Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


February 2008

Letters@windowsitpro.com

RSS
Subscribe to Windows IT Pro | See More Windows OSs Articles Here | Reprints
Or get the Monthly Online Pass—only $5.95 a month!

Microsoft Asks: Who Are You?
I’ve been in IT since 1993, and that seems like an eternity some days. I work for a Microsoft Certified Partner that develops custom software. We’re a Microsoft shop. I’ve spent 10 years working for my current employer, so I would say I’m pretty familiar with the history of Microsoft and IT. I find Microsoft wanting in many ways, mostly because the company continues to make my job difficult.

In response to Karen Forster’s editorial, “Microsoft Asks: Who Are You?” (December 2007, InstantDoc ID 97478), I have to say I find no compelling reason to share any of my personal information with Microsoft. Maybe I’m just old and grouchy, but I don’t see how celebrating my ability to play the kazoo translates into helping me do my job. I have a firm grip on who I am and have never confused myself with my profession. Honestly, Microsoft’s initiative seems like a marketing gimmick. If this kind of email message arrived at my company, it would probably get tagged as spam.

—Curt Hayes

Custom Logon- Tracking Solution Insecure?
The Custom Logon-Tracking Solution (“Windows IT Pro Innovators Share Their Successes,” November 2007, InstantDoc ID 97204) struck me as rather insecure. Any time you have a shared Microsoft Access database that is writeable by large numbers of individuals, you have a potential nightmare.

First, the logon script runs under the user’s ID, which means he or she must have write access to the Access database. Nothing prevents the user from deleting, creating, and modifying records. Anyone with access can forge entries, purge entries, and otherwise modify records. Also, depending on how administrators access the account-logging database, an even bigger vulnerability is possible. In Access 2003, when I open .mdb files, the system warns me that if this .mdb file contains code intended to harm me, it can do so! If non-privileged users modify that .mdb file, opening it allows dangerous Visual Basic for Applications (VBA) code to run. If administrators are careful and never open the .mdb file itself—and always interact with it through table links from another .mdb file—they’re probably safe. If not, they’re vulnerable.

I’m no security guru, but I would suggest using a restricted SQL Server database instead of an .mdb file. Then, I’d create SQL Server stored procedures for creating the logon records and updating the logout time. Those stored procedures would use SQL Server functions to enumerate the machine, the username (using integrated security), the logon time, and so on. I wouldn’t be able to prevent people from trying to insert false data, but I’d know what account was used, what IP address they came from, and when it happened (based on the server’s clock). I’d also restrict the database growth size, set up alarm notifications, and so on.

—Anonymous

There are security vulnerabilities that could lead to problems, especially if the solution is used to store mission-critical or highly sensitive data. In our case, the solution was purely a tool for us to learn which computers were being used and to what extent. Even so, our Access database is stored on a separate share that is completely locked down with several layers of security, including firewalls, file permissions, and GPOs. Only administrators have rights to browse to the location, and only authenticated users on our domain have read/write access to the database. An authenticated user would have to know the exact path and filename of the database to even try to tamper with it. That information would be very difficult for our users— none of whom have local administrative rights—to obtain. Migrating the solution to a SQL Server database would certainly increase security, and I would strongly recommend that option if higher security is needed.

—Brandon Jones

IT as a Career Choice
I read Jeff James’s article, “Windows IT Pro: A Good Career Choice for Your Kids?” (December 2007, InstantDoc ID 97408). Maybe I just got lucky, but my son has been at a keyboard since he could sit up straight on his own. He spent his whole childhood tinkering with hardware to software and everything in between. I don’t see the point of recommending or not recommending IT as a career choice for your kids. It’s like being an artist: Either you can paint or you can’t. Sure, you can go to school and learn how to paint. But that won’t make you a great painter.

I never recommended my son get into IT, but IT got into him from an early age. Too often, kids choose IT solely for the money. Bad decision. IT sucks unless you really, really like it. My son likes it. Right out of high school, he got a position with a high-profile social-networking site making the kind of money I started making only a few years ago. Life just isn’t fair.

—Scott Gutauckis

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

Remote Control Software

Control remote machines from home or the office. ...

WinInfo Short Takes: Week of July 21, 2008

An often irreverent look at some of the week's other news, including an iPhone 3G defeat, 180 million copies of Windows Vista in the wild, Microsoft earnings some more Yahoo silliness, Wii vs. Xbox 360, EU vs. Intel, AMD ousts its CEO, and so much more ...


Windows OSs Whitepapers Replay for Exchange: Enterprise Protection and an Affordable Price

Are You Satisfied?

A Preliminary Look at Deployment Plans for Microsoft Windows Vista

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Shortcut Guide to SQL Server Infrastructure Optimization
With right tools and techniques, you can have a top-performing SQL Server infrastructure without having to cram your data centers so that they're overflowing. Download this eBook to learn how.

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Become a fan of Windows IT Pro on Facebook!
Join us on Facebook and be a fan of Windows IT Pro!

Continuous Data Protection and Recovery for Exchange
Read this white paper to learn about Continuous Data Protection (CDP), Exchange 2007's local continuous replication and cluster continuous replication features.

Rev Up Your IT Know-How with Our Recharged Magazine!
The improved Windows IT Pro provides trusted IT content with an enhanced new look and functionality! Get comprehensive coverage of industry topics, expert advice, and real-world solutions—PLUS access to over 10,000 articles online. Order today!

Tips to Managing Messaging
Discover three fundamental mail and messaging management services - security, availability and control services - and how you can implement them in a Microsoft-centric mail and messaging environment.

Get It All with Windows IT Pro VIP
Stock your IT toolbox with every solution ever printed in Windows IT Pro and SQL Server Magazine plus bonus Web-exclusive content on hot topics. Subscribe to receive the VIP CD and a subscription to your choice of Windows IT Pro or SQL Server Magazine!



Drag & Drop Data Mapping Tool
Try this award-winning data mapping, & transformation tool that supports multiple databases, flat files, Web services, EDI, Excel 2007, & more! Free trial for 30 days!

Overcome bloated Windows file systems
Crossroads FMA delivers powerful yet inexpensive data migration

Bandwidth Monitoring Tool from SolarWinds
Identify largest bandwidth users in seconds. Get the free download now.

Speed Deployment of Vista and Microsoft Office
Read this white paper to learn how you can maximize your Vista and Office investments while lowering costs and increasing efficiency.

Integrated Virtualization Done Right
Download this white paper on server virtualization to begin improving resource utilization and lowering operating costs.

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

KVM over IP Solutions
Learn about a KVM over IP solution that is specifically designed to meet the needs of the distributed IT environment.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound
IT Library Technical Resources Directory Connected Home Windows Excavator SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing