End of Support for Microsoft Windows Server 2003

end windows server 2003

 

A large number of businesses still run Microsoft MSFT -1.71% Windows Server 2003 and it’s unlikely they all will upgrade before Microsoft Corp. ends support on July 14, 2015, say analysts. Companies that don’t upgrade increase their cyber security risks because the company will no longer issue security updates and these systems will be more vulnerable to hackers.

Businesses worldwide run an estimated 23.8 million physical and virtual instances of Windows Server 2003, according to data released by Microsoft in July 2014. Analysts say the technology is more prevalent in industries such as health care, utilities and government. Yet it’s also still used in about 7% of retail point of sale systems, according to a report Thursday by Trend Micro Inc.4704.TO -1.11%

“Microsoft does not plan to extend support for Windows Server 2003 and encourages customers who currently run Windows Server 2003 and have not yet begun migration planning to do so immediately,” said Vivecka Budden, a Microsoft spokesperson, in an email.

South Jersey Techies offers various migration options to include Windows Server 2012 R2, Microsoft Azure, hosting partners and Office 365.

“It is going to be difficult to get this done in time,” said David Mayer, practice director of Microsoft Solutions at Insight Enterprises Inc.NSIT -1.12%, a provider of IT hardware, software and services.

Many of these same industries were impacted by the end of service for the Windows XP operating system on April 8.  Microsoft broadcasts these sorts of moves years in advance, so it shouldn’t come as a surprise to anyone. But, the product was stable and for many companies there simply wasn’t incentive to update.

“In general, everyone has been slow to migrate, especially those with servers that are running applications,” said Rob Helm, vice president of research at Directions on Microsoft consulting firm.

The problem in industries such as health care and utilities is that companies run legacy apps written by vendors who still require Windows Server 2003. For example, there are smaller vendors in health care that have not kept up with development and application modernization, said a health-care CIO who asked not to be identified. A hospital may have an inventory of 100 to 500 different applications and many applications will still require Windows Server 2003, he added.

Electric utilities, for example, widely use Windows Server 2003. There hasn’t been much movement to upgrade those systems, said Patrick C. Miller, founder of the nonprofit Energy Sector Security Consortium and a managing partner at The Anfield Group, a security consulting firm. Instead, utilities are working to better secure and isolate those systems.

“I’m concerned about directory services such as application authentication and user permissions,” said Mr. Miller. “If you compromise an Active Directory server, you get access to everything.”

For now, analysts are recommending that companies work out their risk of exposure and make plans to first migrate those applications that will be most difficult. Companies should make plans to harden servers that can’t be updated. That might entail putting those systems on an isolated network, where they’d be less prone to outside attack, said Mr. Helm.

To protect and upgrade your home or business

 please contact us 856-745-9990 or click here.

 

New Security Threat: CryptoWall

 

crypt

In October of last year news broke about a new form of malware called Cryptolocker. This malware posed a particularly large threat to many business users and led to many quick and important security updates. Now, almost a year later, it appears that the second version of this – CryptoWall – has been released and is beginning to infect users.

What is Crypto malware?

Crypto malware is a type of trojan horse that when installed onto computers or devices, holds the data and system hostage. This is done by locking valuable or important files with a strong encryption. You then see a pop-up open informing you that you have a set amount of time to pay for a key which will unlock the encryption. If you don’t pay before the deadline, your files are deleted.

When this malware surfaced last year, many users were understandably more than a little worried and took strong precautions to ensure they did not get infected. Despite these efforts, it really didn’t go away until earlier this year, when security experts introduced a number of online portals that can un-encrypt files affected by Cryptolocker, essentially neutralizing the threat, until now that is. A recently updated version is threatening users once again.

Cryptolocker 2.0, aka. CryptoWall

Possibly because of efforts by security firms to neutralize the Cryptolocker threat, the various developers of the malware have come back with an improved version, CryptoWall and it is a threat that all businesses should be aware of.

With CryptoWall, the transmission and infection methods remain the same as they did with the first version: It is most commonly found in zipped folders and PDF files sent over email. Most emails with the malware are disguised as invoices, bills, complaints, and other business messages that we are likely to open.

The developers did however make some “improvements” to the malware that make it more difficult to deal with for most users. These changes include:

  • Unique IDs are used for payment: These are addresses used to verify that the payment is unique and from one person only. If the address is used by another user, payment will now be rejected. This is different from the first version where one person who paid could share the unlock code with other infected users.
  • CryptoWall can securely delete files: In the older version of this threat, files were deleted if the ransom wasn’t paid, but they could be recovered easily. In the new version the encryption has increased security which ensures the file is deleted. This leaves you with either the option of paying the ransom or retrieving the file from a backup.
  • Payment servers can’t be blocked: With CryptoLocker, when authorities and security experts found the addresses of the servers that accepted payments they were able to add these to blacklists, thus ensuring no traffic would come from, or go to, these servers again. Essentially, this made it impossible for the malware to actually work. Now, it has been found that the developers are using their own servers and gateways which essentially makes them much, much more difficult to find and ban.

