTP banner with which Exchange responds to incoming client connections. Changing the property's banner from its defaultESMTP MAIL Service, Version: 5.0.2195.1600 (or something similar)is a useful security measure, because it hides Exchange from unauthorized Telnet connection attempts issued by attackers who are trying to footprint your system. To change the banner for property 36907, open MetaEdit and find /LM/Smtpsvc/n, where n is the number of the SMTP virtual server used by Exchange. Then, select Edit New String from the menu to open the Edit Metabase Data dialog box (shown in
Figure 6-6). Figure 6-6. Adding a new property to the metabase based on its internal ID number Since the Id drop-down box lists only standard IIS metabase properties, you have to add this property using its ID number instead. Leave the list box set to (Other) and type 36907 in the box beside it. Then, in the Data text box, type the banner you want the SMTP Service to display to clientsperhaps something like "Stop trying to footprint my server!" Finally, stop and restart the SMTP Service on your machine. Now, when a Telnet client tries to connect on port 25, he'll get the message you specified. Of course, you might not want to use that particular message; it might only annoy the attacker and make her even more
determined to crack your system! By the way, you can do the same thing with your POP3 connection and disconnection strings (IDs 41661 and 41662, respectively) and your IMAP4 connection and disconnection strings (IDs 49884 and 49885, respectively). Be sure to restart these services once you modify their metabase settings.
Hack 58 Hide the Metabase Protect the metabase on your critical web servers by hiding its name and location from attackers. Good security begins with pretty obvious things, such as renaming the default administrator account and assigning it a strong password. The same is true for the metabase, the database used by IIS to store its configuration information. In Windows 2000, the metabase file is metabase.bin and is located in the %SystemRoot%\System32\inetsrv directory. By changing both the name and location of the metabase, you can hide it from malicious hackers, making it harder for them to corrupt the configuration of your web servers. Changing the name of the metabase first involves stopping the IIS Admin Service. This can be done either from the GUI, by using Internet Services Manager (right-click on the server node and select Restart IIS), or by typing net stop iisadmin /y at the command line. Once IIS is stopped, make a copy of metabase.bin before you proceed, just in case something goes wrong, and store this copy offline on a network share or floppy. Then, move metabase.bin to a new folder on your server, making sure the NTFS permissions on the folder include Full Control for the built-in SYSTEM identity and the built-in Administrators local group on the machine. IIS requires these permissions to load the metabase into memory and modify its contents when you change your IIS configuration, and you, as administrator, require these permissions to access the metabase later, if necessary.
Rename the metabase.bin file to something different and give it a unique file extensionsomething like ab345mn7.pqr, for example. Now, open Registry Editor (Start Run regedit) and find the HKLM\SOFTWARE\Microsoft\InetMgr\Parameters key. Add a new value to this key by right-clicking on Parameters and selecting New String Value. Type MetadataFile for the value name and leave the data type as REG_SZ. Double-click on the value and change the value data to the full path to where ab345mn7.pqr (or whatever you've called it) is located, as shown in Figure 6-7. Be sure to include the drive letter in your path. Figure 6-7. Hiding the name and location of the metabase
Now, start the IIS services by typing iisreset /start at the command line. Open Internet Services Manager and verify that you can modify the configuration and save changes successfully. You're metabase is now hidden from attackers, making your web server more secure. Open Windows Explorer and find your %SystemRoot%\System32\inetsrv folder again. Surprise! There's a file named metabase.bin in this directory again. For some reason, when you delete or move this file and restart IIS services, Windows automatically creates a new metabase.bin file in the inetsrv directory. But if you click on this file, you'll see that it's only 610 bytes in size; it's not a working metabase. In fact, go ahead and delete this fileyou don't have to stop the IIS Admin Services to do soand it shouldn't appear again, even if you restart IIS again. The metabase is hidden now, but what about backups of the metabase? [Hack #54] showed how to back up the metabase in order to prevent making configuration errors on your IIS machine. If you've saved the configuration of your IIS machine, copies of your metabase can be found in %SystemRoot%\System32\inetsrv\MetaBack. Unfortunately, there's no way to change the location where metabase backups are stored, so the best thing to do might be to copy these backups to a network share and then delete them from the web server itself. That way, there's only one copy of the metabase on your server, one that's hidden and has a different name than metabase.bin. What about IIS 6? Unfortunately, on Windows Server 2003, creating a HKLM\SOFTWARE\Microsoft\InetMgr\Parameters\MetadataFile Registry key has no effect, so this method doesn't work. But IIS 6 is inherently more secure than IIS 5 for a number of reasons. Because you can encrypt metabase backups to prevent them
from being misused, it's probably not that important that you can't hide the metabase on that platform.
Hack 59 IIS Administration Scripts Here are some handy scripts that can be used to administer IIS from the command line. Microsoft does a pretty good job of developing GUI tools for managing most aspects of Windows, but until only a few years ago they were weak on the scripting side. With the advent of Visual Basic Scripting Edition (VBScript) and the Windows Scripting Host (WSH), administering Windows from the command line became a reality. Incorporating Active Directory Services Interface (ADSI) into Windows 2000 and adding a Windows Management Instrumentation (WMI) provider for IIS into Windows Server 2003 has taken Windows scripting even further, and now you can manage just about any aspect of IIS in particular and Windows servers in general remotely from the command line. Of course, someone still has to write the scripts. Unfortunately, most administrators who work in the real world of supporting businesses' computing infrastructures have little time for the luxury of learning VBScript and WMI. Learning to write your own scripts to administer Windows is a time- consuming affair, and if you're responsible for managing users, keeping servers running, maintaining security, and preparing for disasters, then time is something that's usually in limited supply. Fortunately, Microsoft has done some of the work for you by
developing some handy scripts that can be used to simplify or automate IIS administration. This is especially true of IIS 6 (Windows Server 2003), but there's also some useful stuff you can use for IIS 5 (Windows 2000). IIS 5 Scripts Windows scripting was still in its infancy when IIS 5 was released, but Microsoft decided to include a few basic scripts with it (along with other sample content) to illustrate the power of what IIS could do. Four pairs of sample scripts are found in C:\Inetpub\iissamples\sdk\admin; one script in each pair is written in VBScript and the other is written in JScript, a Javascript (ECMAScript) derivative that's fallen out of favor lately for writing Windows administration scripts. Although these scripts are mainly intended for learning purposes, a couple of them are useful, so I'll briefly summarize what they can do (I'll focus here on the VBScript versions only). Metabase backups and restores can be performed from the command line by using metaback.vbs and metabackrest.vbs. These sample scripts require that you use Cscript.exe, the command-line version of WSH, to run them. For example, if you want to back up the metabase using 14 Nov 03 Backup as the name of the backup, just open a command prompt and type the following command: cscript C:\Inetpub\iissamples\sdk\admin\metaback.vbs "14 Nov 03 Backup" A metabase backup with that name will be created in the %SystemRoot%\system32\inetsrv\MetaBack folder with the filename 14 Nov 03 Backup.MD0. You can even create multiple backups with the same name but different version numbers using the -v switch, like so:
cscript C:\Inetpub\iissamples\sdk\admin\metaback.vbs "14 Nov 03 Backup" -v 15 This command creates the backup file 14 Nov 03 Backup.MD15. Versioning is a good way to keep track of minor configuration changes made while tweaking the metabase to improve IIS performance. And running the script repeatedly with the same backup name but without a -v switch will increment the version number of the backup file each time. Of course, like any script, you can also schedule its execution by using the Scheduled Tasks Wizard so that your metabase backups can take place on a regular basis during off hours. Another script included in iissamples is mkwebsrv.vbs, which lets you create a new web site from the command-line. Here's an example of how it works: cscript C:\Inetpub\iissamples\sdk\admin\mkwebsrv.vbs C:\data -c "New Site" -p 80 This command creates a new web site named New Site, listening on port 80 and having C:\data for its home directory. This script is flaky, though, and can create only one new site before errors happen, so I don't advise using it (there's a much better replacement, which we'll discuss in a moment). The last script is logenum.vbs, which can be used to enumerate the different logging modules installed on IIS. This is basically just a sample script to show how ADSI and VBScript can be used to administer IIS. Because it's not very useful, I won't say more about it. And that's all the scripts in C:\Inetpub\iissamples\sdk\admin. AdminScripts
Hidden away in another folder, C:\Inetpub\AdminScripts, there are many more scripts you can play with. And I do mean hidden; there's absolutely nothing mentioned in Windows 2000 Help concerning these scripts, and there's almost nothing mentioned on Microsoft's web site. You have to dig around in the Knowledge Base at Microsoft Product Support Services (http://support.microsoft.com) to find any information concerning these scripts. That shows the level of commitment Microsoft had to scripting, even as late as Windows 2000, doesn't it? Anyway, let's see what these scripts can do. Most of them are quite short and simple. First, the findweb.vbs script is a useful little utility that can display information about a web site you specify. Here's an example of how it works: cscript C:\Inetpub\AdminScripts\findweb.vbs -w "New Site" Typing this command on my machine displays the IP address, port number, and even the site ID of a web site named New Site. Once you know the ID of a site [Hack #56], you can stop, start, pause, or continue that particular web site by using the stopweb.vbs, startweb.vbs, pauseweb.vbs, and contweb.vbs scripts. For example, the following command stops the web site that has a site ID of 10in other words, New Site: cscript C:\Inetpub\AdminScripts\stopweb.vbs -a 10 There are also similar scripts, such as stopftp.vbs, which can be used to control the status of individual FTP sites. And stopsrv.vbs can be used to stop both web and FTP sites in one operation. For example: cscript C:\Inetpub\AdminScripts\stopsrv.vbs -a w3svc/1 msftpsvc/1 This command stops both the Default Web Site and Default FTP Site, while leaving both the WWW Publishing Service and FTP
Service running. Of course, if you prefer, you can stop these services entirely by using net stop w3svc or net stop msftpsvc. Then there's mkw3site.vbs, which is used to create new web sites. This definitely has more functionality than the sample mkwebsrv.vbs script found in the \iissamples\sdk\admin folder, and it has options for specifying the site's home directory, friendly name, port number, IP address, host header name, and even the site ID if you desire. For example, the following command creates a web site named My Site with a site ID of 101, a home directory of C:\home, and an IP address of 212.44.64.24: cscript C:\Inetpub\AdminScripts\mkw3site.vbs -r C:\home -t "My Site" -i 212.44.64.24 -n 101 A similar script, mkwebdir.vbs, can be used to create virtual directories within a web site and has similar syntax. Chaccess.vbs is an interesting script that lets you modify the web permissions of a site programmatically. For example, the following command sets the web permissions for New Site (site ID 10) to allow Read and Script permissions but deny Write, Execute, and Directory Browsing: cscript C:\Inetpub\AdminScripts\chaccess.vbs -a w3svc\10\ROOT +read -write +script -execute -browse Another interesting script is dispnode.vbs, which can display a host of information about any node in the metabase you specify. For example: cscript C:\Inetpub\AdminScripts\dispnode.vbs -a IIS://localhost/w3svc This command lists the web permissions, default document,
anonymous user account, maximum number of connections, connection timeout, whether logging is enabled, and schema information about the metabase node. Finally, there's adsutil.vbs, the mother of all IIS scripts. This script leverages the Active Directory Services Interface (ADSI) to programmatically manipulate many different aspects of IIS. The power of this little gem is best seen by some examples. You can modify web permissions using a command like this: cscript C:\Inetpub\AdminScripts\adsutil.vbs set w3svc/1/root /accesssource "true" This command allows Script Source Access on your home directory. The same can be done with other permissions, such as Read, Execute, and so on. The adsutil.vbs script can also be handy if you have to restore the metabase from backup after reinstalling IIS (this works only after reinstalling IIS components, not after reinstalling your operating system). If you reinstall IIS and then use Internet Services Manager to restore a metabase backup, you'll receive an error message saying the restore failed. You can simply ignore the error message and type the following command from a command prompt: cscript.exe C:\InetPub\AdminScripts\adsutil.vbs enum w3svc This retrieves the password for the IWAM_computername account used by IIS (the enum option displays pretty much the whole contents of the metabase, which you have to wade through manually or pipe to grep if you have grep installed). Then, open the properties of the IWAM_computername account in Local Users and Groups in Computer Management and type the password you retrieved for it earlier. Finally, restore the same metabase backup again in Internet Services Manager and the metabase should be restored.
You can do many other neat things using adsutil.vbs, such as disabling socket pooling [Hack #60], enabling reverse DNS lookups, enumerating server bindings, configuring IIS to support both NTLM and Kerberos authentication, and modifying just about anything in the metabase you want to play with. For more information on adsutil.vbs, you can find a pile of Knowledge Base articles at the Microsoft Product Support Services web site (http://support.microsoft.com). You should know, though, that with the advent of IIS 6 on Windows Server 2003, ADSI is now considered on the way out and Windows Management instrumentation (WMI) is all the rage. But that's a story for a different book. IIS 6 Scripts Scripted administration of IIS has really matured on the IIS 6 platform with nine well-designed scripts written in VBScript to play with (no IIS 6 scripts were written in JScript). These scripts are much more functional and less likely to break than the sample scripts included with IIS 5. They are found in the %Systemroot%\system32 directory, which is part of the system path and thus makes using them more convenient. Also, instead of using ADSI, these scripts make use of WMI, a more powerful programmatic approach that can do almost anything on both local and remote servers. In the following discussion, I'll leave out the cscript portion of each script command, because by registering CScript instead of WScript (the GUI version of CScript) as your default host for VBScript,
you can omit typing cscript at the beginning of each script command. To register Cscript as your default host, either type cscript //H:cscript at a command prompt or simply try to run one of these scripts. You'll be presented with a dialog box that says "Would you like to register CScript as your default host for VBScript?" Click OK. Once you've done this, you don't need to type cscript at the beginning of a script command and you don't need to include the file extension of your script in the command. This definitely makes things more convenient. Creating and managing web sites First, you can create and manage web sites easily using the iisweb.vbs script. The syntax here is similar to mkw3site.vbs in IIS 5, but it's easier to use because it needs fewer switches to specify options. For example, to create a web site named Sales Web with an IP address of 205.16.45.12 and a home directory of C:\Sales, all you have to do is type the following command: iisweb /create C:\Sales "Sales Web" /i 205.16.45.12
Other options for the /create switch let you specify a port number, host header name, and whether the web site should be started or stopped once it's created. The command displays output that verifies each setting it configures, including the randomly generated site ID number used by IIS 6 to uniquely identify each web site internally. One limitation of creating web sites with this script is that the home directory must be specified as an absolute path and located on the local IIS machine. This means that if you want to use a network share on another server as a home directory for your site, you'll have to open the site using Internet Services Manager and specify a UNC path to the remote home directory. What else can you do with iisweb.vbs? Well, you can use the /delete switch to delete any web site on your server, including those you created using the Web Site Creation Wizard started from Internet Services Manager. Using the /stop, /pause, and /start switches, you can stop, pause, and restart an individual web site (whether it was created with iisweb.vbs or Internet Services Manager) independently of all other sites hosted on the server. You can even stop, pause, or start multiple sites simultaneously by including their names in a single command. Of course, if you want to stop, pause, or start all web sites on your server, using the iisreset command is easier. Finally, the /query switch lets you display a summary of information concerning all web sites running on your machine. By redirecting this summary to a text file, you can quickly document the sites on your server. Once you've created a new web site, you can add new virtual directories to it by using the iisvdir.vbs script. Again, this script can be used to create only local virtual directories (mapped to a physical folder on the IIS machine), not remote virtual directories (mapped to a network share); you can get around this limitation only by using the GUI. But you can also use the
/delete switch to delete virtual directories and the /query switch to display all virtual directories within a given web site, including nested virtual directories. The syntax is easy to remember: iisvdir /create "Sales Web" reps C:\SalesPersons This command creates a virtual directory named reps within the web site named Sales Web and maps this virtual directory to the C:\SalesPersons folder on the machine's hard drive. And guess what? Everything you can do with web sites can also be done with FTP sites by using the iisftp.vbs and iisftpdr.vbs scripts included with IIS 6. Managing the metabase What about managing the metabase? In [Hack #54], we learned the importance of regular metabase backups, and earlier in this hack we saw how the metaback.vbs and metabackrest.vbs sample scripts included with IIS 5 provide basic backup and restore functionality. Such functionality is greatly increased in IIS 6 with two new scripts: iiscnfg.vbs and iisback.vbs. Backing up and restoring the metabase is done by using the /backup and /restore switches of iisback.vbs. These switches include the option of encrypting your backups with a password to make them more secure. For example, the following command creates a backup of Metabase.xml and MBSchema.xml in the MetaBack folder and encrypts the backup with the complex password pa$$w0rD: iisback /backup /b "14 Nov 03" /e pa$$w0rD
One nice added feature that the earlier metaback.vbs script of IIS 5 lacks is the ability to list all backups from the command line and delete any that are no longer necessary by using the /list and /delete switches, respectively. You can also use the /restore switch to restore the metabase from either a backup file or history file, depending on your needs. The other script, iiscnfg.vbs, is a powerful tool for exporting and importing IIS configuration information. The simplest use of this script is iiscnfg /save, which flushes the current in-memory metabase to disk. This is usually done automatically by IIS shortly after configuration changes are made, but if you're experimenting with configuration changes, you can use this to force IIS to save the metabase immediately and create a new history file as well. Metabase exports take all or a portion of MetaBase.xml and save it as an XML file in the directory you specify. For example, the following command takes everything in the metabase about the web site with site ID 1 (usually the Default Web Site) and exports it to the site1.xml file in the C:\stuff folder: iiscnfg /export /f C:\stuff\site1.xml /sp /LM/W3SVC/1 /inherited /recursively Here, the /inherited option ensures that any metabase properties inherited at the /LM/W3SVC/1 level from higher levels, such as /LM or /LM/W3SVC, are explicitly written to the export file (since the target import server might not have these properties specified) and the /children option indicates that metabase subkeys should be recursively included in the export file. This is a great feature, because you can use it to export the exact configuration of a web site and then import the configuration (using iiscnfg /import) into another IIS machine to clone a copy of the web site (you still have to copy the site content, though).
You can even clone the entire configuration of your IIS server by using iiscnfg.vbs to export the root metabase key (/). There's a caveat, though: exported files of metabase properties that are encrypted can't be imported to other machines. Also, you can't export the metabase schema file (MBSchema.xml) by using iiscnfg /export, so if you've made any modifications to the schema, this approach won't work. But most administrators never try to modify the schema anyway, because it's too risky and complicated, so the second limitation isn't really a problem. You can work around the first limitation (encrypted metabase properties); all you need to do is remove or modify any machine- specific settings from the export file before importing it into another IIS server. That means deleting keys that refer to IUSR or IWAM, special built-in accounts used by IIS for authentication purposes; deleting AdminACL settings in the top level (.) of the metabase; deleting keys that specify passwords for remote virtual directories or any other purposes; and modifying any keys that specify paths to content directories not mirrored on the target server. Once you've hacked away and made the necessary changes to your export file, you can import it to another machine and gain an exact clone of your original machine's configuration. There are also other ways to clone configurations. The iiscnfg /copy command overcomes the limitation of exports by copying both the metabase configuration and the schema files to a remote machine. The command calls the iisback.vbs script and removes all machine-specific settings from the metabase, with the exception of content paths. So, if your target machine has a content file structure that is identical to your original machine, you can use iiscnfg /copy to clone IIS in one easy stop. Why not use iiscnfg /copy all the time instead of using iiscnfg /export /sp /? Though using /export is more complex, it also provides you with greater flexibility. It allows you to make any
custom modifications you want to the metabase before you import your configuration to a new machine. For example, the /export switch also includes a /merge option that lets you merge virtual directories to consolidate and simplify a site. You can also use this option to merge good metabase settings over corrupt ones to recover a working metabase after something goes wrong. Anyway, that's just another of those tradeoffs that are common in administering servers: the method that requires more work is more flexible than the rigid, simple approach. Choose the right tool to meet your needs. Managing web applications Finally, IIS includes two scripts to manage web applications (iisapp.vbs) and web service extensions (iisext.vbs). The simple Iisapp.vbs script lists all web applications running on the server, displays their process identity (PID), and indicates the application pool to which they're assigned. The Iisext.vbs script is more powerful and lets you display all web service extensions running on the server, show the actual executables of these extensions, add new extensions, and enable or disable extensions. For example, iisext /listapp displays Active Server Pages, Server-Side Includes, WebDAV, and any other extensions running on your server; iisext /listext does this in shorter form by displaying ASP, SSINC, and WEBDAV; and iisext /listfile displays the DLLs associated with these extensions, such as asp.dll, ssinc.dll, and httpext.dll. Application pools and web service extensions are new features of IIS 6; for more information on them, see IIS 6 Administration (Osborne/McGraw-Hill).
Running scripts remotely
Finally, another powerful feature of IIS 6 administration scripts
is the ability to run them remotely from a Windows XP
workstation or another Windows Server 2003 machine (you can't
run them from Windows 2000 because that platform lacks a WMI
provider for IIS). All of these scripts support the /u and /p
options (to specify credentials that work on the remote machine)
and the /s option (to specify the DNS name or IP address of the
remote machine).
To create a web site named Products with a home directory of
C:\stuff, IP address 202.44.33.11, and port number 80 on the
remote IIS machine named WEBSRV99, type the following
command at a command prompt on your XP workstation:
iisweb /create C:\stuff Products /b 80 /i 202.44.33.11 /s websrv99.mtit.com /u WEBSRV99
Administrator /p pa$$w0rD
Alternatively, telnet into the remote machine (if the Telnet
Server services has been enabled on it) and leave out the /s
websrv99.mtit.com portion of the command. Or, to run the
command locally on the remote server, open a Remote Desktop
Connection to the remote machine (if Remote Desktop has been
enabled on it) and again leave out /s websrv99.mtit.com.
Which method is best? Unfortunately, using the /s option sends
the credentials over the network in unencrypted form, and Telnet
does the same. So, your safest bet is to enable Remote Desktop
and use it for remotely managing IIS machines in your server
room from your administrator workstation in your office.
Custom Scripts If you have a working knowledge of VBScript, ADSI and WMI, you can easily write your own IIS administration scripts to accomplish various tasks. Here are two short but useful scripts to back up and restore the metabase on a remote IIS 5 machine. First, here's the backup script: Dim IISComputer Dim Flags Dim TargetComputer TargetComputer = "IISComputerName" Flags = (MD_BACKUP_SAVE_FIRST Or MD_BACKUP_FORCE_BACKUP) Set IISComputer = GetObject("IIS://" & TargetComputer) IISComputer.Backup "MyBackupFile", MD_BACKUP_NEXT_VERSION, Flags To use this script, simply replace the variables IISComputerName and MyBackupFile with the name of your web server and the full path to the backup file you create. Then, copy and paste the script into Notepad (make sure to have Word Wrap disabled) and save it with a .vbs extension. Make sure you have the latest scripting engines on the workstation from which you run this script. You can download the latest scripting engines from the Windows Script home page at MSDN (http://msdn.microsoft.com/library/default.asp? url=/nhp/Default.asp?contentid=28001169). Here's a similar script for restoring the IIS 5 metabase to a
remote machine: Dim IISComputer Dim TargetComputer Dim BackupLocation TargetComputer = "IISComputerName" BackupLocation = "PathToBackup" Set IISComputer = GetObject("IIS://" & TargetComputer) IISComputer.Restore BackupLocation, MD_BACKUP_HIGHEST_VERSION, 0 Where to Find More Scripts If you're into rolling your own WMI scripts, then more power to you; you have more time on your hands than I do. Busy geeks like me prefer to create our toolkit by collecting prefab stuff from various sources. Here are some places where you can find additional scripts for administering IIS. The IIS Resource Kit (Microsoft Press) was written for IIS 4 (Windows NT) and is a bit out of date. But it still provides a useful introduction to the subject for newbies to Windows scripting. I still use this book from time to time, since IIS 5 is not that much different from IIS 4, but don't use it if you plan to work only with IIS 6, because of the architectural changes and enhancements on that new platform. The CD-ROM included with this book includes a number of useful scripts. The IIS 5 Resource Guide, which is part of the Windows Server
2003 Resource Kit from Microsoft Press, also has some information on ADSI scripting, but it's pretty minimal. Most of the book focuses on deployment issues and performance tuning. Chris Crowe's popular IISFAQ web site [Hack #61] has a pile of useful scripts, many of them written by Chris himself. If you are an administrator who works with IIS, you'd do well to spend a few hours becoming familiar with all the resources on this site. Finally, there's the Windows Script Development Center at MSDN (http://msdn.microsoft.com/scripting/), which has a ton of information on how to get started writing your own WMI scripts, if you have the time and patience to do so. Rod Trent and Mitch Tulloch
Hack 60 Run Other Web Servers Here's how to run another web server, in addition to IIS, on the same machine without conflict over who gets port 80. Ever have problems when you try to run more than web server on the same machine? Or have you run some other web-enabled software together with IIS, only to find that one or both of them break? The problem here is socket pooling, a feature of IIS 5 and later that causes IIS to bind to all IP addresses configured on the server, even on a multihomed machine with more than one network card. The funny thing is that socket pooling even binds IIS to IP addresses that aren't yet assigned to any web site on the machineeven if there's no Default Web Site configured to respond to All Unassigned IP addresses by default. This behavior not only prevents other HTTP software from coexisting with IIS, but it can also cause IIS to return errors to clients. A workaround that sometimes works is to set the HTTP port number for the other software to something nonstandard, such as 8099, but that won't work in most cases unless clients using that software also use that port to connect. By default, however, IIS won't let any other application listen on port 80 (the standard HTTP port), even if it's listening on an IP address that is not used by IIS. Disabling Socket Pooling in IIS 5
Socket pooling is enabled on IIS 5, by default, but it can be disabled to allow other HTTP-enabled third-party software to run side-by-side with IIS, each responding to requests sent to different IP addresses. There are two ways to do disable socket pooling in IIS 5. First, you can edit the metabase by using the MetaEdit utility [Hack #54]. By default, the setting for socket pooling is defined in the metabase schema, but you can use MetaEdit to create a new metabase key called DisableSocketPooling in the location /LM/W3SVC and assign it the value of true (1). In other words, the default value for DisableSocketPooling in the schema is false (0), which means it is false to say socket pooling is enabled. Don't you love those double negatives? The other way to disable socket pooling is to use the adsutil.vbs script included in C:\Inetpub\adminscripts [Hack #59]. Type the following command: cscript C:\Inetpub\adminscripts\adsutil.vbs set w3svc/disablesocketpooling true You should see the response DisableSocketPooling: (BOOLEAN) True. Now, stop IIS services by typing net stop iisadmin /y (which also stops the dependent WWW Publishing Services). Then, restart them by typing net start w3svc (which also starts the parent IIS Admin Service). Socket pooling is now disabled. If you like, you can use MetaEdit to verify that the key has been added. Disabling Socket Pooling in IIS 6 The DisableSocketPooling metabase key is also valid in IIS 6 but, interestingly enough, changing it from 0 to 1 doesn't do anything. That's because socket-pooling functionality has been moved
from the Winsock HTTP listener used in IIS 5 to the new kernel mode HTTP driver (http.sys). As a result, you have to use a nifty little utility called Httpcfg.exe to disable it. This utility is found in the /Support/Tools folder on your Windows Server 2003 product CD, so begin by inserting this CD and double-clicking on /Support/Tools/SUPTOOLS.MSI to install these tools on your server. Next, open a command prompt and type httpcfg set iplisten -i w.x.y.z:n to add IP address w.x.y.z and port number n to the IP inclusion list for http.sys. This inclusion list specifies which IP addresses http.sys listens on and is initially empty by default, which means that IIS listens to all IP addresses (not none, as you might suspect). However, once you add an IP address and port number (i.e., a socket) to the inclusion list, http.sys will now listen only on the specified socket and ignore all others, leaving them available for other applications to listen on. You can add as many sockets to the inclusion list as you choose, and you can display a list of listening sockets at any time by typing httpcfg query iplisten at a command prompt. Don't forget to restart IIS after modifying the list, because http.sys reads this list only on startup. You don't have to restart all IIS services, only the HTTP Service (a subcomponent of the WWW Publishing Services and a service not displayed in the Services console). To restart the HTTP Service, type net stop http /y to stop it and net start w3svc to start it. Note that if you have problems afterwards starting any web sites on your IIS machine, you probably forgot to add their IP addresses to the inclusion list. Other Reasons to Disable Socket Pooling
If running third-party HTTP software together with IIS isn't your cup of tea, there are other reasons why you might want to disable socket pooling. The bandwidth-throttling feature of IIS that is configured through Internet Services Manager throttles bandwidth to all web sites running on IIS equally. The same is true of the performance-tuning settings configured through the GUI. If you prefer to configure these settings on a per-site basis, you have to disable socket pooling before it will work. This is not obvious from the GUI, which presents separate throttling and performance options for each site. The fact that these features don't work as advertised has been an open secret among the IIS community for a long time. They work only when socket pooling is disabled, and it's enabled by default.
Hack 61 IISFAQ Here's a brief overview of IISFAQ, Chris Crowe's valuable web site that every IIS administrator should know about. I started the IISFAQ web site (http://www.IISFAQ.com) in early 2000 initially as a resource to help me maintain a set of answers to frequently asked questions on the Microsoft IIS newsgroupsspecifically, the microsoft.public.inetserver.iis newsgroup on msnews.microsoft.com. The web site has grown up quickly over the years and is now regarded as one of the major sources of information regarding Internet Information Server on the Web. The web site is not affiliated with Microsoft in any way, but I do have limited access to the Microsoft IIS team though my Microsoft MVP status, which gives me access to some of the best information out there. On the site you will find more than 50 categories related to IIS, such as: Administration Configuration Installation
Logging Security Troubleshooting There is also a growing repository of articles and links to content around the Web that we think you will find helpful in your search for information on IIS. We try to break down complex problems into helpful, easy-to-read articles that get to the point. Most of the articles include plenty of screen snapshots to help you follow along easily. The site is kept up-to-date with all the new information that is released regarding IIS on almost a daily basis. The site also specializes in scripts for the management of your web server. There are dozens of scripts written mainly in VBScript, but with the introduction of the .NET Framework we will see more written in C# in the future. The web site is also the official home to a debugging tool called IISState, which you can use to help diagnose problemsfor example, when your web server hangs or causes 100% CPU usage. There are also discussion forums on the site for those who wish to discuss their issues or to give feedback to others who are having problems. My Favorites
Here are a few of my personal favorite articles on the site: Backup & Restore of the IIS Metabase: What tools can I use? (http://www.iisfaq.com/default.aspx? View=A329&P=73) How to Configure ODBC Logging toLlog to a Microsoft Access Database (http://www.iisfaq.com/default.aspx? View=A151&P=141) Troubleshooting ASP and Microsoft Access Databases (http://www.iisfaq.com/default.aspx? View=A396&P=160) And here are some of my personal favorite scripts on the site: A VB script that will archive all the log files for all of the IIS services that are over a specified age, in days (http://www.iisfaq.com/default.aspx? View=A141&P=109). This script uses the Microsoft MAKECAB.EXE command to make a *.cab file. After the CAB file is created, the original log file is deleted if the creation of the CAB file was successful. The CAB file will have the same name as the original log file. You save around 90-95% of disk space. A VB script that uses WMI to allow you to create DNS entries on your DNS Server (http://www.iisfaq.com/default.aspx?
View=A319&P=109). A script that enumerates all web sites using C# (http://www.iisfaq.com/default.aspx? View=A540&P=199). I hope you find IISFAQ a useful resource as you work with IIS. Thanks! Chris Crowe
Chapter 7. Deployment Hacks #62-68 Section 62. Get Started with RIS Section 63. Customize RIS Section 64. Tune RIS Section 65. Customize SysPrep Section 66. Remove Windows Components from the Command Line Section 67. Unattended Installation of Windows Components Section 68. Easily Create a Network Boot Disk
Hacks #62-68 Administering Windows-based networks begins with deployment, and the focus of this chapter is on how to manage the installation (and uninstallation) of Windows 2000/XP/2003 and its individual components. In particular, the first several hacks deal with Remote Installation Services (RIS) and Sysprep, two powerful but complex tools for installing Windows images on large numbers of machines. Other hacks deal with removing unnecessary components manually from the command line, removing components during unattended setup, and creating a network boot disk for unattended installation of Windows. These tips and tools are designed to make the job of deploying Windows easier so that you can get on with the day-to-day job of configuring, maintaining, and troubleshooting systems on your network.
Hack 62 Get Started with RIS Remote Installation Services (RIS) is a complex but powerful tool for deploying Windows images. Here's a guide to getting started with it. In the past, with the many flavors of Windows, there were many ways of configuring and deploying Windows to client machines. Such automated and customized methods included imaging with a tool such as GHOST or scripting with answer files and VBScript or other automation tools to deploy silently and without user intervention. Or, you could make one image on a hard drive and use a hard-drive-cloning device to copy the image to multiple hard disks at once. The technology and methodologies for deploying a customized Windows operating system to client workstations has matured over the years, but not quite to the plug and play capability we would all like to see. As part of Microsoft's change and configuration-management initiative, they developed a service included with Windows 2000 called Remote Installation Service (RIS). RIS supports deploying both automated and customized versions of Windows 2000 and XP Professional to clients that support the PXE/DHCP-based remote technology for remotely installing the operating system on the client computer over the network. The intention that Microsoft was communicating to the corporate technologists when they were developing Windows 2000 was that you could basically plug a new computer into the network, start the computer, authenticate, and the operating system
would be installed and configured for the user within a short matter of time. With a little bit of work, it actually does just that. Not only can you deploy images of Windows 2000 and XP through RIS, but with a tool developed by 3Com (http://www.3com.com/en_US/lanworks/index.html) you also can deploy BIOS updates, other applications, Windows 2000 Server images, and so on. RIS is customizable and flexible; you can modify the Client Installation Wizard to prompt users for information, pass information to setup answer files, and populate environment variables with information. You can deploy disk images with RIS, but I recommend the scripted, silent- installation approach, because it is more customizable. I successfully use RIS in my office to deploy a customized Windows XP Professional image, and it saves me a lot of time. Think of RIS as a network-based boot disk. The client workstation boots onto the network and obtains an IP address from a DHCP server and the location of the RIS server, RIS verifies the client is a known client, and then the Client Installation Wizard appears. It is similar to using a boot disk with NDIS drivers, a custom menu, and prompts via autoexec.bat or some other script called on the disk. Requirements for RIS So, what do you need to get started with RIS? First, you need a PXE-compliant (PXE stands for Pre-Boot Execution Environment) network card and system BIOS that supports setting the LAN as a bootup device. Most network cards todaysuch as ones from Intel, 3Com, SMC, and RealTeksupport PXE. For those workstations that are not compliant, you can create a bootable
disk with a PXE emulator by using a tool that accompanies RIS. Next, you need a Windows 2000 server that is a member of an Active Directory-enabled domain. Active Directory is required, because it provides client authentication and configuration information for the RIS server and RIS also stores its configuration information within Active Directory. Obviously, you need TCP/IP, because it is the basic networking protocol required for a Windows 2000 network. Finally, you need a Windows 2000-compliant DNS server, so that an RIS server can locate an Active Directory controller, and a DHCP server to assign TCP/IP addresses to clients, allowing them to communicate with a RIS server. Hardware requirements The hardware requirements for your RIS server are dependent on how many clients will be supported within your environment. How well RIS performs when deploying Windows to clients depends on the hardware configuration of your RIS serverin particular, the disk subsystem, memory, and networking components of your RIS server. Let's consider each of these briefly: Disk subsystem Storage space for each operating system image you want to deploy must be taken into account, because the size will vary depending on the level of customization, size of images and applications included with each image, and so on. The RIS installation point cannot be on the same volume that the operating system and/or boot files are on. It must be installed on a separate
dedicated volume. Memory In addition to the memory allocated to the operating system, allocate additional memory for the RIS service. Microsoft recommends a minimum of 128 MB for Windows 2000 Server, but I recommend 512 MB for the services and functions this server will be providing, as well as the number of clients it might be supporting. Networking components A network adapter running at 100 Mbps full duplex is best. If you are supporting a large client base, you might want to have two 10/100 adapters. Solid network connectivity between client and server is important, and you must consider your network topology when planning a RIS implementation. As with other Microsoft services you provide on your network, proper planning will help you to determine the configuration of your RIS server, how many you may need, and the placement of them. RIS can run on a member server that provides other services on your network; you just need to determine the impact and whether additional hardware is required to support the additional services. Services associated with RIS
RIS relies on three services to provide the capabilities it offers: Boot Information Negotiation Layer (BINL) The BINL service listens for and answers client DHCP requests (PXE). It also services Client Installation Wizard requests. BINL directs the client to the files needed to start the installation process. This service also checks Active Directory to verify credentials, determine whether a client needs a service, and determines whether to create a new computer account object or reset an existing one on behalf of the client. Trivial File Transfer Protocol Daemon (TFTPD) An RIS server uses Trivial File Transfer Protocol (TFTP) to download the initial files needed to begin the remote installation process to the client. These files include the Client Installation Wizard and all files needed to start Windows 2000 setup. The first file downloaded to the client using TFTP is Startrom.com, a small bootstrap program that displays the Press F12 for Network Service Boot prompt. If F12 is pressed within three seconds, the Client Installation Wizard (OSChooser) is downloaded to begin the remote installation process. When it resides on the server side, this service is called the Trivial File Transfer Protocol Daemon (TFTPD). When it resides on the client, it is simply called TFTP. Single Instance Store (SIS) or Groveler
The SIS services consist of an NTFS filesystem filter and a service that acts on the volume on which the RIS images are kept. SIS services reduce the storage requirements needed to store these images by combining duplicate files. Installing RIS On Windows 2000 Server, go to Start Settings Control Panel. Double-click Add/Remove Programs, and then double- click Add/Remove Windows Components. Scroll down, choose Remote Installation Services, and then click Next. Insert the Windows 2000 Server CD-ROM into the CD-ROM drive and click OK. The necessary files are copied to the server. Click Finish to end the wizard. When you are prompted to restart your computer, click Yes. When the server has restarted, log on to the computer with an account that has administrative privilege. I recommend you always apply the latest service pack for Windows 2000, because it might have fixes or enhancements to RIS. For example, Service Pack 3 includes support for deploying Windows 2000 Server and Windows XP Professional (the original RIS supported deploying Windows 2000 Professional only) and resolves networking issues with RIS clients and installation issues (such as RIS clients hanging during setup). There are also specific hotfixes for RIS, but these are available only if you are experiencing the specific issue and they require a call into Microsoft support to obtain the update. The directory structure of RIS is flexible; it is designed to support many different languages and hardware platforms. The following directories are created for the RIS service during installation.
OSChooser This directory contains all of the files needed by the client installation wizard. As noted, the OSChooser directory supports many different types of hardware platforms and languages. However, only the x86 platform is supported for RIS in Windows 2000. Setup This directory contains the images that have been installed on the RIS server. Notice that the existing operating system images also contain a corresponding Templates directory, which contains the SIF file used for unattended installation of the operating system on the client computer. The SIF file also contains the friendly description string and specific image details that are displayed to end users of the client installation wizard and in the Tools tab within the administrative UI. Note that for an image to be displayed in both the administrative UI and the client-installation-wizard UI, it must contain an associated *.sif file template. Tools This directory contains tools that are designed to support deployment through RIS, such as BIOS updates, virus tools, and so on. To set up RIS after installation, go to the command prompt or Start Run and type RISETUP.EXE to start the Remote
Installation Service Setup Wizard. Follow the instructions on the screen. It will guide you through configuring RIS, and the last step will be to create an image of your Windows 2000 Server/Professional or Windows XP Professional from the CD. I won't get into detail here, because it is a straightforward process, but see Microsoft Knowledge Base article Q298750 (http://support.microsoft.com/default.aspx?scid=kb;en- us;298750) for any assistance you might need. Once you complete the process of configuring RIS, the server must be authorized in Active Directory. This ensures that rogue servers with those services installed (either by accident or intentionally), will not impact or disrupt network operations. Log onto a domain controller in the root domain with Domain Administrator or Enterprise Administrator rights. Go to Start Programs Administrative Tools and click on the DHCP snap-in. Right-click DHCP in the upper-left corner of the screen, and then click Manage Authorized Servers. If the RIS server does not appear in the list, click Authorize and enter the IP address of the server. Once you're finished setting up RIS, you can customize it to the needs of your own networking environment [Hack #63]. Matt Goedtel
Hack 63 Customize RIS Once you know the basics of setting up RIS, you can customize it for the needs of your own networking environment. In [Hack #62], we looked at how to install and set up RIS on a Windows 2000-based network. Once RIS is successfully installed and authorized in Active Directory, you are ready to customize your RIS settings to meet your needs. This might include setting installation restrictions, defining a computer- naming policy, configuring client response options, prestaging clients in Active Directory, and permitting clients to install operating system images. Configuring RIS To configure the RIS server to respond to client requests, you need to log onto one of your domain controllers or install the Administrative Tools package (adminpak.msi) on the member server that is running the Remote Installation Service. Execute the Users and Computers MMC snap-in, right-click on the server that is running RIS, and you will see a tab labeled Remote Install. On this tab, you can enable RIS to respond to client requests (which is enabled by default) and enable the option to not respond to unknown clients. This ensures that you support only prestaged computer account objects in your forest as part of your security strategy. If you have multiple RIS servers as
part of a load-balancing strategy and one fails or is unstable, you can deselect the option to allow it to respond to client requests. The Advanced Settings button displays a window that allows you to configure additional settings for RIS clients, such as the default computer name that is generated for each client when a user selects Automatic Setup on the Client Installation Wizard (CIW) screen. By default, the username of the user who authenticated in the CIW is used for the computer name, along with a number. The username can be customized to use different variations, which you can control by using variables recognized by Active Directory and the BINL service. For example, CorpWks%# = CorpWks2 uses a number incremented each time a computer account is generated when an image is deployed/installed via RIS. You can refer to online help or Microsoft TechNet for other variables or variations. Taking advantage of the Advanced Settings is dependent on the standards currently implemented in your environment. If you have different standards per department, site, or domain, you will need to determine if you can leverage this feature. You might need to use a different solution during the build process. If you are predefining the computer names, which are matched to the unique GUID of that workstation, then this is a nonissue. In this screen, you also have the option of specifying the organizational unit (OU) in which the computer accounts are created. By default, they are created in the Computers container. Predefining computer accounts in RIS If you are security-conscious or want to ensure that systems are not arbitrarily imaged from RIS without approval, you should
enable the "Do not respond to unknown computers" option on the RIS server. This also allows for greater flexibility, but it requires some up-front work on the administrator's part. Specifically, you can precreate the computer accounts in their respective OUs in Active Directory. Based on the organizational structure of the company and delegation of administration, this will also have some bearing on how you plan your implementation of RIS. When precreating the computer accounts, you need to select the "This is a managed computer" option and the GUID of that computer is required. For computers that come from one of the leading PC vendorssuch as Compaq, HP, or Gatewaythe GUID can be found on a sticker adhered to the PC case. If the system does not have that sticker, you can create the GUID by using the MAC address of the network card installed in the PC, or you can boot up the PC and access the BIOS; the GUID might be displayed on the main screen. When using the MAC address of the network card, since the GUID is a 32-byte value, you need to pad the first 20 bytes with zeros; the remaining 12 bytes is the MAC address. To load-balance your RIS servers manually, when you create the computer account and specify it is a managed computer, you can specify the RIS server to own (i.e., support) the client. I don't like this approach, because there is too much overhead management. Also, if the server were to become unavailable, your clients would be unable to obtain any images, updates, or components until that server became available again. Setting up a dynamic load-balancing solution with RISby defining one RIS server as the bridgehead and all other RIS servers behind it to serve only the imagesis a better approach. I have not used any other approach, but I have been looking into how to leverage clustering or other solutions to further bolster the redundancy of RIS.
Client Installation Wizard The screens that are presented to the client when he interfaces with RIS are in OSCML format (similar to HTML and modeled after HTML 2.0 format) and have a .osc extension. You have great flexibility in how to present those screens to clients, based on your organizational needs and a touch of personalization (e.g., adding your company name to display in the screens). There are also state variables that you can use to make your image installations more dynamic; the values of the response are passed back via BINL to the answer file located in the template folder of the particular image. You can have up to 64 unique variables to use with the CIW. All variables, with the exception of the %LANGUAGE% variable, are set after successful login. As always, make a backup copy before modifying the original file, in case you run into an error or you want to revert back to the original for any reason. OSChooser and the BINL service use the following variables: LANGUAGE The only variable that can be set prior to logon. This variable indicates the language in which the user wants to view the screens. All OSC screens, as well as any ENUM functions the server performs, are pulled from that language. The default value of this variable matches the default language of the server. Refer to the Multilng.osc file located in the RemoteInstall\Oschooser directory for an example of how to make the server multilingual.
SUBERROR The server sets this variable internally for any errors it encounters. You can add this variable to an error message screen to diagnose internal failures inside the server. MACHINEOU Indicates to the server where the new machine account should be generated. MACHINENAME Indicates to the server the name of the new machine. SERVERNAME Indicates the name of the server to which OSChooser is connected. SERVERDOMAIN Indicates the domain name of the server to which OSChooser is connected. BOOTFILE Indicates when a tool is about to be started.
NETBIOSNAME The NetBIOS name generated (using the DnsHostnameToComputerName( ) call) for the computer on which the image is being installed. SIFFILE This variable is local to the server path of the SIF that the user selected to install the OS. It is similar to the following example: X:\RemoteInstall\Setup\English\Images\Win2000.pro\I386\Templates\Ristndrd.sif OPTIONS This variable is filled with the results of an ENUM action by the server. It contains OSCML and should be placed between a tag and a tag. See the Tools.osc file located in the RemoteInstall\Oschooser%Language% directory for an example. MACHINEDOMAIN The domain that the new client attempts to join during GUI-mode setup. This might not correspond to the MACHINEOU variable's domain.
SYSPREPPATH The path to the sources for a Riprep-based image if you use Riprep.exe to create your images. For example: X:\RemoteInstall\Setup\English\Images\Win2000.prep\I386 INSTALLPATH The TFTP relative path to the installation imagefor example, Setup\English\Images\Win2000.pro. SYSPREPDRIVERS Indicates the path the server thinks best fits the Riprep- based image. This path is used to find plug and play drivers. MAC Sent by OSChooser to indicate the MAC address of the client. GUID Sent by OSChooser to indicate the GUID address of the client. MACHINETYPE
Sent by OSChooser to indicate the type of hardware on which OSChooser is running. For example, on Intel platforms, you would use INTEL = "i386" USERNAME, *PASSWORD, USERDOMAIN OSChooser looks for the credentials specified by these three values to process the logon request. *PASSWORD is a short-lived variable that is overwritten as soon as possible on the server and is not accessible to OSC files or SIF files. TIMEZONE Set by the server to the server's current time-zone setting. This setting is helpful if you are replicating images to remote servers in different time zones. RIS Custom Installation Wizard Now, let's look at how to customize the RIS Custom Installation Wizard screens and how you can modify them to suit your environment. Here are the default screens that are displayed during the client login and installation process when deploying operating system images to clients using RIS: Welcome.osc Displays the welcome screen to the user.
Login.osc Displays the login screen and requires the user to log into the domain. Choice.osc Displays the setup optionsAutomatic, Custom, Restart, Maintenance, and Toolsto the user. Remote Installation Service (RIS) Group Policy settings control which options appear. OSAuto.osc Determines whether a computer account already exists in Active Directory with the same GUID as the computer that is running Client Installation Wizard. If a duplicate is found, DupAuto.osc is displayed. If no duplicate is found, then OSChoice.osc is displayed. DupAuto.osc Displays a message indicating that a duplicate GUID was found in Active Directory and instructs the user to contact the network administrator. OSChoice.osc
Displays the list of operating system images available to the user who logged onto the RIS server. Warning.osc Displays a warning to the user that the hard drive is going to be formatted and all information will be lost. Install.osc Displays a summary page to the user. All these screens are modeled after HTML Version 2.0 specifications and are simple text files with an .osc extension, indicating they are in the format of OSChooser Markup Language (OSCML). All of these files are installed in the RemoteInstall\OSChooser<language> folder. The files listed in this hack are only a subset of the total number of .osc files stored in this folder. With these files, you customize client login screens in a variety of ways, including changing the text in the title or in the main body and adding additional input fields. You can then use that new information to further tailor the unattended installation of your Windows OS image through RIS. When working with different languages, you will need to modify Multiling.osc to list the languages that will be supported by RIS; then, rename Multiling.osc to Welcome.osc. There are 24 predefined variables you can use within your own custom screens or answer files. These variables are available only in the Install.osc file and in the answer file. Some variables have predefined values, while others do not. To learn more about the predefined variables, see the following URL at Microsoft's web site:
http://www.microsoft.com/windows2000/techinfo/reskit/en- us/default.asp?url=/windows2000/techinfo/reskit/en- us/distrib/dsed_dpl_flwz.asp To learn more about configuring your own Custom Installation Wizard screens, see the following Microsoft Windows 2000 Resource Kit article, which breaks down the tags that are supported in OSCML: http://www.microsoft.com/windows2000/techinfo/reskit/en- us/default.asp?url=/windows2000/techinfo/reskit/en- us/distrib/dsed_dpl_KEMO.asp You have a great deal of flexibility when hacking the screens used in RIS; you can even create your own screens to request information for your automated build. Say you want to create a screen to prompt for the local administrator account password, the location of the user's computer, and so on. With the default screens and the reference material provided by Microsoft, you are on your way. Deploying Windows Images Configuring RIS to deploy Windows images is a simple and straightforward task. However, there are limitations to configuring RIS with Windows 2000 and Windows XP images. You cannot slipstream service packs into the i386 image on an RIS server for Windows 2000 Professional images. To handle this issue, see Microsoft Knowledge Base Article 258868 (http://support.microsoft.com/default.aspx?scid=kb;en- us;258868). When you want to slipstream SP1 into a Windows XP image, you
will need to obtain a hotfix from Microsoft, because there are security changes in SP1 for Windows XP. See Microsoft Q Article 327536 (http://support.microsoft.com/default.aspx? scid=kb;en-us;327536) to obtain the hotfix. Beyond those two important items, you might also run across minor compatibility issues with video and network cards. If you have Service Pack 3 for Windows 2000 installed on your RIS server, you will also be able to support the deployment of Windows 2000 Server. To add additional images to RIS for deployment, execute RISSetup.exe. This executable also accepts two command-line parameters: -check Runs only the server component of RIS setup. It performs a verification of the components of RIS and corrects them. -add Installs a new CD-ROM-based version of Windows XP Professional, Windows 2000 Professional, or Windows 2000 Server. I recommend you keep handy the deployment guides that complement Windows 2000 or Windows XP and refer to them when you are customizing a build for automated deployment. Also, keep an eye out for any new material posted by Microsoft or the other technical resources on the Web, to help you along the way. Reference material is always a good thing.
Once you've customized RIS for your own environment, you might need to tune it further to make RIS server run effectively [Hack #64]. Matt Goedtel
Hack 64 Tune RIS If you can't afford the resources to run a dedicated RIS server for your environment, you can use RIS on a dual-purpose serveras long as you tune it carefully. Let's talk about fine-tuning RIS if there are other folders on the volume (i.e., other than the OS images used by RIS) and how to handle the restoration of the volume managed by SIS. To do this, we will have to dig deeper into how SIS works. By storing a only a single copy of data in a folder on the volume, SIS helps reduce the amount of disk space that contains the OS images used by RIS. When SIS Groveler starts, it searches the root of each NTFS volume to see if it contains the SIS folder named SIS Common Store and a file called MaxIndex within that directory. If the Groveler finds this folder and file and if the SIS filter driver is installed on the system, the Groveler knows to search for and consolidate duplicate files on the volume. SIS uses the same technology as the Indexing Service, and it is designed to not consume CPU time when the system requires it for other functions. The exception is when disk space drops below a specific value; in this case, the Groveler will increase CPU usage regardless of system activity, to ensure that disk space is not entirely consumed. To effectively manage duplicate files that it detects when scanning a volume, SIS places the data in the SIS common store and the original files are changed to reparse points with
referrals to the .sis file. When the application tries to access the original file, the filesystem redirects any file I/O to the .sis file in SIS Common Store. For example, if SIS detects the file net1.ex_ in both the RIS\SETUP\ENGLISH\IMAGES\WindowsXP.Pro\i386 and \SETUP\ENGLISH\IMAGES\WindowsXP.Pro.SP1\i386 folders, it places the duplicate file in the SIS common store and the references of those files are changed to reparse points with referrals (or links) to the .sis file. Now, let's say you have a dual-purpose Windows 2000 Server that is both a file-sharing server and a RIS server. The volume that houses the RIS OS images also has the file shares. When the Groveler service performs its daily ritual, it will scan through all folders on that volume. To improve efficiency of SIS and restore SIS links or reparse points, you can exclude certain directories from the Groveler scan. To exclude a directory on a single volume, modify the Grovel.ini file located in the SIS Common Store folder (this folder is hidden by default). First, you will need to modify the NTFS permissions of the folder, because only SYSTEM has full control rights by default. Then, under the [Excluded Paths] section, add the required entryfor example, Directory 1 Folder = \Folder1. Note that the value to the left of the equals sign can be of any designation you wish. Now, stop and restart the Single Instance Storage service and you're done. To exclude a directory on all volumes, open Registry Editor and add an entry to the following key: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Groveler\ExcludedPaths The value can have any namefor example, Folder 1 Directory REG_SZ \Folder1. Again, after you've done this, stop and restart the Single Instance Storage service.
In an enterprise environment, you should have a dedicated Windows 2000 server or servers to provide RIS images, depending on how many desktops you are supporting. In a smaller environment, it is reasonable to have a multipurpose server provide RIS, as long as it has the resources to support the additional overhead. Finally, to restore a volume that is managed by SIS, follow the instructions in KB Article 263027 (http://support.microsoft.com/default.aspx?scid=kb;en- us;263027). How you handle a restore depends on the failure you are faced with, such as failed disk drives, controllers, or the like. Follow this article carefully to ensure you are not faced with data corruption because of the linked files managed by SIS! For more helpful information on using RIS to deploy Windows, see my column at myITforum.com (http://www.myitforum.com). Matt Goedtel
Hack 65 Customize SysPrep Using SysPrep to deploy Windows can be a nightmare, unless you find a way to minimize the number of images you have to maintain. Are you in charge of imaging workstations in your company? Do you have multiple hardware platforms deployed throughout your company? Do you maintain more than five images of those workstations? If you answered "yes" to any of these questions, then this hack might just ease your workload. By using Microsoft's SysPrep utility, system administrators can reduce the number of PC images that are maintained on a daily basis. Using the approach in this hack, I have moved away from maintaining between 15 and 20 images and now have to update only 2 or 3 images for our entire company. I support nearly a dozen different types of workstation hardware, including several hardware specifications for laptops. SysPrep, while not inherently easy to configure or understand, is well worth the time and energy invested. Getting Started On the lowest platform deployed at your company, install the operating system and leave the administrator account password blank. By leaving the administrator password blank, you prevent
passing it in plain text via the sysprep.inf file. For our example, we'll use the following credentials: Name: Company Name Organization: Company Name Computer Name: XXXXXX (whatever you want) Administrator Password: (blank) Create an administrative equivalent account called Test with a password: UserID: Test (or whatever else you want to use) Password: test! (or whatever) Now, decide on the Network Options. Check the radio button that reads "Users must enter a user name and password to use the computer" or "Leave the machine connected to the WORKGROUP." Once the operating system is installed, build a new image from scratch by using the Test account. This image should include the latest operating service pack and security patches, in addition to all software that is to be included in the base image. So that you don't have to rely on hindsight, it is recommended that you upload this base image before applying the SysPrep files. That way, if something goes wrong with the SysPrep process, you still have a valid image and won't have to reinstall all the software again. Make sure to keep this uploaded base image separate from all other SysPrep-generated images. Naming the image NoSysPrep might be a good naming convention. Now, create a folder called C:\SysPrep on the base-image machine. Copy the following files to the newly created folder: Sysprep.exe
Prepares the hard drive on the master computer for duplication Setupcl.exe Regenerates new SIDs for the computers Pnpids.exe Helps you identify common names for supported Plug and Play devices Msdpnp.txt Contains inf settings for supported devices Sysprep.inf The answer file to be used for applying an unattended image to a machine Now, copy all drivers, for all hardware platforms, to C:\SysPrep\Drivers from wherever they reside (whether on a CD- ROM or a network drive). This directory structure will be used when you modify the sysprep.inf file. Note that it is important to download the latest drivers for every type of hardware platform in your company. If hard-drive space is not an issue, it might be a good idea to place all device drivers in separate folders for each unique hardware platform in your company.
Once all the drivers are copied locally, log out of the Test account and log on as administrator. (The password should still be blank at this point.) Delete the Test Profile by right-clicking on My Computer and selecting Properties. Then, from the User Profiles tab, highlight the Test Account and press the Delete key. Next, delete the Test account by right-clicking on My Computer, selecting Manage, expanding Local Users and Groups, highlighting Test Account, and pressing the Delete key. Run Disk Cleanup (Start Programs Accessories System Tools Disk Cleanup). Then, remove the following two entries from the Registry to keep the base image tidy: HKLM\Microsoft\Windows\CurrentVersion\RecentDocs HKLM\Microsoft\Windows\CurrentVersion\ RunMRU Change the administrator password from blank to something appropriate to the security needs of your environment. Then, from the command prompt, run the following command: C:\SysPrep\sysprep.exe -pnp By running the sysprep.exe utility, the PC will be powered down once you click OK. This might take several minutes to complete. The -pnp parameter here indicates Plug and Play. Now, upload new image and name it SysImage to prevent overwriting the original image. Upon reboot, the SysPrep wizard will run, finding all drivers for each particular hardware device in the system. Understanding the SysPrep.inf
The key to making SysPrep work on multiple hardware platforms lies in customizing the SysPrep.inf file and the command used to invoke the sysprep.exe utility. This following sections explain each section of the SysPrep.inf file. The following code is taken directly from the sysprep.inf file included with the utility, along with my explanations. SysPrepMassStorage The key to the SysPrep.inf file lies within the SysPrepMassStorage section: [SysPrepMassStorage] Primary_IDE_Channel=%windir%\inf\mshdc.inf Secondary_IDE_Channel=%windir%\inf\mshdc.inf These two strings tell the operating system where to look for the IDE drivers. When you run a full-blown Setup from any Windows setup disk, Setup goes out and looks for the default IDE drivers for the primary and secondary IDE controllers before the GUI phase of Setup begins. After it finds the default drivers, it continues with whatever task it needs to perform. After all the files have been copied over and the setup is completed, it will either keep the default IDE drivers or look for a more updated one from the path provided in the SysPrep.inf answer file. It rarely prompts for an updated driver, unless you have another IDE controller installed (i.e., in addition to the primary and secondary controllers). Note that %windir% is the environment variable used to describe the location of the Windows files. For Windows NT/2000
operating systems, the Windows files are located in C:\Winnt. For Windows 9x/XP operating systems, Windows files are located in C:\Windows. By using this environment variable, the SysPrep.inf file can be used for nearly all operating systems without additional coding. The Mshdc.inf file references the Microsoft Hard Drive Controller .inf file. PCMCIA*PNP0600=%systemroot%\inf\mshdc.inf *PNP0600=%systemroot%\inf\mshdc.inf PCMCIA\KME-KXLC005-A99E=%systemroot%\inf\mshdc.inf PCMCIA_-NinjaATA--3768=%systemroot%\inf\mshdc.inf PCMCIA\FUJITSU-IDE-PC_CARD-DDF2=%systemroot%\inf\mshdc.inf *AZT0502=%systemroot%\inf\mshdc.inf PCI\VEN_10B9&DEV_5215=%systemroot%\inf\mshdc.inf PCI\VEN_10B9&DEV_5219=%systemroot%\inf\mshdc.inf PCI\VEN_10B9&DEV_5229=%systemroot%\inf\mshdc.inf PCI\VEN_1097&DEV_0038=%systemroot%\inf\mshdc.inf PCI\VEN_1095&DEV_0640=%systemroot%\inf\mshdc.inf PCI\VEN_1095&DEV_0646=%systemroot%\inf\mshdc.inf PCI\VEN_0E11&DEV_AE33=%systemroot%\inf\mshdc.inf PCI\VEN_8086&DEV_1222=%systemroot%\inf\mshdc.inf
PCI\VEN_8086&DEV_1230=%systemroot%\inf\mshdc.inf PCI\VEN_8086&DEV_7010=%systemroot%\inf\mshdc.inf PCI\VEN_8086&DEV_7111=%systemroot%\inf\mshdc.inf PCI\VEN_8086&DEV_2411=%systemroot%\inf\mshdc.inf PCI\VEN_8086&DEV_2421=%systemroot%\inf\mshdc.inf PCI\VEN_8086&DEV_7199=%systemroot%\inf\mshdc.inf PCI\VEN_1042&DEV_1000=%systemroot%\inf\mshdc.inf PCI\VEN_1039&DEV_0601=%systemroot%\inf\mshdc.inf PCI\VEN_1039&DEV_5513=%systemroot%\inf\mshdc.inf PCI\VEN_10AD&DEV_0001=%systemroot%\inf\mshdc.inf PCI\VEN_10AD&DEV_0150=%systemroot%\inf\mshdc.inf PCI\VEN_105A&DEV_4D33=%systemroot%\inf\mshdc.inf PCI\VEN_10AD&DEV_0571=%systemroot%\inf\mshdc.inf Referring back to the SysPrepMassStorage section of Sysprep.inf, the two strings below the primary/secondary controllers (not shown) are unique IDE drivers for your own specific hardware. If you have a unique IDE controller and would like to use drivers other than the MS defaults, you can add them to this section. You must be very careful when adding a line in the SysPrepMassStorage section of the .inf file. By using only the downloaded drivers, instead of the Microsoft default drivers, you
might get an error message stating that there is an invalid disk. If you are running a different IDE driver, you might want to run the driver setup at the end of the SysPrep process. This can be accomplished by placing the setup string in the RunOnce section of the SysPrep.inf answer file. This should then update the IDE controller to the driver that you prefer to use, in addition to creating a stable SysPrep run. Another thing to consider is an already-configured IDE controller that is a part of your base image. You might lose the updated IDE driver, because the SysPrep setup-wizard parameter pnp (Plug and Play) will overwrite your preconfigured driver. There is a way around this SysPrep feature: omit the pnp parameter when you run sysprep.exe. Omitting the pnp parameter when you run SysPrep runs only a portion of PnP process and not the full PnP feature. While this might prevent the loss of a preconfigured IDE driver on your workstation image, you should use caution when you choose not to run the full pnp parameter. Running the full pnp parameter as a part of the SysPrep process will indeed allow one image to locate and install a variety of unsupported hardware configurations. If the default Microsoft IDE driver or the specific IDE driver is not detected, then SysPrep will not run correctly. Unattended The following lines in the Unattended section mean that the whole SysPrep setup will not stop or pause for anything. Note that you can document the SysPrep.inf file by using a semicolon as a comment marker, as shown here above the actual command:
[Unattended]
; the following optional line means setup won't pause for anything, including errors
UnattendedMode = FullUnattended
The following lines skip the license agreement and any other
prompts dealing with licensing:
OemSkipEula = Yes
OemPreinstall = No
The following line tells SysPrep the folder location for hardware-
specific drivers that are not included with the operating system:
OemPnPDriversPath = sysprep\Drivers\1\NIC;sysprep\Drivers\1\Sound\W2k;sysprep\Drivers\1
Sound;sysprep\Drivers\1\video;sysprep\Drivers\6\NIC;sysprep\Drivers\7\NIC;sysprep\Drivers
7\Video;sysprep\Drivers\8\NIC;sysprep\Drivers\8\Sound;sysprep\Drivers\8\Video;sysprep|
Drivers\Evo\3c0XNic;sysprep\Drivers\Evo\IntelNic;sysprep\Drivers\Evo\Nvidia;sysprep
Drivers\Evo\Sound;sysprep\Drivers\Evo\Sound\Smaxwdm\W2k;sysprep\Vli8\Keyboard;sysprep
Vli8\NIC;sysprep\VLi8\Sound;sysprep\Vli8\Video
Typically, you should copy all drivers into a C:\Drivers folder and
separate them on a machine-by-machine basis. To keep this line
from becoming unmanageable, abbreviate hardware-specific
folders and document them accordingly. In this particular
instance, the 6 represents hardware running at 600 Mhz, 7
represents 733 Mhz, 8 represents 866 Mhz, and so on. Use any
method that fits your environment.
If the image you created has all the drivers for all the different
hardware, then the OEMPNPDRIVERSPATH is not needed. However, I recommend you reference all drivers, just in case the manufacturer makes any hardware changes. You do have to copy all the drivers into the SysPrep folder. The space is lost for the image but will be reclaimed after SysPrep finishes, because the image automatically deletes itself. Just make sure that the drivers you need are inside the SysPrep folder. GuiUnattended In the GuiUnattended section, the asterisk beside AdminPassword means the local administrator password is blank: [GuiUnattended] AdminPassword=* OEMSkipRegional=1 TimeZone=20 OemSkipWelcome=1 By having a configured local administrator password on your image, this SysPrep answer file will not null out the password, keeping the password the same. This creates good security by not passing the administrator password via the SysPrep.inf file. UserData
The UserData section is pretty self-explanatory: [UserData] FullName="YourCompanyNameGoesHere" OrgName="YourCompanyNameGoesHere" ComputerName=xxxxxx Productid=License info goes here Display By configuring the screen settings in the Display section, you can prevent the screen from coming up to the far-right or far-left side of the monitor. The display will be centered. These settings can be configured to suit your company's needs: [Display] ConfigureAtLogon=0 BitsPerPel=16 XResolution=1024 YResolution=768 VRefresh=75 AutoConfirm=1
The BitsPerPel section references the color. Make sure to check the hardware compatibility with a hardware refresh rate (VRefresh). A refresh rate of 75 should work for most hardware, but sometimes 65 is a better option. The AutoConfirm setting is enabled so that confirmation is already set, thus preventing a change back to the default setting. Identification The Identification section configures a PC to join a specific workgroup: [Identification] JoinWorkgroup=WORKGROUP The workgroup name can be almost anything. If you want to have the PC automatically join a domain, other command lines are needed. Networking The Networking section tells SysPrep to use the default network settings, including Client for Microsoft Networks, File and Printer Sharing, and TCP/IP (DHCP): [Networking] InstallDefaultComponents=Yes
Within this section you can also add additional protocols, clients, services, static IP, and other networking options. The only issue I have encountered, when running sysprep.exe with the -pnp switch (which causes SysPrep to perform a full device enumeration using Plug and Play), is that my company's preconfigured DNS settings are overwritten because the network card is redetected during the SysPrep process. A possible solution to this issue is to add a line in the RunOnce section of the SysPrep.inf file that will automate reconfiguring those DNS entries. GuiRunOnce Finally, by adding the following line to the GuiRunOnce section of the SysPrep.inf file, a script is run from the local machine: [GuiRunOnce] Command0=C:\temp\Scriptfile The script file can perform a wide variety of commands. Be sure the file exists on the machine before you reference the command in the SysPrep answer file. Now you know how to customize the SysPrep.inf file for your environment! For more helpful information on using SysPrep, see my column at myITforum.com (http://www.myitforum.com). Janis Keim
Hack 66 Remove Windows Components from the Command Line Here's a handy utility you can use from the command line to remove Windows components and protected files. When asked to remove simple game files from a company's workstations, I replied quickly that it would not be a problem. After all, how tough could it be to delete four executables and their shortcuts? Well, on Windows 2000/XP machines, it can be a little difficult. When you try to delete the files, the OS will see that those files are missing and will replace them (or restrict you from deleting them). Why the files sol.exe, freecell.exe, and so on are considered critical system files is beyond me, but in order to get rid of them you will need to use the sysocmgr.exe utility. The sysocmgr.exe tool is used to add or remove windows components. This utility takes advantage of an answer.txt file that can be scripted and pushed via Systems Management Server (SMS) and other methods. For the purposes of this hack, we will use the answer.txt to remove four famous games from the computer. In our case, the answer.txt file will look something like this: [Components] solitaire = off freecell = off
pinball = off minesweeper = off The utility will parse only the [Components] and [NetOptionalComponents] sections of the file, so you can easily wrap it in with other answer files or inf files. Running the Hack The command line for the utility has several switches, but these are the most important ones for our example: /i The location of the inf for sysocmgr.exe. This is different than the answer file and is normally in the System32 directory. /q Runs the utility in quiet mode to suppress prompts. /r Suppresses a reboot (if required).
