Saturday, June 07, 2014

New significant issues - IE and OpenSSL

One Extremely Important Patch Tuesday!
This coming patch Tuesday we'll have a patch (hopefully) for an IE bug that's been in the wild for about 6 months depending on the source.  A CDATA use after free flaw that apparently can be exploited by javascript and it affects a broad swath of Windows systems.  For once the details have been withheld as near as I can tell which is saying something.  Usually someone leaks the info and you have a bunch of bad actors using the code.  If it hasn't been leaked it would be a super-human triumph over our natural instinct to put ourselves above the security of others. Kudos to the researcher who apparently hung on for a very long time to a massive exploit that could have been running Godzilla-like through the computer world otherwise. Even though Microsoft was slow to put out a patch the researcher held out and did the right thing in my opinion.

Open SSL was cracked wide open again
If you believe that only poorly made products are vulnerable to security issues or if you're one of those who believe that only open software is exploit free then you might want to rethink your position.

Open SSL has been made much more "open" by a new CSS Injection bug. (here) This allows an attacker to force an Open SSL implementation of SSL/TLS to use weak key material and thereby allow a man-in-the-middle attacker to decrypt a session potentially.  But this is not the only issue... consider the DTLS recursion flaw, DTLS invalid fragment vulnerability, SSL mode release buffers null pointer deref, SSL mode release buffers session injection, and the anonymous ECDH denial of service.  Basically you have a recipe for disaster if you're a APT soldier for hire.

I believe that two forces are at work here on the sudden explosion of exploits against the underpinnings of our online world.  
A) the Snowden revelations 
I know it may seem far fetched but the reasoning is thus: if you know that there is an organization with the ability to deconstruct and observe much of what we do online you must also assume they have the means to do so.  If you believe they have the means to do so, you begin to open your mind to the possibility that encryption systems we rely on are more vulnerable than what we originally thought.  From there, it's logical to take a second look at these encryption systems.  When we begin to find that there are significant flaws we prove the supposition.  Once we prove the supposition true the cycle begins once more and we look deeper, finding more issues and so the cycle goes.

B) the Eye of Mordor principle
When the curiosity of the hacking world is focused on a fad or the exploit-du-jour we see a phenomenon which I call the "Eye of Mordor". Essentially the focus of the hacking world is collectively the "Eye of Mordor".  Once the eye focuses on a single product or company etc. then the bugs start to be ferreted out. A case in point was the focus of The Eye on Microsoft's operating system.  Now that Linux is represented on more desktops it begins to draw The Eye just like when Frodo put the ring on.  

What does that mean for the future?
I predict we'll see a lot more ground-breaking attacks on crypto and against the underpinnings of the systems that employ it.  We'll see the world begin to get more serious about staying secure from everyone and everything else. No product will take off without having strong encryption and bold marketing promises to keep data out of the hands of virtually everyone. Lastly, governments that like to skim data, in an effort to satisfy themselves that everyone is playing ball, will find other means of getting it... probably by new regulation. 



Friday, June 06, 2014

Is antivirus a waste of time?

Symantec turns from prevention to remediation (article) as the company comes to grips with dropping detection rates for new viruses and malware.  Many savvy companies have already begun to analyse viruses using multi-engine systems like Virus Total which can generate a consensus on a piece of malware if you're lucky.

To what do we owe this great turn of events?
a) Could it be the cool tricks APTs use to bypass antivirus disclosed at RSA 2013?
b) The tips given at BlackHat 2013 to fool virus engines?
c) Could it be the codifying of those tricks into Metasploit for the script kiddies to push-button hack?
The answer is Yes.

The tricks used by APTs and by hackers in general to bypass anti-virus are very easy and extremely effective... so much so, that trying to detect them would be almost impossible and if detected would lead to a huge amount of false positives since many programs share those same API calls.  So the former revelation by Symantec is just common-sense... not a shock or even really that surprising.

So what is a person to do?

For a long time now I've championed the use of a Trip-Wire like app.  Just a simple hash of files and key registry segments... if those areas change then the user is given the opportunity to restore them to the original settings.  You can take this idea as far as you want, with VMs or what have you.  User's are not perfect and we all know they can be fooled easily but even savvy kids know that when they're surfing the web they should not have something get installed that they didn't ask for.

