June 29, 2012

Top 10 tips for navigating Windows 8 Metro

Moving around Windows 8 Metro isn't intuitive, so here are some pointers

The classic example: How do you turn off a Windows 8 machine?

The answer: swipe out the Charm menu from the right side of the screen, choose Settings, touch the power button, and choose Shut Down. Simple, yes?

RELATED: This Windows 8 tablet might actually be a PC

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training
at certkingdom.com



HARDWARE: 12 available devices to test drive Windows 8

Windows 8's Metro interface is anchored by the Start screen, a collection of colored rectangles called tiles that are labeled with text to explain what they are. So the mail application says Mail and has a stylized envelope displayed on it. The tile to access the Windows store says Store on it and features a stylized shopping bag.

The Start screen stretches out horizontally and may take up several screens that can be scrolled by sliding a finger on a touch screen or left-clicking the arrow buttons in the bottom corners.

Metro is distinguished by its use of the full screen to display current applications. All the chrome of the navigation bars and systems tray so familiar in earlier versions of Windows are gone. Tools that serve these functions are hidden off-screen.

Some of these comprise the charms bar, a set of buttons hidden to the right of the screen. They can be called out with the swipe of a finger on a touch screen. These charms are labeled Search, Share, Start, Devices and Settings.

Swipe the left side, and you get the applications bar, which displays a thumbnail of each running application. Pressing any one of them brings it to fill the main screen.

Those are the basics, but there's still a lot to know. Here are 10 tips for performing useful tasks in Windows 8 that you might never discover on your own. Tasks can be carried out using touch or mouse and keyboard.

1. Returning to the Start screen: It's easy to lose your way in Windows 8 when you're just learning it, and finding the Start screen can help re-anchor you. To find it using a touch screen, swipe out the Charms bar on the right and press the Start charm. With a mouse, click the bottom-left corner screen. You'll know it's ready for the click when a tiny image of the Start screen pops up. On a keyboard, press the Windows key.

2. Organizing the Start screen: The Start screen is made up of a large number of tiles, so separating them into categories makes it easier to find the ones you want. Drag tiles either with a finger or using a mouse and dropping related tiles near each other.

3. Naming groups of tiles: Zoom out on the Start screen to get an overall view of the Start screen tiles. This can be done using a two-fingered pinching gesture or clicking on the minus button in the lower right. Find the group you want to name, right-click on it and choose Name Group, type the name and press Enter. Or touch the group, choose Name Group and type in the name.

4. Pinning tiles: Not all applications are displayed on the Start screen. To add one, right-click or touch a blank spot on the Start screen and click or touch All Apps when it appears on the bottom. Right-click or touch the app you want to pin, then click or touch Pin to Start.

5. Displaying administrative tools: Right-click the mouse in the lower left corner. Or press the Windows key + X and the tools menu appears in the lower left. Or, while on the Start screen, press the Windows key + I, select Tiles, press Enter, press the space bar to change Show Administrative Bar to Yes. Administrative tool tiles will be pinned to the extreme right of the Start screen. Or swipe out the Charms bar, touch Settings, touch Tiles, flip the switch to Yes.

6. Search: In Windows 8, the Search charm can be used to search the system or, if it is invoked while in an application, to search the application. To search, access the Charms bar, choose Search and type in the search term. If you want to search the Start screen, just start typing your search term on the Start Screen. After your first keystroke, a search window appears. It will be searching apps by default, so if you want to search something else, you have to press or click on it.

7. Switching from app to app: When you have more than one app open, click in the upper right to reveal thumbnails of all active apps and click on the one you want. With touch, swipe out from the left side of the screen then back to the left side again without lifting your finger. That will reveal the thumbnails (this display is called the Switcher). Press the one you want.

8. Snapping apps: Metro supports displaying two apps at once, one in a narrow strip at either the right or left and one occupying the rest of the screen. The smaller one is said to be snapped to the side. To do so, type Windows key + . and it snaps on the right; press them again and it snaps to the left; do it again and it becomes full-screen. To switch between the snapped app and the main app, drag the vertical dividing bar between the two toward the center until the main app snaps to the other side.

9. Closing a Metro app: Metro apps idle in a low-power state in the background when not in use, but to shut them down, swipe from the top of the screen and, without lifting your finger (or releasing the left key if you're using a mouse), drag to the bottom. The app will first shrink and, as it reaches the bottom, will disappear.

10. Getting out of Metro: Had enough Metro? Press Alt + Tab and release when you get to the desktop.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training
at certkingdom.com

June 27, 2012

The 10 most demanding jobs in IT

Emerson survey cites roles requiring 'Always-On' availability

What are the 10 most demanding jobs in IT?