/u Specifies the location of the answer (unattended) file. /w Prompts the user to reboot instead of rebooting automatically (if required). Putting it all together, our command line to remove the games components on Windows 2000/XP machines looks like this: sysocmgr /i:c:\winnt\inf\sysoc.inf /u:c:\UnattendSetup\answer.txt /q Removing these four games does not require a reboot, so we didn't bother to put in the any of the reboot switches. Hopefully, this will prove useful in your environment; but, as always, test first. Donnie Taylor
Hack 67 Unattended Installation of Windows Components Here's a simple way you can add or remove system components when deploying Windows 2000 and later. If you're responsible for administering a large number of computers, you appreciate methods of automating common administrative tasks. A need to add or remove individual system components might result from a change in corporate policy, discovery of security vulnerability, or simply a newly emerged business need. Using sneakernet for such tasks might take considerable amount of time. Fortunately, Microsoft provides a way to accomplish this task in an unattended way. Windows 2000 and XP contain the SYSOCMGR.EXE file in the %systemroot%\system32 folder. When executed, this command-line utility analyzes the content of two files: sysoc.inf (the existing configuration file, located in %systemroot%\inf folder) and a specially formatted text file (which you can give an arbitrary name) that contains a listing of components to be added or removed. The sysoc.inf file is used by Windows when running the Add/Remove Programs applet in the Control Panel. It's format is typical of standard .inf files: it is divided into several sections, each starting with a name enclosed in square brackets. The [Components] section consists of multiple lines, one per component. Each line starts with the component name, followed
by references to .dll and .inf files used during installation or uninstallation. Hide entry determines whether the component appears in Add/Remove Programs applet. The second text file (which you need to create) can have an arbitrarily chosen name; for example, c:\comp.txt will do nicely. This file can be created using Notepad and should contain the [Components] section, followed by one or more lines of the following format: Component_Name = On/Off Here, On is used for installation and Off is used for uninstallation. For example, to remove Windows Messenger and add Faxing, the file should contain the following lines: [Components] Msmsgs=Off Fax=On You can also install optional networking components by including the line Netoc=On and the additional section [NetOptionalComponents]. This section would contain lines that refer to different networking components, such as SimpTcp or wins, like so: SimpTcp=1 wins=1 A value of 1 causes installation and 0 causes uninstallation. The names of the components are the same as the ones used during unattended installation of the operating system, which are documented in the Unattended.doc file on the Windows
installation CD in the Support\Tools folder. Running the Hack Once you've created your Comp.txt file, you can now use sysocmgr.exe in unattended installation mode to add or remove Windows components. Simply run the following command: SYSOCMGR.EXE /i:%windir%\inf\sysoc.inf /u:c:\comp.txt Note that this approach will not work with the COM+, Distributed Transaction Coordinator, Microsoft Fax, and Windows Media Player services, because these components are not removable. Marcin Policht
Hack 68 Easily Create a Network Boot Disk One of the headaches of deploying Windows is creating network boot disks. Here's a speedy solution. Creating a network boot disk is not very difficult, but it always seems to take longer than it should. The Instant Network Boot Disk from Qual-IT removes the hassle. The Instant Network Boot Disk works with most network cards. It quickly provides network access, and it includes filesystem tools and other network utilities. The tool provides full support for Windows 9x, NT, 2000, and XP platforms and includes multinational keyboard support, advanced memory configuration, and a debug mode for troubleshooting drivers that refuse to load. The disk loads completely into RAM for ultra-fast performance and includes support for static IP addresses or DHCP and built- in PCMCIA support for some PCMCIA drivers. It also includes PING- and IPCONFIG-compatible utilities and lets you preconfigure your network adapter settings. To use the tool, first go to the Qual-IT web site at http://www.qualit-uk.com and click the Tools menu option. Find the latest version of Instant Network Boot Disk and download it to your machine. To create a network boot disk, you need a blank floppy and the appropriate driver for your network card. The steps for creating a boot disk are simple. First, run the tool
to create a generic boot disk and then copy your NIC driver to the disk. If space is an issue, delete the included drivers to make room for new ones you need. Now, reboot from the disk and select the "CONFIGURE THIS DISK" option when it appears. Provide the required setup informationfor example, the hostname, the IP address or using DHCP, your NIC card, and so on. Now, save your settings and reboot. Detailed configuration and troubleshooting information is included on the disk in the readme.txt file. I've found this utility to be a real time- and headache-saver. Add it to your list of tools today! Patrick Sklodowski
Chapter 8. Security Hacks #69-78 Section 69. Fundamentals of a Virus-Free Network Section 70. Antivirus FAQ Section 71. Rename the Administrator and Guest Accounts Section 72. Get a List of Local Administrators Section 73. Find All Computers that Are Running a Service Section 74. Grant Administrative Access to a Domain Controller Section 75. Secure Backups Section 76. Find Computers with Automatic logon Enabled Section 77. Security FAQ Section 78. Microsoft Security Tools
Hacks #69-78 Probably no aspect of the system administrator's job is more important these days than security, and this is especially so with systems running Windows. The ever-increasing threats of viruses, worms, Trojans, and other exploits means administrators have to spend time and energy learning how to protect their company's networks against the wiles of malicious hackers on the Internet. This chapter looks at some of the ways you can protect your network from these threats, and includes topics like best practices in virus protection, protecting Administrator accounts, securing backups, protecting domain controllers, and finding machines with automatic logon enabled. A security FAQ and a review of security tools you can download from Microsoft's web site round of this chapter and help you build an arsenal of best practices and tools that can help keep your network secure. For additional security hacks on the topic of deploying and managing security fixes on your network, see Chapter 9.
Hack 69 Fundamentals of a Virus-Free Network Here are some fundamentals you need to pay attention to if you want to keep your network free of viruses. This hack details some of the fundamentals of having a virus- free network, which I have identified through trial, error, and observation in the almost three years of working in the dual role of SMS/Virus Protection Administrator for my employer. As a result, we've had zero network downtime due to virus infection since January of 2000 until now (December 2003). Awareness The first fundamental is awareness. Simply put: you can't protect your network against a threat if you don't know the threat exists. Administrators need to keep up-to-date on viruses, current virus trends, and application and operating-system security vulnerabilities. How aware an administrator is about these subjects is very important, because it effects all the decisions that an administrator will make to protect a network from viruses. There are several ways to gain awareness if network threats. For information on viruses and virus trends, the web sites of
antivirus software vendors are the best place to start (I will discuss antivirus software shortly). All of those companies have some kind of virus-information section on their web sites. I recommend checking the web site that corresponds with the antivirus software that your company uses several times a day (every couple of hours is even better). Virus writers are getting smarter and more devious everyday, and another virus like Nimda or Blaster could spread across the globe in a matter of hours or even minutes if given the right conditions. The more often you check, the better chance you have of getting a heads up on the next virus that goes worldwide. Since antivirus vendors partly rate the threat level of a virus on how many samples of a virus have been submitted to them by their customers, it is also a good idea to check more than one web site for virus information. I recommend checking out two or three, just to keep an eye on things. Here are a few good antivirus web sites: Symantec (http://securityresponse.symantec.com) Network Associates (http://vil.nai.com/vil/newly- discovered-viruses.asp) Trend Micro (http://www.trendmicro.com/vinfo) Computer Associates (http://www3.ca.com/virusinfo) F-Secure (http://www3.ca.com/virusinfo) I usually concentrate on Symantec, Network Associates, and Trend Micro's web sites. According to the latest ICSA Labs 2002 Virus Prevalence Survey (http://www.icsalabs.com/2002avpsurvey/index.shtml), these three companies make up about 89% of the global antivirus software market share. If a new worldwide virus outbreak happens, one of these three companies is probably going to be the first to have information on it.
Microsoft has also recently started an Antivirus Information web site (http://www.microsoft.com/security/antivirus/) to provide one place for information on viruses that involve security vulnerabilities in their software or operating systems. This is also an excellent source of information for using Microsoft products to help you keep viruses from infecting your network. Microsoft also has a Knowledge Base article that lists other antivirus software vendors (http://support.microsoft.com/default.aspx?scid=kb;en- us;Q49500). For application and operating-system security vulnerabilities, I recommend signing up for the NTBugtraq mailing list (http://www.ntbugtraq.com). If a security vulnerability comes out, you can usually read it on this list before you will see it anywhere else. Other good web sites include SecurityFocus (http://www.securityfocus.com), CERT Coordination Center (http://www.cert.org), and TruSecure's ICSA Labs (http://www.icsalabs.com). I also recommend signing up for Microsoft's Security Notification Service (http://www.microsoft.com/technet/security/bulletin/notify.asp), which will notify you via email each time a security vulnerability from Microsoft is announced and will provide information if there is a fix. The complexities of viruses are increasing every day, as the Nimda and Blaster viruses have taught us all. The vulnerabilities that Nimda used to propagate were several months old when that virus went worldwide. The Blaster virus taught us this lesson again as it spread globally less than a month after the vulnerabilities it used were announced. If more administrators had been aware of those vulnerabilities, then Nimda and Blaster would not have had as big an impact as they did. The lesson to learn here is this: to win the war against viruses, awareness is
the first weapon that you should have in your arsenal. Antivirus Software The second fundamental for a virus-free network is antivirus software. Now this might seem pretty obvious; anyone who has worked in the Information Technology game long enough knows that antivirus software is essential, especially with viruses increasing in sophistication everyday. However, which features to look for in corporate antivirus software might not be quite so obvious. The following list of features are things I have identified in my experience to be most helpful in enterprise antivirus software: Certification Look for a product that has been certified for use with the operating systems you are using. ICSA Labs (http://www.icsalabs.com) is a good place to look. Easy to update One of the most important things to look for is antivirus software that makes it easy to update virus definitions. Antivirus software that requires updates to be deployed with third-party software distribution or any other means that are separate from the antivirus software's own processes can lead to logistical problems when deploying the updates, depending on the size of the network environment and the method of deployment.
Antivirus software with some kind of built-in update process is much more desirable. Also, antivirus software that has updates that require user intervention or a reboot to install can lead to similar logistical problems. A built-in, automated, and silent update delivery system will yield much better results and ensure that the software is updated properly. Frequency of updates When checking out antivirus software, take a look at the company's web site to see how often they provide updates and how they handle virus definition files in emergencies. Make sure that their policy meets the needs of your environment. Centralized configuration Antivirus software that has the ability to configure all the clients on your network from one centralized console is a lot easier to manage and helps ensure that configuration is consistent. Real-time background scanning Antivirus software that has the ability to scan files in the background, without user intervention, is essential in today's virus environment. Being able to configure which files the software scans in the background is also important.
Heuristic capability Antivirus software that has the ability to detect virus- like behavior in a file's operation could help identify new viruses and new variants of already-discovered viruses. Remote scanning capability If you have a virus incident on your hands, the ability to initiate a scan remotely on one workstation or server, and the entire network if necessary, could be what keeps your network from getting damaged due to a virus infection. Alerting capability With the speed that viruses spread these days, it is essential to have antivirus software that is able to send alerts when a computer virus is found. Without this functionality, you could have viruses hitting every workstation and server on your network and you wouldn't know about it. Support for mobile computers Not many businesses today can survive with out laptops. If at all possible, look for software that is able to handle updating computers that are constantly mobile.
Reporting capability If you work for anyone that has Manager in her title, then you are going to have to produce some kind of report on virus activity at one time or another. Help yourself out by looking for antivirus software that can create those reports for you. This list is by no means exclusive. Some of the things I have listed here might not be important to you at all, and I might not have included things that you consider important. The list of essential features depends on the networking environment you are working in and the operating systems that you have to support. Hopefully, this list will lead you in the right direction if you are considering your own needs for antivirus software. Interception The third fundamental of a virus-free network is interception. Simply put: a user can't execute a virus if the virus isn't there. In the current environment of viruses, things can change quickly. Since a large percentage of viruses in the wild propagate through email these days, a new virus can spread worldwide in a few hours under the right conditions. Depending on the virus, sometimes it takes antivirus software companies several hours to come up with virus-definition files that can contain a new worldwide threat. The best way to protect your network from new virus threats like this is to block all incoming instances of the file types that are known to propagate viruses from reaching your corporate email system. Now, some would tell you just to block certain files or certain subject lines in emails, because the thought of blocking too
much email would cause too many problems. Back when the Loveletter virus came out, this might have been a viable option. Now it is not. The sophistication of viruses has increased, and now just about everything a virus generates is random. (A good example is the W32.Klez.H@mm virus; see http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.h@mm.html The only common thread you can use is the file types that viruses themselves use. Are legitimate files going to stopped by using this method? Yes, they will. However, the rewards greatly outweigh the minor inconvenience that this method might cause your user base. In the almost three years I worked in my previous job, we stopped over 7,300 viruses. From that number, I would say that over 90% of the viruses that we stopped were volatile email attachments. On several occasions, using this method protected us from worldwide virus threats before antivirus vendors were able to provide new virus-definition files. With all of this in mind, the next thing to think about is which file types need to be blocked. A good place to start is the files that are restricted from being accessed after the Outlook 98/2000 E-Mail Security Update (http://office.microsoft.com/assistance/preview.aspx? AssetID=HA010550011033&CTT=6) has been installed (this is functionality is embedded into Office XP): .ade Microsoft Access project extension .adp
Microsoft Access project .bas Visual Basic class module .bat Batch file .chm Compiled HTML Help file .cmd Windows NT command script .com MS-DOS application .cpl Control Panel extension
.crt Security certificate .ext Application .hlp Windows Help file .hta HTML applications .inf Setup information file .ins Internet communication settings .isp Internet communication settings
.js JScript file .jse JScript encoded script file .lnk Shortcut .mdb Microsoft Access application .mde Microsoft Access MDE database .msc Microsoft common console document .msi
Windows Installer package .msp Windows Installer patch .mst Visual test source file .pcd Photo CD image .pif Shortcut to MS-DOS program .reg Registration entries .scr Screen saver
.sct Windows Script Component .shs Shell Scrap object .url Internet shortcut .vb VBScript file .vbe VBScript encoded script file .vbs VBScript script file .wsc Windows script component
.wsf Windows script file .wsh Windows Scripting Host settings file At my organization, we use a large part of this list, in addition to other files we feel could pose a potential threat in the future due to their nature. For example, we also restrict the following files: .ocx Active X control .swf Shockwave Flash object .wmv Windows Media audio/video file The way in which this policy is implemented depends on the configuration of your network and which security measures that you currently use. For an additional perspective on which file types to block, see the following section.
Blocking potentially unsafe email attachments is by no means the only security measure that you should take to protect your network from viruses. However, if you add this protection to what I have outlined here, you will have strong groundwork that could protect you from the next virus threat. Be sure to check out my column at myITforum.com (http://www.myitforum.com) for more tips on keeping your network virus-free. Interception Redux Here's another perspective (mine, Brian Rogers) on how to keep your network free of viruses by configuring your antivirus software to block certain file types. I'd like to share my own recommendations for file types that should be blocked to keep your network free of viruses. I posted this list to the AntiVirus discussion forum at myITforum.com (http://www.myitforum.com) awhile back. I compiled my list from various web sites and added a few of my own: .bas Microsoft Visual Basic class module .bat Batch file .cab
Cabinet installation file .chm Compiled HTML help file .cmd Microsoft Windows NT command script .com Microsoft MS-DOS program .cpl Control Panel extension .crt Security certificate .exe Program
.hlp Help file .hta HTML program .inf Setup Information .ins Internet Naming Service .isp Internet Communication settings .js JScript file .jse Jscript Encoded Script file
.lnk Shortcut .mde Microsoft Access MDE database .msc Microsoft Common Console document .msi Microsoft Windows Installer package .msp Microsoft Windows Installer patch .mst Microsoft Visual Test source files .pcd
Photo CD image, Microsoft Visual compiled script .pif Shortcut to MS-DOS program .reg Registration entries .scr Screen saver .sct Windows Script component .shs Shell Scrap object .shb Shell Scrap object
.url Internet shortcut .vb VBScript file .vbe VBScript Encoded script file .vbs VBScript file .wsc Windows Script Component .wsf Windows Script file .wsh Windows Script Host Settings file
Ever since we blocked attachments with these extensions, we haven't had a single virus infection via email. Chris Mosby and Brian Rogers
Hack 70 Antivirus FAQ Rod Trent of myITforum.com, shares his answers to some frequently asked questions on the subject of virus protection. As CEO of myITforum.com (http://www.myitforum.com) and author of several white papers on security topics, I frequently get questions on protecting Microsoft platforms from viruses, worms, and other threats. Here's a short selection of some questions and my answers. By the way, you can find lots of additional information about protecting your networks at myITforum.com. Is It Real or a Hoax? Q: How can you tell whether a virus threat is real or just a hoax? A: Keep the following links handy the next time a user sends you an email saying that one of their AOL buddies alerted them to a new and threatening virus. These links should be your first line of defense when a new virus is reported in the wild: CERT Institute (http://www.cert.org) McAfee's Virus Hoaxes (http://vil.mcafee.com/hoax.asp) Symantec's Hoax Page (http://www.symantec.com/avcenter/hoax.html)
TrendMicro Hoax Page (http://www.antivirus.com/vinfo/hoaxes/hoax.asp) Sophos' Hoax Page (http://www.sophos.com/virusinfo/hoaxes/) Virus Busters (http://www.itd.umich.edu/virusbusters/) Virus Myths (http://www.stiller.com/myths.htm) Hoax Warnings (http://www.europe.datafellows.com/news/hoax.htm) Disabling Antivirus Programs Is Not Enough Q: How can I disable my antivirus software temporarily when I need to troubleshoot some problem on my system? A: Occasionally, you might be forced to disable antivirus software temporarily to troubleshoot problems with applications, printing, or the OS itself. On Windows 2000 computers, just shutting down the virus engine service is not enough to disable it temporarily. You also have to disable the device drivers associated with the antivirus software. Here's how to temporarily disable popular antivirus products on Windows 2000. Right-click on My Computer and select Properties. Click the Hardware tab and click the Device Manager button. Click the View menu and click Show Hidden Devices. Now, expand Non-Plug and Play Drivers to find the Antivirus drivers on your system. Right-click on the correct driver and click Disable. Table 8-1 identifies the names of the device drivers that correspond with products from popular antivirus software vendors. Note, however, that the device drivers for each
application can change, so be sure to verify these device drivers at the appropriate vendors' web sites. Table 8-1. Device drivers for antivirus software products Vendor Device drivers Symantec symevent.sys McAfee NaiFiltr and NaiFsRec Norton NAVAP, NAVENG, and NAVEX15 Inoculan INO_FLPY and INO_Fltr Kernel32.exe Has Encountered a Problem Q: I get an error message saying that Kernel32.exe is encountering a problem. Is that a system glitch or a virus? A: If you receive error messages about Kernel32.exe encountering a problem, you need to update your antivirus program, because Kernel32.exe is not a Microsoft file (though Kernel32.DLL is). So, if you see this error message, quickly update your antivirus program and attempt to fix the virus outbreak on the computer.
This issue can occur if your computer is infected by one of the following viruses: Worm_Badtrans.b, Backdoor.G_Door, Glacier Backdoor, Win32.Badtrans.29020, W32.Badtrans.B@mm, and Win32/PWS.Badtrans.B.Worm. Stinger Tool Q: Is there a virus-removal tool that can remove multiple viruses, instead of the single tools offered by vendors? A: On the McAfee help forums, you'll find information on a removal utility called Stinger. This tool is constantly updated to include new removal information for new viruses. You can find more information about Stinger at http://forums.mcafeehelp.com/viewtopic.php?t=764, and you can download the tool from http://vil.nai.com/vil/stinger/. Rod Trent
Hack 71 Rename the Administrator and Guest Accounts Renaming the default administrator and guest accounts is a simple but effective step to help secure your machines. To enhance system security on your Windows server-based network, you should rename the administrator account. You should choose a name that does not identify it as an administrator account, to make it difficult for any unauthorized user to break into the computer or network. One of the account settings in Windows 2000/2003 allows you to enter an account name to rename the administrator and guest accounts automatically using Local Security Policy (for standalone machines in a workgroup) or Group Policy (in an Active Directory environment). To access local policy settings, click Start Run, type mmc, and press Enter. Select File Add/Remove Snap-in. Click the Add button, scroll through the list until you see Group Policy (in Windows 2000) or Group Policy Object Editor (in Windows Server 2003). Click add, then finish (the default is to manage Local Computer). Expand Local Computer Policy, Computer Configuration, Windows Settings, Security Settings, Local Policies, and Security Options. If you like, you can save this console with a familiar name to have this MMC snap-in available for future use. Once you've selected Security Options, you should see a screen similar to Figure 8-1 (if you're running
Windows Server 2003 or Windows XP). Figure 8-1. Policy settings for the default administrator and guest accounts in Windows Server 2003 and Windows XP In the pane on the right, you can see that the first five options detail policies for Accounts. The last two options in the Accounts section are used to rename the administrator account
and rename the guest account. Clicking on "Accounts: Rename administrator account" brings up the screen shown in Figure 8- 2. You will see a similar screen if you select the Guest option. Simply type whatever name you want to use and click OK. This automatically renames the administrator or guest accounts. Figure 8-2. Renaming the default Administrator account Some Considerations Note that if your machine belongs to a domain, the local policy settings you configure using the previous method might be overwritten by any Group Policy settings defined at the domain, organizational unit (OU), or site level. Windows 2000 provides only the first two Accounts policy settings and they're named differently than the settings shown in
Figure 8-2. The Windows Server 2003 setting named "Accounts: Rename administrator account" is simply named "Rename administrator account" in Windows 2000, and likewise with the Guest account policy setting. Windows XP, however, is identical to Windows Server 2003 in this regard. Finally, as a further security precaution, after you rename the accounts, you might want to add another administrator and guest account (through the User Accounts option). Once you create these accounts, give them a secure password, but give the accounts no rights to anything. Even if the administrator and guest accounts are compromised, the potential intruder will have no rights to do anything to the computer. John Gormly
Hack 72 Get a List of Local Administrators Local administrators can do anything on their machines. Here's a quick way to determine who has this power. When an intruder penetrates a network's defenses, the intruder generally tries to elevate the privileges of his account to that of local administrator on the machine. Once the intruder has achieved this, he can do anything he wants to do on the machine. So, if you think your network defenses have been penetrated, it's a good idea during the triage stage to check which accounts are local administrators on your machines. Using the GUI, this can be done using the Local Users and Groups node in Computer Management, but that is tedious. A faster way to identify individuals who have local computer administrator rights is to use the following VBScript, which you can customize further as desired. The Code Just open a text editor such as Notepad (make sure you have Word Wrap disabled), type the following code, and save it with a .vbs extension as GetAdmins.vbs:
computername = createobject("wscript.network").computername set group = getobject("WinNT://" & computername & "/administrators,group") s = "" for each account in group.members s = s & account.name & vbcrlf next msgbox s Running the Hack Running the hack is simple. Just create a shortcut to it and double-click on the shortcut. A dialog box will display which user accounts are local administrators on the machine, as shown in Figure 8-3. From this list, you can easily detect any unauthorized administrator-level accounts, such as backd00r, that might indicate that the system has been compromised by a malicious hacker. Figure 8-3. A list of local administrators on a member server
Make sure you have the latest scripting engines on the workstation from which you run this script. Download the latest scripting engines from the Microsoft Scripting home page (http://msdn.microsoft.com/library/default.asp? url=/nhp/default.asp?contentid=28001169). Note also that, when working with the Active Directory Services Interface (ADSI) you must have the same applicable rights you need to use the built-in administrative tools. Hacking the Hack The script gets the contents of the local administrators group, but you can easily alter the group information in the script to retrieve the information from any local computer group if you desire. For example, to display members of the Users group just change this line: set group = getobject("WinNT://" & computername & "/administrators,group") to this: set group = getobject("WinNT://" & computername & "/users,group")
Then, run the hack again. Rod Trent
Hack 73 Find All Computers that Are Running a Service Use this script to find rogue web servers, misconfigured clients, and other potentially insecure systems on your network. Querying the status of a service across multiple computers can be an extremely useful tool. You can check for the SMS client service, antivirus services, or even viruses/Trojans that run as a service. Under most interfaces, such as WMI or ADSI, you need to check the status of services with an account that has administrator rights on the machine you are targeting. It turns out that in many organizations there are quite a few PCs on the network that have done a phenomenal job of removing most of the IT department's administrator rights. These unmanaged PCs can be a real risk at times. One day, I noticed that when you query a remote box with the Windows 2000 services snap-in for the MMC, you do not need administrator rights to check on the services that reside on remote boxes. You simply need an account in a trusted domain with simple user-level rights. On further investigation, it was revealed that what in fact was going on was a direct query to the Service Control Manager (SCM), as opposed to some API call through WMI or ADSI. One of the best free third-party tools that also queries the SCM is Psservice from Sysinternals (http://www.sysinternals.com). Although this is strictly a command-line utility, we can tweak it with some parameters and do some fancy parsing to make efficient use of it in a script.
First, the script will search IP addresses by subnet, using a ping response, and find the Windows-based machines by parsing out a NetBIOS call. Then, it will determine if the machine is running a particular service, by querying it with Psservice, and log the results in tab-delimited format. This will retrieve the following data in the log file: IP address, computer name, currently logged-on user, domain or workgroup to which the machine is joined, and the status of the service. The IP address is included even if the node is not pingable and can be treated as a key in most cases. The computer name is resolved with a DNS lookup on the IP address and then, if a NetBIOS name is found, it is switched to that name. Note that this could be blank if both methods fail. The currently logged-on user field should display data if the machine is NetBIOS-compatible and someone is currently logged on. However, if no one is logged on, it will be blank. Note that this logon name could be a domain account or a local account; there is no way to tell. The domain (or workgroup) to which the machine is joined is the domain (or workgroup) associated with the computer account, not the user account. The status of the service can be any of seven possible values, as shown in Table 8-2. Table 8-2. Possible values for server status Status Description UnPingable The IP address does not respond RUNNING Service is running STOPPED Service is stopped
PENDING Service is starting or stopping Blank Service does not exist Your account does not have minimal user- Access is Denied level rights to the box The RPC server is Computer is running Win9x,Win 3.x, or is a unavailable Samba box There are several items you will need before the script will run. First, you need the Psservice utility that comes with the Pstools suite from Sysinternals. Place the psservice.exe utility in the same directory as the script itself. You also need to register the free System Scripting Runtime COM object from Netal (http://www.netal.com/ssr.htm). To register the COM object, copy the DLL to your system32 directory and use regsvr32 to register it. You'll need to do this for every box you run the script from, but this does not need to be done on the remote machines. By the way, I highly suggest reading through the documentation on both of these valuable pieces of software. The Code Type the following script into Notepad (with Word Wrap disabled) and save as FindNTService.vbs. Alternatively, since this is a long one, you're probably better off downloading the source from http://www.oreilly.com/catalog/winsvrhks/.
' Dennis Abbott - speckled_trout@hotmail.com ' you need to register the Scripting System Runtime from www.netal.com in ' your System32 directory on the machine you are running this script from ' first. ' You also need the utility psservice.exe from www.sysinternals.com in ' the same directory as this script and you need a text file with the ' subnets listed with a linefeed after each subnet. ' ' example of subnet listing ' ' 192.168.0.0 ' 192.168.1.0 ' 34.54.78.0 ' ' You can view the script in action by opening the log file with a ' realtime log file viewer such as SMS Trace from Mircosoft. ' 'On Error Resume Next
Option Explicit Dim Title 'used for dialog boxes as well as the log file name Dim PathToScript 'path to the directory that the script is running from Dim PathToLogFile 'full path including filename of the log file Dim WshShell 'shell object Dim WshNet 'network object Dim WshFso 'file system object Dim WshSysEnv 'environment variable object Dim ScriptNet 'System Scripting Runtime object from www.netal.com Dim ComSpec 'path to cmd.exe Dim DataFile 'file containing machine names Dim LogFile 'log file for stats Dim CompName 'name of the current remote target computer Dim User 'user logged on to remote computer Dim Domain 'domain that the remote computer is joined to Dim IP 'IP address of remote computer Dim CurLine 'used when parsing text files
Dim NbtFile 'file parsed for NetBIOS information Dim SubnetFileName 'file containing subnets to be searched Dim I 'counter Dim SysFolder 'the system folder Dim TimeOut 'timeout in milliseconds for ping Dim Go 'gives user option to quit Dim ServiceToCheck 'name of the service to look for--NOT THE DISPLAY NAME Dim EditSubnets 'give user option of editing subnet file Dim File 'File object Dim Subnet 'current subnet being searched Dim Service 'Status of the service Dim ServFile 'file parsed for the service information Set WshShell = CreateObject("WScript.Shell") Set WshFso = CreateObject("Scripting.FileSystemObject") Set WshNet = CreateObject("WScript.Network") Set ScriptNet = CreateObject("SScripting.IPNetwork")
SysFolder = WshFso.GetSpecialFolder(1) PathToScript = Left(WScript.ScriptFullName, & _ (Len(WScript.ScriptFullName) - (Len(WScript.ScriptName) + 1))) Title = "FindNTService" Set WshSysEnv = WshShell.Environment("SYSTEM") ComSpec = WshSysEnv("COMSPEC") Timeout = 125 'collect input Go = MsgBox("This utility will search the network by subnet to find " & _ "all machines running a particular service." & vbcrlf & _ "To do this you must supply a text file with the subnets and the name of " & _ "the service." & vbcrlf & vbcrlf & "Do you wish to continue?",vbyesno,Title) Select Case Go Case VbYes Case VbNo Wscript.Quit(0) End Select
If WshFso.FileExists(PathToScript & "\psservice.exe") <> True Then MsgBox "The PSSERVICE utility does not exist....GOODBYE" & vbcrlf & _ "You can get PSSERVICE from www.sysinternals.com",vbok + vbcritical, _ Title Wscript.Quit(0) End If If WshFso.FileExists(SysFolder & "\sscrrun.dll") <> True Then MsgBox "The sscrrun.dll does not exist....GOODBYE" & vbcrlf & "You can get sscrrun.dll from www.netal.com",vbok + vbcritical, Title Wscript.Quit(0) End If ServiceToCheck = InputBox("enter the service name(not display name) that " & _ "you want to search for.",Title,"w3svc") If ServiceToCheck = "" Then MsgBox "you did not enter a service name....GOODBYE",vbok + vbcritical, Title Wscript.Quit(0) End If SubnetFileName = InputBox("enter the path to the file that contains " & _ "the subnets.",Title,PathToScript & "\subnets.txt")
If WshFso.FileExists(SubnetFileName) <> True Then MsgBox "The subnet file does not exist....GOODBYE", _ vbok + vbcritical, Title Wscript.Quit(0) End If EditSubnets = MsgBox("Do you want to edit the subnets file?",vbyesno,Title) Select Case EditSubnets Case vbyes WshShell.Run "notepad " & SubnetFileName,1,True Case vbno End Select PathToLogFile = PathToScript & "" & Title & "" & Month(Now) & "" & Day(Now) & "" & Year(Now) & "-" & Hour(Now) & "" & Minute(Now) & ".log" Set LogFile = WshFso.CreateTextFile(PathToLogFile) Set File = WshFso.GetFile(SubnetFileName) Set DataFile = File.OpenAsTextStream(1,0)
LogFile.WriteLine "IPaddress" & vbtab & "ComputerName" & vbtab & _ "LoginName" & vbtab & "Domain" & vbtab & "Status" Do While Not DataFile.AtEndOfStream Subnet = DataFile.ReadLine LogFile.WriteLine subnet & vbtab & vbtab & vbtab & vbtab & _ "beginning subnet " & Now Discover(subnet) Loop MsgBox Title & " script is done. The log file is located here." & _ vbcrlf & PathToLogFile Function Discover(boundary) Subnet = Left(boundary,InstrRev(boundary,".")) For i = 1 to 254 IP = subnet & i CompName = Null User = Null
Domain = Null Curline = Null Service = Null If ScriptNet.Ping(ip,,,Timeout) <> 0 Then LogFile.WriteLine IP & vbtab & vbtab & vbtab & vbtab _ & "UnPingableClient" Else CompName = ScriptNet.DNSlookup(IP) If InStr(CompName,".") <> 0 Then CompName = Left(CompName,InStr(CompName,".")-1) End If Call GetNBTstat(IP,User,Domain) Call GetService(IP, Service) Call WriteToLog(IP,CompName,User,Domain,Service) End If Next End Function
Function GetNBTstat(IP,User,Domain) WshShell.Run ComSpec & " /c nbtstat -a " & IP & " >" & PathToScript & _ "\nbt.txt",6,True Set NbtFile = WshFso.OpenTextFile(PathToScript & "\nbt.txt", 1, True) Do While NbtFile.AtEndOfStream <> True CurLine = NbtFile.ReadLine If InStr(CurLine,"---") <> 0 Then CurLine = NbtFile.ReadLine CompName = Trim(Left(CurLine,InStr(CurLine,"<")-1)) End If If InStr(CurLine,"<03>") <> 0 Then If Trim(Left(CurLine,InStr(CurLine,"<03>")-1)) <> _ UCase(CompName) and Trim(Left(CurLine,InStr(CurLine,"<03>")-1)) <> _ UCase(CompName) & "$" Then User = Trim(Left(CurLine,InStr(CurLine,"<03>")-1)) End If End If
If InStr(CurLine,"<1E>") <> 0 Then If Trim(Left(CurLine,InStr(CurLine,"<1E>")-1)) <> _ UCase(CompName) and Trim(Left(CurLine,InStr(CurLine,"<1E>")-1)) <> _ UCase(CompName) & "$" Then Domain = Trim(Left(CurLine,InStr(CurLine,"<1E>")-1)) End If End If Loop NbtFile.Close End Function Function GetService(IP,Service) If CompName <> "" and User <> "" or Domain <> "" Then WshShell.Run ComSpec & " /c " & PathToScript & "\psservice \" _ & IP & " query " & Chr(34) & ServiceToCheck & Chr(34) & " >" _ & PathToScript & "\service.txt",6,True Set ServFile = WshFso.OpenTextFile(PathToScript _
& "\service.txt", 1, True) Do While ServFile.AtEndOfStream <> True CurLine = ServFile.ReadLine If InStr(CurLine,"STATE") <> 0 Then Service = Trim(Right(CurLine,InStr(CurLine," ")-1)) End If If InStr(CurLine,"RPC") <> 0 Then Service = CurLine End If If InStr(CurLine,"Access") <> 0 Then Service = CurLine End If If InStr(CurLine,"function") <> 0 Then Service = CurLine End If If InStr(CurLine,"Unable") <> 0 Then Service = CurLine End If
Loop If InStr(Service,vbcr) <> 0 Then Service = Left(Service,InStr(Service,vbcr)-1) End If End If End Function Function WriteToLog(IP,CompName,User,Domain,Service) If IP <> "" Then LogFile.Write IP End If LogFile.Write vbtab If CompName <> "" Then LogFile.Write CompName End If LogFile.Write vbtab If User <> "" Then
LogFile.Write User End If LogFile.Write vbtab If Domain <> "" Then LogFile.Write Domain End If LogFile.Write vbtab If Service <> "" Then LogFile.Write Service End If LogFile.WriteLine End Function Running the Hack First, create a text file that contains the subnets you wish to query. Each subnet should end with .0 and be on its own line in the file. You can name the file subnets.txt and save it in the same directory as the script. Now, simply run the script by double- clicking on it; it will prompt you for input. The first input is just an introduction to the script. Clicking No will exit the script altogether.