I agree it's time to go back to a leaner AV with greater attention to segmentation of information and an absolutely rock-solid restoration capability.  There are few things more frustrating than removing a virus only to find that you have to re-build a home user's machine from scratch because there are still tentacles of the bug infesting the remotest areas of the OS.

But good luck finding this kind of solution for a price you can stomach.  Maybe an AV company will build this up but if the past is any indication it will come with 100 megs of useless legacy crap installed with it.  So far it seems that freeware solutions steer clear of this type of app maybe due to patents in the area or simply because it's dangerous to restore anything to a computer and thereby risk the legal repercussions of not getting it perfect.

What does the business do?

Business will have to turn to multi-engine AV systems and to anomaly detection systems like Fire Eye, Tripwire, Splunk to catch hacks after the fact.  You can roll your own tools, write Snort rules, block massive lists of IP addresses. I believe the industry is coming to a tipping point where lower costs tools are needed.  I enjoy writing my own, but most companies don't have the people with the skills to take a day or two on a new tool.  Also, pet projects can take on a life of their own as their capabilities need to expand to support additional systems and log types.  I recently wrote a sniffer and a log analysis system that feeds into SQL Server (with full text search).   A few stored procs shape the data into useful intel but parsing new and varied types of logs becomes a pain point and Splunk starts looking better if you have a wide variety of input.  These are the kinds of decisions you'll find yourself dealing with more and more as the attackers continue to outpace the defenders.

I'll talk more about how to deal with this tipping point shortly as a reset is needed to tip the scales back in the favor of defense.



.

Monday, January 20, 2014

Interesting traffic

I hooked up Fiddler the other day to do some run of the mill testing and I started seeing these requests...

http:// rssgov.windows.microsoft.com/usagovrssfeed.rss

I shut down the browsers and continued to see this request periodically.  I pulled up the URL in a browser and got nothing.  It would seem to be a continual polling performed by Windows to see if the government has anything to say in which case what happens?  Would a dialog box pop up?  Would you see an amber alert or a public service announcement warning about something dire?  Is it more like an amber alert for cyber attack information?  Would Windows do something like lock down ports or respond in some remote-controlled manner like an anti-botnet?

I'll continue to look into this and see what I can find.

Tuesday, September 24, 2013

Apple Lock-screen woes continue

After the lock screen problems with IOS6 where you could bypass the lock screen using the emergency call function, now IOS7 has a lock screen problem all it's own.

With IOS7 you can bypass the lock screen and access, transfer, view, email, tweet and facebook all the pictures on the phone. From the photo app you can access the contacts including their phone numbers and email addresses. You can also send out career-ending tweets or facebook posts. You can turn on Air-Drop and "drop" all their pictures to another phone if you think of turning it on prior to unlocking the phone!

Videos online show the procedure but don't readily give an idea of how to reproduce it because timing is everything. Here's the HOW:

1) Push the home button to wake up the phone if it's turned off.
2) Slide the photo icon up from the bottom of the screen (this will activate the camera app if they phone user end-tasked it previously
3) Push the home button to go back to the locked home screen
4) Flick the bottom panel upward
5) Click calculator (calculator app opens)
6) Push the top button for about 5 seconds until the phone presents you with the "Slide to power off" message and more importantly the "Cancel" button at the bottom of the screen
*** Do these two things as one step and try to get the timing right ***
7) Click cancel - push the home button twice (the push of the home button must happen about 1/2 of a second after the push of the cancel button... and the second click of the home button is about 1/2 second after the first home button click. The way I do it is say out-loud Click-Click clicking the button with each verbal cue)
8) You can scroll through open apps but the only app that lets you in is the calculator and apps available through the home-slide function

If you have an iPhone with IOS7 I'd recommend keeping it with you physically. If you do have to leave it somewhere you will need to edit your settings and turn off access to the control panel in the lock screen. (this option allows you to still use the control panel in unlocked mode) And of course, watch for an OS update and install it asap when it's available!

Wednesday, February 06, 2013

The New Face of Pen Testing

A recent pen test changed my viewpoint on the industry standard practices.  The old ways are no longer working.  Not only are industry standard pen tests not working they are providing a false sense of security.

Given the latest generation of firewalls that are adaptive and resistant to scanning we would expect that port scanning and repeated door knocking would be less effective.  So why are we still being charged for a type of scan that is ineffective?