Well, according to a survey by Emerson Network Power, a provider of high-availability data center infrastructure management products, they are:

1. Executive director/administrator
2. IT procurement
3. CIO
4. IT manager/director
5. IT operations
6. Data center manager
7. Engineering
8. IT security
9. Applications/software development
10. Database management


MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training
at certkingdom.com


LOOKING: Want a new IT Job? Now's your chance

Emerson surveyed 800 IT professionals from four regions -- the U.S., Asia, Europe and Latin America -- representing 17 work roles and 18 industries, at businesses ranging from 50 to more than 10,000 employees. Most questions were designed to gauge who and what role in IT was "Always-On" -- a reference to Emerson's business in power supplies -- and used an agreement scale ranging from strongly disagree to strongly agree.

There we three open-ended questions:

• How many hours per week do you work at your IT job? Include paid and unpaid hours.

• What are the most demanding aspects of your IT job?

• Please describe one or two situations that best illustrate how your IT job requires you to be Always-On: always available, always working at peak capacity and always accurate.

Respondents at the executive director/administrator level -- including administrator, leader, department head and director -- have hands-on involvement in every aspect of IT: strategic, operational and tactical. All say they work on many projects at once, and that their work requires a high level of intelligence. Only 25% agree or strongly agree that success depends on things out of their control; that they are accountable for success, and that translates into high job demands, the Emerson survey found.

IT procurement officials identified themselves as analysts, buyers, representatives, supervisors, consultants, directors and other leaders. More than half of respondents say they don't have control over their schedules and don't have time to do quality work. They indicate multiple pressures: urgency, demanding clients often in different international time zones, staying up on the latest equipment and filling pressing staffing needs.

CIO scores highest on "dependencies and multi-tasking," according to the Emerson survey. Responses show particularly high requirements to work on many projects at once and make important decisions quickly, and those decisions can be required any time. Other respondents say they have to be available to take emergency calls and have been tracked down even on vacation.

Demands of the job also include motivating and orchestrating the work of others. CIOs also indicate more than did any other IT role that they are responsible for a large part of the company's budget.

IT manager/director might be called on to put out fires or do routine work at any time, including nights and weekends, the survey found. Respondents say demands include juggling several projects at once, solving problems quickly and working at peak capacity at all times.

Respondents also say they have responsibility for a large portion of the company's budget and for leading the meetings they are in.

IT operations personnel include technician, manager, analyst, operator and specialist. They report working on high-stress projects with constant time pressure and responding to after-hours incidents, the Emerson survey found.

Data center managers were in the top three for "dependencies/multi-tasking," the top four for "availability" and the top five for "quick response." They also scored more than 30% higher than average in agreeing they don't control their own schedule -- 70% for data center managers compared to 45% on average.

Job demands and responsibilities include working fast, handling confidential information, troubleshooting, managing budgets, hardware maintenance and "everything," the Emerson survey found.

Engineers scored high in "dependencies, "multi-tasking" and "quick response." More than 80% agree or strongly agree that others depend on their work a great deal, 91% say they immediately read all messages received and 86% quickly respond to all inquiries. Thirty percent of the respondents work for consulting engineering companies, and "perfection" was cited as one of the job demands.

Making emergency decisions is noted as a typical demand of the IT security group. Eighty-nine percent of the security respondents agree or strongly agree they make important decisions quickly -- the highest score of all the IT roles.

But this group also scores lowest on quick response, the Emerson survey found. Sixty-one percent agree or strongly agree they quickly respond to all inquiries, but the average across the top 10 Always-On jobs is 76%. More than half of IT security respondents say that success depends on things out of their control.

Application and software developers are apparently able to concentrate on their work more than others. One-third or less report having no time for quality work and no time to think things through.

This group scores highest in quick response, though, the Emerson survey found. Eighty-seven percent of respondents say that others depend on their work a great deal; and job demands include developing new applications for the workplace or industry, some involving highly complex issues.

Database managers have a similar profile to application/software developers: 87% say others depend on their work a great deal, but 58% say they have no time for quality work and 47% say they have no time to think things through.

Those responses are consistent with the demands of the job, the Emerson survey concludes, which include working under pressure while troubleshooting various issues on a daily basis, often under tight project deadlines.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training
at certkingdom.com

June 26, 2012

The two most feared attacks and how to avoid them

Large organizations with ample resources quake in their boots over two common security threats. Here's your best defense

These days when I'm consulting with big businesses, governments, and other organizations, two main topics come up over and over: pass-the-hash attacks and hacktivism. One government client put it thusly: "Our department considers pass-the-hash attacks our No. 1 threat, above all other computer threats." A lot of things are broken in the security world, so to pick out one and call it the greatest threat is saying something, especially since the customer has what most readers would consider nearly unlimited funds, a multitude of competing vendor partners, senior management support, and a horde of experts with whom to discuss the problem.