The next input is the name of the service; this is not the same as the display name, so be careful here. Table 8-3 shows some examples of services for which the display name differs greatly from the service name. This information can help you detect rogue web servers running secretly on your network, client machines whose antivirus software has been disabled, or machines with SMS client software disabled, making them difficult to keep updated with security patches and service packs. Table 8-3. Display names and corresponding service names Display name Service name World Wide Web Publishing Service w3svc Norton Antivirus Client Norton Antivirus Server SMS Client Service clisvc The next prompt is the full path to the text file that contains the subnets. At this point, you can enter a different text file if you wish. Lastly, you have the opportunity to modify the subnets file before you begin. The scan will begin either after you click No or after you close Notepad. You will be notified when the script is finished with a pointer to the log file; there is no progress indicator as the script runs. If you need to cancel the script, go into Task Manager and kill the wscript.exe process.
I have used this script to find machines on which the SMS Client Service has been disabled. I have also found numerous IIS web servers and their owners. Lastly, this utility does a great job of finding the FLC service, which is better known as the FunLove virus. I get a big kick out of sending directors a list of developer machines that have FunLove on their box, have also disabled SMS, and are not running antivirus software. Always deploy this script in a lab environment first and do your own benchmarking before pinging those 32,000 nodes. Dennis Abbott
Hack 74 Grant Administrative Access to a Domain Controller Here's a hack that will help you secure any domain controllers you have running at a remote site. Active Directory has introduced many new levels of complexity to server and security management. For example, if you would like to grant a remote site administrator the rights to install software or services on a domain controller, that person would have to be a domain administrator. Granting that person domain administrator rights introduces the possibility of that user creating new accounts with administrative rights. Obviously, this is not an ideal situation. The following steps show how to grant a user the same level of rights as an administrator of a member server or a workstation on a domain controller, while preventing that user from having rights to Active Directory. Please note that this hack does not eliminate all possible security risks, and the users who are granted these rights need to be highly trusted
- Log onto a domain controller with full domain administrator rights. Make sure your Active Directory domain is in native mode. Inside of Active Directory Users and Computers, create a global security group called DCAdmins. Add all users/groups that will need administrative access to the domain controllers to this group. Create another global security group called DenyDCAdmins. Add the DCAdmins group to the DenyDCAdmins group. Inside of Active Directory Users and Computers, right-click on the domain name and choose Properties. Click on the Security tab (if the Security tab is not available, go to the View menu and choose Advanced). Click on Add and choose the DenyDCAdmins group. Once the group has been selected, click on the Deny checkbox next to Full Control in the Permissions area, as shown in Figure 8-4. Figure 8-4. Denying Full Control permission for the DenyDCAdmins global group
Now, all users or groups that are members of the DCAdmins group have full administrative access to all domain controllers but do not have any access to Active Directory.
These users won't even be able to browse Active Directory to apply permissions on shares or files. It is generally a best practice for these users to have two accounts: one for administering the domain controllers and another for day-to- day use. Overall, this is a great approach to limit security for remote administrators and operations teams that need to be able to make changes on domain controllers. I highly recommend trying this approach before blanketing your Active Directory environment with unnecessary domain administrators. Tim Mintner
Hack 75 Secure Backups Protect critical business information by restricting who can back up and restore it. In a small organization, a single administrator might be responsible for backing up and restoring data stored on servers. In a large enterprise, however, it's more likely that administrative responsibilities will be delegated among various groups. Windows 2000 and Windows Server 2003 include special built-in groups for such purposes, but we'll also see how creating custom groups can give you even greater control over who can back up and restore your data. Using Backup Operators There are actually two different Backup Operators groups in Windows 2000 and Windows Server 2003: a local group and a domain local group. What's the difference between local and domain local groups? Local groups are defined in the SAM database on a member server or workstation, while domain local groups are stored in Active Directory on domain controllers. As a result, member servers and workstations have a built-in local group named Backup Operators, and membership of this group is modified by using Local Users and Groups in the Computer Management console.
By contrast, domain controllers have a built-in domain local group also named Backup Operators, and membership in the group is modified using the Active Directory Users and Groups (ADUC) console (the group is located within the Built-in container for each domain). In the GUI, the domain local Backup Operators group is actually labeled as "Built-in local" instead of "Built-in domain local." This is an error in the GUI. So, what exactly can members of the Backup Operators group do? First, they can back up any file or folder on the server on which the group resides. This means that if you belong to the Backup Operators group on a member server, you can back up and restore files on that member server (and only that member server). But if you belong to the Backup Operators group on a domain controller, you can back up and restore files on any server in the domain. Backup Operators can also perform certain other tasks, such as interactively logging on to the console of the server and shutting the server down. And members of the built-in Server Operators group can do everything Backup Operators can, in addition to being able to create and manage shared folders and printers. So, who belongs to the Backup Operators group? By default, nobody. The idea is that these users have a powerful abilityto make copies of sensitive business data and restore these copies to another machineso you should think carefully before
you make anyone a member of this group. How do Backup Operators get these abilities? By the user rights assigned to them. User rights indicate authorization or privilege to perform some task and are assigned by using Group Policy (in an Active Directory environment) or Local Security Policy (on standalone servers in a workgroup). In a Group Policy Object (GPO), user rights are found under Computer Configuration Windows Settings Security Settings Local Policies User Rights Assignment (see Figure 8-5). Figure 8-5. User rights displayed in Group Policy
By default both the Backup Operators and Administrators built- in groups are assigned the following user rights: Back up files and directories Restore files and directories Again, on a domain controller, the Server Operators group also
has these rights by default. What's interesting about these two privileges is that they override any NTFS permissions that files and directories might have. Thus, even if the Backup Operators group is explicitly denied Read permission to a folder, members of this group can still back up the folder and its contents. In other words, user rights take precedence over permissions. Mind you, there is a hack that enables a user to back up files and folders on a machine without assigning them the preceding rights. The trick is to assign them, at a minimum, the following special NTFS permissions on the file or folder: Traverse folder/execute file List folder/read data Read attributes Read extended attributes Read permissions You might use this method to grant a user the ability to back up copies of sensitive documents to a local folder on his workstation. By assigning these permissions, users can back up the contents of the folder but can't read the files stored in it. The rational for using this approach, instead of assigning the necessary rights to the user, is that for security reasons you might want to ensure that the user has as few rights as possible, in case the user's account is compromised by an intruder. In
other words, though this approach is more complicated, it can help guard against elevation of privilege attacks. Restricting Access to Backups A company's disaster recovery plan often overlooks the fact that those who perform backups shouldn't necessarily be the ones who restore from backups when things go wrong. That's because performing a backup is a routine administrative task that should be done regularly and delegated to some responsible user, but restoring a backup can actually provide the user with access to the backed-up data itself. For example, by restoring a backup job to a rogue server on the network and then running cracking tools locally on the server, the user could gain access to sensitive data and compromise the company's business. The solution is to ignore the built-in Backup Operators group and create two new security groups instead. For instance, you might name them something mundane, like Backup Group and Restore Group, or something more creative if you prefer. Then, assign the right to "Back up files and directories" to Backup Group and "Restore files and directories" to Restore Group. Don't assign any other rights to these two groups. Now, assign selected users to each group as desired. Typically, the membership of Backup Group is be more inclusive than Restore Group and should include both junior administrators (who have actual responsibility for day-to-day backups) and senior administrators (who can be there in a pinch if things go wrong). Of course, the junior administrators should not be members of the default Domain Admins group; if they are, they will automatically have the "Restore files and directories" privilege as well.
The Restore Group, however, should have only senior administratorsthe most trusted members of your IT departmentas members. Whether or not they are all domain administrators is another question; best practice suggests that membership in Domain Admins should be as highly restricted as possible, and potential members of this group should be carefully screened during your company's hiring process. If you think one bad apple spoils the bunch, wait till you see what one corrupt administrator can do to your business! If you assign the "Back up files and directories" right to a group and then find that a user who belongs to this group has difficulty backing up one or more volumes, check the disk quota restrictions on those volumes to ensure they aren't restricting the user from accessing those volumes. Another approach you can use to secure your backups is to take advantage of a setting available on the Backup Job Information dialog box (see Figure 8-6). This dialog box appears after you start the Backup utility, select the volumes or folders you want to back up, and click the Start Backup button. By selecting the checkbox labeled "Allow only the owner and the Administrator access to the backup data," you configure permissions on the backup job so that only the individual who created the backup and the default administrator account can restore the backup.
Figure 8-6. Allowing only the backup owner and administrator to restore the backup While this approach is easier than the approach I described earlier, it doesn't provide the same level of security as separating those who can restore data from those who back it up. Also, you can enable this setting only if you are backing up to a new tape or overwriting an old one; if you're appending your backup set to an existing tape, the setting is not available. In other words, the restriction offered by this setting is applied on a tape-by-tape basis, not a job-by-job basis. So, the lesser degree of security offered by this approach, coupled with its lack of flexibility, leads me to suggest you avoid using this setting and instead use the two-group approach I described previously.
Hack 76 Find Computers with Automatic logon Enabled Having automatic logon enabled on a computer can be a security risk. Here's a quick way to find out which machines on your network have automatic logon enabled. While enabling automatic logon [Hack #4] in Chapter 1 can be useful in certain scenarios, such as a test network, it can also be a security risk, especially if it is enabled on a computer without the administrator's knowledge. Here is a quick and dirty way to locate all machines that have automatic logon enabled in their Registry. You'll need the following tools: The regfind.exe utility, which is available from the Windows NT/2000 resource kits. A list of machines to search, which can be obtained in many different ways (including an SMS report, server manager, etc.). The list should be a plain text file named serverlist.txt in the following format: server1
server2
server3
server4
etc...
A user account that has administrative rights to the
Registry on the machines being queried. Typically, a
domain administrator account will work just fine.
Create a batch file that will use the provided list and kick off
regfind. For this we will use the FOR DOS command (all on one
linetext is wrapped here to fit the constraints of the page):
for /F %%A in (serverlist.txt) do (regfind.exe -m \%%A -p "hkey_local_machine\software
microsoft\windows nt\currentversion\winlogon" -n "Autoadminlogon" >results.txt)
You can see that we are simply parsing the serverlist.txt file for
each server name, then instructing regfind to locate that
Registry key. There are two caveats, though. First, the results
can be hard to read while the search is going on. It is
recommended that you pipe the results to a text file (the
preceding example does this). Second, regfind is case-
sensitive. This can make the search a bit longer, but it's still
fairly easy. Instead of just a one-line batch file, you simply have
a few more (almost identical) lines. A larger sample of the
completed batch file looks something like this (again, all on one
linebeware of line wrap):
for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \%%A
-p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n "Autoadminlogon" >results.txt) for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \%%A -p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n "AutoadminLogon" >results.txt) for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \%%A -p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n "AutoAdminlogon" >results.txt) for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \%%A -p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n "AutoAdminLogon" >results.txt) for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \%%A -p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n "autoAdminlogon" >results.txt) for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \%%A -p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n "autoadminlogon" >results.txt)
for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \%%A -p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n "autoAdminLogon" >results.txt) for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \%%A -p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n "autoadminLogon" >results.txt) Using this method, you can scan a select list of workstations/servers for this key fairly quickly. Hacking the Hack This procedure can easily be modified to find out other Registry keys as well, simply by changing the key name to search for. Enjoy! Donnie Taylor
Hack 77 Security FAQ Rod Trent, CEO of myITforum.com, shares his answers to common security questions. At myITforum.com (http://www.myitforum.com), we often get questions regarding general network-security issues, and I try to answer them in the form of a Security FAQ. Here's a short selection of the most common questions we receive, along with my responses. You can find more security tips at myITforum.com. Steps to Computer Security What can I do to make sure my computer is secure? It depends on whether you are a consumer or a business. Consumers Consumers should start by using an Internet firewall on all PCs and laptops. An Internet firewall can help prevent outsiders from getting to your computer through the Internet. If you use Windows XP, enable the built-in firewall feature on that platform.
You should also update your computer regularly, either by using the Automatic Updates feature or by regularly visiting the Windows Update web site to download the latest Microsoft security updates. Also, make sure your antivirus software is up- to-date; installing, configuring and maintaining your antivirus software is absolutely essential. Businesses Businesses should follow a similar but more involved procedure. Start by verifying the configuration of your firewalls for both Internet and intranet. By auditing your firewall configurations, you ensure they comply with your company's security policy. Firewalls are your first line of defense, and best practice requires blocking all ports that are not actually being used by applications on your network. Business should also protect their networks by requiring employees to follow the precautions outlined by Microsoft (http://www.microsoft.com/protect/) on both their home PCs and laptops, especially if they use these machines to connect to your enterprise. PCs and laptops that VPN or RAS into your network must be protected by a properly configured firewall. Businesses must also keep their systems up-to-date with the latest security patches from Microsoft. To do so, subscribe to Microsoft's free security notification service and use Microsoft update services to automatically obtain patches for your network, see [Hack #78] for more information. Finally, business should invest in antivirus software, because such protection is absolutely essential for keeping sensitive business data safe from attackers.
Vulnerability Types Q: What are the vulnerability types that I need to monitor against? A: There are three basic types of vulnerability: Administrative vulnerability The failure to observe administrative best practices, such as using a weak password or logging onto an account that has more user rights than the user requires to perform a specific task. Product vulnerability A security-related bug in a product that is addressed by a security bulletin/hotfix or a service pack. Physical vulnerability The failure to provide physical security for a computer. Physical vulnerability can include leaving an unlocked workstation running in an area that is accessible to unauthorized users, leaving a server room unlocked or open, or losing a laptop or leaving it at a customer site. Strong Password Policy
Q: What is the best practice to follow when creating policies for user passwords? A: Each company's security-level needs are different, but in general, strong passwords should be at least six characters long, should not contain all or part of the user's account name, and should contains at least three of the four following categories of characters: uppercase letters, lowercase letters, Base 10 digits, and nonalphanumeric symbols found on the keyboard, such as !, @, and #. How Microsoft Handles Security Q: Is there any documentation on how Microsoft handles security against worms and viruses? A: Yes. Microsoft has released a "Security at Microsoft" white paper on how they handle security issues (http://www.microsoft.com/downloads/details.aspx? FamilyID=73f1ba8e-a15c-4c05-be87-8d21b1372485). This paper describes what Microsoft's Corporate Security Group does to prevent malicious or unauthorized use of digital assets at Microsoft. This asset protection takes place through a formal risk-management framework, risk-management processes, and clear organizational roles and responsibilities. The basis of the approach is recognition that risk is an inherent part of any environment and that risk should be proactively managed. The principles and techniques described in Microsoft's white paper can be employed to manage risk at any organization. Reporting Security Incidents to Microsoft
Q: How can I report a security incident or vulnerability to Microsoft? A: If you have purchased Microsoft support, you should contact your Technical Account Manager (TAM). You can also use the web form at https://s.microsoft.com/technet/security/bulletin/alertus.asp to submit incidents and vulnerabilities. Reporting Security Incidents to Government Authorities Q: We've just had a security incident. Who can I call to report it? A: The FBI encourages the public to report any suspected violations of U.S. federal law. Never think that your security incident is insignificant. Your incident might be part of a larger attack or the beginning of a larger attack. You can find your local FBI Field Division information at http://www.fbi.gov/contact/fo/fo.htm. Getting Government Security Clearance Q: How can you apply for security clearance for a government job? A: In our daily newsletter at myITforum.com (http://www.myitforum.com/newsletter.asp), we sometimes post open positions for jobs in the government sector that require special security clearance before applying. Several folks have wondered what it takes to get the security clearance, and a list of good tidbits of information were posted to the myITforum.com
Off-Topic list (http://www.topica.com/lists/myOTforum/). Here are some additional places you can find information on government security clearance: FBI Information Sheet: http://www.fbi.gov/clearance/securityclearance.htm Security Clearance for IT Pros: http://www.jobcircle.com/career/coach/jf_2002_09.html Security Clearances: http://www.taonline.com/securityclearances/ Rod Trent
Hack 78 Microsoft Security Tools Here's a quick guide to various tools from Microsoft to help secure your systems against attack. This list represents my personal take on the wide variety of security tools currently offered by Microsoft. It includes tools for security assessment, patch management, security scanning, system updating, lockdown, auditing, intrusion detection, virus protection, and system cleaning. There's also a brief list of RFCs that every security professional (including those who work with platforms other than Windows) should become familiar with. I plan to update this list at myITforum.com (http://www.myitforum.com) as new items become available. If you have any suggestions to add to the list, drop me a note at myITforum@cinci.rr.com. Assessment, Patch Management, and Software Update Services and Tools The Microsoft Baseline Security Analyzer (MBSA) (http://www.microsoft.com/technet/security/tools/Tools/mbsahome.asp is a popular security tool that scans single systems or multiple systems across a network for common system misconfigurations and missing security updates.
Software Update Services (SUS) (http://www.microsoft.com/windowsserversystem/sus/default.mspx simplifies the process of keeping Windows-based systems up- to-date with the latest critical updates. See [Hack #89] in Chapter 9 for tips on using this tool. QChain (http://support.microsoft.com/default.aspx? scid=KB;EN-US;296861) allows administrators to script the installation of several patches without requiring multiple reboots. To use this tool, you create a batch file to update your security configuration with hotfixes. Note that QChain is not required if you are running Windows 2000 Service Pack 3 or later, or more recent versions of Windows, such as XP and 2003. Finally, the KB 824146 Scanning Tool (http://support.microsoft.com/default.aspx?scid=kb;en- us;827363) can be used to identify computers on networks that do not have the 823980 (MS03-026) and the 824146 (MS03- 039) security patches installed. Automatic Scan and Update Tools for Windows and Office To keep your operating system up-to-date with patches, use the Windows Update web site (http://windowsupdate.microsoft.com), which scans your computer and provides a selection of updates tailored for your operating system, software, and hardware. For updating Microsoft Office products, use the Microsoft Office Product Updates web site (http://office.microsoft.com/officeupdate/default.aspx).
Lockdown, Auditing, and Intrusion Detection Tools The IIS Web Server Lockdown Wizard (http://www.microsoft.com/technet/security/tools/tools/locktool.asp works by reducing the attack surface of Internet Information Services and includes URLScan to provide multiple layers of protection against attackers. Note that this tool is designed only for IIS 5 (Windows 2000); because IIS 6 (Windows Server 2003) has this functionality built into it, a download isn't necessary for that platform. The UrlScan Security Tool (http://www.microsoft.com/technet/security/tools/tools/URLScan.asp helps prevent potentially harmful HTTP requests from reaching IIS web servers. This tool also is designed mainly for IIS 5, because much (but not all) of the functionality of UrlScan is built into IIS 6. EventCombMT is available as part of the Security Guide Scripts Download (http://www.microsoft.com/downloads/details.aspx? FamilyID=9989D151-5C55-4BD3-A9D2-B95A15C73E92). This multithreaded tool parses event logs from many servers at the same time, which is highly useful for monitoring your event logs for signs of intrusion. The Cipher Security Tool for Windows 2000 (http://www.microsoft.com/technet/security/tools/tools/cipher.asp permanently overwrites deleted data on hard drives. It's basically a replacement for the cipher command used to manage the Encrypting File System (EFS) from the command line.
Virus Protection and Cleaner Tools The Office 2000 Update Service Pack 3 (http://www.microsoft.com/downloads/details.aspx? FamilyID=5C011C70-47D0-4306-9FA4-8E92D36332FE) includes the Outlook 2000 SR1 E-mail Security Update (OESU), which prevents users from accessing several potentially dangerous file types when sent as email attachments. It also increases the default security zone settings within Outlook. The SQL Server 2000 Security Tools (http://www.microsoft.com/downloads/details.aspx? FamilyId=9552D43B-04EB-4AF9-9E24-6CDE4D933600) can help you determine whether your computer or environment is vulnerable to the Slammer worm. Top Security RFCs Finally, here are some Request For Comment (RFC) documents that every security professional should become familiar with. These RFCs apply to any enterprise networking environmentpure Microsoft, mixed Windows/Unix, or pure Unix: RFC 2196 Site Security Handbook (ftp://ftp.rfc-editor.org/in- notes/rfc2196.txt) Describes how to develop security policies and procedures for sites connected to the Internet
RFC 2504 Users' Security Handbook (ftp://ftp.rfc-editor.org/in- notes/rfc2504.txt) Similar to the Site Security Handbook, but designed for users. RFC 2350 Expectations for Computer Security Incident Response (ftp://ftp.rfc-editor.org/in-notes/rfc2350.txt) Describes expectations for computer security incident response teams. These RFCs are also worth skimming through: RFC2828 Internet Security Glossary (ftp://ftp.rfc-editor.org/in- notes/rfc2828.txt) A glossary of security terms and abbreviations RFC 2577 FTP Security Considerations (ftp://ftp.rfc- editor.org/in-notes/rfc2577.txt) A collection of tips on how to implement FTP servers securely RFC 3013 Recommended Internet Service Provider Security Services and Procedures (ftp://ftp.rfc-editor.org/in- notes/rfc3013.txt) Describes expectations of security for ISPs
Rod Trent and Mitch Tulloch
Chapter 9. Patch Management Hacks #79-89 Section 79. Best Practices for Patch Management Section 80. Beginners Guide to Enterprise Patch Management Section 81. Patch-Management FAQ Section 82. Enumerate Installed Hotfixes Section 83. Apply Patches in the Correct Order Section 84. Windows Update FAQ Section 85. Obtain Updates via the Windows Update Catalog Section 86. Use Automatic Updates Effectively Section 87. Use Group Policy to Configure Automatic Updates Section 88. Automatic Updates FAQ Section 89. Software Update Services FAQ
Hacks #79-89 Patch management is a way of life for system administrators nowadays. With the proliferation of Internet worms and other threats, new patches are being released for Windows platforms on an almost weekly basis. Testing these patches and deploying them on production systems takes time and energy. Occasionally, something goes wrong and a patch designed to correct one problem actually creates another. The first key to effective patch management is proper business practices: test, deploy, and verify. The second key is proper tools. Windows 2000 Windows Server 2003 come with built-in several tools, while others can be obtained from Microsoft's web site and third-party vendors. The third key is knowledgeknowing how patch-management tools work and how to troubleshoot them when things go wrong. The hacks in this chapter touch on all three keys to effective patch management and help enlarge your understanding and skills in this crucial area of a system administrator's job description.
Hack 79 Best Practices for Patch Management By understanding the different kinds of patches and following a simple regime, you can keep your critical systems free from known vulnerabilities. Patch management is probably the biggest concern of IT departments these days. With new vulnerabilities being discovered almost every week, keeping systems up-to-date with patches is often a full-time job, especially in large enterprises. In addition, the lag time between when a vulnerability is discovered and when a virus or worm appears in the wild is now measured in weeks rather than months. This puts tremendous pressure on vendors to release patches before they've even been fully regression-tested. The result is that sometimes patches fix the problem they're designed to address but break something else unintentionally in the process. Customers often blame vendors in such circumstances but, let's face it, there's a war going on and, like most wars, it's messy. Patch Flavors Before you plan a patch-management strategy, it's important to understand the differences between the various different flavors of patches. Microsoft classifies patches into three basic
categories: hotfixes, roll-ups, and service packs. Hotfixes Hotfixes are small patches designed to fix a single problem and are developed either in response to a security advisory or by customer request. Hotfixes are typically issued either to plug security holes, such as buffer overflows, or to fix features that don't behave as intended. Not all patches are created equal; hotfixes that address broken functionality are developed by Quick Fix Engineering (QFE) teams at Microsoft Product Support Services (PSS), whereas those that address security vulnerabilities are identified and developed by the Microsoft Security Resource Center (MSRC). Roll-ups Occasionally, Microsoft combines several hotfixes together into a single package called a roll-up. This is typically done when several security issues have been identified within a short time interval, and its purpose is to simplify the job of installing hotfixes for administrators. Unfortunately, this is not always a good idea. There have been instances in which installing multiple patches broke applications, and the headache then arises: figuring out which patch in the roll-up actually caused the problem.
Service packs At pretty regular intervals, Microsoft combines all hotfixes issued for a platform into a single package called a service pack. These service packs are cumulativefor instance, Service Pack 3 includes all hotfixes issued both before and since Service Pack 2 appeared. While service packs undergo more thorough testing than individual hotfixes, there have nevertheless been a few instances in which a service pack caused new problems while solving others. MSRC Ratings System Hotfixes that address security vulnerabilities are also called security fixes, and the MSRC rates these according to a four- point scale from high to low. This is a useful scheme for administrators, because it allows them to decide which fixes should be applied as soon as possible and which can be deferred until later or even ignored. The ratings also refer to the types of vulnerabilities they guard against. An example of a critical issue might be a self-propagating Internet worm that can bring servers to their knees and wreak other kinds of havoc, while important means that your confidential business information might be at risk of being lost, stolen, or corrupted. Moderate means you have a properly configured firewall and are following good security practices, so you won't likely to be affected by this problem, though it's still possible. Finally, low means it would take a combination of a genius hacker and a totally negligent system administrator for this exploit to occur (but it's still remotely possible).
Strategies for Patch Management My own strategy for effective patch management can be summarized as Policy, Process, Persistence (PPP). Let me unravel this, along with some helpful recommendations from Microsoft. Policy The first step in developing a patch management strategy is to develop a policy that outlines the who, what, how, when, and why of patching your systems. That takes planning, and with administrators being as busy as they are these days, it's difficult to allocate time for proper planning. Still, planning is essential. My view is that the difference between planning and an ad hoc fix-it-when-it's-broke approach is the difference between peace of mind and success, and constant anxiety and a disaster waiting to happen. It all boils down to being proactive instead of reactive. Proactive management anticipates problems in advance and develops policies to deal with them; reactive management adds layer upon layer of hastily thought-up solutions patched together using bits of string and glue. It's easy to see which approach will unravel in the event of a crisis. Once you have a patch-management policy in place (usually it's part of your overall security policy) and a notification arrives of a critical vulnerability in some product, you immediately know who will deal with it, which tools will be used to deploy the patch, whether it needs to be done sooner or later, and so on. For example, a simple element of a patch- management policy might be that critical or important patches should be applied immediately, while moderate or low patches
should be submitted to a team member for further study. Another example is proactively scheduling a specific day of the week or month for installing patches (usually weekends, in case something breaks), as opposed to the drop-everything, the-sky- is-falling approach common in a reactive environment. Making a decision tree that addresses these issues ahead of time reduces anxiety and speeds response when the time comes to patch something. Process The detailed procedure you will use to respond to vulnerabilities and deploy patches should be explicit within your security policy. In this regard, we have some help from Microsoft, which recommends following a six-step process.
- Notification Information comes to you about a vulnerability, including a patch meant to eliminate it. Notification might be sent via email from the Microsoft Security Notification Service, a pop-up balloon when you're using Automatic Updates, a message displayed in the Software Update Services (SUS) web console, or some other method. It all depends on which tools you use to keep your systems patched and up-to-date (we'll summarize these tools in a moment).
- Assessment
Based on the patch rating and the configuration of your systems, you need to decide which systems need the patch and how quickly they need to be patched to prevent an exploit. Obviously, having an accurate inventory of systems and applications running on your network is essential if you want to keep your network secure against intrusion. 3. Obtainment How you get the patch you need depends on which patch-management tools you choose to deploy. In general, such tools range from completely manual (e.g., visiting the Windows Update web site) to almost entirely automatic (e.g., via Automatic Updates or SUS). Like everything in security, there is a tradeoff: the manual approach is slower, but it gives you more control. 4. Testing Testing should always take place before you apply patches to production systems. Test your patches on a testbed network that simulates your production network. Remember that Microsoft can't test all possible effects of a patch before releasing it, because there are thousands of applications that can run on servers and millions of combinations of applications. So, make sure you test patches before deploying them, especially if you have custom code running on your machines. If you need a way to justify the cost of purchasing duplicate equipment for a testbed network, tell the boss it's like insurance.
- Deployment Deploy a patch only after you've thoroughly tested it. You are then ready to apply it, but do so carefully. Don't apply it to all your systems at once, just in case your testing process missed something. A good approach is to apply patches one at a time, testing your production servers after each patch is applied to make sure applications still function properly. That's the problem with security roll-ups: by combining several fixes into a single package, the probability of a patch going wrong and breaking something is multiplied. Again, it's a tradeoff: roll-ups speed up patch deployment but give you less control over the result. Fortunately, even a tool like Automatic Updates can be hacked to apply one patch at a time [Hack #86].
- Validation This final step in the process is often forgotten: making sure that the patch has actually been installed on the targeted systems. Fortunately, there are tools available to scan your network to see whether your systems are properly patched by looking for changes in the server's filesystem and Registry to verify that a patch has been installed properly (see [Hack #80]) As far as notification is concerned, never install a patch that is attached to an email message purportedly sent to you by Microsoft. Microsoft doesn't send out
patches by email (it sends out notification bulletins only). Such attachments are most likely spam or possibly even viruses, so don't open them! Persistence Policies are useless and processes are futile unless you persist in applying them consistently. Network security requires constant vigilance, not just because of the new vulnerabilities and patches that appear almost daily, but also because new tools are constantly being developed to handle the growing problem of keeping systems patched. At the time of this writing, Microsoft's whole patch-management strategy is in a state of flux. So, we are on the horns of a dilemma. If you assert that Microsoft is responsible for ensuring that Windows systems are patched and up-to-date, then you should agree that Microsoft should have the right to package their products with automatic patching turned-on, so that patches are downloaded and installed automatically whether or not administrators want them. However, most administrators won't agree to this, because they want to maintain control and don't trust Microsoft. In that case, you should agree that the administrators who deploy and configure Windows systems should be considered responsible
for keeping them patched properly. Unfortunately, incidents like the Slammer worm, which propagated using unpatched Microsoft SQL 2000 servers, clearly indicate that not all administrators act responsible when it comes to keeping their systems up-to-date with patches. To be fair, though, poorly patched systems are not always the fault of administrators; sometimes, they are the fault of tight-fisted CEOs who refuse to budget adequate funds for hiring IT staff or procuring patch-management tools and test systems. The point is that if Microsoft can't control the patching process, then it's pushed back onto the users. And a few irresponsible users can wreak havoc on the systems of responsible ones through the flood of worm traffic they unleash through their unpatched systems. Responsible users then cry out, "Microsoft should stop this from happening!," when perhaps they should be suing the companies that don't keep their systems properly patched. I might add another P here for Practice. Once you've developed your patch- management policy, you should periodically have your staff practice the procedures so that the procedures become second nature. Mind you, with the number of patches coming out of Redmond these days, who needs to practice?
Patch-Management Tools Once you have a policy in place and have outlined a detailed process for handling patches, what tools can you use to deploy patches to your systems? Once again, various tradeoffs are involved, including power versus simplicity and risk versus control. Here's a quick summary of what's currently available from Microsoft. Windows Update The granddaddy of all patch-management tools, Windows Update is a web site (http://windowsupdate.microsoft.com) that allows users to scan their computers manually to see which hotfixes, roll-ups, or service packs need to be installed. Windows Update also offers add-ons and enhancements that Microsoft develops for Windows. The advantage of this approach is that users have complete control over which patches are installed on their system. The disadvantages, however, are numerous. First, your computer must be connected to the Internet, which is where most threats come from. Second, you must have cookies enabled; there goes your privacy, some might say. Third, you must allow ActiveX controls to run, which is another potential source of vulnerability. Finally, you must be a member of the local administrators group when you use Windows Update. This one is serious; in a corporate environment, it means you have to give employees administrative privileges so that they can keep their machines up-to-date.
Clearly, Windows Update is suited only for small offices and home networks as a patch-management solution. Automatic Updates Starting with Service Pack 3 for Windows 2000, Microsoft includes a feature called Automatic Updates on all subsequent versions of Windows. This feature has some of the security weaknesses of the Windows Update approachnamely, your machines must be connected to the Internet and Internet Explorer must be configured to allow ActiveX controls to run. But on the plus side, Automatic Updates doesn't require that users have administrative privileges, as Windows Update does. The main advantage of Automatic Updates is that it enables systems to download new patches automatically when they become available on the Windows Update web site and install them according to a schedule the administrator can specify. For more information on how this tool works, see [Hack #86]. Software Update Services (SUS) The Software Update Services (SUS) tool is available as a free download from Microsoft and takes Automatic Updates several steps further. Instead of requiring each system to be connected to the Internet, SUS downloads and stores patches on one or more SUS servers, where administrators can review them and either approve or decline their installation. Client computers then have their Automatic Updates component configured to point toward the SUS servers instead of the Windows Update
web site as the source for their patches. This approach has all the advantages of Automatic Updates, without the disadvantages of requiring every machine to be exposed to the Internet. SMS Software Update Services Feature Pack At the high end of things is Microsoft Systems Management Server (SMS), a powerful but complex tool for deploying, configuring, and maintaining large numbers of systems. The SUS Feature Pack enables SMS to leverage SUS technology to determine which systems need which patches, push the patches out and install them, and report the results. The Feature Pack gives you more granular control than SUS over which systems receive which patches, lets you build an inventory of installed patches for each system, has better reporting tools, and overcomes SUS's limitation of 15,000 client computers (though, in reality, SUS starts to become unmanageable around 5,000 clients). For further information, see http://www.microsoft.com/smserver/downloads/20/featurepacks/suspack/ Third-party tools Finally, there are a number of third-party patch-management tools available. GFI LANguard Network Security Scanner (N.S.S.) from GFI (http://www.gfi.com/) is a good one. In addition to identifying and deploying patches each system needs, N.S.S.
can also scan for other vulnerabilities, such as weak password policies and ports that shouldn't be open, and inform you how to harden your systems better. There are also other patch- management systems available from third-party vendors; a quick search on Google will turn up several.