Recently a fortune 500 company performed a costly pen test on a network segment running critical systems and returned no results at all.  Thinking that was impossible I ran a few tests of my own with the same tools that they used.  I got two ports on the first IP and then nothing after that.  I tried to mix it up using NMAP with the most stealthy settings.  I decided to pwn them using my Nessus skills and even tried a zombie and spoofing different addresses and nothing worked.  I was shut out.  Nessus and other tools failed to get anything from our ninja-like firewall.

Now that I had established that the standard tool-set was producing almost nothing except false warm fuzzies I broke out "my" set of tools.  And I did what I do very well... break the rules.  We know that companies on the net are spying on us in unprecedented ways and without restriction.  Why not take advantage of their legally sanctioned espionage and leverage their data sets to reflect our own systems?

A day and a half later with 138 vulnerabilities and counting and a full network diagram including IPs, servers, web sites, email addresses, technologies, phone numbers, all laid out in perfect searchable and browseable order.  A couple hours of hand testing and searching some specific vendor sites and I found even more issues not determined by any of the new "black hat" tool-sets that I use.

I realized five very valuable lessons:
1) The cost of a pen test does not predict its effectiveness
2) Standard pen tests against active firewalls are useless and give a false sense of security
3) Standard pen tests use tools that are basically out-dated in four ways
    a) they rely heavily on port scanning
    b) they rely heavily on CVE lists and CVE lists don't have a monopoly on vulnerability info
    c) they don't leverage the Google factor enough
    d) they require firewall exceptions which distort the important "view of the hacker"
4) We need to use the tools hackers actually use, not the ones we're sold by security intelligencia
5) There never will be a substitute for hand testing

David Cross

Sunday, January 13, 2013

Java Security Woes

Rapid 7 published an exploit for Java versions prior to 7.7 which gives an attacker full control of the affected computer.  All that needs to happen is to lure a user to a web site that has a particular set of code running on it.  Now that this exploit is in the wild (available in public to hackers and wannabe's alike) you need to take action.

Lately Oracle has had a bad run of security issues with Java.  For years vulnerability testers have focused their efforts on Windows or other high visibility targets, but now that Java runs on more machines world wide than any other technology, hackers are taking notice.

Recently the US government, apparently a new source of computer security wisdom, (yes I am fully aware of the irony) is recommending turning Java off.  Curiously though, given all the machinations Java had to go through to get around Microsoft's proprietary protections, uninstalling it is rather more difficult than it would seem.  Java runs outside of the normal task-managed applications.  You can't just pop up task manager and kill java apps.  You can't just turn it off with one browser setting either.  There are many ways to invoke java by HTML and half a dozen ways you need to stop it using registry tweaks and IE settings.

So now what can be done?  If it's so hard to turn off that you can't be certain you've shut them all down you may want to simply uninstall the entire JRE (Java Runtime Environment).  That gets kind of inconvenient if you're a Java developer.  If you're not it's probably the best alternative to ensure that you're actually safe for the time being.  YouTube is a good resource for understanding the removal process and does a better job than 100 static screen shots.  How to uninstall Java from Windows  Uninstall Java from Mac

If that solution doesn't sound good you or your child runs Minecraft and is complaining the next day you have the option of upgrading to JRE to 7.11 and praying really hard. If you like that option here is the link to install JRE 7.11. (yes 11 major security patches in a year - YIKES!)  http://www.oracle.com/technetwork/java/javase/downloads/jre7-downloads-1880261.html So upgrade and take your chances is always an option.

For now I've uninstalled JRE on my PC and will probably break down and install the update on my sons' computer for Minecraft.   

I hope this helps!  I wish there was an easier way.  Personally I think that disabling Java is the least recommended course of action because it leaves you open to feeling secure even though there is likely some way to still invoke Java by the browser that remains in place.  Additionally, leaving the vulnerable version on your computer even if it's turned off is a risk because at some point in time it will likely get turned back on and it will be in an ideal state for cyber criminals to take advantage of.

If you choose "the road less traveled by" and it makes "all the difference" please let me know.

David

BTW you'll want to patch up to 7.12 now. Good luck!

Friday, September 07, 2012

Duplicate Section Defined in Web.config

I looked into a web.config parsing error which troubled me on one web server and not another...

It was an ASP.net web application with elements of .Net 2 but compiled under 3.5.   The app would compile fine but upon publishing the app there would be config errors. The particular error depended on if you were in the IDE or IIS7.  In IIS 7 the app would load and run fine but would not allow you to edit any site settings without throwing a "duplicate script section" error.  Basically it was implying that the script attribute had already been defined.

