Archive for the 'The Investigator’s Computer' Category

Page 3 of 4

Power User 111 – Windows Security Threat

Hack into a Windows PC – no password needed

A security consultant based in New Zealand has released a tool that can unlock Windows computers in seconds without the need for a password.

To use the tool, hackers must connect a Linux-based computer to a Firewire port on the target machine. The machine is then tricked into allowing the attacking computer to have read and write access to its memory.

With full access to the memory, the tool can then modify Windows’ password protection code, which is stored there, and render it ineffective.

“If you have a Firewire port, disable it when you aren’t using it,” Ducklin said.

“That way, if someone does plug into your port unexpectedly, your side of the Firewire link is dead, so they can’t interact with your PC, legitimately or otherwise.”

The moral of this story is: don’t let unauthorised people have physical access to your computer and shut off the Firewire port unless you are actually using it.

Paperless Office?

I don’t believe in the paperless office. I remember a client who tried to impose the “paperless office”. Employees kept paper files in their car trunks and they would sneak out to the parking lot to review critical paper files and notes throughout the day.

However, we can streamline how we handle paper files. Here are some good articles on the subject.

  • Paperless office is pure fiction: report
  • Is Paperless Possible?
  • 6 tips for a ‘paperless’ office
  • 12 Tips for an Organized Desk
  • “Paperless Myth: Rumours of Paper’s Demise Have Been Greatly Exaggerated” By Ulla de Stricker
  • “Why I Prefer Hardcopy” By Katrina Hughes
  • Power-User 110 – Browser Add-ons

    I do not use IE as my default browser due to security concerns. For several years I have used Firefox, first to address the security issue, then because I liked the tabs and add-ons. Here are my favorite add-ons.

    NoScript  allows JavaScript, Java and other executable content to run only from trusted domains of your choice, e.g. your home-banking web site, and guards the “trust boundaries” against cross-site scripting attacks (XSS). Such a preemptive approach prevents exploitation of security vulnerabilities (known and even unknown!).

    Tab Mix Plus provides all sorts of Tab options that don’t exist in Firefox.

    Cooliris Previews lets you preview a web link without having to open up the whole page. You can expand the preview to a full tab/window, navigate within the preview, e-mail the site/page link to others, etc..

    PDF Download solves all the problems with opening PDF files in Firefox.

    Zotero is a citation manager, recommended and supported by about 100 academic institutions.

    Split Pannel allows you to view two pages simultaneously for comparison or copying info from one to the other. Can be resized by dragging the bar between the main browser and new panel.

    Internote allows you to create persistent sticky notes on a web page which will be there once you return. Notes are very customizable, and come with many small, useful features. A manager is available, in which you can see all of your saved notes, edit them, print them, and delete them.

    Resurrect Pages 1.0.8 allows you to see dead pages, broken links by searching through five big page cache/mirrors: CoralCDN, Google Cache, Yahoo! Cache, The Internet Archive, and the MSN Cache.

    The two following add-ons save time and allow access to pages that are browser specific without switching browsers to view IE only websites.

    User Agent Switcher allows access to sites that might restrict your access based on which browser you are using. Since it does not render a page as another browser might and doesn’t work with every site.

    IE Tab enables use of the embedded IE engine

    Another List of Social Networking Sites

    Wikipedia maintains a long list of social networking websites. The links are to other Wikipedia articles about the listed sites so that you can get a feel for what the sites might offer.

    Power User 109 – What’s Running on Your Computer?

    Your computer is running slow. You’ve used system cleaners and virus checkers, spyware and malware removal tools and more. Now you’re in Task Manager looking at what’s running on your computer — what in the world is crss.exe? pmmon.exe? isass.exe? You might as well be looking at ancient hieroglyphics.

    Try Process Library. It allows you to search for meaningless process terms and retrieve familiar easy to understand descriptions of each process. Quickly find out if a process is needed or malicious and what to do with it. Complete with search, security rating, description, and recommended action, this is the perfect tool for cleaning up unwanted processes haunting your computer.

    (Reproduced with permission from The SurfReport Vol. 96)

    MS Office Phooey

    The drastically redesigned MS Office 2007 interface, called the Fluent User Interface, (FIU), and yes, it is pronounced Phooey, should be a wonderful exercise in frustration.

    The tradional toolbar has been replaced with the “ribbon” that is supposed to be an improvement over the old toolbars, if I ever figure-out where anything is really located. Thankfully the keyboard commands still work.

    The people who will suffer most the most performance degradation with this redesign are knowlegable users who employ a wide variety of the features.

    Combine the performance degradation with the new file format and you have a massive migration project for the power users.

    Thank-you MS for something else that I won’t use until there are no other options.

    Power User 108 – Styles & Templates

    A style is a set of text formats such as fonts, sizes, text alignment, spacing, etc.. A style can then be used to create text or to format existing text.

    Styles should form a hierarchy that makes the report look organised and consistent. MS Word is not a typewriter. For instance, the normal style is the paragraph style. It should be set-up to insert the space before and after the paragaraph. The typist does not insert carriage returns to start a new paragraph.

    Every document is based upon a template. A template is a collection of document formatting options upon which a new document is based. A template should not have more than 20 styles.

    Templates need to be properly managed throughout the company. The templates provide a consistent reporting format and the text that is frequently repeated in each report. To properly maintain the templates they should reside in only one directory on one server. If a change is made it is made by an authorised person and only one template needs to be altered.

    In MS Word, a template ends with .dot as in normal.dot. It is not a document that is used over and over again, all the while collecting style after style, until it causes Word to crash because it is creating corrupted documents.