Hack 80 Beginners Guide to Enterprise Patch Management Here's another take on managing the patch-management cycle effectively in a large enterprise environment, written by an expert on the subject. One of the most heated and wildly debated subjects in many organizations today is the subject of desktop security. When large IT organizations have an enterprise product like Systems Management Server (SMS) deployed, security teams usually push to the desktop teams the task of ensuring that the latest security updates released by Microsoft are installed. This means that the responsibility of ensuring that a high percentage of clients in the environment are patched rests on the shoulders of desktop support personnel members or SMS team members. In order to better distribute this responsibility, it's best to understand the functionality that can be extended in the following steps:
- Identify vulnerable systems Assess the business impact of patching Package patches for distribution
Test patches Evaluate successes and failures Finish up Before we discuss each of these steps in detail, if you are currently looking to evaluate which tools would be best for your organizations patch-management strategies, take a look at these helpful links from Microsoft's two heaviest hitters: Patch Management Using Microsoft Software Update Services http://www.microsoft.com/technet/treeview/default.asp? url=/technet/itsolutions/msm/swdist/pmsusog.asp Patch Management Using Microsoft Systems Management Server http://www.microsoft.com/technet/treeview/default.asp? url=/technet/itsolutions/msm/swdist/pmsmsog.asp Identifying Vulnerable Systems SMS stands out from SUS the most in its ability to report on the current client state. In the past, SMS_DEF.MOF updates accomplished this by pulling data from the Registry in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix and basing distributions on that data. However, with the advent of the
SUS Feature Pack for SMS (SUSFP), this is no longer necessary. A more robust security hotfix and reporting mechanism can now be added to your infrastructure. Installed and missing updates are reported through normal SMS inventory, so collections and queries can be based on of this information. Microsoft also supplies a web-based reporting package with built-in reports to give high-level overviews of an organization's patch state. The job of an IT administrator to manage the environment will be significantly easier if she is able to view which updates are already installed and which are a priority to be deployed. Assessing the Business Impact of Patching The business impact of patching is mostly comprised of developing patch distribution schedules and policies. Each company's needs are different and patch distribution should conform to those specific needs. Many desktop IT divisions let mandates from their security teams determine when and how patches should be deployed; generally, this causes more harm than good. Do your customers have schedules to meet as well? Shipping dates for when the product must be out the door? What if you send a package with 10 critical system updates to 100 workstations? Problems might occur through no fault of your own, no matter how much testing is done prior to deployment. Optimal success is gained by talking to your customer base to determine the best dates for distribution. If a major product order is being shipped on the 15th, you should probably wait until the 20th to send out updates. What, then, guarantees the least amount of interruption to users, while still ensuring success? Most of the time, this is encapsulated in your company's workstation reboot policy. If
most IT administrators had their druthers, every workstation would get restarted on a daily basis or the administrators would be allowed to force system restarts whenever they want to during distributions. But in the real world, especially for engineering or R&D-driven companies, this is not a reality. Even if you are using the SUS Feature Pack (SUSFP) to give your user base the ability to install their updates early, it is still difficult to manage workstations that might not get logged onto for weeks at a time or workstations that run test simulations and cannot get restarted even while a distribution is happening. There is no easy answer to this, and many different internal solutions have been developed by various organizations. If you are faced with this dilemma and are not able to use the built-in tools (such as the SUSFP), the best option is to speak with other members of the IT community in forums, newsgroups, or mailing lists and learn which methods they use to overcome this problem. However, it is crucial to keep two ideas in mind: the impact to your user base and whether the solution still ensures successful installation. Packaging Patches for Distribution If your organization is already using the SMS SUS Feature Pack's patch-installation agent (i.e., the Distribute Software Updates Wizard functionality) for distribution, you can pretty much ignore this section because everything you need is already done for you. Microsoft has developed a common template in the SUSFP that consistently applies patches in a safe fashion, so the SMS administrator no longer needs to perform constant scripting. Most companies using SMS that have not made the transition to SUSFP to distribute patches haven't done so either because their organizations have either specific user-base needs (such as workstations in labs that
might go long periods without being looked at) or a scattered hierarchy of sites and multiple administrators that would need to replicate the same settings repeatedly (this scenario introduces an increased possibility for human error, along with other issues). If you decide to write your own package to suit your company's needs, make sure you perform the following major steps in your code repeatedly for each patch:
- Determine if the patch is already present by checking for a Registry key's existence, file version, and so on. You'll spend a lot of time reading through Microsoft security bulletins to figure out which data to look for. Detect which operating system your package is running on and install the correct version of that patch for each bulletin. Verify successful installation by again checking for a Registry key's existence, file version, and so on. But this time you will need to code in failure messages (MIFs for SMS) and logging so that you can troubleshoot issues that might arise later. QChain the patches. Many people forget to do this step. This process is a simplified flow of what needs to be done for a solid patch-distribution package. It might look easy at first glance, but when you are dealing with over 15 hotfixes, the package size can grow quite considerably, and the time the administrator spends coding and working out bugs greatly increases as well. In the past, packages that do just these simple tasks have been known to grow to a few thousand lines of
code! It's easy to see why using the SUSFP Patch Installation agent would make an SMS administrators job easier, since these steps are already done. Proper hotfix command-line switches are really all you need to research. Testing Patches Proper testing procedures should be at the foundation of every software distribution, regardless of weather they are hotfixes. Your company's client base might have any number of different configurations that could effect distribution. I won't discuss package testing in detail here, because entire books can be written on the subject, but I will add a couple of notes. First, test the patch in its raw installer form from Microsoft to eliminate any chance of causing problems on the system. Next, when testing configurations on workstations that are designated for testing, do the majority of your tests via SMS once you are confident that the package functions correctly. Many problems can be uncovered when distributing via SMS. Because the majority of your enterprise will execute the installation in this method, the majority of your testing should mirror that use. Also, note that there is no substitute for beta testers among your customer base. Not only will you get more feedback if a problem arises, but they are also using the tools that could be affected. Finally, base distributions on testing; don't base testing on distributions Evaluating Successes and Failures
Verifying that the client base is up-to-date after distribution might be the most important phase in this entire process. Managing the patch state in your enterprise will never be finished as long as there is person out there who is smarter than the Microsoft developers, which is why companies need to patch in the first place. Unfortunately, many organizations distribute an update and never look at reports to make sure that a high- enough percentage of machines are updated. If your infrastructure is functioning properly, the reporting methods you used earlier to identify vulnerable systems (such as the SUSFP) should show that the patch-installation state is higher after distribution. If this is not the case (if installations are failing but notifications of the failure are not sent back to the IT administrator), you will need to look into either your reporting mechanism or your packaging technique. Finishing Up Thoroughness and attention to detail are the most important aspects to managing a company's patch state. Although there are many delivery machines (such as SMS) that can be used to apply patches to your workstations, the same basic premises should be followed throughout the entire process. Even in this heightened time of hacking, viruses, and worms, a solid patch- management process and attentive IT administration can avoid almost any vulnerability by actively keeping workstations' patch state updated. Do some research on Microsoft patch release dates and virus/worm release dates. You'll find that in almost every instance a patch has been released far ahead of time. When administrators fail to apply these updates, frantic patching is often required when an attack happens. Do you and your
customers a favor: avoid these emergencies by having a stable enterprise patch-management solution in place. See Also Here is a brief list of useful links on different aspects of enterprise patch management: Security bulletin email notifications (http://www.microsoft.com/security/security_bulletins/decision.asp White paper on improving patch management (http://www.microsoft.com/security/whitepapers/patch_management.asp Security policy, assessment, and vulnerability analysis (http://www.microsoft.com/technet/treeview/? url=/technet/security/topics/assess/) Choosing a security update management solution (http://www.microsoft.com/windows2000/windowsupdate/sus/suschoosing.asp How the SMS Software Update Services Feature Pack works (http://www.microsoft.com/smserver/techinfo/administration/20/using/suspackhowto.asp Windows patch-management tools (http://www.nwfusion.com/reviews/2003/0303patchrev.html
BigFix (http://www.bigfix.com/website/index.html) Shavlik (http://www.shavlik.com) Richard Threlkeld
Hack 81 Patch-Management FAQ Rod Trent of myITforum.com shares his answers to some frequently asked questions on the subject of patch management. As CEO of myITforum.com (http://www.myitforum.com) and author of white papers and articles on patch management, I frequently get questions on different technical aspects of deploying patches for Microsoft platforms. Here is a selection of some common questions and my answers. You can find additional entries in the Patch Management FAQ at myITforum.com. Downloadable Security Updates Q: Can hotfixes be downloaded from Microsoft without using Windows Update or SUS? A: You can download the hotfixes via the Windows Update Catalog, TechNet/Security Bulletin Search, and the Microsoft Download site. To download them using the Windows Update Catalog, first add a Windows Update Catalog link to your Windows
Update page. This gives you quick access to download updates manually from the Windows Update Catalog. Go to the Windows Update Web site (http://windowsupdate.microsoft.com) and click Personalize Windows Update. Then select the checkbox labeled "Display the link to the Windows Update Catalog under See Also" and click the Save Settings button. To use the Microsoft TechNet/Security Search feature, simply go to http://www.microsoft.com/technet/security/current.asp. Finally, you can download hotfixes from the Microsoft Download Center at http://www.microsoft.com/downloads/. Article and Bulletin Search Q: Where can I search for a specific Microsoft security bulletin? A: Use the HotFix & Security Bulletin Service at http://www.microsoft.com/technet/security/current.asp. Email Notification Q: How can I be notified when new security patches are available? A: You'll want to sign up for the Microsoft Security Notification Service at http://www.microsoft.com/technet/security/bulletin/notify.asp.
Old Updates Q: I went to the original page to download some old updates, but they are no longer available to download. How can I access them? A: You can manually download and install them using the Windows Update Catalog. See http://support.microsoft.com/? kbid=323166 for details. Updates for Older Operating Systems Q: I can get updates from the Windows Update web site for Windows XP and Windows 2003. Where can I find updates for earlier operating systems? A: To obtain updates for earlier operating systems, go to of the following links: Windows 2000 (http://www.microsoft.com/windows2000/downloads/) For Windows 98 (http://www.microsoft.com/windows98/downloads/) Windows 95 (http://www.microsoft.com/windows95/downloads/) Windows NT 4.0
(http://www.microsoft.com/windowsnt/downloads/) MBSA Support Q: Is there a support forum specifically for Microsoft Baseline Security Analyzer (MBSA)? A: Yes. Microsoft provides a newsgroup specifically for MBSA. It can be found on the msnews.microsoft.com news server in the microsoft.public.security.baseline_analyzer newsgroup. You can also access and interact with the newsgroup through the Google MBSA News Group Access interface at http://groups.google.com/groups?hl=en&lr=&ie=UTF- 8&safe=off&group=microsoft.public.security.baseline_analyzer. Rod Trent
Hack 82 Enumerate Installed Hotfixes Here's a script you can use to list all hotfixes installed on a machine. Ever wish you could quickly and easily look at a computer and find out which hotfixes were installed, when they were installed, and by whom? Here is a sample script that shows you how to accomplish this; if you know VBScript and WMI, you can customize it further as necessary. This script will enumerate the installed hotfixes on a computer and display the output in a message box. The following items will be displayed about each installed patch: the name of the computer on which the hotfix is installed, the description of the hotfix, the hotfix ID, the installation date, and who installed the hotfix. The Code Type the following code into Notepad (with Word Wrap disabled) and save it with a .vbs extension as EnumerateHotfixes.vbs: strComputer = "." Set objWMIService = GetObject("winmgmts:" _
& "{impersonationLevel=impersonate}!\" & strComputer & "\root\cimv2") Set colQuickFixes = objWMIService.ExecQuery _ ("Select * from Win32_QuickFixEngineering") For Each objQuickFix in colQuickFixes Wscript.Echo "Computer: " & objQuickFix.CSName & vbCrlf &_ "Description: " & objQuickFix.Description & vbCrlf &_ "Hotfix ID: " & objQuickFix.HotFixID & vbCrlf &_ "Installation Date: " & objQuickFix.InstallDate & vbCrlf &_ "Installed By: " & objQuickFix.InstalledBy & vbCrlf Next Running the Hack Open a command prompt, change to the directory in which the script is located, and type cscript.exe EnumerateHotfixes.vbs. Figure 9-1 shows sample output from running the script. Figure 9-1. Enumerating hotfixes on a Windows 2000 machine
To ensure the script works properly, make sure you have the latest scripting engines on the workstation from which you run this script. You can download the latest scripting engines from the Microsoft Scripting home page (http://msdn.microsoft.com/scripting/). Also, since the script uses the Active Directory Services Interface (ADSI), you must have the same applicable rights you need to use the built-in administrative tools. Hans Schefske
Hack 83 Apply Patches in the Correct Order Deploying patches properly can sometimes mean applying them in the right order, as this experience can testify. There is a specific order you should follow when applying Microsoft security patches. Microsoft's policy (a little understated) is that you need apply patches in the order in which they are released. Understanding Microsoft's naming convention for security patch releases is definitely critical for you to understand patch order. See the article at http://www.myitforum.com/articles/20/view.asp?id=5894 to understand the security patch naming convention. What could happen if you patch out of order? Microsoft's patches are released with the assumption you have a patch-management policy in place and that you have applied all patches to date. So, when they develop the next patch, they also assume that the system to which you will apply the latest patch release has the proper file versions. If you apply the patches out of order, you can effectively overwrite a secure file. For example, say the RPC DCOM worm is patched by using MS03-026. If you have this patch, you will not be affected by the worm. But if you apply MS03-010 after you apply MS03-026, a secure DLL will be overwritten with an insecure one, reopening the vulnerability that MS03-026 patches.
Why would someone do this, you might ask? The RPC DCOM worm was something you couldn't get away from. The Department of Homeland Security issued warnings, Microsoft issued warnings, and the warning was blasted all over TV and Internet. This woke up a bunch of system administrators, so they patched with MS03-026. And, since they were patching, they might as well get the other patches they had missed up to that point, applying MS03-010 after the fact. So, make sure that you are apply your patches in the order in which they are released. If you have some catching up to do, take the extra time to get it right! Rod Trent
Hack 84 Windows Update FAQ Rod Trent of myITforum.com shares his answers to some frequently asked questions regarding Windows Update. Windows Update is a simple solution that can be used to keep individual systems up-to-date with patches released by Microsoft. Despite its simplicity, however, not everything about it is obvious and I often get questions about different aspects of how it works. Here is a selection of some of these questions and my answers. For more entries in the Windows Update FAQ, see my column at myITforum.com (http://www.myitforum.com). Windows Update Information Collection Q: I'm worried about privacy. What information does the Windows Update site collect when I access the site? A: Windows Update is committed to protecting your privacy. To provide you with the appropriate list of updates, Windows Update must collect a certain amount of configuration information from your computer. None of this configuration information can be used to identify you. This information includes the operating- system version number, Internet Explorer version number, version numbers of other software for which Windows Update provides updates, Plug and Play ID numbers of hardware devices, and Region and Language settings.
The configuration information collected is used only to determine the appropriate updates and to generate aggregate statistics. Windows Update does not collect your name, address, email address, or any other form of personally identifiable information. Windows Update also collects the Product ID and Product Key to confirm that you are running a licensed copy of Windows. A licensed copy of Windows ensures that you will receive ongoing updates from Windows Update. The Product ID and Product Key are not retained beyond the end of the Windows Update session. To provide you with the best possible service, Windows Update also tracks and records how many unique machines visit its site and whether the download and installation of specific updates succeeded or failed. In order to do this, the Windows operating system generates a Globally Unique Identifier (GUID) that is stored on your computer to uniquely identify it. The GUID does not contain any personally identifiable information and cannot be used to identify you. Windows Update records the GUID of the computer that attempted the download, the ID of the item that you attempted to download and install, and the configuration information listed previously. Personalizing Critical Updates Q: On the Windows Update web site, I'd rather not see certain updates, but the web site won't let me personalize them. Is something wrong? A: You cannot use the Personalize button to personalize Critical Updates. If you click Personalize, you will receive a message that states that the Critical Update section cannot be personalized. Sorry!
Clearing the Secure Sockets Layer Q: Windows Update fails when I try to use it. What can I do? A: If the Windows Update site fails, one of the steps to fixing the problem is to clear the Secure Sockets Layer. Open Internet Explorer, on the Tools menu, click Internet Options, and then click the Content tab. Then, under Certificates, click Clear SSL State. Click OK when you receive the message that the SSL cache was successfully cleared. Another thing to check is your firewall configuration; TCP port number 443 (https) needs to remain open for access to the Windows Update web site to work. To make sure this port is open, type https://www.microsoft.com:443 in your web-browser address line and click Go. If you are unable to access the Microsoft web site by using this address, you need to open the port on the company firewall (or personal firewall, depending on your networking environment). Removing Items from Your Windows Update List Q: How do I remove items from the Product Catalog list? A: To personalize your available updates, you can remove items from the Product Catalog list on the Windows Update web site. First, connect to the Windows Update site (http://windowsupdate.microsoft.com) and click Product Updates. Then, click Personalize and clear the checkbox next to the items that you do not want to see listed in the Product Catalog. Click Update to save the changes.
Changing Windows Update Schedule Q: I've tried to modify the schedule for updates, but as soon as the computer is rebooted, the settings revert back to the default. A: If you try to change the Critical Update Notification settings by using the Task Scheduler and restarting your computer, your changes will not be saved. This behavior occurs because, by design, you cannot modify or disable the Windows Critical Update Notification schedule through the Task Scheduler. Once the computer is rebooted, the Registry or local GPO settings reset the schedule. Manually Installing the Windows Update Controls Q: What can I do if the ActiveX controls I downloaded and installed from the Windows Update site become corrupt? A: You might need to install the controls manually. You can do this by downloading, extracting, and installing the controls from the Windows Update web site. Where you obtain these controls depends on the version of Windows you have. For Windows 98 and ME, download the controls from http://v4.windowsupdate.microsoft.com/cab/x86/ansi/iuctl.cab. For Windows 2000, XP, or 2003, download the controls from http://v4.windowsupdate.microsoft.com/cab/x86/unicode/iuctl.cab After downloading the controls, save the .cab file to its own directory. Then, right-click on the .cab file and choose to extract
the files. You can extract the files to the same directory you created to house the .cab file. Finally, right-click the iuctl.inf file and click Install. Rod Trent
Hack 85 Obtain Updates via the Windows Update Catalog Whether you use it to download patches or driver updates, the Windows Update Catalog can be your friend. The Windows Update Catalog provides a comprehensive list of updates that can be distributed over a corporate network. It is a one-stop location for Windows updates, fixes, and enhancements, as well as Designed for Windows Logo device drivers. To obtain updates from the Windows Update Catalog, first select a category (see Figure 9-2). The Microsoft Windows category has updates and fixes for all Windows operating systems, from Windows 98 to Windows XP and the Windows Server 2003 family. The hardware drivers category provides you with driver updates for many of the devices on your network. Figure 9-2. Downloading updates using the Windows Update Catalog
Now, set your search criteria to find the updates you need. Finally, download your selected updates to the location of your choice (e.g., your local hard drive, a server share on your network, or a disk). Now, let's dig a little deeper into how to use the Catalog effectively.
Adding the Windows Update Catalog to Windows Update One of the ways you can customize Windows Update is to add a link to the Windows Update Catalog. This gives you quick access to download updates manually from the Windows Update Catalog. First, go to the Windows Update web site (http://windowsupdate.microsoft.com) and click Personalize Windows Update. Now, click to select the "Display the link to the Windows Update Catalog under See Also" checkbox. Finally, click Save Settings. You now have a link to the Windows Update Catalog when you visit Windows Update. Downloading Windows Updates from the Windows Update Catalog To download updates for Windows for managed deployment in your organization, first go to the Windows Update Catalog at http://v4.windowsupdate.microsoft.com/catalog/, or use the custom link you added to your Windows Update page in the previous section. Then, click "Find Microsoft Windows updates" or "Find updates for Microsoft Windows operating systems." Click the appropriate operating system and language for the update that you want to download, and then click Advanced Search Options to refine your query. Click Search, and then click the appropriate category for the update you want to download (e.g., Updates and Service Packs) and locate the update. Click Add. Repeat the previous steps to find and add additional updates to your download basket. Then, click "Go to download basket." In
the "Type or browse to the download location of your choice" box, type the full path for the folder in which you want to save the patch, or click Browse to locate the folder. Click Download Now, and then click Accept to accept the license agreement. Distribute your updates and install them on your machines. Downloading Driver Updates from the Windows Update Catalog If you need updated device drivers, the Windows Update Catalog is the place to get them. To download manufacturer hardware drivers from the Windows Update web site, go to the Windows Update Catalog at http://v4.windowsupdate.microsoft.com/catalog/ or use the personalized link you created previously. Click "Find hardware driver updates" or "Find driver updates for hardware devices." Then, click the appropriate hardware category for the driver update you want to download. Click the manufacturer name, the operating system, the language, and any other items that you want to search for, and then click Search. Locate the driver you want, and then click Add. Repeat the previous steps to find and add additional driver updates to your download basket and click "Go to download basket." In the Type or "browse to the download location of your choice" box, type the full path for the folder in which you want to save the patch, or click Browse to locate the folder. Click Download Now, and then click Accept to accept the license agreement. You can now install the downloaded drivers or distribute them to machines that need them on your network.
Rod Trent
Hack 86 Use Automatic Updates Effectively Automatic Updates is an easy way to ensure that your Windows servers are properly patched against critical vulnerabilities, but there are some nuances to using it effectively. The other day, a power blackout temporarily knocked out my company's servers. I should have tested the UPS more often, but you know how it is. Anyway, when the power came back on, the servers rebooted. I was sitting at the console of one of them, about to log on, when the server suddenly rebooted itself again. Virus? Disk problem? I stared at the screen, worried for a moment, and then suddenly realized: Automatic Updates! Whew! Automatic Updates is a patch-management feature that replaces the earlier Critical Update Notification utility that you used to download from Microsoft's web site for Windows 98 or later. Microsoft first made Automatic Updates available for download for Windows 2000 systems running Service Pack 2. Later, when Service Pack 3 was released, Automatic Updates was included as a component of that service pack. Automatic Updates is also included on both the Windows Server 2003 and Windows XP platforms. Automatic updates lets administrators schedule the automatic downloading and installation of critical security updates from Microsoft's Windows Update web site, making it no longer necessary for administrators to use Windows Update to keep their systems patched manually.
Using Automatic Updates The way you configure Automatic Updates depends on your platform. On Windows Server 2003 and Windows XP Service Pack 1, use Control Panel System and select the Automatic Updates tab. On Windows 2000 Service Pack 3 or later, use Control Panel Automatic Updates. Whichever platform you use, the configuration options are the same. Figure 9-3 shows the configuration options for Windows Server 2003. Figure 9-3. Automatic Updates feature in Windows Server 2003
The checkbox lets you enable or disable Automatic Updates on the machine. By default, Automatic Updates is enabled and the
second option under Settings is selected. The three Settings options represent different levels of automation. The first option"Notify me before downloading any updates and notify me again before installing them on my computer"is the least automated solution. Windows automatically checks the Windows Update web site for new updates shortly after system startup and every 22 hours thereafter (minus a random offset of up to 5 hours). If new updates are available for download, a notification message appears above the status area at the bottom right of the logged-on user's desktop. However, only administrators can download and install these updates. If the second option"Download the updates automatically and notify me when they are ready to be installed"is selected, Windows automatically checks for new updates according to the scheduled described previously. But this time, if updates are found, they are automatically downloaded in the background. Once downloading is complete, a notification message asks if you want to install them. The third option"Automatically download the updates, and install them on the schedule that I specify"is the most automated solution for keeping your system up-to-date with critical security patches. Windows still checks for new updates according to the previously described schedule, but it then allows you to schedule when downloaded updates should be automatically installed. You can schedule installation of updates every day or once a week at a time of your choosing (the default time, 3:00 a.m., is a good choice, because system and user activity is usually low then). What actually happens when the scheduled time arrives depends. If a user is logged on at the scheduled installation time, a notification message gives the user five minutes to log off before installation starts. By default, the machine reboots
when these five minutes are up, but this behavior can be changed by editing the Registry (we'll see how in a moment). On the other hand, if the user is an administrator, he has the option of declining installation until the next scheduled day and time. If no one is logged on to the machine, the updates are installed automatically and, if necessary, the machine reboots (this is usually the case). Finally, if the machine is down when the scheduled time occurs, installation of updates commences approximately one minute after the machine finishes booting (this time interval can also be changed only by editing the Registry). If you choose one of the first two methods, a list of available updates is displayed and you can download and/or install only the updates you choose by deselecting the updates you want to decline. If you choose the third option, everything is automatic. Which approach is best? While keeping your systems up-to-date with the latest patches is important, there have been occasions when a patch has broken one feature while fixing another, resulting in systems freezing up or becoming unstable. On critical servers, it's probably best to download updates automatically but not install them until you've had a chance to install them on a test machine to ensure that no system problems or application incompatibilities result. We'll talk about how you can do this in a moment. There's another reason for not using the fully automated option on critical servers: Microsoft sometimes releases multiple patches at a time, and if you install all of them and the machine becomes unstable, it's hard to trace which patch caused the problem. I suggest that when multiple patches become available and you've tested them, use the following hack to safely install them on your critical servers. First, click the Automatic Updates notification icon in the status area and click Details to display a list of available updates, as
shown in Figure 9-4. Deselect all the patches in the list except the one you want to install first. This will download and/or install only the selected patch (if you're installing updates that have already been downloaded, it will delete all other downloaded updates from your system). Note that the declined patches will not be displayed in future lists generated by Automatic Updates, but by clicking the Declined Updates button (see Figure 9-3 again) you can choose to have Windows notify you again about the updates you declined so you can download/install them later. Once you've installed the first update on your production system and verified it hasn't caused any negative effect, repeat the process to install the second update, third update, and so on. Figure 9-4. List of downloaded updates ready to be installed
The main downside of this hack is that your system might require extra reboots. The advantage is that it's safer and helps you pinpoint the source of any problems that arise. For more details on how to keep Windows systems patched and up-to- date, see [Hack #79]. To remove an installed update that's
causing problems, go to Control Panel Add or Remove Programs Change or Remove Programs and uninstall the offending update. Hacking Automatic Updates While basic configuration of Automatic Updates is done through the GUI, you can tweak it further by hacking the Registry. This approach is useful mainly in a workgroup environment; to learn how to configure Automatic Updates in an Active Directory environment, see [Hack #87]. To configure Automatic Updates by hacking the Registry, run regedit.exe and find the following key: HKLM\Software\Policies\Microsoft\Windows Under this key, add a subkey named WindowsUpdate, and under that key add a subkey named AU: HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate\AU Then, populate this key the following values and assign them data values as desired (all of them are of type Reg_DWORD). First, the NoAutoUpdate value determines whether Automatic Updates is enabled (0) or disabled (1) on your system. The AUOptions value then determines which of the three scheduling options is used: a
value of 2 causes Windows to notify you before downloading updates, a value of 3 automatically downloads updates but notifies you before installing them, and a value of 4 automatically downloads and installs updates without user intervention. The ScheduledInstallDay value determines the day on which downloaded updates are installed when AUOptions has a data value of 4. A value of 0 for ScheduledInstallDay means that downloaded updates are installed every day, while values 1 through 7 mean that updates are installed once a week on Sunday (1) through Saturday (7), respectively. The ScheduledInstallTime value determines the time on which downloaded updates are installed when AUOptions has a data value of 4. ScheduledInstallTime can have any integral data value from 0 through 23, representing the hours of midnight through 11 p.m., respectively. The offset time, in minutes, that Automatic Updates waits after the computer restarts before it tries installing overdue updates is determined by RescheduleWaitTime and can range from 1 to 60 (1 is the default). The NoAutoRebootWithLoggedOnUsers value determines whether Automatic Updates is allowed to reboot (0) or prevented from rebooting (1) the machine to complete the installation of updates when a user is currently logged on to the machine. Note that if you set the value of NoAutoRebootWithLoggedOnUsers to 1, Automatic Updates won't be able to check the Windows Update site for new updates until the system is rebooted. Finally, if UseWUServer is set to 1, the computer will obtain updates from an internal SUS server instead of from the Windows Update web site. Note that this value applies only when Software Update Services (SUS) is being used to deploy critical updates across your network.
Once you've made these Registry modifications, they won't take effect until you reboot your machine. After rebooting, if you try to configure Automatic Updates using the GUI, you'll see that all the options are grayed out, even if you're an administrator. Don't worry, though; just delete the HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate key and its contents, reboot, and you'll again be able to configure Automatic Updates by using the GUI!
Hack 87 Use Group Policy to Configure Automatic Updates Use Group Policy to simplify the configuration of Automatic Updates in an Active Directory environment. Configuring Automatic Updates [Hack #86] is a lot of work if you have to do it separately on every machine on your network. Fortunately, in an Active Directory environment, you can use Group Policy to simplify the job. First, open an existing Group Policy Object (GPO), such as the Default Domain Policy, or create a new GPO and link it to the appropriate domain, organizational unit (OU) or site. Then, add the wuau.adm template to the GPO so that the Group Policy settings for Automatic Updates will be added to your GPO. This is done as follows (note that these steps are unnecessary if you have Windows Server 2003). Begin by expanding Computer Configuration to show Administrative Templates. Then, right- click on Administrative Templates, select Add/Remove Template, click Add, select wuau.adm from the list of templates in the %Windir%\Inf folder, click Open, and then click Close. Now, configure the GPO settings for Automatic Updates by expanding Computer Configuration Administrative Templates Windows Components and selecting Windows Update in the pane on the left, as shown in Figure 9-5.
Figure 9-5. Using Group Policy to configure Automatic Updates Let's dig into what the various settings in Figure 9-5 mean. The first setting, "Configure Automatic Updates," lets you perform basic configuration of Automatic Updates for computers in the domain, OU, or site to which the GPO is linked. The options here
are the same as the options available when you manually configure the feature using Control Panel's Automatic Updates utility (Windows 2000) or System utility (Windows Server 2003 and Windows XP); refer to Figure 9-3 for details. The next setting, "Specify intranet Microsoft update service location," applies only if you plan on using Software Update Services (SUS) to deploy updates. The "Reschedule Automatic Updates schedule installations" option determines the time that Automatic Updates will wait after the computer restarts before installing updates that have already been downloaded and are past the scheduled time for installation. Value ranges from 1 to 60 (values are in minutes); the default is 1 if the setting is not configured and 5 when the policy is enabled. By disabling this policy, the installation of overdue updates is deferred until the next scheduled installation day and time. Finally, "No auto-restart for scheduled Automatic Updates installations" determines whether the logged-on user will be forcibly logged off in order to complete the installation process when a reboot is required. Enabling the policy means that machines will not be forcibly rebooted. While this would seem like a good idea (so users won't lose their work), it does have a downside: Automatic Updates won't be able to check the Windows Update web site for new updates until the machine is rebooted. Enabling these policy settings will override any configuration of Automatic Updates that was done locally using Control Panel and will prevent you from making such changes locally, even as an administrator (the options in the properties sheet of Figure 9- 3 would be grayed out). However, changing these policy settings back to Not Configured will restore the manual settings previously configured for Automatic Updates (though a reboot is required). And while changes made to these policies are
automatically applied to client computers every 90 minutes (plus a random offset of up to 30 minutes), you can test the settings immediately by forcing a policy refresh with the command secedit /refreshpolicy machine_policy on Windows 2000 or gpupdate /force on Windows Server 2003. Some Recommendations If you want to configure different Automatic Updates policies for different users or computers, either create multiple GPOs, link each to a different OU, and place users and computers into these OUs accordingly, or filter the GPO settings to prevent their inheritance by specific users, computers, or groups. You can also check the Security log in Event Viewer if you want to see whether the machine has been rebooted to install scheduled updates. Look for the following Event IDs: Event ID 21 "Restart Required: To complete the installation of the following updates, the computer must be restarted. Until this computer has been restarted, Windows cannot search for or download new updates." Event ID 22 "Restart Required: To complete the installation of the following updates, the computer will be restarted within five minutes. Until this computer has been restarted, Windows cannot search for or download new updates."
Digging Deeper There's another policy that controls how Automatic Updates works, but it's not found under Computer Configuration. Instead, it's found in User Configuration Administrative Templates Windows Components Windows Update "Remove access to use all Windows Update features." This policy prevents the currently logged-on user from opening the Windows Update web site in Internet Explorer, in order to manually download and install updates on his machine. Actually, when you open windowsupdate.microsoft.com, an "Access Denied" page appears, explaining that a policy is preventing you from using the site. Enabling this policy also has the effect of preventing Automatic Updates from notifying users when new updates are ready to install. In other words, no notification icon will appear in the status area to inform you that updates are ready to install. Finally, even local administrators on the machine are affected by this policy! And domain administrators are affected too! So, why would you want to use this policy? While it prevents users from visiting Windows Update or interacting with Windows Update, it doesn't prevent Automatic Updates from operating if the feature has been configured at the computer level by using the policies discussed in the previous section. This is because this setting is a per-user policy, not a per-machine one, so it affects only users; it doesn't affect configuration done at the machine level. Enabling this policy might be a good idea, because it prevents users from trying to download and install updates on their own, even if they have administrative privileges.
While this policy is present on Windows 2000, Microsoft says it works only on Windows XP and Windows Server 2003. But my own experience is that it also works on Windows 2000. While this policy prevents users from using the Windows Update site, it still leaves the Windows Update icon in the Start menu, tempting users to explore and see what it does. You can remove this icon from the Start menu by enabling another policy: User Configuration Administrative Templates Start Menu & Taskbar "Disable and remove links to Windows Update." This removes even users' temptation to try to keep their machines up-to-date by themselves. Administrators would do well to use such policies and to explore similar restrictions on user activity provided by Group Policy.