After finding that there was no duplicate and that all the tags were closed properly I checked it with another IIS instance and it worked fine.  This told me that it was probably related to the framework version on the app pool.

I right-clicked the site name in IIS, clicked Manage Application and picked Advanced Settings...

Then I clicked Application Pool and changed it from "Classic .Net App Pool" (framework 4.0) to ASP NET V2 Integrated.  (I used Integrated rather than V2 Classic because the script tag definitions in question called for Integrated mode)

Immediately the site settings like authentication etc. were editable in IIS without throwing errors.

So if you have a similarly impossible configuration error in IIS, check your framework version since xml tag implementations can differ from version to version... each framework "sees" the Web.Config file in a different context and may not understand some settings or choke on deprecated settings.

Tuesday, July 03, 2012

Y2K Micro

The addition of a leap second to the world's atomic clocks this weekend produced some spectacular crashes of Java software around the web.  (One might wonder why not in other software?  But that question is complicated enough to require a separate post) Some of the more notable epic fails were in Redit, StumbleUpon, Yelp and FourSquare and other systems running Hadoop and Cassandra possibly in combination with Firefox.
In 2006 we reported a large-change clock vulnerability that affected Zone Alarm, Norton, and several other anti-virus vendors and Microsoft.  The security companies quickly remedied the problem but Microsoft hedged until we produced a proof of concept exploit.  Software vendors typically don't really care too much about date based issues unless they affect security or credibility.

The leap-second clock problem was a small-change clock issue which probably should have been tested just in the likely event that someone would eventually block the time synch port and duplicate this issue by accident.  It is incumbent upon developers of 24x7 software to plan for the unexpected and test their systems for time-change crashes and vulnerabilities.  Timing attacks in various forms are often part of a hacker's arsenal and should be part of every test plan.

As authentication systems and date-based database transactions rely more strongly on precise clock synchronization, it is important for the computing community to take clock changes a little more seriously and notify industry ahead of time so these issues can be tested and addressed.  Leap-second tweaking will continue in the future as the earth and moon continue to synchronize.  Software, just like the earth and moon, has to adjust accordingly.

Saturday, June 16, 2012

Threat Modeling with Customers as Assets


One thing I've been contemplating lately is if the security world isn't missing something when threat modeling.
Threat modeling will generally list assets and then see what kinds of threats can threaten those assets and see what the expected loss might be.  Assets are typically thought of as being physical systems like a web server or database. 

But a consideration has been percolating since I had a discussion with one very confident threat modeler working for a fortune 100 company.  I suggested that it would be possible to consider a customer, who has a company distributed token and can move their data from one service to another in seconds, could be considered an asset.  This credentialed expert was absolutely beside himself with indignation, "the business doesn't own the customer. And a customer is also not an asset because a customer can't be attacked or exploited!" 

Oh really?

Follow me down this rabbit hole and see if there isn't a case to be made for at least considering that your customers might be an asset.

An asset is defined as:
"Any item of economic value owned by an individual or corporation, especially that which could be converted to cash. Examples are cash, securities, accounts receivable, inventory, office equipment, real estate, a car, and other property. On a balance sheet, assets are equal to the sum of liabilities, common stock, preferred stock, and retained earnings. From an accounting perspective, assets are divided into the following categories: current assets (cash and other liquid items), long-term assets (real estate, plant, equipment), prepaid and deferred assets (expenditures for future costs such as insurance, rent, interest), and intangible assets (trademarks, patents, copyrights, goodwill)."

As a business do you invest money to retain customers? - maybe you don't own customers but you invest in them -
As a business do you carefully maintain and grow your customer base?
As a business do customers provide you money? (maybe not unlike accounts receivable?)
As a business, if all of your customers leave do your physical assets have any value beyond their depreciated physical value?

So I think a reasonable person would agree that customers are an investment which pays dividends over time.  Also note in the definition of asset the sub list of "intangible assets" which include... goodwill.  Your customers represent a huge pile of cash which may or may not be delivered to your revenue stream. (think Netflix when they changed their terms and service model)

So let's say for the sake of argument that customers are the embodiment of goodwill represented in terms of accounts receivable and have been invested in both in terms of advertising dollars and education as you have tried to help your customer keep themselves secure while they use your product.