Defending against pass-the-hash atttacks
The reason pass-the-hash attacks are so feared is that once the password hashes have been obtained, the attackers can move around the compromised environment with ease. Hashes can be used to access any protected resource within the same forest. Worse, if a domain admin has logged on to a computer, a local attacker with Administrator credentials can harvest the domain admin authentication hashes right out of memory.

[ Prevent corporate data leaks with Roger Grimes' "Data Loss Prevention Deep Dive" PDF expert guide, only from InfoWorld. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

I think it is the latter attack, the ability for an attacker to elevate themselves to domain administrator -- just because a domain admin had logged on to a box -- that scares defenders the most. Essentially, the trustworthiness of your domain admin credentials are now an exponential factor of every computer they have ever been used on.

How to fix it? The best way is to not have any domain admins. Even if attackers compromise elevated accounts, their access is less than elevated domain admin. And if they add themselves to the domain admins group, an alert will be generated quickly because your monitoring software will know that should be an empty group. Here are other actions you can take:

Never log on to a normal end-user workstation as a domain administrator. Limit your domain administrator logons to domain controllers or special file servers. By never logging onto regular workstations, you significantly reduce risk.
If you have to log on using domain admin (or other elevated credentials), always do so from a trusted computer. These are known as "jump" boxes. These jump boxes can be unique per user, virtual machined, and flashed cleaned after every use. The idea is to always log on to boxes that you know are clean.
Do as many administration tasks and fixes as possible using remote console tools, which are less likely to leave password credentials in memory on the remote computers. Most pass-the-hash attacks take interactive log-ons (unfortunately Remote Desktop and Terminal Services are interactive log-ons), so the less of them you do, the better.
If you have to interactively log on to a computer, after you are through, reboot the computer (if possible). Rebooting removes the credential temporarily stored in memory.
Frequently update elevated account passwords. I have many clients who change passwords after every use, often with the help of third-party software. That way, if an attacker grabs the credentials out of memory, so what? They aren't any good anymore.

The No. 1 way to prevent pass-the-hash attacks is to keep the bad guy from getting domain admin or local admin in the first place. After doing your best to achieve that, see how far you can get using the other recommendations above.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training
at certkingdom.com


The looming hacktivist threat
Another growing fear involves hacktivism-style attacks. Most companies point to the malicious success of the Anonymous group. Each CIO I've spoken with is increasingly worried that determined adversaries will get access to data if they want it.

You might ask why they don't fear APT (advanced persistent threats) as much. They do, but most have already been through that pain and are living with the outcome and response. And unlike APT, which usually steals data silently, hackivists steal data or cause DoS attacks, and they publicize the fact to embarrass the entity and cause it to lose customers, trust, and money. In many circles, the publicity factor is worse than some city-state threat looking to steal intellectual property.

How do you defend against hackivist threats? Most attacks of this ilk begin with a compromised Internet-facing host or social engineering of credentials from a trusted employee. If you're worried about hackivists, start here.

First, conduct a penetration test on your outward-facing assets. Why let random attackers be the first to test your new Internet-facing application, server, database, or defense? Use your own testers and/or hire "red teams" to fill the role of the rogue hackivist.

Make sure all custom application code has undergone security development lifecycle creation and review. Make sure all your software is created from the ground up with security built in from the start and not as an afterthought.

Engage in strong antisocial engineering education for all end-users who are in a position to release credentials or protected information. Recently, I was asked to assess how well a large company's antisocial engineering education and policies were working to prevent hackers, calling in over the phone, from obtaining credential information or other employee-related data from administrative assistants.

At this company, the assistants are part of the first-tier support for such information, and they're all trained to ask for specific information and/or to check for confirmation with superiors before releasing such data. I was amazed with the results. Although the company has thousands of administrative assistants, often changing, each with varying levels of computer skills and malware awareness, the education program has been highly successful.

After hundreds of over-the-phone hacking attempts each year, as far as I know, only one hacker was successful in the course of the last decade in obtaining a password reset and none were in obtaining personally identifiable information. No one knows if every attempt (successful or not) was noted, but when going back and auditing accesses and password resets, we were able to verify that nearly 100 percent of them were legitimate and valid requests when reported as such, and vice versa.

I got to listen (or read transcripts) to many of the recorded phone calls of hackers trying to obtain protected information from administrative assistants. The calls went something like this: The hacker would always start by being as friendly as possible, while asking for access to confidential information or a password reset. When challenged to produce the verifying information, the hackers always became more hostile. The more the assistants resisted, the more the hackers challenged. Many times, by the end of the call, the hacker would explode in anger and threaten the assistant's job security. I wondered how well I would have handled such a call early in my career. It showed me that a well-run education program could work.

Of course, you can't rely on end-user education alone. I prefer systematic DLP (data loss prevention) solutions. DLP software monitors your content and traffic flows to prevent unauthorized access. False positives are still a problem, but recent improvements have helped.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training
at certkingdom.com

Bookmark and Share