Hack 88 Automatic Updates FAQ Rod Trent of myITforum.com shares his answers to some frequently asked questions about the Automatic Updates feature of Windows 2000/XP/2003. As CEO of myITforum.com (http://www.myitforum.com), I often get technical questions about Automatic Updates and other Microsoft patch-management tools. Here are a few of the more common questions and my answers. You can find additional tips about using Automatic Updates at myITforum.com. Service Still Running After Disabling AutoUpdate Q: I've disabled Automatic Updates by going to AutoUpdate properties in the Control Panel, double-clicking System Properties, and then clicking the Automatic Updates tab. But the AutoUpdate service still runs. Can this be turned off? A: AutoUpdate is an always-on service. Disabling this service by accessing the properties disables only the client behavior. Disabling Critical Update Notification
Q: How do I disable the Critical Update Notification feature of Automatic Updates? A: The Critical Update Notification is controlled through the Task Scheduler. If you want to disable the Critical Update notification but keep it installed on the computer, open the Task Scheduler and delete any tasks for Critical Update Notification. For Windows XP and Windows 2003, scheduled tasks are accessed under Program Files Accessories System Tools Scheduled Tasks. In Windows 2000, however, Task Scheduler is available under Settings Control Panel Scheduled Tasks. AU Overrides WU Q: If you use the Windows Update web site on a machine that has Automatic Updates enabled, what is the result? A: Automatic Updates might try to install updates, even though the Windows Update web site was used. Unfortunately, Automatic Updates is not smart enough to understand when you've decided to use Windows Update instead. When updates are downloaded via Automatic Updates, the download information is stored on the local computer, and this information doesn't change if an update is installed afterward. Note that Automatic Updates will still display a message that updates are available. This will be fixed in a future version of Automatic Updates, but for now, install the Automatic Updates version of the update, so its installation records are updated correctly. The "you have updates" message will go away once the updates are installed using the Automatic Updates client.
Rod Trent
Hack 89 Software Update Services FAQ Rod Trent of myITforum.com shares his answers to some frequently asked questions regarding Software Update Services (SUS). Software Update Services (SUS) is a free patch-management product you can download from Microsoft's web site (http://www.microsoft.com/windowsserversystem/sus/). SUS is an excellent solution for keeping small and mid-sized corporate networks up-to-date with patches released by Microsoft. For large enterprise networks, I recommend using Systems Management Server (SMS) as a complete solution. Here are some common SUS questions and my answers. For more entries from the Software Update Services FAQ, search for "Software Update Services" at myITforum.com (http://www.myitforum.com). Operating System Support Which operating systems are supported under SUS? SUS is supported on the following Microsoft Windows platforms: Microsoft Windows 2000 Professional (with SP2 or later) Microsoft Windows 2000 Server (with SP2 or later) Microsoft Windows 2000 Advanced Server (with SP2 or
later) Microsoft Windows XP Professional Microsoft Windows XP Home Edition Microsoft Windows Server 2003 Older versions of Microsoft Windows, including 95, 98, NT, and ME, are not supported by SUS. Active Directory Support Q: Is Active Directory required for SUS to work? A: No, it's not required. However, SUS works well with Active Directory. Separating Workstations and Servers Q: How can you approve different update lists for workstations and servers? A: If you need different approved lists for workstations and servers, install two different SUS servers in your environment: one specifically for workstations and one just for servers. Control Panel Icon Q: My Automatic Updates service is running in Services. But in Control Panel, there is no Automatic Updates icon. I am running Windows XP SP1.
A:Windows XP Automatic Updates is not available in the Control Panel. Instead, it has its own tab in My Computer Properties. Approving Updates After First Synchronization Q: I just installed SUS and downloaded the horde of old updates. How do I handle these? Is there some way to remove them? Or do I need to approve them all? A: Go ahead and approve all updates. If the computers already have the specific updates installed, they will ignore them. This allows you to put all old updates into the list of already approved updates so that you can filter them out. Downloading and Testing Updates Q: I see the downloaded updates in the SUS\Content\Cabs directory, but how can I install a specific update for testing without knowing the Q-number associated with a bulletin? A: Instead of spending a lot of time trying to associate a Q- number with the downloaded filename, use SUSAdmin to download the specific update you want. Simply open SUSAdmin by using the URL http://SUSServerName/SUSAdmin and click the Approve Updates link. Locate the update you want to test and click the Details link. When the Details windows displays, click on the filename link. This downloads the update executable to your computer, where you can test the installation.
Order of Updates Q: Do I need to worry about patching out of order through SUS? A: The installation is done on the client side (Automatic Updates) and there is no particular order enforced, but it should work correctly in whatever order the installs are done. The functionality of the old qchain.exe is built into the current update.exe that is used to install patches, and it is supposed to be smart enough to not overwrite newer binaries with older ones. Detecting Connection Q: How can I tell if my system is connecting to the SUS server? A: Check the SUS log file on your system, at %systemroot%\Windows Update.log. Knowing When the Server Is Synching Q: How do I know if my SUS server is synching? A: Open Task Manager and switch to the Processes tab. Locate a process called WUSyncSvc.exe. If your SUS server is currently synching updates, this process will be loaded and active. Also, the Software Update Services Synchronization Service will be started and running in the list of computer services. Cleaning the Updates Directory
Q: I have uninstalled SUS due to a full hard drive, but the drive remains full. Is there something else I need to delete? A: SUS does not remove the synchronized updates during the uninstall. You'll need to remove the files located in the SUS\Content\Cabs directory manually. Modifying SUS IIS Rights Q: I modified the rights for the SUS and SUS\Content\Cabs folders and now clients cannot download updates. What should these rights be set to? A: Set anonymous access on the IIS root of the SUS server and give access to the Everyone group. Analyzing the SUS Log Files Q: Is there a tool/utility that can parse the SUS IIS log file and create any sort of readable report? A: There is a standalone SUS Reporting Utility tool you can use. An online version is located at http://www.susserver.com/Software/SUSreporting/. TimeExpire Q: Have you seen the following line in the patchinstall.log file when you send multiple security patches in the same package?
TimeExpire: Sending Command1 message, CurrentTime = (14900746), StartTime = (14879725) A: This is not an error. It means that the countdown timer expired without the user selecting any option and the system is now taking the default action (reboot, install, or postpone). Entries before or after this line should shed more light as to what was done. SUS and Name-Resolution Issues The clients connect OK, and they receive notification that updates are ready to download. I then click the icon to receive a list of updates that are needed. When I click the "Start Download" button, the window disappears and nothing happens. Any ideas? This particular issue is because a result of a name-resolution problem. Create an LMHOST file entry pointing to the SUS server. Then, the downloads and installations should proceed as expected. SUS Feedback Q: Is there an email alias for submitting comments, suggestions, and requests for SUS directly to Microsoft? A: Yes. You can email cwufdbk@microsoft.com. You might not receive a direct response, but Microsoft does monitor this mailbox.
Rod Trent
Chapter 10. Backup and Recovery Hacks #90-100 Section 90. Collect Disaster Recovery Files Section 91. Back Up Individual Files from the Command Line Section 92. Back Up System State on Remote Machines Section 93. Back Up and Restore a Certificate Authority Section 94. Back Up EFS Section 95. Work with Shadow Copies Section 96. Back Up and Clear the Event Logs Section 97. Back Up the DFS Namespace Section 98. Recover with Automated System Recovery Section 99. Recovery Roadmap Section 100. Data Recovery of Last Resort
Hacks #90-100 Backing up systems and configurations for services is your first line of defense against a disaster. Unfortunately, this is often more complicated than it sounds. Restoring an entire system from scratch is usually a complex and time-consuming procedure, and it is usually not necessary when only one component or feature has become corrupted or lost. This chapter looks at the backup process and examines how to back up specific entities, such as your System State, certificate authority (CA) information, Encrypting File System (EFS) keys, and Distributed File System (DFS) namespace. We also look at how to back up something as simple as an individual file from the command line, to something as complicated as an entire system using the new Automated System Recover (ASR) feature of Windows Server 2003. Also included is a script that can be used to collect disaster recovery files and event logs from remote Windows 2000 servers. We also map out procedures you can use to recover a failed system, short of restoring everything from backup, navigating through a maze of options (such as Safe Mode, Emergency Repair, Last Known Good Configuration, and the Recovery Console). Finally, we mention a few services you can call on when your worst nightmare happens and you need to recover your business data from a failed disk that has no backup.
Hack 90 Collect Disaster Recovery Files Use this handy script to gather emergency repair files and event logs from Windows 2000 servers on your network. Collecting Emergency Repair (ER) files can be a tedious, time- consuming, and often forgotten task for Windows 2000 administrators. Usually, the lowest man on the totem pole gets this responsibility only after a server goes down, when the easy fix would have been to use the ER diskette but an updated ER diskette was unavailable, leaving the server down for hours. Management then begins searching for a GUI-based product that will collect ER files and simplify everyone's life. Companies like Aelita charge $99 per server to collect ER disks from a remote server and charge $599 per server to collect remote event logs. If you follow this hack, you'll learn how to script the collection of ER files and event logs from remote servers for free. The script runs an update of the system's Emergency Repair files using rdisk.exe, uses the built-in winmsd.exe utility to save system information, and uses the following Microsoft Windows NT/2000 Server Resource Kit tools: srvinfo.exe To collect more information about the system
srvcheck.exe To audit shares and security settings dumpel.exe To save information from the system's event logs. After it collects all this information, the script copies it to the repository server. If you schedule the script to run at least once a month, you'll have most of the information you need to restore the system in the event of a failure. In my environment, I run the script every Sunday evening. When choosing a suitable repository server, make sure the machine has enough hard-drive space to hold all the disaster recovery files. I run this script against 70 servers and use 650 MB of space. An NT 4 server machine will use about 1.5 MB of space on your hard drive, and a Windows 2000 Server will use about 20 MB of space. If you can, run the script on a Windows 2000 machine, because using UNC path names are easier, srvinfo.exe will work properly, and the script can be scheduled to run under a different user account. The Code There are four separate files you need for running this hack: Disaster.bat, PassList.bat, ReadList.bat, and ServerList.txt. Following is the code for each of them; instructions on how to customize them for your own environment are covered in the next section.
Disaster.bat REM *********************** REM Author: David Jaffe REM Runs Disaster Recovery Commands On Servers. REM Version 1.1 REM Will Break Out NT 4 Servers From Windows 2000 Servers In Next Version REM *********************** If "%OS%"=="Windows_NT" goto MAIN If not"%OS%"=="Windows_NT" goto DOSEXIT :MAIN REM This copies ERD files from the target computer to a central repository net use Q: \%1\c$ c:\winnt\system32\xcopy.exe q:\winnt\repair*.* e:\erd%1\ /q /r /h /y net use Q: /delete /y
REM Collect Services and Driver details plus more info about the server. Writes the REM text file to the folder where the script ran from. winmsd \%1 /a /f REM Collects Basic Info about remote target. Writes a text file to the folder where the script ran from. srvinfo -ns \%1 >srvinfo.txt REM Collects Shares and security settings. Writes a text file to the folder where the script ran from. srvcheck \%1 >shareinfo.txt REM Collects all event logs and writes text files for each node. Writes the REM text file
to the folder where the script ran from.
dumpel -f eventsys.txt -s \%1 -l system
dumpel -f eventapp.txt -s \%1 -l application
dumpel -f eventsec.txt -s \%1 -l security
REM Copies and deletes all text files found in the folder the script ran from.
REN serverlist.txt serverlist.doc
copy c:\erdscript*.txt e:\erd%1
DEL c:\erdscript*.txt
:DOSEXIT
echo
echo This Program Requires NT 4 Or 2000 Server To Run
echo
ReadList.bat
REM Reads The ServerList.txt And Passes The Names to Passlist.bat REN serverlist.doc serverlist.txt for /F %%A in (c:\erdscript\serverlist.txt) do (call c:\erdscript\passlist.bat %%A) PassList.bat REM Runs The Commands Listed In Disaster.bat Incremmentally On Each Machine Listed In ServerText.txt c:\erdscript\Disaster.bat %1 ServerList.txt servernameA servernameB servernameC servernameD servernameE
and so on....... Running the Hack To make the script work in your network, download the files from http://www.oreilly.com/catalog/winsvrhks/ (there is also an NT version of the scripts, if you still have NT servers running on your network and want to collect ER information from them as well) into a directory named ERDSCRIPT on the repository server. Then, customize the code in each file as follows for your own networking environment. Disaster.bat Change all path statements to reflect where you want the disaster recovery files stored. The current script copies everything to e:\erd%computername% and locates all executables at c:\erdscript, so you should modify these according to your own environment. ReadList.bat The lines c:\erdscript\serverlist.txt and call c:\erdscript\passlist.bat %%A should be changed to reflect the path and folder the files were unzipped to.
PassList.bat The line c:\erdscript\Disaster.bat %1 should be changed to reflect the path and folder the files were unzipped to. ServerList.txt List all servers from which you want to collect disaster recovery files. Use one machine name per line. Conclusion Using some basic scripting knowledge, you have protected your organization from extended down times and possibly thousands of dollars wasted on a GUI version of this script. Take a look at the following figures to see how you could increase your department's bottom line and take a step forward in your career: Aelita ERDisk = $99.00 Aelita EventAdmin = $599.00 Total money spent on just 1 server = $698.00 Total money spent on 50 servers = $34,900.00 Total time spent implementing a free script = Half a day The look on the boss's face when you ask for a raise and then present proof on how much money you just saved the company = priceless!
David Jaffe
Hack 91 Back Up Individual Files from the Command Line You can't back up individual files using the ntbackup command, but there's a workaround. The normal syntax of the ntbackup command in Windows 2000 and Windows Server 2003 lets you select specific folders to back up, but it doesn't let you select specific files. For example, to back up your C:\data folder as D:\backups\031105.bkf you would type the following at the command line (where /j indicates the descriptive name of the backup job and /f means we're backing up to file instead of to tape): ntbackup backup C:\data /j "Nov 5 2003 backup of Data folder" /f D:\backups\031105.bkf But what if you want to back up an individual file in the \data folder but not the entire folder? This is easy to do using the GUI version of the Backup tool. Just start the tool, switch to the Backup tab (click Advanced Mode when the wizard starts in Windows Server 2003), expand the C: drive, select the \data folder, and check off the specific files you want to back up. However, doing this from the command line presents a problem, because the syntax of ntbackup doesn't allow you to specify files. There is, however, a workaround: you can specify the names of the specific files you want to back up in a backup selection (*.bks) file (also called a script selection file) and use the @ symbol to specify this file in your ntbackup command, as follows
(where filename.bks is your backup selection file): ntbackup backup @filename.bks /j "Nov 5 2003 backup of Data folder" /f D:\backups\031105.bkf The problem is, you can't create a .bks file from the command line; you have to do it from the GUI. Creating a .bks file To create a .bks file using the Backup utility, you simply create a backup job with the selected files you want to back up and then save the job without actually running it. Then, you can copy the .bks file to another location and use ntbackup to back up the files from the command line. For example, say the folder C:\data contains three filesproducts.doc, sales.doc, and reports.docand you want to back up only products.doc from the command line. Start the Backup utility (switch from the wizard to advanced mode in Windows Server 2003), expand the folder tree, and check the box beside products.doc, as shown in Figure 10-1. Figure 10-1. Using Backup to create a backup selection file
Now, simply select Jobs Save Selections to create your .bks file (specifying a filename like onefile.bks), and close the Backup utility. By default, any .bks files you create are stored in your user profile in the C:\Documents and Settings\username\Local Settings\Application Data\Microsoft\Windows NT\NTBackup\Data folder. To see this hidden folder in Windows Explorer, select Tools Folder Options View "Show hidden files and
folders."
When you open onefile.bks using Notepad, it contains one line of
text:
C:\data\products.doc
Now, copy onefile.bks to a directory with a shorter path, like
C:\BKS, since you don't want to have to type C\Documents and
Settings...\Data at the command line. Now you can back up the
single file products.doc from the command line as follows:
ntbackup backup @C:\BKS\onefile.bks /j "Nov 5 2003 backup of Data folder" /f D:\backups
031105.bkf
Make sure you don't forget the @ sign
before your .bks file; if you do, the backup
will fail without warning (a backup-job file
will be created, but you won't be able to
restore from it). Also, be sure to enter the
absolute path for the .bks file, because
relative paths aren't supported.
Hacking the .bks file
We've seen how easy it is to back up individual files using
ntbackup, by first using the GUI Backup utility to create a .bks
file. Once you've created such a file, it's easy to hack it using a
text editor such as Notepad, because its syntax is easy to
understand. In fact, its syntax is so simple you can simply
create a .txt file containing the right information and then rename
it with a .bks extension, instead of using Backup to create the
.bks file first. In other words, it gets even easier!
Anyway, if we start with our existing file, onefile.bks, and later
decide that we want to back up both the products.doc and
sales.doc files, all we need to do is add a second line to the file,
to make it read as follows:
C:\data\products.doc
C:\data\sales.doc
You can also use your .bks file to back up entire folders or
volumes by adding their paths to the file, as follows (you should
include the backslash at the end of your volume or folder):
E:
F:\budgets
You can also back up the System State information on your
server by adding the following line (make sure there is no space
between the words System and State):
SystemState
You can also back up shared folders by specifying their UNC
path:
\SERVER7\Docs
You can even back up a subfolder within a share (again, note the
trailing backslash):
\SERVER7\Docs\Latest
Finally, you can back up a volume or folder and exclude certain
files or folders. For example, the following .bks file backs up the
entire C:\data folder with the exception of products.doc:
C:\data
C:\data\products.doc /exclude
Creating and customizing .bks files this way gives you a lot of
flexibility for performing backups from the command line.
Unfortunately, neither the ntbackup command nor .bks files
support the use of wildcards. Perhaps we'll see that support in
Longhorn (http://msdn.microsoft.com/longhorn/).
Hack 92 Back Up System State on Remote Machines Here's a hack that let's you use the Backup utility to perform a network backup of System State information on remote computers. The term System State is used in Windows 2000 and later to describe various information used to boot, configure, and run the operating system. At a minimum, System State consists of the Registry, boot files, the COM+ class registration database, and any system files running under Windows File Protection. Servers might have additional System State information, depending on their role. For example, on a domain controller, System State also includes the Active Directory directory service database and the contents of the SYSVOL directory, but if the domain controller is also a DNS server, then System State includes the DS-integrated DNS zone data as well. And if a server is running IIS, then its System State normally includes the IIS metabase as well [Hack #54]. Backing up System State information is critical for recovery from a disaster, and using the Backup utility, it's easy to back up the System State of the local machine. From the GUI, simply start the utility (Accessories System Tools Backup), switch to Advanced Mode if your machine is running Windows Server 2003, switch to the Backup tab, select the checkbox labeled System State (see Figure 10-2), and configure the remaining
backup options as required. The usual practice is also to back up your boot and system volumes when you back up System State, to ensure you have enough information to recover your system after a disaster. Figure 10-2. Backing up System State on a domain controller Note that the checkboxes for the various components of System State are grayed out in Figure 10-2. This is because System State information is interdependent, so you can't back up or
restore parts of it; you can restore the System State in its entirety only. After all, it would be useless to back up the directory service database if you didn't also back up Registry keys associated with the service! Backing up System State from the command line is even simpler: just include the systemstate option in your ntbackup command. For example, to back up the System State data to file as D:\backups\101103.bkf using 10 November 2003 as the name for your backup job, type the following at a command prompt (or include it in a batch file): ntbackup backup systemstate /j "10 November 2003" /f "D:\backups\101103.bkf" The Windows help documentation says that the Backup utility (and its command-line equivalent, ntbackup) can be used only to back up the System State of the local computer. This is unfortunate, because backing up System State is critical for server-recovery purposes. It would be nice if you could back up System State for remote machines over the network, instead of having to do it locally on each server. Fortunately, there's a workaround you can use to accomplish this. It's a two-step process that involves configuring a backup job locally on the remote machine and then configuring a network backup to run from your local server that has the tape drive attached. Configuring Backup on the Remote Machine First, go to the remote server whose System State you want to back up and log on as a domain administrator or member of the Backup Operators group for the domain. Create a new folder on the server and share it using a name like Sysback; this folder will
be used as a temporary in-transit location for storing a backup of the server's System State, so configure NTFS permissions on the folder so that only members of Domain Admins and Backup Operators have access to it. Now, start the Backup utility on the server and configure it to back up the System State to file (not tape) so that the backup- job file (*.bkf) is saved in the Sysback share you created earlier. Choose the appropriate backup options and schedule the backup to occur at desired intervals. Configuring Backup on the Local Machine Return to your local server (the one with the tape drive attached) and map a drive to the Sysback share on the remote server. You could do this by right-clicking on My Computer and selecting Map Network Drive, or you could do it from the command line using the net use command, whichever you prefer. Now, start Backup on the local machine and configure it to include the mapped drive as part of your backup job. The mapped drive will be displayed in the Backup utility with a checkbox beside it; just select the checkbox to back it up. Finish configuring backup options and schedule your job to run at desired intervals. Now, when the backup job runs on the local machine, it will back up the System State of the remote machine as desired, provided you coordinate your schedules so that the backup job runs first on the remote machine. Of course, you can also use ntbackup to configure your backup jobs from the command line, if desired. And if Terminal Services (Remote Desktop in Windows Server 2003) is running on the remote server, you could configure the remote job without actually having to walk over to where the remote machine
resides. Evaluating This Approach You may or may not want to use this approach to back up the System State of your remote servers. Local backups (using a tape drive attached to each server) certainly cost more in terms of hardware and are more work to administer, but they don't have the single point-of-failure problem that network backups (using a centralized backup server with attached tape drive) might experience. And while network backups can generate considerable network traffic, by scheduling backups to take place during off hours or by using a dedicated second LAN, you can minimize this issue. Like most decisions administrators have to make concerning their networks, it's a tradeoff. By the way, this hack also shows that you can use the Backup utility to back up the Registry on remote computerssomething else Windows help says you can't do!
Hack 93 Back Up and Restore a Certificate Authority Backing up your local Certificate Authority is essential, because it forms the foundation for public key cryptography (PKI) for your organization. If you're thinking of using IPSec in an enterprise environment to encrypt virtual private network (VPN) communications for your remote users, or if you're considering securing email communications in your enterprise by encrypting messages and signing them digitally, then chances are you've thought of deploying your own local Certificate Authority (CA) by using the Certificate Services component of Windows 2000 and Windows Server 2003. The advantage of doing this using Certificate Services, instead of letting a public third-party organization issue and manage it, is that it costs nothing; you can issue, manage, renew, and revoke digital certificates for users throughout your enterprise for free. However, the hidden cost of doing this is that you need to know what you're doing. In particular, what if something goes wrong with the server that functions as your root CA? Proper backups are the key, but knowing how to restore in different situations is even more important. At the heart of your certificate system is the root CA, which authorizes and validates all digital certificates issued by your enterprise. A small or mid-sized company will typically have only one CA, which functions as root CA and issues certificates
for all users and systems on your network. A large enterprise might find this single-CA solution doesn't scale well enough and as a result might choose to deploy a hierarchy of CAs, with a single root CA at the top and one or more subordinate CAs underneath. In a CA hierarchy, the job of the root CA is simpler: to issue certificates for subordinate CAs, which then issue other certificates directly to users. In either case, the key to holding the whole situation together is your root CA. If it goes missing or becomes corrupt, then all the certificates issued by the hierarchy become invalid, because they can't be validated back to the root. So, protecting your root CA is protecting the heart of your network's whole system of encrypted communication and certificate-based authentication system. Backing Up a CA The simplest way to back up your root CA is the most straightforward: simply use the Backup utility (System Tools Accessories) and select the option to back up the System State of the machine. This will back up everything on the machine that is critical for restoring it, in case a disaster occurs and your root CA server is toast. Then, when you rebuild your server and restore the System State information from tape, your new server will now be the root CA for your enterprise and all the certificates that were previously issued by your old machine will still be valid. To be safe, Microsoft generally recommends that you restore your root CA on a machine with hardware that is identical to your old machine. But the critical issue here is that your disk layout must be similar to the layout of the old machine, especially if you stored your certificate database and log files in a nonstandard location (by default, they are located in the
%SystemRoot%\system32\CertLog folder, but you can change this location when you install Certificate Services). You also have to make sure your new server has the same name as the old machine, because the name of a CA can't be changed after Certificate Services is installed. The name can no longer be changed, because the name of the machine is included within the root CA's own certificate, so changing its name would cause the whole certification-validation process to fail (for a similar reason, you can't change the domain membership of a CA either). However, System State backups are useful only for recovering from a complete failure of your server, and other things might go wrong with your root CA, such as corruption of the certificate database or certificate log files, some unknown problem that prevents the Certificate Service from starting and requires you to reinstall this service, or the need to move your root CA to a different machine on your network (something you might not have considered). The reason for the last issue is that administrators sometimes don't consider the fact that a root CA is designed to last for years or, more likely, for decades. Once you've deployed a public key infrastructure (PKI) within your organization and started issuing certificates to users for encrypted messaging and secure communication, users become dependent on the transparency of the whole process from their own point of view. The last thing you want to do is build a nice, functional PKI system for your network and have to tear it all down someday and build another, all because you have to change which server hosts the role of root CA. To prepare for the eventuality of recovering a corrupted root CA (which is still a functioning server, however) or moving the root CA role to another server, you need to perform a different kind of backup, one that backs up only what's essential for the machine to function in that role. Fortunately, Microsoft has made this easy by providing a Certification Authority Backup Wizard. Let's
see how this wizard works and what it does. Certification Authority Backup Wizard The Certification Authority Backup Wizard facilitates backing up key data found on your root CA, including the server's own digital certificate (called a CA certificate), its private key (used for generating digital signatures and decrypting encrypted information), the database and associated log files containing certificates previously issued by the server, and the queue of certificate requests still pending to be processed by the machine. This information is sufficient to restore your root CA if something is corrupted and the Certificate Service won't work. As we'll soon see, however, there's one additional piece of information you need to restore this data to a different machine. To start the Certification Authority Backup Wizard, open the Certification Authority console under Administrative Tools. Then, right-click on the node that represents your root CA (or the subordinate CA you want to back up in a distributed enterprise scenario) and select All Tasks Backup CA to start the wizard. The main screen of the wizard offers several choices, as shown in Figure 10-3. Figure 10-3. Backing up key data for a CA
The first time you back up your CA using this method, be sure to at least select the option to back up the private key and CA certificate for your CA. This will ensure that you can at least restore your CA in the event of an emergency, though if you do only this you will still have to reissue certificates to users. Therefore, in addition to backing up the private key and CA certificate, it's a good idea to also include in your backup the issued certificate log and pending certificate request queue for your server, which contains information about all certificates already issued by your CA and any requests from clients still pending. When you choose this option in the Certification Authority Backup Wizard screen (shown in Figure 10-3), you
also have the option to perform an incremental backup of your CA, which makes a backup of only those changes to the certificate database since your last full backup. This is trickier than it looks, so let's look deeper at the results of the backup process. If you choose only the first option, to back up the private key and CA certificate, and specify a folder such as C:\certback as the target for your backup, the result of the backup will be a file named CA_Name.p12, where CA_Name is the name you specified for your CA when you installed the Certificate Service on the machine and the *.p12 file extension means the file uses standard PKCS #12 cryptographic syntax. Since you are required to specify a password later in the wizard, this backup file is itself secured by being password-protected. Best practice here is to choose a complex, difficult password to protect your backup, but make sure you don't forget the password; otherwise, you won't be able to restore your root CA later. If you choose the other option, to back up the issued certificate log and pending certificate request queue, a subfolder named Database will be created in your certback folder. Inside this Database folder, copies of the certificate database files and certificate database log files for your CA will be created. The log files are basically transaction files that record changes made and pending to the database. Now, let's say you backed up everythingprivate key, CA certificate, certificate log, and queueon Monday, but on Thursday you processed a lot of certificate requests from users and now need to update the backup. There are two ways you could do this. First, you could simply back up everything again to a new (empty) folder and then discard your old backupnice and simple. The other way (the way recommended by Microsoft) is to make an incremental backup of your certificate log and queue, but if you try to save your incremental backup in the certback folder,
you get an error saying that you can make backups only to an empty folder. In this case, you might then create a subfolder under certbackperhaps a folder such as certback\17Nov03, which indicates the date you made your incremental backupand then back up to this folder instead of certback. The result will be to create another folder named DataBase, this one located at certback\17Nov03\DataBase. Within this folder, you'll find transaction logs but no database. Then, the following week, you can perform an incremental backup to a new folder named certback\24Nov03, and so on. Now, should you ever need to restore your CA from backup, you have to restore the full backup first, followed by all your incremental backups, in order. That's a lot of work. See why you might want to just perform a full backup every time instead? By the way, if you're wondering about the grayed-out "Configuration information" option in Figure 10-3, that option is used only for backing up a standalone CA (i.e., a CA installed on a standalone server in a workgroup environment). If you're working in an Active Directory environment (which is more likely), then the configuration information for your CA is stored in Active Directory and therefore doesn't need to be backed up separately like this. The nice thing in Windows Server 2003 is that this option is not even visible in the wizard when you're backing up an enterprise CA (i.e., a CA installed on a domain controller or member server in an Active Directory environment). Restoring a CA to a Working Server If your root CA becomes corrupt or your Certificate Services fails to start but your server is otherwise working fine, you can use your previously created backup to restore the private key,
root CA, certificate database, and transaction logs to their most recent working state. Just start the Certification Authority console in Administrative Tools, right-click on the root CA node, and select Restore CA to open the Certification Authority Restore Wizard, which is basically a mirror image of the Backup Wizard. If Certificate Services are running, they will be stopped temporarily to continue the restore. Select which components you want to restore, browse to locate the *.p12 backup file created earlier, and enter your password to begin the restore process. Once the restore is finished, Certificate Services will restart and you should have a working CA again for your organization. What if it still doesn't work? In that case, you might have a corrupt metabase. Internet Information Services (IIS) is a supporting component for the CA web enrollment portion of Certificate Services, and if the IIS metabase becomes corrupt, your CA won't be able to process CA enrollment requests. The solution, once you've restored the CA, is to restore the metabase as well [Hack #54]. Once the metabase has been restored, you should be able to load the Certificate Services web pages and process certificate requests again. If your root CA still doesn't work, your only solution might be to rebuild the machine from scratch and restore System State from tape backup media. This is a time-consuming process, but if your server is running Windows Server 2003, you might be able to speed the process by using the new Automated System Recovery [Hack #98] feature of that platform. Restoring a CA to a Different Server While root CAs are intended to last decades for large organizations, the actual hardware platforms they run on become
obsolete in time spans much shorter than the projected lifetime of the CA. As a result, you might someday find yourself wanting to move the role of root CA from an old machine to a more powerful new one. Leaving aside the problem of upgrading the operating system itself (who knows what version of Windows we'll be running ten years from now?), let's see now how to move the root CA role from one server to another, a process usually called upgrading your CA. First, make a full backup of the private key, CA certificate, certificate database, and transaction logs by using the wizard- based method described earlier in this hack. The result of the backup process is a password-protected file named CA_Name.p12 that contains the root CA's own certificate and private key, plus a Database folder that contains the database files and transaction logs. Then, back up the following Registry key on your old root CA: HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\CA_Name This key contains critical information about how Certificate Services are configured on your machine, and you will need this key to move your CA role to a different machine. Make sure you also make a note of the location where the certificate database and log files are located on your server. By default, they are both in the %SystemRoot%\system32\CertLog folder, but you might have placed them on a separate drive for increased performance when you installed Certificate Services on your old machine. Next, you need to prepare your new server to host the role of root CA for your organization. Take the server off the network and rename it with the same name as the old root CA. This step is essential, because the name of the server is included in all certificates issued by the CA. So, in order for previously issued certificates to be validated, the new root CA must have the same name as the old one. While Windows Server 2003 now
supports a process that lets you rename your domains and domain controllers, it's obviously simplest if you use a member server for your root CA, because member servers are easier to rename than domain controllers. Copy the CA_Name.p12 file and Database folder from your old machine to a temporary folder somewhere on your new machine, and have the Registry key exported from the old machine ready for import as well. Now, begin installing Certificate Services on your machine by using Add/Remove Windows Components (Control Panel Add/Remove Programs). When prompted to specify which kind of CA you want to install (enterprise or standalone, root or subordinate), select "Advanced options" (Windows Server 2003 replaces "Advanced options" with "Use custom settings to generate the key pair and CA certificate instead," but everything else is similar) and click Next to display the Public and Private Key Pair screen of the Windows Components Wizard, as shown in Figure 10-4. Figure 10-4. Importing the backed up information from your old root CA
Click the Import button, browse to locate the CA_Name.p12 backup file on your server, and enter the password you specified when you backed up your old CA. Complete the remaining steps of the wizard, being sure to specify the same path for the certificate database and log files that you were using on your old CA. Then, restore your database and log files from backup discussed in the previous section. Finally, restore the Registry key you backed up on the old CA to your new CA.
Restart Certificate Services, and you should now have a working root CA running on new hardware that will last you five years? Three years? Who knows, the way hardware platforms are advancing these days. Just be sure to test your new root CA thoroughly in all its aspects (e.g., processing certificate requests, validating certificates, and renewing and revoking certificates) before finally decommissioning your old root CA! Decommissioning the Old CA If you still want to use your old server for some other purpose on your network (as opposed to discarding it in the big blue bin behind your building), then you still have to do two things. First, you have to remove Certificate Services from it. But before you do this you need to remove the CA certificate and private key themselves, because you don't want them kicking around on some old machine on your network. To remove these cryptographic items, open a command prompt and type certutil -shutdown to stop Certificate Services on the machine. Then, type certutil -key to display a list of all cryptographic keys installed on the machine. Contained within this list should be a key named for the CA itself (CA_Name), which you can remove from the server by typing certutil -delkey CA_Name (enclose CA_Name in quotes if it contains spaces). Now you can use Add/Remove Programs in the Control Panel to uninstall Certificate Services, allowing you to use your old machine for some other purpose on your network. But don't forget this second step: rename your server so it won't conflict with the new root CA on your network!