Let's go further and examine this claim that a customer cannot be attacked by a hacker.  I would suggest that it's not only possible but it is part of your threat model and sphere of business.  It is your concern.  My justification is as follows:

1) customers can be socially engineered
2) customers can be attacked by spam, trojans, viruses
3) customers can be lured away if service is denied from the customer's computer
But when someone tells me that something is impossible the lateral thinker in me feels compelled to find an exception to the rule... what if the customer is attacked by DOS and thereby denied service and leaves your service because it never works?  What if a browser helper object is put on the user's browser that denies service to Amazon Web Services or Netflix or Gmail?  What if a BHO stops service to one company and facilitates it with another?  I can think of one such BHO - Cool Web Search. So such a thing has already happened.  Microsoft has already realized they they need to protect their customers via anti-spyware and anti-virus in order to keep their company alive.
So your customers can be threatened!  The customer can take their money elsewhere.  If compromised, the customer could lead to a general compromise of your entire system. The following source indicates that customer data is an asset and probably could be considered even when transient. http://pentest-standard.org/index.php/Threat_Modeling  Consider for a moment what happens when the customer has tiny bit of our data such as an access key or certificate?

Could you educate your customer about how to keep their secret key secret? 

Could you educate your customers about how to avoid being socially engineered? 

Could you educate them on how to keep their computers secure? 

Could you educate your customer on how to avoid service interruptions? 

I think the answer to all these questions is yes even if it would lead to an extra expense...  You probably already have spent money trying to educate your customer to some degree.  So maybe you can't entirely control your customer but the customer can be educated and controlled, and even somewhat protected.  * almost like an asset *  You could provide your customer with a security token for example, or a X509 certificate.  Maybe you could even put a program on their computer that assists them in securing their credentials.

Now you can say that you're not responsible for the customer... and why should you be?  Why take on an extra expense for something you can't control?  Given the threats we face you may want to consider changing your thinking.  Operating system vendors like Microsoft understand that they need to make efforts to secure their customer in order to keep them.

The following is a hypothetical which may illustrate the point-

What happens if a customer uses your company's lowest assurance method of login to your cloud hosting services... a shared key for example.  A hacker uses Google to find the customer's exposed code using a specialized search.  Imagine then, the hacker uses the customer's login and secret key to create a fully authenticated message to the customer's account gaining access to a VM that can't be traced back to them.  Then the hacker uses the new zero-day ring 3 VM breakout to compromise the host running hundreds of VMs inside the cloud service.  From there, the hacker or nation-state can leverage sufficient computing power to crack other systems in minutes.  The hosting company now has a compromised reputation, and permanently compromised revenue stream all because they didn't consider their customer is an asset.

So should a business fold users into their threat model?  The answer I would say "depends".  Customer=Asset does not compute for every industry.  But if your customers have highly portable data that can be taken elsewhere and and your business' reputation for security is the only thing between it and disaster... including your customer as an asset in your threat models may be the only sensible approach.

DC





Friday, June 01, 2012

Extreme Browsing

TAILS

If you are testing security or you simply want to surf without tracks you might enjoy TAILS which is a bootable DVD running Debian.  Essentially this will allow you to turn most any machine into a completely safe virtual browsing envrionment.  Check out the download here: https://tails.boum.org/download/index.en.html


Surfing "Home Style" with Socks

SSH tunneling for a home-away-from-home experience.  Ever find yourself behind a corporate firewall or untrusted network and want to check your personal email or your facebook account to see what you need to bring to the party tonight?  If you just need to browse safely you can easily do this via SSH and get your encrypted session from wherever you are to home.  Your home computer will then make requests on your behalf and pass the data back to your browser in an encypted session. If you're checking email you can usually do this via the web as well even on your POP accounts as most POP providers have browser front-ends you can access if you have the URL.

How do you set up this little magic trick and surf stright though firewalls and super IDS/IPS systems?

1) Set up a linux box at home with port 22 (SSH) incoming and outgoing on your firewall.  (Make sure the account has limited privileges and a very strong password)  If you know what you're doing you may even want to set up certificates.  

2) If you're on linux you're good to just open a shell and SSH -D (see the detail below) to your home machine and skip to step 3.  If you're on Windows you'll need Cygwin or Open SSH etc.  I have a small Windows app that I wrote to accomplish this in about 800KB if you want to set up on Windows and don't care to install a bunch of stuff.  [If you comment with your email I can send you a copy]

The popular thing is to use -N -L and pick your ports but there's a far easier way for the browser using built-in Sox proxy capability. Using a Sox proxy you can shorten your SSH command and save yourself some head ache and configure your browser more easily.