    Power User 107 – MS Word

    If you must use Word, then get what some users are calling the “Word Sanity Package” – a collection of utilities that address Word’s most irritating shortcomings:

    * Payne Numbering Assistant – replaces Word’s utterly mystifying auto-numbering/outlining system with an interface that makes it actually work the way people expect it to.

    * Metadata Assistant – a must-have for every Word user. Removes Metadata from outbound Word, Excel and Powerpoint files. Also lets you view all the Metadata contained in documents you receive.

    * Levit & James CrossEyes – similar to WordPerfect’s Reveal Codes for Word. This is a real time-saver as it let’s you “look under the hood” of your documents to find and resolve problems.

    * CrossFingers from Levit & James – repairs corrupted Word files. Unfortunately, this tool is needed more often than it should be.

    * Stylizer from Levit & James – conforms internally generated and externally received documents to your standard styles. It reduces the time wasted by Word documents others send to you that contain messed up styles that begin to infiltrate and ruin your internal document base.

    Dangerous Googling

    Google accounts present a serious risk to employees who use them in the workplace. Google accounts allow you access to Gmail and another interestng feature, your search history. Unfortunately, your Google account does not time-out.

    Now imagine you’re at work. You sign-on to your Google account and check your mail and use Google Reader to check some RSS feeds. You are then called away from your desk. You don’t sign-off, afterall, its only Google. Well your collegue drops by and decides to do a search and check his mail. He searches for a prostitute for tomorrow evening and checks his Gmail and finds yours.

    Your collegue has now added some interesting entries to your search history and read your mail. My Yahoo presents a similar risk.

    This leads me to think of some interesting oportunities that this offers if I set-up virgin Google and My Yahoo accounts and place them on an unattended PC.

    How To Be A Power User 106

    Did you know you can streamline your start menu? It’s always amazes me how PC users suffer with a horrible mishmash in the start menu. To sort the entries in the start menu alphabetically, right click on the start button and then on Properties. In the Start Menu tab, click on Customize. This is where you can add or remove items from the Start Menu. It also offers you the opportunity to Sort the menu items alaphabetically when you click on Sort.

    Once you click on Sort, click on OK and wait for the PC to work its magic. Click OK again and go to the newly alphabetically arranged start menu. If for some reason a few items don’t sort to where you want them, then Left click and hold the mouse button down while you drag the item to its proper place and just release the mouse button.

    Google Face Filter

    If you are looking for pictures of a particular person, then start your search in Google Image Search and the put “&imgtype=face” (without the quotation marks) at the end of the search results URL. This filter will then provide a new results page with only portrait-like pictures.

    Try a search on paris. The results will relate to Paris (the City), France, the Eiffel Tower, Paris Hilton, etc.. A search on paris, but with “&imgtype=face” appended to the end, returns results mostly of Paris Hilton and other faces, because they match face results. Now try a search on google. Without the face filter you get screen captures of the Google home page. If you add the face filter parameter to the URL, you get pictures of people and faces related to Google.

    I found an interface for the face filter, which does not require you to enter the filter to the URL, that appears to work very well.

    While this Google filter works very well, it does not provide every usable picture for the person you are looking for. The picture has to be very much like a portrait to appear in the results of this filter. This is a good tool but it isn’t perfect, but then what is?

    How To Be A Power User 105

    Well organized, efficient, and fast, describe the Power User.

    To get fast access to files, a Power User will create 3 toolbars to access the most used folders from the desktop or from within applications. These toolbars will appear at the top, left, and right margins of the screen.To create the toolbars just right-click a folder and drag it to the desktop and create a shortcut there. Next drag it to the edge of the using the left mouse button and release the the mouse button and you now have a toolbar. To enlarge it, pass the cursor over the edge until the double arrow appears and drag the edge to to where you need it.

    You can add another folder to the toolbar by right-clicking on an unused part of the toolbar and selecting Add a Folder. Now right-click on the toolbar and select Always on Top and Auto-Hide.

    Folders with a large number of files or URL’s may occassionally take some time to display their contents. To avoid this problem, orgainize the folder contents into separate sub-folders.

    How To Be A Power User 104

    When you install software it frequently adds features you don’t want. One such feature is loading itself, or some part of itself, at startup. This makes the boot process much too long and unnecessarily ties-up memory resources.

    To correct this annoyance click on Start then Run. In the dialog box type msconfig and hit enter. Now select the Start-up tab and uncheck the offending programmes and restart your PC.

    You will be confronted by a warning message. Read it carefully. Do not check the box to eliminate it just yet. Got to Start/Run and enter msconfig again. Look at the General tab, you will notice some changes but don’t do anything. Use your PC for a day to be sure everything runs OK and then shut it off normally. When you start it the following day, check the box to eliminate the warning message if everything is working properly.

    However, if you experienced problems go to Start/Run and enter msconfig and revise your choices in the Start-up tab or select Normal Stat-up in the General tab.

    How To Be A Power User 103

    Everyone who uses MS Office needs two little extras that make writing reports easier.

    The first is a Windows Clipboard extender called Ditto. This saves every item copied to the normal clipboard for easy access in any application, MS or not.

    The next indispensible programme is a Dictionary and Thesaurus called WordWeb. This is the easiest to use of all the similar programmes I have tried. Just click on a word and open WordWeb from the QuickLaunch toolbar.

    The best feature of these two programmes is the cost — they are free.

    How To Be A Power User 102

    In our quest for true Power User status we need to have a spartan looking desktop. Eliminate the clutter of icons and URLs that inhabit your desktop. Learn to use the Start Menu to start programs now that you have it working properly. If you have a few programmes that you insist in starting from the desktop, organize the shortcuts in folders.

    Your desktop should look something like this uncluttered desktop.

    Desktop