Hack 94 Back Up EFS Backing up EFS recovery keys is essential if you want to be able to recover encrypted documents after a disaster. The Encrypting File System (EFS) lets you encrypt files so that unauthorized individuals can't read them. Normally, this is a good thing, because it helps secure data stored on a machine's hard drive. However, this hack is concerned with what happens when something goes wrongfor example, if a user's machine becomes toast, taking their EFS private key and certificate to Never-Never Land. The key to being able to recover encrypted files when something goes wrong is having a designated recovery agent already in place. Then, if you lose your EFS private key, the recovery agent can decrypt your encrypted files in an emergency. Every time you encrypt a file, EFS generates a unique File Encryption Key (FEK) that it uses to encrypt only that file. In other words, each encrypted file has its own unique FEK. In addition, the FEK is itself encrypted by using your own EFS public key and incorporated into the header of the file. Later, if you want to read the encrypted file, EFS automatically uses your EFS private key to decrypt the FEK for the file and then uses the FEK to decrypt the file itself. The FEK is thus used for both encrypting and decrypting the file (a process known as symmetric encryption), while your EFS public/private key pair is used for encrypting and decrypting the FEK (known as asymmetric encryption). This combination of symmetric (or secret-key) encryption and
asymmetric (public-key) encryption is the basis of how EFS works. But what happens if you lose your EFS private key? This might happen if your machine has two drives: a system drive (C:) and a data drive (D:), where encrypted files are stored. By default, your EFS keys are stored on your system drive, so if C: becomes corrupted, then the encrypted files on D: will be inaccessible, right? That's where the recovery agent comes in. Each time you encrypt a file, the FEK is encrypted with both your own EFS public key and the EFS public key of the recovery agent. That means that the recovery agent can always decrypt the FEK by using its EFS private key and thus decrypt the file when something goes wrong and your own private key is lost or corrupt. What are these recovery agents? By default, on standalone Windows 2000 machines, the built-in local administrator account is designated as a recovery agent, so you can always log on as administrator and decrypt any encrypted files stored on the machine. You can add other users as recovery agents by using the Local Security Policy console, which you can open by using Start Run secpol.msc. Then, expand Security Settings Public Key Policies Encrypted Data Recovery Agents, right-click on that node, and select Add to start the Add Recovery Agent Wizard. Any user accounts that already have X.509v3 certificates on the machine can then be added as recovery agents. On standalone Windows Server 2003 machines, the built-in administrator account is not a designated recovery agent. In fact, there are no default
recovery agents in Windows Server 2003 in a workgroup environment. You must designate an account for this role. In a domain environment, things are a little different. The built-in domain administrator account is the default recovery agent for all machines in the domain, and you can specify additional recovery agents by using Group Policy. Open the Group Policy Object (GPO) for the domain, OU, or site in which the intended recovery agent account resides, and navigate to Computer Configuration Windows Settings Security Settings Public Key Policies Encrypted Data Recovery Agents. Right-click on this node and select Add to start the same Add Recovery Agent Wizard as before, but this time browse the directory to locate the account you want to add. Once Group Policy refreshes, your new recovery agent will be able to decrypt files encrypted by other users, but only if the users encrypt the file after the new recovery agent was designated. This is because files encrypted previously have no information about this new recovery agent in their headers and therefore can't be decrypted yet by the new recovery agent. Fortunately, if the user who encrypted a file simply opens and then closes the file, this alone is sufficient for EFS to add the new recovery agent to the encrypted file's header. The moral of the story is that you should think before you implement EFS, and designate recovery agents before you allow users to start
encrypting files. Otherwise, you might find yourself sending out an unusual email to everyone saying, "Please open and then close all files you have encrypted on your machines" or something similar. Backing Up Encrypted Data and EFS Keys Backing up files that have been encrypted using EFS is easy: simply use the Backup utility to back them up like any other files you would back up. What's really important is that you also back up the EFS certificate and public/private key pair for each user who stores data on the machine. Since EFS is implemented on a per-user basis, this means you have to back up this information for each user individually. However, this information is stored in the user profile for each user, which means that simply by backing up user profiles you also back up their EFS certificate and keys. More specifically, a user's EFS private key is stored in the \Application Data\Microsoft\Crypto\RSA subfolder within that user's profile, while the user's EFS public key certificate and public key are stored in the \Application Data\Microsoft\SystemCertificates\My Certificates\My folder under the subfolders \Certificates and \Keys. You can back up users' EFS certificates and key pairs as part of your regular backup program and, if you have roaming user profiles configured, you can do this centrally from the file server where such profiles are stored. If you don't have roaming profiles implemented and users store important documents on their own machines, it might be necessary to have users back up their own profiles locally by using Backup to back up to file instead of tape. Unfortunately, this guards against profile corruption only, and it might not help if a disk failure causes the backed-up profile to be lost as well. A better alternative is to have users
export their EFS certificate and private key to a floppy and have them store it somewhere safe. That way, if their system drive crashes, they can still decrypt information on their data drive by importing their previously exported EFS certificate and private key. The steps to export a user's EFS certificate and private key are fortunately quite straightforward and can be done easily by any user. Simply open Internet Explorer, select Tools Internet Options, switch to the Content tab, click the Certificates button, and select the Personal tab, as shown in Figure 10-5. Figure 10-5. Exporting the EFS certificate and private key for user jsmith
Then, select the certificate you want to export (the correct certificate will display "Encrypting File System" beneath "Certificate intended purposes," near the bottom of the properties page) and click Export to begin the Certificate Export Wizard. Choose the option to include the user's private key in the export (the public key is automatically included in the certificate), specify a password to protect your export file, and choose a name and destination for your export file. As mentioned previously, users will typically export their EFS keys to a floppy, but you could burn them to a CD or even store them on a secure network share if you prefer. The important thing is,
wherever you export this information, keep it safe so that no one except the user and trusted administrators can access it. Anyone who gets their hands on the export file and cracks the password can use it to decrypt any encrypted files they have access to. The result of this export process will be a *.pfx file (called a Personal Information Exchange file), located in the target folder or media. Then, if the user's EFS keys later become corrupted and the need arises to reinstall these keys, this can be done either by repeating the previous process (but clicking Import instead of Export in Figure 10-5) or more simply by double-clicking on the .pfx file itself to start the Certificate Import Wizard. This wizard is smart enough to figure out that the EFS certificate and private key stored in the .pfx file should be imported into the user's personal certificate store. An interesting option to consider when exporting a user's EFS certificate and private key is to delete the user's private key from his profile during the process. This option is labeled "Delete the private key if the export is successful" and is found on the penultimate page of the Certificate Export Wizard. If you choose this option, you'll be able to encrypt files by using EFS, but you won't be able to decrypt them unless you supply the private key on some mediumsomething that might be an option to consider in a high security environment. Restoring EFS Keys If a user's EFS private key becomes corrupted or lost and the user hasn't backed up the key to a floppy as described in the previous section, then it's time for the recovery agent to step in. On a standalone machine, you can simply log on using the built- in administrator account, locate the encrypted folders the user
can no longer access in Windows Explorer, right-click on each folder, select Properties, click Advanced, and clear the "Encrypt contents to secure data" checkbox for each folder. This decrypts the files within the folders and enables the user to read them again. In a domain environment, you typically don't want to log on to a user's machine as a domain administrator and see a local user profile being created for your account as a result. Instead, simply instruct the user to use the Backup utility to back up to file any encrypted volumes or folders on her machine. The resulting backup file (*.bkf file) processes files it backs up as a data stream and preserves their encrypted status. Then, have the user copy her .bkf file to a network share where you as domain administrator can access the backup file, restore it to another folder, decrypt any files the user needs, and copy these files to the share where the user can access them. While this is the most common solution, there's another approach that's worth considering: unite the user with his EFS keys again. Even if the user hasn't previously exported his keys to a floppy for safekeeping, chances are, in a domain environment, that you make regular backups of user's profiles (assuming roaming profiles are enabled). By simply restoring a user's profile from backup you restore his EFS certificate and keys, allowing him to read his encrypted files again. Then, tell him politely but firmly to immediately export his certificate and keys to a floppy, because you don't want to have to go through this again! If EFS is being used to encrypt files on a file server where multiple users store their files, then this process can be complicated if you've designated different recovery agents for different groups of users. In particular, you might need to determine which recovery agents are designated for any encrypted files that users can no longer access. To do this, you
can use the efsinfo command-line utility included in the Windows 2000 Server Resource Kit. This handy little utility can tell you who originally encrypted a file and who the designated recovery agents for the file are. Just type efsinfo /r /u filename, where filename includes the path to the encrypted file. Once you know any recovery agent for the file, you can proceed to decrypt it as shown previously. What if the individual who can't access her encrypted files is your boss and she needs access to her files immediately? Export your own EFS certificate and private key to floppy as a domain administrator or other recovery agent, walk the floppy over to your boss's office, insert the floppy into her machine, import the certificate and private key, and decrypt her files. Then, delete the certificate and key from her machine. When she tries to encrypt a file again, a new EFS certificate and private key will automatically be generated. Smile, because you've acted like Superman, and send her an email later asking for a raise. But what if your own EFS certificate and private key as domain administrator or recovery agent is lost or corrupt? Backing Up Recovery Agent Keys Obviously, it's a good idea for administrators and other recovery agents to also make backup copies of their own EFS certificates and private keys. Otherwise, a point of failure exists in this whole recovery process and users' encrypted files could be lost forever and unrecoverable. If you're operating in a workgroup environment, recall that the built-in local administrator account is the default recovery agent in Windows 2000. This means you have to back up the EFS
certificate and private key of the administrator account, so log on to the machine using this account and use Start Run secpol to open Local Security Policy as before. Select the Encrypted Data Recovery Agents node under Public Key Policies in the left pane, right-click the EFS certificate in the right pane, and select All Tasks Export to start the Certificate Export Wizard. Choose the option to export the private key as well, specify a password to protect the export file, and specify a name and destination for exporting the informationtypically, some form of removable media, such as a floppy. Keep that floppy safe. In a domain environment, the built-in domain administrator account is the default recovery agent and the EFS certificate and private key are located on the first domain controller in the domain (the one that created the domain when you ran dcpromo on it). Log onto this machine using that account, use Start Run dompol.msc to open the Domain Security Policy, select Encrypted Data Recovery Agents in the left pane, right-click the EFS certificate in the right pane, again select All Tasks Export to start the Certificate Export Wizard, and proceed as before. If you are not given the option to export the private key, you might not be logged onto the right domain controller, so change machines and try again. Another method for exporting certificates and keys is to use the Certificates snap-in. Open a blank MMC console, add this snap- in while logged on as administrator, expand Certificates - Current User Personal Certificates, and find the certificate you want to back up by looking under the Intended Purposes column, as shown in Figure 10-6. The power of this approach is that you can also use it to back up and restore other sorts of certificates and keys, including EFS keys.
Figure 10-6. Using the Certificates snap-in to back up a recovery agent key Now that you've backed up your recovery agent's EFS certificate and keys, you're ready for the worstunless your dog eats your floppy!
Hack 95 Work with Shadow Copies Shadow copies are a new feature of Windows Server 2003 that lets you save point-in-time copies of your filesan excellent complement (but not a replacement) for your regular backup plan. Windows Server 2003 includes a new feature called the Volume Shadow Copy Service (VSS) that can save administrators time when users are concerned. When shadow copies are enabled on an NTFS volume, Windows makes point-in-time shadow copies (or snapshots) of files on the volume at predefined intervals. Users can then access these shadow copies to recover accidentally deleted or overwritten files without requiring the administrator to intervene to restore these files from backup media. This feature also allows users to compare current versions of documents with previous versions, to check for differences without requiring that users actually save separate versions of these documents along the way. Either way, administrators are freed from the hassle of responding to users' requests for restoring their files from backups, and any time gained nowadays for the harried network administrator is an asset. On the other hand, implementing shadow copies on file servers is not a replacement for a regular backup program, because shadow copies are stored on disk in the same way the original files are stored. So, if a disk goes on your file server, it could mean that both the original files and shadow copies might be
gone, depending on how you've configured your file server. Also, shadow copies are read-only copies and can't be edited directly. In fact, a shadow copy of a file isn't really a file at all; it's a block-by-block record of changes that were made to the file since the last shadow copy was made. So, to protect your business from data loss, be sure to combine shadow copies with regular tape backups using the Windows Backup utility or some third-party product. Implementing Shadow Copies Like most successful IT initiatives, implementing shadow copies starts with good planning. Disk space considerations are a good place to start, since shadow copies require a minimum of 100 MB of free space for each volume on which you enable them. That minimum can also grow quickly, depending on how actively users modify their files and how aggressively you've scheduled shadow copies to occur. In fact, even if you only have a few kilobytes of files on your file server, the first time a shadow copy of a volume is made, it takes up the full 100 MB space allocated to this feature. By default, the maximum amount of disk space used for shadowing a volume is 10% of the size of that volume. So, if you shadow a 20 GB data volume on your file server, up to 2 GB of space will be needed to store the shadow copies of files on this volume. However, if the need arises, you can increase this maximum at any time. This is important, because if the maximum is reached, then shadow copies start dropping the oldest versions to make room for the new.
If this 10% limit reminds you of the default settings for Recycle Bin, you're right. Shadow copies are designed to function as a kind of network-enabled recycle bin for your users. In other words, if you enable shadow copies on a volume, any shared folders on the volume automatically save point-in-time versions of documents in these shares. Actually, it would be nice if the Recycle Bin automatically did that locally as well. (Perhaps in Longhorn?) One planning option to consider seriously is to store shadow copies on a different volume than the one where users' data files reside, preferably on a different physical drive as well. That way, you can plan separate disk-space needs for original files and their copies. However, many administrators don't realize that if you discover later that your shadow volume is insufficient and you want to move the shadow copies to a different volume, doing so causes you to lose all shadow copies of user files. Backing up the shadow volume in this case and restoring it to the new volume won't work, because VSS can't be configured manually to find its copies in a moved location. To work around this problem, you can store your shadow copies on a dynamic volume, which you can extend later by adding free disk space on the same drive or another drive. Also remember that shadow copies are enabled on a per-volume basis. So, when you enable this feature on a data volume, all shared folders on that volume will have shadow copies created
for files within them. This is an important issue that is usually not considered in the planning stage. In fact, this issue should actually be considered before you even set up your file server in the first place. In other words, to implement shadow copies effectively, you need to ensure that shared folders on your file server are grouped together appropriately onto separate volumes, according to the level of user activity for those shares. Group together shares within which users frequently modify files according to how often they modify them: high-activity shares on one volume, medium activity on another, low activity on a third. This will help you plan separate shadow-copy schedules for each volume: frequent copies for high-activity volumes and infrequent copies for low-activity volumes. If you are planning on upgrading your Windows 2000 file servers to Windows Server 2003, consider reorganizing the volumes and shares on your servers as part of the upgrade process. Configuring shadow copies is basically a three-step process: configure it on the server, configure it on the client, and educate users how to use it. The last step is often forgotten from the IT perspective, because it's not strictly in the "techie" realm of things, but it's just as important as the other two steps. For increased security, shadow copies are disabled on all NTFS volumes until you enable them on the server. If you're logged on locally, the easiest way to enable shadow copies is to right-click on any volume, select Properties, switch to the Shadow Copies tab, select the volume on which you want to enable shadow copies, and click Enable (see Figure 10-7). Figure 10-7. Enabling shadow copies on a volume
Actually, before you enable this feature on a volume, it's a good idea to first review the default settings for shadow copies by clicking on the Settings button shown in Figure 10-7. The
default settings store the shadow copies on the same volume as the one you are enabling, use up to 10% of the volume to store copies, and make new shadow copies of files every weekday (Monday through Friday) at 7 a.m. and noon. The rationale behind the schedule is to save copies before users arrive at work (when they open their files) and around lunchtime (when they are halfway through their workday). You can create almost any schedule you want for when shadow copies should occur, but avoid scheduling it to occur too often (e.g., once an hour), due to the excessive load it will place on your server. When planning your schedule, also remember that shadow copies will save a maximum of 64 different versions of a file before deleting older versions to make room for new versions. So, if you leave the default twice-a-day schedule in place, users will be able to restore a version up to 32 days old. Anything older than that you'll have to restore from backup for them. Be sure to clearly communicate to users your schedule of when shadow copies will be made so that they don't rely on this feature excessively. Users should still consider themselves responsible for making versioned copies of files they work on and should view shadow copies only as a tool of last resortjust in case they accidentally delete a file or overwrite itrather than something they'll use to save versions of their work. As administrator, you can also force a shadow copy to occur at any time; just select the volume and click the Create Now button shown in Figure 10-7. This can be a useful feature if there are certain times when user activity is high, such as year-end finalization of budgets. Instead of modifying your schedule, you could manually create an extra shadow copy or two during the days just before the deadline. You might be wondering where shadow copies are stored on a volume. If you create a new 5,000 MB data volume E:, enable
shadow copies on the volume, and click Create Now to generate shadow copies immediately (even though there are not files yet on your volume), then, when you select the E: drive in My Computer, you should see around 4,900 MB of free space. In other words, shadow copies immediately use the minimum 100 MB allocated to it the first time they operate. But your drive is still empty when you open it in Windows Explorer. If you use Tools Folder Options View to show hidden files and unhide hidden system files, you'll see a folder named System Volume Information that has System and Hidden attributes enabled; that's where your shadow copies are all stored. This volume is accessible only to the built-in system account on your server, not to administrators. Once you've reviewed and modified the shadow-copy settings for a volume and enabled shadow copies on that volume, your server begins to save shadow copies of all files stored on the volume. That includes all files, not just ones in shared folders on the volume. In other words, even if you modify a file locally on the volume and the file is stored in a folder that isn't shared, a shadow copy will still be created for that file. That way, if you later decide to share the folder for others to access, a history of versions of files in the folder will be displayed. In a network environment, where it's not convenient to log on locally to your file server, you can still enable shadow copies by using Computer Management. Just open Computer Management on your administrator workstation, connect to the remote file server, right-click on the Shared Folders node, and select All Tasks Configure Shadow Copies. This works only from workstations running Windows XP Professional with Service
Pack 1 and the Windows Server 2003 Administration Tools Pack or, alternatively, from another machine that is running Windows Server 2003. Once shadow copies are enabled on the server, they still have to be enabled on the users' client computers. By default, only Windows Server 2003 has shadow-copy functionality built right into it; all previous versions of Windows require that special client software be installed on them before users can use this feature to access previous versions of files. If your desktop computers are running Windows XP Professional (the desktop operating system that most closely integrates with Windows Server 2003 on the back end), you can install shadow client software on them easily. Just share the %Systemroot%\System32\clients\twclient\x86 folder on your server, and then instruct users to connect to this share and double-click on twcli32.msi to run the Windows Installer File. Alternatively, you could use the software-installation feature of Group Policy to deploy this feature automatically to all desktop machines in an organizational unit, domain, or site. You could even email the installer file to your users, along with instructions on how to install and use it. If your desktops are running Windows 2000 Professional (with Service Pack 3 or later) or Windows 98 Second Edition (SE), you need to download a different shadow-software client from the Microsoft Windows Download Center (http://www.microsoft.com/downloads/) and deploy it by using one of the methods described previously (you also have to
install the same client software on the server). If your desktops are running Windows NT 4.0 Workstation or Windows Millennium Edition (ME), then you're out of luck. Using Shadow Copies Let's say you've enabled shadow copies on volume E: on a Windows Server 2003 file server, and this volume is used to store users' files in a series of shares named Budgets, Projects, and so on. How can a user access previous versions of her files in these shares, and what actions can she perform on them? Say a user uses Start Run \servername\budgets, where servername is the name of the file server where the Budgets share is located. This will open a window on the user's desktop, displaying all files stored in that share. Users can right-click on a particular file in that share, select Properties, and switch to the Previous Versions tab shown in Figure 10-8. If this tab is missing, then the user's computer doesn't have the shadow-copy client software installed. Figure 10-8. Accessing previous versions of a file using shadow copy client software
All previous point-in-time versions of the selected file are displayed in this tab (if no previous versions are displayed, the file hasn't been modified since it was created). The View, Copy, and Restore buttons enable the user to perform different tasks with these versions. For example, to view the contents of a previous version, click View. This is helpful when you're not sure which previous version is the one in which you wrote that lovely paragraph but later deleted in a fit of writer's despair. Once you've found the previous version of the file you want, you could save it to your My Documents folder and give it a descriptive name. Alternatively, if you already know which version you're interested in (such as the most recent previous version) you
could click Copy to copy that version to a different location. If you're really confident, you could click Restore to overwrite the current version of the file (the one you're working with as a user) with the previous version specified. If you're not even sure which file had that wonderful paragraph you wrote, but you know it's in the Budgets share, you could right-click on an empty area within the open share window, select Properties, and switch to the Previous Versions tab of the share itself. This displays all previous shadow copies made of that share and lets you view previous versions of individual files within the share, copy a previous version of all files in the share to another location, or roll back all files in the share to the specified previous version. The bottom line is, when educating users on how to use shadow copies, tell them to ignore the Restore button and always use View and Copy instead. One user carelessly restoring an entire shared folder to its previous version could result in lost work and its accompanying frustration for other users who have access to the same share. Of course, if users work only with their own files but store them in the same share, this might not be an issue, depending on how NTFS permissions are configured on the shared folder. But if users have collaborative access to a document, problems can result when using shadow copies. Of course, such problems can result even without shadow copies functionality. Here's something else to consider that is often forgotten: NTFS permissions change differently, depending on whether you copy a file or move it. So, in the case of shadow copies, if you restore a previous version of a file, it overwrites the original file in its original location but maintains the same NTFS permissions as the original file. But if you copy a previous version of a file to a different location on your drive, the copy inherits the permissions of the folder you copy it to.
Traps In addition to poor planning and scheduling, resulting in insufficient disk space, there are a few other things you need to watch out for when implementing shadow copies. The first thing has to do with the block-based mechanism by which the VSS makes copies of changes made to files. If the filesystem cluster size is smaller than this block size, some of your shadow copies might disappear when you defragment your volume using the built-in Disk Defragmenter node in Computer Management. To prevent this from happening, always ensure that volumes on which shadow copies are stored have cluster sizes of 16 KB or greater. By default, on Windows Server 2003, any volumes larger than 2 GB will have a cluster size of only 4 KB, which is insufficient. To solve this problem, when you format the volume, specify an allocation unit size of 16 KB instead using either Disk Management or the /a switch with the format command. On large volumes, you could use even higher cluster sizes of 32 or 64 KB. But if the volume will be used to store many small files, this can result in much wasted space on your drive. So, 16 KB is probably the optimal solution in most cases. If you upgraded your server from Windows NT 4.0 Server and the volume was converted from FAT to NTFS by using the convert command, you're out of luck. Because convert always uses an allocation unit size of 512 bytes to optimally align with FAT filesystem boundaries, don't use a converted volume for storing shadow copies on a server. However, if your machine was previously running Windows 2000 Server, you might be in luck, because that platform allowed you to format FAT volumes with larger cluster sizes.
Here are some other things to watch for: Don't enable shadow copies on a volume that has mount points on it. A mount point (or mounted drive) is a special volume that is attached to an empty folder on an NTFS volume. In other words, a mount point named Data could be attached to the folder E:\Stuff if volume E: is formatted using NTFS. In Windows Explorer, Data would appear just like any other volume, and mount points would therefore provide a way to get around the 26- letter limit for naming volumes using drive letters. The problem is that mount points are not included when shadowed copies are made for a volume, which means that files stored in these mounted drives will not have previous versions accessible to users. Also, if you share a mount point that's located on a volume that has shadow copies enabled, users won't be able to access previous versions of files in the folder attached to the mount point. So, it's best to avoid mount points entirely on shadowed volumes. Avoid using shadow copies on dual-boot configurations, where Windows Server 2003 and some earlier operating system such as Windows NT 4.0 Server are installed on the same machine. Corruption of shadow copies has been known to occur in such scenarios. Best practice is usually to enable shadow copies on any volume where data files are stored, because the enhanced Backup utility included with Windows Server 2003 can back up open files on a volume on which shadow copies are enabled. That means that if users
leave files open on their machines at night, the files can still be backed up instead of being locked and prevented from being backed up as in previous versions of Windows Backup. In this kind of scenario, it might be a good idea to schedule additional shadow copies to occur an hour or so before Backup is scheduled to run. You can also turn backing up of shadowed volumes on and off using the /SNAP switch in ntbackup, the command-line version of the Backup utility. Don't enable shadow copies on a system or boot volume, because there have been reports of excessive generation of shadow copies. This causes poor system performance, especially on domain controllers where the contents of Active Directory is frequently updated. Programs that create many temporary files on these volumes can also cause shadow copies to grow quickly and fill up your volume if you give them enough room to do so, and a system volume that fills up is one that blue- screens. If you accidentally delete any of the default hidden administrative shares on your server, you won't be able to enable shadow copies on any volumes on your machine. Fortunately, Microsoft has a workaround in such circumstances. Search the Knowledge Base on Microsoft Product Support Services (PSS) at http://support.microsoft.com for information on how to restore default administrative shares. Finally, before you delete a volume that has shadow copies enabled on it, disable shadow copies on the volume. If you don't, your event log might fill up with ID
7001 error messages, which can be annoying.
Hack 96 Back Up and Clear the Event Logs Here's a nifty script you can use to back up and clear the Event logs on your servers. Managing Event logs is an essential part of a system administrator's job. These logs are useful for a number of reasons, including troubleshooting system problems, verifying that services are functioning properly, and detecting possible intrusion attempts. While Event Viewer can be used to save and clear these logs, it can be handier to use a script you can run manually (by double-clicking on a desktop shortcut) or automatically at different times (by adding a task to the Scheduled Tasks folder). This hack provides a script to do just that. This VBScript will back up your Windows Event Logs and then clear the information contained within them. The Code Type the following script into Notepad (make sure to have Word Wrap disabled), and save it with a .vbs extension as archivelogs.vbs: Option Explicit
On Error Resume Next Dim numThreshold Dim strMachine Dim strArchivePath Dim strMoniker Dim refWMI Dim colEventLogs Dim refEventLog If WScript.Arguments.Count < 2 Then WScript.Echo _ "Usage: archivelogs.vbs <archive_path> [threshold]" WScript.Quit End If If WScript.Arguments.Count = 2 Then numThreshold = 0
Else numThreshold = WScript.Arguments(2) If Not IsNumeric(numThreshold) Then WScript.Echo "The third parameter must be a number!" WScript.Quit End If If numThreshold < 0 OR numThreshold > 100 Then WScript.Echo "The third parameter must be in the range 0-100" WScript.Quit End If End If strMachine = WScript.Arguments(0) strArchivePath = WScript.Arguments(1) strMoniker = "winMgmts:{(Backup,Security)}!\" & strMachine Set refWMI = GetObject(strMoniker)
If Err <> 0 Then WScript.Echo "Could not connect to the WMI service." WScript.Quit End If Set colEventLogs = refWMI.InstancesOf("Win32_NTEventLogFile") If Err <> 0 Then WScript.Echo "Could not retrieve Event Log objects" WScript.Quit End If For Each refEventLog In colEventLogs 'if shouldAct( ) returns non-zero attempt to back up If shouldAct(refEventLog.FileSize,refEventLog.MaxFileSize) <> 0 Then If refEventLog.ClearEventLog( _ makeFileName(refEventLog.LogfileName)) = 0 Then WScript.Echo refEventLog.LogfileName & _
" archived successfully" Else WScript.Echo refEventLog.LogfileName & _ " could not be archived" End If Else WScript.Echo refEventLog.LogfileName & _ " has not exceeded the backup level" End If Next Set refEventLog = Nothing Set colEventLogs = Nothing Set refWMI = Nothing Function shouldAct(numCurSize, numMaxSize) If (numCurSize/numMaxSize)*100 > numThreshold Then shouldAct = 1 Else
shouldAct = 0 End If End Function Function makeFileName(strLogname) makeFileName = strArchivePath & "" & _ strMachine & "-" & strLogname & "-" & _ Year(Now) & Month(Now) & Day(Now) & ".evt" End Function Running the Hack To run the script, use Cscript.exe, the command-line script engine of the Windows Script Host (WSH). The script uses the following command-line syntax: archivelogs.vbs machine archive_path [threshold] In this syntax, machine is the name of the server, archive_path is the path to where you want to save the backup, and threshold is an optional parameter that checks to see the size (in MB) of the logs.
If the logs are above the threshold value you specify, the script will back them up. Otherwise, it will skip them. The following example shows how to run the script and provides typical output when the script is executed against a domain controller. The archive directory C:\Log Files must first be created on the machine on which you run the script. C:>cscript.exe archivelogs.vbs srv210 "C:\Log Archive" Microsoft (R) Windows Script Host Version 5.6 Copyright (C) Microsoft Corporation 1996-2001. All rights reserved. Security archived successfully System archived successfully Directory Service archived successfully DNS Server archived successfully File Replication Service archived successfully Application archived successfully
C:> The result of running the script is a set of files in C:\Log Files of the form srv210-Application-20031217.evt, srv210-Security- 20031217.evt, and so on. Note that each archive file is named according to the server, event log, and current date. If you plan on using the Backup utility instead to back up the Event log files on your Windows 2000 servers, it might surprise you to know that being part of the Backup Operators group will not allow you to back up or restore these Event log files; this right is available to only local or domain administrators! Rod Trent
Hack 97 Back Up the DFS Namespace If you've implemented the Distributed File System (DSF) on your network, you need to back up your DFS namespace regularly. The Distributed File System (DFS) is a feature of Windows 2000 Server and Windows Server 2003 that lets you create a single logical tree of shared folders that are physically located on different file servers on your network. This makes it easier for administrators to manage shared folders, and it also helps users find shared resources, since the resources appear from the user's point of view as a single hierarchical set of folders on a single machine. As a result, to locate a particular shared folder on the network, users don't have to know the actual file server on which the folder resides; they just have to connect to the DFS tree and browse until they find the folder they require. Then, if the user has the appropriate permissions to access the folder, he can do whatever he needs to do with the files stored within it. A collection of shared resources arranged in a logical hierarchy like this is called a DFS namespace. This namespace begins with the DFS root, which forms the bottom of the DFS tree. The branches of the tree are called DFS links and they map to shared folders on different file servers across your network. Windows 2000 Server machines can host only one DFS root (hence, only one namespace), but the Enterprise Edition of Windows Server 2003 supports multiple DFS roots on a single machine. If you're using DFS, it's important that you back up your DFS
configuration for your Windows 2000 domain. Unfortunately, many disaster-recovery products on the market that support Windows 2000 do not have a native add-in to support the backup and restoration of the DFS namespace. Fortunately, Microsoft has included in Windows 2000 two command-line-based tools (DFScmd and DFSUtil) to facilitate such a need. While the functionality in these tools is also provided in the GUI by the DFS snap-in for the MMC, using the command- line tools gives you the added flexibility of using them to create a script that you can execute via Task Scheduler to automate the backup process if your DFS topology changes often. DFScmd The first command-line utility, DFScmd, allows you to back up the DFS namespace to a text file that can be accessed later to restore the namespace if necessary. Here's the syntax to perform a backup: DFScmd /view \DFSName\DFSShare /BATCH >> "path\filename.bat" For example, if you have a domain-based DFS namespace for the domain Consoto.net, with a DFS root named DFSRoot, then your backup syntax would look like this: DFScmd /view \Consoto.net\DFSRoot /BATCH >> C:\Temp\dfsbackup.bat Here's an example of what is saved in this batch file: REM BATCH RESTORE SCRIPT REM dfscmd /map "\consoto.net\DFSRoot" "\servera.consoto.net\DFSRoot" "DFS Root for
Consoto.Net members." dfscmd /map "\consoto.net\DFSRoot\Departments\Finance" "\serverb.consoto.net\finance$" "Finance Department." dfscmd /map "\consoto.net\DFSRoot\Departments\ISS" "\serverb.consoto.net\dept_iss$" "Information Systems Department." dfscmd /map "\consoto.net\DFSRoot\Domain Support\IIS Published Sites" "\serverc.consoto.net\inetpub$" "IIS Web Sites published for Internet/Intranet Access." The command completed successfully. To restore the DFS volume structure (namespace) from the server it was originally hosted on to a new file server in the domain, perform the following steps. Start Distributed File System from Administrative Tools and on the Action menu click New DFS Root. Click Next and then choose the proper type of DFS root for your domain. Select the server that will host the DFS root and then click Next. Select the share that will become the DFS Root Share and then click Next. Finally, insert a comment, click Next, and then click Finish. The new DFS root is now available. Now, run the batch file created earlier to restore the DFS volume structure. When the batch file has completed execution, verify that the namespace has been properly created. In our example, the DFS namespace should now appear in the Distributed File System Administrator like this: DFSRoot Departments
Finance ISS Domain Support IIS Published Sites DFSUtil The second command-line utility, DFSUtil, allows you to query and perform troubleshooting of the DFS metadata with domain- based DFS implementations. DFS metadata is configuration information of DFS that is stored in the Active Directory-based Partition Knowledge Table. The functionality of the command- line-based DFSUtil parallels the functionality of the Distributed File System MMC snap-in. While DFScmd is a built-in operating system command, DFSUtil can be found on your Windows 2000/2003 product CD under the Support\Tools directory in the SUPPORT.CAB file. If you plan on using these utilities, I recommend you download the latest SUPPORT.CAB file from Microsoft's web site at http://www.microsoft.com/downloads/ if you are running Windows 2000 Service Pack 2 or later. The service packs include updated versions of DFSUtil.exe that resolve issues encountered with the original version found on your Windows 2000 Server CD. Matt Goedtel
Hack 98 Recover with Automated System Recovery Automated System Recovery (ASR) is a new feature of Windows Server 2003 that makes recovering from a disaster a whole lot easier. Rebuilding a server after a disaster is generally not a trivial task. The process usually involves reinstalling Windows from scratch, reconfiguring disk partitions to the exact configuration they had before the failure, and then restoring the system volumes, boot volumes, and all your data volumes. The process is not especially complicated, but it takes a considerable amount of time to do it right, usually with significant involvement of the administrator along the way. With Windows Server 2003, however, things have suddenly gotten much easier. Automated System Recovery (ASR), a new feature included in the Backup utility, greatly simplifies the process of recovering a server that won't boot because of severe problems with the system/boot volume, such as Registry corruption. By automating the process of restoring a failed server, ASR saves you time and reduces the chances for making mistakes. ASR is an essential part of the Recovery Roadmap [Hack #99] for troubleshooting problems that might happen to Windows servers, and this hack leads you through the process step by step. I'll also clarify how best to use this feature and how to resolve problems that can arise.