Execute on your client machine:
ssh -D 9050 [username]@[remote.server.name]
(remote.server.name is the IP or address of your linux box at home which is running SSH)

Your tunnel awaits!  Your session will expire eventually but while SSH is connected you will be able to set up your browser and surf safely using the port you chose.

3) Set your browser to use a Sox proxy at 127.0.0.1 port 9050 (or whatever port you want to default to.  Type in your destination into the browser such as:  http://www.ithumbmynoseatsensiblesecuritypolicies.com and voila you're surfing around all sensible precautions and filters.

You can set a specific browser instance (say Chrome or FireFox or IE) to always connect Socks.  This way you can keep your regular browser normal and playing nicely through the firewall and then open your browse-by-home super secret browser and surf like you're on your home network.

Of course this violates all corporate policies we know and love.  It also gives you a taste of what can be done if you let your home network or corporate network get hacked.  You shouldn't use this if you intend to stay compliant with any sensible regulation or policy.  But in a pinch this will get you home-style access from behind the great firewall of China.

You are what you surf so be safe.

DC

Friday, May 25, 2012

Yahoo and Facebook team up to snarf usage data

Yahoo now requires you sign an agreement when you use their comment system to leave comments on political news.  The agreement gives them the right to use any Facebook data they deem necessary and naturally they exclude themselves from all liability in taking and using whatever data they want.  If you haven't already clicked through the agreement blindly you may want to check it out and read the agreement text.

Yahoo and Facebook use "nonce" which is a one time usage key assigned to a user for a specific session which generally changes with time.  This is to stop cookie replay or man in the middle attacks but do nothing useful against "boy in the browser" attacks or XSRF.  XSRF is particularly useful in exploiting sites like Facebook, Google, Yahoo etc. which keep you logged in 24x7x365 unless you explicitly log out.  Facebook thoughtfully keeps you logged in even when you log out because they know you really don't ever want to leave...

The downside with sites like YouTube/Gmail and Facebook is that if you poke around Anonymous posts long enough you will find that they are actively exploiting your perpetually logged in status and the nonce system does nothing to stop your browser from making the evil request on your behalf. I found a link posted by an Anon member which opened up blogger.com and activated the change-password page.  But this issue illustrates a point with the danger of the perpetual login-session which all of the big-brother style systems are implementing.  When sites keep you perpetually logged-in in order to watch your behavior and to provide "convenience" then they are keeping themselves open to the possibility of a world-wide breach which could be exploited quickly to reach 100% of systems that view the poisoned page.

At least with a boy in the browser type of attack, attackers are limited to doing what Facebook and others already do... gain personal info about you or using your account for spam.  There is a small measure that sites can provide which stops the boy-in-the-browser attack which is for the developers to keep the submit button deactivated until keyboard input is received and validated in some way.

When using these super-sites you would be well advised to log out of them before going on a surfing session.

Tuesday, September 13, 2011

.Net IDE Error 9009 on compiling a project with post-build commands

The compile error 9009 may also come in the flavor of error 22 or error 1 on projects with a post-build command.  Sometimes it will even have multiple errors on the same item.  What is happening can be generally found by cutting the post-build command out of the error summary at the bottom of the IDE and pasting it into notepad, removing the prefix and postfix data and then trying it in the command line dos-box.

Generally there are three main things that will mess up post-build commands...
1) bad path
2) a path with a .,:=[ ] in it
3) a path with a space in it

Because DOS 8.3 naming conventions still live under the covers of post-build command execution you can expect to get hamstrung by any of these scenarios.  If you're developing under your personal workspace in windows you likely are being affected by number 3.

There is an easy way to deal with each of the above problems.
1) check your paths by pasting them into a File Explorer window
2) replace any of those characters with an underscore _
3) put your paths (even system named path variables) in double-quotations. "$(MyPath)\bin\debug\" for example.

Friday, March 11, 2011

Installing a .Net app as a service without using installutil

Possibly the easiest way to install a .net service without needing to have installUtil.exe on the server is to open a command prompt as Administrator (right-click the command prompt menu item and pick Run As Admin)

Once your command prompt comes up you can simply enter the following command line editing in your service name and path referencing the following example.  (note the space after the = sign is critical)

sc create MyServiceName binPath= "C:\program files\My Service\MyService.exe"

Tuesday, November 02, 2010

Convert Int64 to Binary

I had a situation where I needed to convert an Int64 to a Sql.data.linq.binary and just could not find any valid posts on the net for how to make it happen.  Those that I did find had mistakes in their implementation and either didn't compile or were converting to a base64 which is out of this universe wrong-headed.

I solved it by combining combining two wrong answers to make a right answer.  (And they say that "two wrongs don't make a right" but I've heard that three left turns do!)  Here's the real way to do it...

System.Data.Linq.Binary myBinaryVar = null;

myBinaryVar = new System.Text.ASCIIEncoding().GetBytes(Convert.ToString(myInt64Val,2)); 

Saturday, October 23, 2010

.NET 4 Assembly Security's Fresh-New DLL Hell

If you've been installing applications that use the .net 4.0 framework you probably have seen this message:
------------------
Problem signature:

Problem Event Name: CLR20r3
Problem Signature 01: cps.fuzzypreproc.exe
...
Problem Signature 04: Cps.FuzzyPreProc
...
Problem Signature 09: System.IO.FileNotFoundException
OS Version: 6.0.6002.2.2.0.272.7
----------------

If you're like me, you first checked to see if all your assemblies were copied locally and that your .exe permissions were appropriately set.  When you discovered that all these things were in order you probably started searching the net only to find millions of hits describing how this error has plagued developers in every form or .net for different reasons over the years.  Basically your Google results are a misleading spam of old problems and solutions.

If you have this problem AND are building with Visual Studio 2010 in .Net 4.0 you will experience this error for a different reason than all the other generations past that have suffered with it.  (The security requirements of .net 4.0)  .Net 2.0 used to use something called security "transparency" which allowed the .net 2.0 clr to find a matching dll and load it no matter if it was in the GAC or not.  No doubt this was done to ease the pain of .net developers competing against fast and loose java deployments which require little more than pushing a cleverly disguised .zip file to the server.  Now that security is being built into VS2010 more seriously we find that strongly named assemblies need a little more care. 

Specifically if you have a strongly named assembly and are design-time binding it. Reffing it directly in the designer you will be forced to install it into the GAC.  This means that your installer must be run locally on the server and the assemblies will be loaded into the GAC as trusted assemblies with appropriate permissions.  But your app will no longer find assemblies in it's local directory just by virtue of being there.  This new change is designed to resist hacking by keeping a malicious software developer from dropping a strongly named assembly in the local directory of an application and have it get picked up by the exe when it runs next.  Even though this would likely require a trusted access to a server (maybe even admin access) Microsoft is trying to lock down the deployment environment against tech savvy attackers.

If you have seen this bug, chances are it's been with a frequently updating tool set like a Telerik or some similar GUI tool set that tries to keep up to date with the latest compilers.  The problem does not seem to affect assemblies built with former versions of .net even if they are used under .Net 4.0. 

Solution:
So what do you do to fix this problem?  Microsoft suggests that you can use the solution in the post below, allowing for apps to use CLR 2.0 conventions if necessary, or you can run the client install of your tool set on the server (... i know... probably forcing you to fork out more dollars to the vendors and causing you more licensing problems) or you can build your own installer and digitally sign it.  A common suggestion is configuring a click-once install but there are permissions problems with it if installed remotely and you still have the problem of getting your assemblies into the GAC.  So I'd recommend the 2.0 support only if other solutions are impractical.  You may want to run as administrator and open Explorer to c:\Windows\Assembly\ and drag your files into the GAC.  But good form probably dictates having a signed install if you're going to be doing this regularly.  But once the strongly named assemblies are in the GAC this problem will magically disappear.

Sunday, October 17, 2010

'Error initializing queued image'

Working with Faxman you may receive the following error: 'Error initializing queued image'.  This error occurs when faxman is trying to create an appropriate outgoing image for a fax document usually using a .FMF or a .PDF. 

If you are using a .FMF file then likely the error is an issue of access.  For example you are running the faxman service under a "Local" account and the file resides on a share. 

For most other cases you may have the incorrect file path, incorrect file name or wrong file type!  Check your file type to ensure it's coming in as a proper .FMF or proper .PDF file.  Put a debug line in your code just as you add the filename to the fax.  Copy the file path out and paste it into your file browser to ensure it's valid.  Dump it to MadEdit or another binary capable text editor to take a peek at what's inside.  Chances are if your path is correct then you will discover the file type is a standard tiff (not a FMF) or an incompatible 3rd party type.