ASR Backup The simplest way to back up your system with ASR is to use the Backup or Restore Wizard that starts by default when you select Accessories System Tools Backup. Simply start the wizard, select "Back up files and settings," and choose the option to back up "All information on this computer." Then, specify the remaining backup job parameters as usual. The result is that all information on your hard drives is backed up, including the boot, system, and data volumes. Later, should a disaster occur, you can restore your system by using the ASR restore process to the exact configuration it had earlier. The backup is done by using shadow copies [Hack #95] to ensure that any open files on the system and boot volumes are properly backed up. Note, however, that this applies mainly to the system and boot volumes, which are critical for successful ASR backup. While shadow copies are also used to back up data volumes, these shadow copies are deleted afterward unless you've specifically enabled shadow copies on these volumes to help protect users' work from accidental loss or damage. An alternative method for performing ASR backup is to start Backup and switch to Advanced Mode. Then, under the Welcome tab (Figure 10-9), select the Automated System Recovery Wizard button. This wizard lets you back up only information on your system and boot volumes that is critical to restore your system; it does not back up any data volumes, which are usually best left for your regular backup program to handle anyway. Figure 10-9. Starting the Automated System Recovery Wizard
During the ASR backup process, you're asked to insert a blank, formatted floppy to create a system recovery disk (commonly called an ASR floppy). This floppy is critical to the ASR restore process, so it's worth digging a little deeper into how it's used. The ASR backup process saves two files onto your floppy: the ASR state file (asr.sif), which contains information about the disk signatures and configuration of disk volumes on your machine, and asrpnp.sif, which contains information about different Plug and Play devices on your system. These two files are critical for the recovery of your system, because they connect the underlying hardware configuration with the operating system above it. As we'll see in a moment, you need to insert
this floppy at the beginning of the ASR restore, in order to rebuild the disk subsystem and hardware configuration of your system before restoring the contents of the system and boot volumes. What if you have no floppy disk drive on your machine? Fortunately, you can still use ASR to back up your system, but its a bit of a workaround. During the ASR backup process copies of these asr.sif and asrpnp.sif files are also saved in the %SystemRoot%\Repair folder on your server. So, when you receive a prompt at the end of the backup process to insert a floppy, simply ignore the prompt and instead copy asr.sif and asrpnp.sif from Repair to a network share on another server (one that has a floppy disk drive installed). Then, copy the files from the share on that server to a blank floppy you insert into its drive, and you now have a working ASR floppy for your backup. Then, go buy a USB external floppy drive, because you'll need it if you ever have to rebuild your original server from the backup set you created. In other words, you can perform ASR backup without a floppy, but you cannot perform an ASR restore without one. What if you lose your ASR floppy? Well, the procedure just described will work in this case too. Just insert a new blank, formatted floppy into your server and copy asr.sif and asrpnp.sif from the Repair directory to the floppy. Note that these files must be located in the root folder on the floppy for the restore process to work, so use a separate floppy for each ASR backup; don't try to combine several ASR backups in different folders on one floppy. However, since the Repair directory is located on the boot volume of the system itself, if your system volume is toast, then so is your Repair directory and the files within it. So, what if you've lost your ASR floppy and the Repair directory is gone with your hard drive? There's still a workaround that can save your bacon: use
the Backup utility on a different machine to open the backup catalog for the ASR backup set you want to restore, expand the %SystemRoot%\Repair directory on the boot volume, select asr.sif and asrpnp.sif as the files you want to restore, insert a blank floppy, and restore these two files to the root of the floppy. Presto! You now have a recovered ASR floppy you can use to initiate a restore. ASR Restore The ASR restore process in a nutshell is as follows: first, the disk configurations are restored; then, your system and boot volumes are formatted; and, finally, a bare-bones version of Windows is installed that starts Backup and rebuilds your system and boot volumes from your ASR backup set stored on tape media. Note that your system and boot volumes are formatted. Clearly, using the ASR restore process should be considered a last-ditch effort, to be used only when everything else fails. See [Hack #99] for information on how to choose between the various recovery options for Windows servers.
Using ASR restore Let's look at a restore in more detail. First, make sure you have your ASR floppy, tape backup media, and original installation files for Windows Server 2003 (i.e., the product CD). If you have any mass storage controllers on your server that require an updated driver to replace the one on the product CD, be sure to have this handy as well. Alsoand this might be importantbe sure to back up any data files or folders located on your system or boot volumes. Since ASR reformats these volumes, anything other than the Windows operating system files that are located on these volumes might be lost. Mind you, best practice is to never store data files on these volumesyou should store them on separate volumes insteadso if you've been following this practice you have nothing to worry about, right? Note that I said might be lost, not will be lost. While Windows documentation says that non-operating system files stored on system/boot volumes won't be restored by ASR, my own experience is that they are restored sometimes and other times not. So, just to be safe, back up these volumes separately using normal backup procedures so you can later restore any missing data files. Now, insert your product CD and boot from your CD-ROM drive (press the appropriate key to do this if required). Press F6 when prompted if you have an updated device driver for your mass storage device. Then, press F2 when text-mode setup prompts you to perform ASR restore, and insert the ASR floppy when asked to do so. The recovery process will rebuild the disk signatures and partition table, reformat the system/boot volumes, copy installation files, and begin installing Windows. A short while into the installation of Windows, the Automated System Recovery Wizard screen will ask you to specify the
location of the tape backup media where your ASR backup is located. Once you specify this, the recovery process continues and it's considerably faster than the Windows installation process itself, which is nice. Be sure not to interrupt this process; otherwise, you'll have an incomplete and nonfunctional server. Once the restore process is finished, the logon screen appears and you're done. That is, you're done unless your system was totally fried and you have to rebuild it from scratchin which case, you have to complete the procedure by restoring any data volumes on your server from your regular backup sets. Here's one more thing that's helpful, but not documented. Running the ASR restore process also creates a setup.log file that identifies the system and boot volumes, checksums for kernel files, the directory where Windows is installed, and the device drivers loaded during setup. A copy of this file is placed in %SystemRoot%\Repair and also another one is placed on the ASR floppy itself, which is handy for verifying the details of the restore process. Print that log and keep a record of it for troubleshooting purposes later. Hacking the restore If your original machine is really toast, you can use ASR to restore to a different machine. However, to do this, you must ensure that the hardware on your new system is identical to your original (toasted) system, with the exception of the video card, network card, and hard disks, which can be different brands or types. Concerning hard disks, however, make sure the number of hard drives in your new system is equal to or greater than the
number of hard drives on the old system, and also make sure that the storage capacity of each drive is the same or larger than drives on your old system. If you're using ASR to restore a failed server to another system with hardware that does differ significantly from the old one, there's a workaround: you can hack the asr.sif file to make the ASR restore process install additional device drivers (or any other kinds of files) that might be needed by the text-mode setup process to install Windows successfully and complete the recovery. The asr.sif file is a text file with different sections, identified by brackets: [VERSION] Signature="$Windows NT$" ASR-Version="1.0" [SYSTEMS] 1="SRV230","x86","5.2","C:\WINDOWS",1,0x00020112,"360 0 -60 0-10-0-5 2:00:00.0 0-4-0-1 2:00:00.0","Central Standard Time","Central Daylight Time" [BUSES] 1=1,3
[DISKS.MBR] 1=1,1,1,0xdbe3dbe3,512,63,255,16514064 By adding an additional [InstallFiles] section, you can specify additional files that need to be copied to the machine during text-mode setup. For example, adding the following section will cause the driver file MyDriver.sys to be copied from the root of the floppy disk that has the volume label My Drivers to the %SystemRoot%\System32\Drivers folder on the machine: [InstallFiles] 1=1,"My Drivers","Floppy","%SystemRoot%\System32\Drivers\MyDriver.sys","My Company Name", 0x00000001 During text-mode setup, a prompt will ask you to insert the floppy disk that has the driver file for My Company Name, and the 0x00000001 flag indicates that this prompt will always appear. Other flags can also be used, including 0x00000006, which indicates that ASR recovery can't proceed unless you load the specified driver file; 0x00000010, which indicates that any existing copy of MyDriver.sys should be overwritten by the new file; and 0x00000020, which prompts before overwriting an existing version of the file. Using this hack, you can customize the ASR restore process to make it successful, even if there are some hardware differences between the original machine and the new one. Using ASR
Finally, many administrators don't understood when to use ASR to back up the system and when they should just use regular backups. You should back up your system anytime you change your hardware or operating system configuration. Examples of such changes might include upgrading to a new version of the operating system, installing service packs or hotfixes, adding new disk storage or changing the partition layout of your volumes, switching from basic to dynamic storage, installing a new Windows component or service, installing and configuring a third-party application, installing new hardware or upgrading device drivers, and so on. Doesn't this sound suspiciously like the instructions for creating the old Emergency Repair Disk (ERD) on Windows NT/2000? Yes, though ASR is a far more powerful feature than the ERD. since it backs up the System State and Registry on your machine, it does include similar functionality to the ERD, including saving a copy of your Registry hives in the Repair folder. But while the ERD could be used only to replace corrupt or missing system files or Registry hives, ASR is a complete system-recovery feature that does everything the ERD did and moreautomatically. You don't need to use ASR for backup when your system is tuned and running perfectly and only user data files are being created, modified, or deleted on your server. If you've properly partitioned your system so that all user data files are on data volumes separate from the boot and system volumes, then you can simply back up these data volumes on a daily basis to ensure nothing is lost in the case of a disaster. But if you change your basic operating system or underlying hardware in an significant way, use Backup to create a new ASR backup set so that you can recover your system to its current state, should massive failure occur.
Hack 99 Recovery Roadmap When it comes to troubleshooting startup problems, finding the right tool for the job is the key. Would you try to crack a walnut with a bulldozer? Or pry open a door with a toothpick? Every tool has its purpose, and using the right tool for the job gets the job done quick and easy. The same is true concerning the maze of troubleshooting options available for restoring Windows 2000 and Windows Server 2003 systems that fail on startup. Safe Mode, Last Known Good Configuration, Emergency Repair Disk, Recovery Console, Automated System Recovery, Windows Startup Diskwhich should you use and in which situations? This hack helps you get your toolbox in order by answering that question. Windows 2000 I'll start with Windows 2000 and then highlight differences in troubleshooting issues on the newer Windows Server 2003 platform. Obviously, we won't be able to cover every possible scenario or even the intricate details of specific situations, but if you follow the procedures outlined in this hack, you should be able to get started and figure the rest out yourself, with the help of various Knowledge Base articles on Microsoft Product Support Services (http://support.microsoft.com).
To make things crystal clear, here's the big picture, right from the start:
- If the system won't boot, boot with the Last Known Good Configuration. If that fails or isn't an option, try booting into Safe Mode or one of its variants. If that fails or isn't an option, try using the Recovery Console together with a Windows Startup Disk to repair your machine. If that fails or isn't an option, try the Emergency Repair Process to repair your machine. If that fails, you'll probably have to completely rebuild your machine from tape backup media. There are exceptions to this procedure, based on possible knowledge you have of what might be wrong with your machine, and we'll talk about that later. But first, let's unpack these steps one at a time. Last Known Good Configuration When you press F8 during the startup process (or when you see the "Please select the operating system to start" message, if you have the Recovery Console installed), the Windows
Advanced Options Menu is displayed. One of the options on this menu is Last Known Good Configuration, which uses the Registry settings that Windows used for its last successful logon. Every time you boot Windows and log on successfully, this information is updated in the Registry and becomes your next version of Last Known Good Configuration. This applies only to normal mode; logging on to Safe Mode successfully does not update your Last Known Good Configuration settings. Digging a little deeper, when you use Last Known Good Configuration, Windows restores the HKLM\SYSTEM\CurrentControlSet Registry settings from a previous set of settings, such as ControlSet001 or ControlSet002. In addition, Last Known Good Configuration also rolls back the device drivers used by your system to those that loaded during your last successful logon. However, Last Know Good Configuration cannot be used to restore missing or corrupt operating-system files. When should you use Last Known Good Configuration to recover your system? Choosing this option overwrites any Registry changes or device-driver configuration changes you made during your last successful logon session and restores your system to the previous logon session's configuration. In other words, you lose any configuration changes made and any updated drivers installed since the last successful logon to your system. As a result, you should use this tool only if you think that some configuration change you recently made or a device driver you updated might be causing your system to fail upon startup. Typically, a problem like this will cause a STOP error (blue screen) of some sort, and the message on the screen might give you a clue about which driver or service might be causing the failure. So, the moral of the story is, if you change something, reboot, and your system won't start, try Last Known Good Configuration to restore your system.
Safe Mode If you think your problem isn't due to a recent misconfiguration error on your part and you haven't updated any device drivers lately, then try Safe Mode if your system won't start. Safe Mode lets you start your system using a minimal set of device drivers and services. This allows you to get to a logon screen and start using Windows to look for what might be wrong. Safe Mode can also be accessed by using the Advanced Options menu by pressing F8. There are three versions you can use: Safe Mode, Safe Mode with Networking, and Safe Mode with Command Prompt. I suggest you always try Safe Mode with Networking, because might may need to access your Windows installation files on a network distribution point to repair your serverfor example, by extracting driver files from a .cab file. If Safe Mode with Networking fails, try Safe Mode; if that works, then something might be wrong with your network card or networking subsystem settings. If that fails, try Safe Mode with Command Prompt so that you can at least get to the Windows command-line troubleshooting tools to look for what's wrong with your system. You can log on to Safe Mode by using either a domain administrator account or the local administrator account. On a domain controller, the local administrator account is the only local account present on the machine and is stored in a minimal version of the SAM database found on member servers and workstations. This is also the account used to run the Recovery Console, and it uses the password you specified when you first installed Windows (unless it's been changed). When should you use Safe Mode and its variants? Usually, you might try this if you recently installed new hardware or software
on your machine, not necessarily during the most recent logon session. Once you're logged on in Safe Mode, you can start disabling hardware devices one at a time until you find exactly which device is causing the problem. Or, if the issue is software- related, you can try to reconfigure or even uninstall different applications to isolate the problem and then see if you can reboot in Normal Mode. Some of the Windows tools you might use in Safe Mode to try to determine the cause of startup failure include Event Viewer, System Information (Start Run msinfo32), Device Manager, and so on. Also, successfully booting into any version of Safe Mode creates a log file named Ntbtlog.txt (found in %SystemRoot%) that describes the services started and the drivers loaded during startup. By examining this list, you might be able to determine which failed service or missing/corrupt driver is preventing Windows from starting, and then you can use the GUI tools to fix your problem. Recovery Console The Recovery Console is a command-line interface that you can start either by selecting it from the Boot Loader menu (if you've previously installed the Recovery Console on your server) or directly from the product CD. You must log onto the Recovery Console using the local administrator account on your machine, even if it's a domain controller. Recovery Console provides you with a minimal version of Windows that lets you run various commands to perform tasks such as copying and replacing system files, enabling or disabling problem services, repairing a boot sector, or even reformatting your drive.
Best practice is to install the Recovery Console on your machine before you need it. That way, you won't be running around looking for your product CD when a disaster occurs and you can't start your system. To install the Recovery Console on a machine, insert the product CD, open a command prompt, change to the I386 folder on the CD, and type winnt32 /cmdcons. If you haven't installed the Console and need to run it directly from the CD, insert the CD and select the Repair option. Windows Startup Disk Sometimes, Windows won't boot because the boot sector is damaged on your system volume or a virus has infected your master boot record. A Windows Startup Disk can be extremely handy in such circumstances. The name of the disk is a bit of a misnomer, because you can't start Windows from the disk itself. Rather, the disk can be used in conjunction with the Recovery Console to repair certain kinds of problems that might arise. But first, here's how to create one of these disks so that you'll have it ready when you need it. Stick a blank floppy disk into your machine and double-click on My Computer. Right-click on your A: drive and select Format. Check the option for Quick Format and click Start to format your disk. Now, double-click on the C: drive to open it in My Computer, select Tools Folder Options, and on the View tab clear the checkbox labeled "Hide protected operating system files." Drag and drop the boot.ini, ntldr, and ntdetect.com files from the root of the C: drive to your floppy, and include the Bootsect.dos and Ntbootdd.sys files if these are also present. Open a command prompt window and type attrib -h -s -r a:*.* to set the attributes properly for the files on your floppy. Eject the floppy and label it Windows Startup
Disk or something similar. Finally, hide your protected system files again in My Computer so that you don't accidentally try to delete any of them. Now, if your system won't start because of a damaged master boot record, a corrupt boot sector, or missing or corrupt system files such as Ntldr or Ntdetect.com, you can start the system by using the Recovery Console (from the product CD if necessary), insert your Windows Startup Disk, and copy the files you need from the floppy to your C: drive. Then, you can run other Recovery Console commands to repair the boot sector (using the fixboot command), repair the master boot record (using the fixmbr command), and so on, until you have a working system that will start. Emergency Repair Process The only other thing you can usually try (short of reinstalling Windows from scratch) is the Emergency Repair Process. This feature of Windows 2000 is basically a holdover from Windows NT. The Emergency Repair Disk (ERD) itself isn't as useful (since a floppy can't contain the whole Windows 2000 Registry) as the other actions that are performed by Windows when you create this disk. In particular, when you create an ERD by starting the Backup utility and selecting Tools Create an Emergency Repair Disk, be sure to select the "Also backup the Registry to the repair directory" option, which backs up all your Registry hives to the %SystemRoot%\ Repair folder. Then, when you need to repair the Registry or replace missing or damaged files on your machine, you can press L when the startup process asks you for your ERD floppy. Doing so will ignore the floppy and use the information in the Repair directory instead. Of course, if
your boot volume is badly damaged, your Repair folder might be corrupt or missing, in which case you will likely have to reinstall Windows from scratch anyway. The repair process finds the boot.ini file, reads the ARC paths to the operating system, and then attempts to load the %systemroot%\System32\Config\Software Registry hive. If the boot.ini file is corrupt or missing or if the Software hive is corrupt, the repair fails (unless you actually do have an ERD handy, in which case the repair process can gain access to a working copy of the Setup.log file for your machine). Hopefully, you updated your EFD the last time you reconfigured your machine or installed new hardware on it to keep it current. Windows Server 2003 Things are pretty much the same in Windows Server 2003, except for one major difference: the ERD of Windows 2000 has been replaced by the new Automated System Recovery (ASR) feature of Windows Server 2003 [Hack #98]. This new ASR feature is a powerful tool of last resort for restoring your system when everything else fails. ASR includes the functionality of ERD and much, much more and can really save your bacon in an emergency when your server won't start and everything else (Last Known Good Configuration, Safe Mode, Recovery Console) fails. Right Tool for the Job Finally, here's a list of the proper tools to use when any of these common issues prevent your system from starting:
A configuration change made during the last logon session Try Last Known Good Configuration and reconfigure accordingly. A device driver updated during the last logon session Try Last Known Good Configuration and try a different driver. Server misconfiguration Try Safe Mode and reconfigure accordingly. A newly installed device Try Safe Mode and disable, reconfigure, or uninstall the device. A newly installed application Try Safe Mode and uninstall the application. A newly installed hotfix or service pack Try Safe Mode and uninstall the hotfix or service pack.
A problem service that prevents Windows from starting Try using the Recovery Console to reconfigure or disable the service. A corrupted boot sector or master boot sector Try using the Recovery Console and repairing the problem. A missing or corrupt system file Try using the Recovery Console and copying the file from a Windows Startup Disk or from the installation files on CD or a distribution point. Registry corruption Try using the Emergency Repair Process to restore the Registry or restore the System State from tape backup media using Safe Mode. Massive corruption or loss of system files or the Registry Try the Automated System Recovery (ASR) feature of Windows Server 2003 if you previously created an ASR backup set; otherwise, rebuild your server from scratch by reinstalling Windows.
Hack 100 Data Recovery of Last Resort When the hard drive crashes on your server and your tape backup turns out to be a dud, who you gonna call? Use this hack. You have critical data on your server and your hard drive crashes. And you haven't made a backup recently. What do you do? I know, not making regular backups is irresponsible, but these things happen. Or perhaps you have a RAID 5 unit and the unimaginable happens: two drives fail simultaneously. And Friday's backup tape is unreadable, because you haven't cleaned the tape drive for over a year. Another example of being irresponsible, but let's lay aside the blame until we fix the problem, okay? So, what do you do? You need a data recovery companyfast. I know seasoned administrators who have been in this unfortunate situation, and here's a list of companies they've recommended to me that you can try if this ever happens to you: Ontrack A popular data-recovery service provider that offers various levels of services, including in-house, remote, and do-it-yourself. They also have a partner program that offers discounts based on referrals and resale. They have worldwide locations in the US, Europe, and Tokyo. Their web site is http://www.ontrack.com.
DriveSavers An industry leader in data recovery that offers free estimates. They also have a terrific list of tips on their site (http://www.drivesavers.com), explaining how to anticipate and prevent drive problems before they occur. ActionFront An ISO 9001:2000 Certified company with data recovery labs in Atlanta, Santa Clara, and Toronto. On their web site (http://www.actionfront.com), you'll find a free 22-page Data Emergency Guide you can download, and it's definitely worth a read. These are only a few of the many data recovery services out there, but they come highly recommended by competent IT professionals I know personally, so I pass them on to you. However, you should know that data recovery usually isn't cheap, so clean that tape drive regularly if you don't want to break your IT budget! By the way, if you've ever had to use a data-recovery service yourself and would like to recommend them, feel free to post a comment on this book's web page (http://www.oreilly.com/catalog/winsvrhks/).
Colophon Our look is the result of reader comments, our own experimentation, and feedback from distribution channels. Distinctive covers complement our distinctive approach to technical topics, breathing personality and life into potentially dry subjects. The tool on the cover of Windows Server Hacks is a squeegee, which dates back to the Middle Ages, when fishermen used a wooden ancestor of this tool called a squilgee to scrape fish entrails off the decks of their boats. In Moby Dick , author Herman Melville writes of the whaler's tool known as a nipper, describing them as 'leathern' squilgees cut from the tail of a whale. In Melville's story, not only does this precursor to the squeegee clean whale oil from the deck, but 'by nameless blandishments, as of magic, allures along with it all impurities.' The modern squeegee was born at the turn of the 20th century, when window washers began using a 'Chicago squeegee.' This heavy steel contraption used two rubber blades, held into place by 12 screws. While easier to use than implements made of wood and whale tails, it was far from perfect. One window cleaner, Ettore Steccone, set out to improve the squeegee, and in 1936 he patented a device called the New Deal. This squeegee, now called the Ettore, is still in wide use by professional window cleaners today. Though Steccone eventually lost his patent, the light weight and distinctive single slit-cut rubber blade of his tool served as a blueprint for all squeegees that followed. Philip Dangler was the production editor and proofreader for Windows Server Hacks. Brian Sawyer was the copyeditor. Marlowe Shaeffer, Mary Brady, and Darren Kelly provided quality control. Johnna VanHoose Dinse wrote the index. Hanna Dyer designed the cover of this book, based on a series
design by Edie Freedman. The cover image of a squeegee is an original photgraph by Hanna Dyer. Emma Colby produced the cover layout with QuarkXPress 4.1 using Adobe's ITC Garamond and Helvetica Neue fonts. David Futato designed the interior layout. Andrew Savikas converted this book to FrameMaker 5.5.6 with a format conversion tool created by Erik Ray, Jason McIntosh, Neil Walls, and Mike Sierra that uses Perl and XML technologies. The text font is Linotype Birka; the heading font is Adobe Helvetica Neue Condensed; and the code font is LucasFont's TheSans Mono Condensed. The illustrations that appear in the book were produced by Robert Romano and Jessamyn Read using Macromedia FreeHand 9 and Adobe Photoshop 6. This colophon was written by Philip Dangler. The online edition of this book was created by the Safari production group (John Chodacki, Becki Maisch, and Madeleine Newell) using a set of Frame-to-XML conversion and cleanup tools written and maintained by Erik Ray, Benn Salter, John Chodacki, and Jeff Liggett.
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X account information searches, Active Directory account management, Active Directory users accounts Active Directory, listing disabled administrator, renaming guest, renaming inactive, retrieving no expiration users, preventing local ActionFront, data recovery Active Directory accounts, listing disabled contact information, storing/displaying
DC (Domain Controller), checking existence domains list all computers listing information display OUs control delegation creating automatically creation automation object modification sending information to HTML page site assigned, viewing trust relationships, listing users account expiration account information searches account management
disabling domain account name change Windows 2000, unlocking domain account Windows XP icon restore ADM files administrator account renaming, security domain controller access local, listing AdminScripts folder ADSI (Active Directory Services Interface) adsutil.vbs administrative script ADUC (Active Directory Users and Computers) console aging, DDNS antivirus software archivelogs.vbs code AspAllowSessionState property, metabase hacks
AspBufferingOn property, metabase hacks AspProcessorThreadMax property, metabase hacks AspQueueConnectionTestTime property, metabase hacks AspScriptFileCacheSize property, metabase hacks AspThreadGateEnabled property, metabase hacks ASR (Automated System Recover) backups and assessment tools, security attribution for use of code examples auditing tools, security automatic log on after booting configuration manual script method
Sysinternals Automatic Updates FAQ Group Policy and patches and awareness, security and
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X Backup Operators Server Operators and Backup utility bks files CAs backups access restriction ASR and 2nd CA CAs command line, individual files configuration local computers
remote computers DFS namespace 2nd DHCP databases EFS keys ER files, collecting Event logs last resorts metabase (IIS) quick backups Recovery Agent keys recovery file collection security shadow copies System State remote computers bks files boot disk, creating for network
boot up, automatic log on businesses, security FAQ
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X CacheISAPI property, metabase hacks CAs (certificate authorities) backups 2nd decommissioning restores Certification Authority Backup Wizard certification, anti-virus software Chaccess.vbs administrative script ChangeIP.vbs code ChangeWINS.vbs code CheckMembership.vbs Cipher Security Tool for Windows 2000 CIW (Client Installation Wizard), RIS and
CIW (Client Installation Wizards), RIS and code examples in this book, use of code listings archivelogs.vbs ChangeIP.vbs ChangeWINS.vbs CheckMembership.vbs CreateOU.wsf CreateUserHomeDirectory.vbs DelegateOU.vbs DeleteOldComputers.vbs DisabledAccounts.vbs Disaster.bat EnumerateHotfixes.vbs ExportAdUsers.vbs FindUser.vbs GetAccountInfo.vbs
GetAdmins.vbs GroupMember.vbs LogoffIcon.vbs ModifyUsers.vbs ModifyUsersOU.vbs OU2HTML.vbs PassList.bat PWDNeverExpired.vbs ReadList.bat ReleaseRenew.vbs ServerList.txt Static2DHCP.vbs vbtree.vbs command line backup individual files printer management Registry keys find and replace
Run As Windows component removal commands, executing on each computer in domain computer accounts, retrieving inactive computer name, printer management and computers automatic logon enabled finding finding, security listing all on domain, Active Directory CON2PRT command configuration anti-virus software backups local computers remote computers log on, automatic
networks, changing with Netsh remote computers, displaying RIS consumers, security FAQ contact information, storing/displaying in Active Directory CreateOU.wsf code CreateUserHomeDirectory.vbs code CSV files group membership and password expiration
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X Data Replicator databases DHCP backups recovering WINS, recreating damaged DC (Domain Controller), checking existence of DDNS (Dynamic DNS) aging scavenging default printers, setting based on location DelegateOU.vbs code delegating, OU control
DeleteOldComputers.vbs code DesktopChecker DFS (Distributed File System), namespace backups 2nd DFScmd utility DFSUtil DHCP (Dynamic Host Configuration Protocol) databases backups recovering scavenging and servers availability redundant, installing static IP, changing from directory trees, displaying disabled accounts, listing in Active Directory
DisabledAccounts.vbs code disabling EFS Disaster.bat code DNS (Domain Name System) error messages newsgroups troubleshooting domain controllers, admin access domains account disabling, Active Directory Active Directory list all computers listing computers, executing command on each users, searching for downloading scripting engine
scripts drag and drop to Run menu drive mapping logon script information network drives renaming shared folders DriveSavers, data recovery
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X EFS (Encrypted File System) backups disabling keys backups 2nd restores encryption data backups EFS, disabling enterprise patch management EnumerateHotfixes.vbs code environment variables adding
removing retrieving ER (Emergency Repair) files collecting winmsd.exe utility and rdisk.exe and error messages, DNS Event logs backups clearing information script EventCombMT tools example code from this book, use of executables, Run As and expiration passwords, checking for non-expired
user accounts ExportAdUsers.vbs code extending Group Policy
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X FAQs Automatic Updates patch management security Windows Update file types blocked, security files ADM EFS, disabling usage monitoring find and replace in command line, Registry keys FindUser.vbs code folders
AdminScripts EFS, disabling shared, drive mapping
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X GetAccountInfo.vbs code GetAdmins.vbs code government security clearance GPO (Group Policy Object) group membership enumerating to CSV file logon script information Group Policy ADM files Automatic Updates and extending GroupMember.vbs code guest account, renaming
GUI IIS 5 and IIS 6 and Run As and
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X hiding/showing metabase HotFix & Security Bulletin Service hotfixes downloadable listing installed HTML, OU display Hyena utility, file use and
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X icons, logoff on desktop ID 36907, metabase hacks IIS (Internet Information Services) administration scripts introduction metabase backup web servers, running IIS 5 administration scripts metabase backups, restoring metabase, location map socket pooling, disabling
IIS 6 administrative scripts metabase backups location map restoring backups XML Map socket pooling, disabling IISFAQ web site inactive accounts retrieving installation RIS Windows components Instant Network Boot Disk interception, security and intrustion detection tools
IP (Internet Protocol) adapter information, changing static, switching to DHCP IP addresses releasing renewing
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X KB 824146 Scanning Tool
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X local accounts, preventing user creation local administrators, listing local machines, backup configuration lockdown tools, security log on automatic after booting finding enabled computers manual configuration script method Sysinternals printer management based on computer name logical structure of metabase
logoff icons, placing on desktop LogoffIcon.vbs code logon scripts drive mapping information membership checking Lost Password Recovery
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X mapped drives logon script information renaming mapping drives network drives shared folders mapping metabase mappings, group membership and MaxEndPointConnections property, metabase hacks MBSA (Microsoft Baseline Security Analyzer) support membership, logon script information metabase
backing up quick backups hacks hiding logical structure management scripts mapping physical structure restoring Windows Backup utility MetaEdit Microsoft security and reporting tools ModifyUsers.vbs code ModifyUsersOU.vbs
MSRC ratings system myITforum.com
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X Netsh network configuration network configuration settings network adapters IP information WINS settings Network View networks anti-virus software boot disk, creating configuration, changing with Netsh drive mapping file useage
NICs, removing orphaned printers, connecting to shared Run As and service managment, remote machines virus-free newsgroups, DNS NICs (network interface cards) orphaned, removing two-NIC environment, NLB and NLB (Network Load Balancing), implementing ntbackup, command line and
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X Ontrack, data recovery organization of book orphaned NICs removing OU2HTML.vbs code OUs (organizational units) control delegation creating, automating HTML page display objects, modifying users property modification
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X PassList.bat code passwords expiration, checking for non-expired Lost Password Recovery tool policies users changing patch management best practices enterprise patch management FAQ introduction policies processes
tools 2nd vulnerable systems and patches Automatic Updates 2nd business impact distribution email notification flavors hotfixes downloadable MSRC ratings system order of application roll-ups service packs SMS SUS testing
Windows Update FAQ permissions for using code examples permissions, user configuration physical structure of metabase PPP (Policy, Process, Persistence) Print Manager Plus printers computer name and default, setting based on location managing automatically mappings, group membership and network, connecting to shared Printers folder, Run As processes, finish before terminating PWDNeverExpired.vbs
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X QChain quick backups, metabase
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X rdisk.exe, ER files ReadList.bat code recovery ASR (Automated System Recover) file collection startup troubleshooting Recovery Agents, key backups redundant DHCP servers, installing Regfind utility 2nd Registry keys, find and replace in command line ReleaseRenew.vbs code releasing IP addresses Remote Assistance, shortcuts to
remote computers backups configuration System State configuration display network services, managing shut down renaming mapped drives renewing IP addresses Restore Groups restores CAs EFS keys metabase RFCs (Request For Comments) RIS (Remote Installation Services) CIW And
configuration customizing installation overview predefining computer accounts system requirements tuning Windows images deployment roll-ups Run As 2nd command line executables and GUI and limitations network shares and Printers folder shortcuts
Task Manager Windows Explorer and Run menu, drag and drop to RUNDLL32 command
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X scanning anti-virus software tools for scavenging, DDNS scripting engine, downloading scripts automatic logon downloading event log information IIS administration running remotely testing VB, WMI agents and
[See Run As] Secondary Logon service Secure Sockets Layer, clearing security administrator account renaming local, listing antivirus FAQ assessment tools auditing tools awareness and Backup Operators backups computers, finding domain controllers, admin access FAQ file types blocked government clearance
guest account, renaming interception and intrusion detection tools lockdown tools Microsoft reporting tools password policies patch management tools reporting to government authorities software update tools virus protection FAQ 2nd tools virus-free networks vulnerability Server Monitor Lite
Server Operators, Backup Operators and ServerList.txt code ServerListenBacklog property, metabase hacks and service packs Services node, remote machine management shadow copies backups and implementation uses shared folders, drive mapping shortcuts to Remote Assistance Run As shut down remote computers SMS (Systems Management Server) socket pooling disabling
IIS 5 IIS 6 reasons for software update tools, security SQL Server 2000 Security tools startup, troubleshooting static IPs, DHCP switch Static2DHCP.vbs code SUS (Software Update Services) patches and Sysinternals, auto log on SysPrep, Windows deployment and system requirements, RIS System State, backups remote computers
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X Task Manager, Run As and termination, finish process prior to testing scripts third-party tools Data Replicator Lost Password Recovery myITforum.com Network View Server Monitor Lite VNC (Virtual Network Computing) tools DNS troubleshooting patch management
third-party Data Replicator Lost Password Recovery myITforum.com Network View Server Monitor Lite VNC trust relationships, listing in Active Directory
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X updates tools for UrlScan Security Tool users account information search, Active Directory accounts, no expiration Active Directory account management disabling domain account name changes groups, enumerating membership to CSV file home directory configuration local accounts, preventing creation
membership, logon script information OU, properties modification passwords, changing permissions, configuring searching for utilities Hyena, file use Regfind regfind.exe
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X variables environment adding removing retrieving vbtree.vbs code virus protection FAQ tools virus-free networks anti-virus software basics file types blocked
interception and VNC (Virtual Network Computing) VSS (Volume Shadow Copy Service) backups and implementing copies shadow copy uses
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X web applications, administrative scripts Web Server Lockdown Wizard web servers, IIS and web sites administrative scripts DNS troubleshooting tools IISFAQ Windows command line, removing components deployment, SysPrep and image deployment, RIS and installing components, unattended Windows 2000, locking accounts
Windows 2000/3000, implementing NLB Windows Backup utility, metabase Windows Explorer, Run As and Windows NT, recreating WINS databases Windows Server 2000/3000, recreating WINS databases Windows Update catalog controls, manual install Critical Updates, personalizing FAQ information collection removing items schedule changes Secure Sockets Layer and Windows XP Active Directory icon restore winmsd.exe utility, ER files and WINS (Windows Internet Name Service)
databases, recreating damaged settings, changing for all adapters WMI (Windows Management Instrumentation) agents, VB scripts and IIS administration workstation, printer settings WSH (Windows Scripting Host), IIS administration
[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] A B C D E F G H I K [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] L M N O P Q R S T U [ ] [ ] [ ] V W X XML metabase map, IIS 6