Happy debugging,
David

Friday, October 15, 2010

A fix for using Faxman under Visual Studio 2010

If you have run into the following error as pictured below:
Mixed mode assembly is built against version 'v1.1.4.122' of the runtime ... while using the faxman component under Visual Studio 2010 and .NET 4.0 there is a work-around.
 Open your app config.  Your startup segment should look roughly like the one below.
Change the opening startup tag to contain the "useLegacyV2Runtime..." element.



Adding this line should get you building and running in no time until Faxman comes out with a newer implementation.

I hope this can get you working again.

David Cross

Friday, September 10, 2010

Software Death Cycle and the Real Cost of Your Software

Software projects continue to be developed 24x7 in every country in the world.  The software shop or internal development group always vociferously argue that their project will save money.  Millions of dollars will be typically spent.  But what is the real lifetime of that software?

The answer is 2 years.

The reason for this varies but here are the contributing factors:
1) business requirements change
2) technologies change
3) software never meets the functionality need because it's late and or not finished
4) another group claims that they can replace the software with added efficiency using "new" technology and more strict methodologies in less time and with lower cost

Business requirements change over time and this inevitability leads directly to 4 on the list.  How much money do you spend rebuilding the same software every two years?  Why does new technology always justify a complete redesign? 

Sunday, July 26, 2009

Vista Drivers on Mac OSX (boot camp)

Several iterations of Mac OS have allowed dual boot capability with Windows. Essentially you can partition your hard drive using the boot camp program and allocate space to other operating systems.

Installation of Vista on using bootcamp:

Follow the prompts through creating your partitions.

You'll want to allocate at least 40+ GB of space for Vista. More space is required obviously if you want to add significant programs to it.

**To install Vista put the Vista disk inside BEFORE you click "Start Install" otherwise bootcamp will crash.**

Allow the Vista install to start.

Pick the partition you want to install Vista on.

Vista will complain about the partition not being the correct type... click on Advanced or Options on the Vista install screen and then click "Format". Vista will then do what it should have done in the beginning and prepare the partition and will install it's files.

Starting the Operating System You Want:

Restart your Mac and hold down the Option key as the screen goes dark during reboot. This will trigger the bootcamp menu and it will list the installed operating system that are available to boot to.

You can change your default by booting to your Mac side and changing the default in your system options bootcamp section.

Inevitable Driver Problems:

One of the lingering problems however has been the issue of drivers for Vista. The internet is filled with all kinds of bad advice on this topic and you are likely to get in trouble if you dig around too long. Before you waste any time on that try the easy way:

1) boot to your Vista side
2) put your Mac OSx CD, or bootcamp CD in if bootcamp comes on a separate disk (generally it will be the OS install disk itself)
3) it magically installs all the drivers you need
4) reboot

That's it!

If you follow this advice you will save yourself (as I can attest) hours of technical support and hours and hours of surfing the web and trying poorly informed advice from message boards after Apple technical support says that this is a "Microsoft problem" and you should talk to them instead.

I do know from experience that Microsoft USED to support these drivers and removed them from the Vista install (I wonder why?) So it is BOTH an Apple and Microsoft problem. Let's hope Apple tech support reads this blog and finds out how to install Vista properly using Boot Camp.

Sunday, April 05, 2009

Humanizing Software

Recently we've begun working with Ultimus, a BPM system which I believe is on the verge of revolutionizing software development. Does this mean Business Process Management software is ready for prime time? Yes and No. Some issues with new versions of Windows keeps it off of the new gold standard Windows 2008 Server. Other issues with form submission that will negate form data entries unless you click in the form prior to submitting it. Speed of course is relative but when you're talking the speed of Ultimus versus phone, sneaker-net or IM you're still talking a big time savings.

Where I think BPM shines is in queueing work flow and in creating a manageable people process around data.

Instead of hard and fast rules coldly analysing and rejecting people or charging them extra money etc, why don't we involve humans in the process at critical decision points? Instead of creating a log jam effect I believe it's possible to send "threshold" cases for human review. This gives you the efficiency of blindingly fast determinations with questionable decisions being routed to a human gaining the best of both worlds. I believe that quality software in the future will ensure human interaction instead of avoiding it.