How do I prevent my systems and devices from being infected?

Unlike other viruses and malware, CryptoWall doesn’t go after passwords or account names, so the usual changing of your passwords won’t really help. The best ways to prevent this from getting onto your systems is:

  • Don’t open any suspicious attachments – Look at each and every email attachment that comes into your inbox. If you spot anything that looks odd, such as say a spelling mistake in the name, or a long string of characters together, then it is best to avoid opening it.
  • Don’t open emails from unknown sources – Be extra careful about emails from unknown sources, especially ones that say they provide business oriented information e.g., bank statements from banks you don’t have an account with or bills from a utilities company you don’t use. Chances are high that they contain some form of malware.

Microsoft IIS: Disabling the SSL v3 Protocol

 

Depending on how your Windows servers are configured, you may need to disable SSL v3.

Note that older versions of Internet Explorer may not have the TLS protocol enabled by default. If you disable SSL versions 2.0 and 3.0, the older versions of Internet Explorer will need to enable the TLS protocol before they can connect to your site.

For a Simpler Way to Disable the SSL v3 Protocol:

DigiCert is not responsible for any complications or problems if you decide to use this .zip file to disable the SSL v3 protocol on your server.

  1. Log into your server as a user with Administrator privileges.
  2. Download DisableSSL3.zip, extract the .zip file contents, and then double-click DisableSSL3.reg.
  3. In the Registry Editor caution window, click Yes.
  4. Restart server.

If you prefer to do it yourself, follow the steps in the instruction below.

Microsoft IIS: How to Disable the SSL v3 Protocol

  1. Open the Registry Editor and run it as administrator.For example, in Windows 2012:
    1. On the Start screen type regedit.exe.
    2. Right-click on regedit.exe and click Run as administrator.
  2. In the Registry Editor window, go to:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\Schannel\Protocols\
  3. In the navigation tree, right-click on Protocols, and in the pop-up menu, click New > Key.
  4. Name the key, SSL 3.0.
  5. In the navigation tree, right-click on the new SSL 3.0 key that you just created, and in the pop-up menu, click New > Key.
  6. Name the key, Client.
  7. In the navigation tree, right-click on the new SSL 3.0 key again, and in the pop-up menu, click New > Key.
  8. Name the key, Server.
  9. In the navigation tree, under SSL 3.0, right-click on Client, and in the pop-up menu, click New > DWORD (32-bit) Value.
  10. Name the value DisabledByDefault.
  11. In the navigation tree, under SSL 3.0, select Client and then, in the right pane, double-click the DisabledByDefault DWORD value.
  12. In the Edit DWORD (32-bit) Value window, in the Value Data box change the value to 1 and then, click OK.
  13. In the navigation tree, under SSL 3.0, right-click on Server, and in the pop-up menu, click New > DWORD (32-bit) Value.
  14. Name the value Enabled.
  15. In the navigation tree, under SSL 3.0, select Server and then, in the right pane, double-click the Enabled DWORD value.
  16. In the Edit DWORD (32-bit) Value window, in the Value Data box leave the value at 0 and then, click OK.
  17. Restart your Windows server.You have successfully disabled the SSL v3 protocol.

For instructions about disabling browser support for the SSL v3 protocol, see Disabling Browser Support for the SSL 3.0.

 

10 places to recycle your cell phone

EcoAtm

Here are 10 places to take your phones so they can be refurbished, reused, or recycled and diverted from the landfill.

1. EcoATM

EcoATM is an automated kiosk that collects your unwanted cell phones and tablets and gives you cash for them. It’s made by the same people that make CoinStar, so you’ll find them by the checkout lines at various grocery store chains. It accepts devices from any era or in any condition, and offers anywhere between a few bucks to a few hundred dollars in return. EcoATM partners with R2 certified e-waste reclamation facilities to ensure they are recycled, or gives the phones a second life.

2. Eco-Cell

Eco-Cell is a Louisville, Kentucky-based e-waste recycling company. It partners with nonprofits and organizations such as the Jane Goodall Institute. Bins are located in coffee shops and other businesses around the country, where the collected phones are shipped to Eco-Cell in Louisville. If the phones are reusable, they resell them and pass some of the money back to the owner. If they are not reusable, the phones are recycled and the owner is paid the money for the value of the recycled materials.

3. Best Buy

Best Buy has recycling kiosks in their stores in the US, as well as recycling in-store for no charge to you. They typically limit it to three items per family, per day. From there, they work with recycling companies to make sure the phones and other electronics don’t end up in landfills.

4. Hope Phones

The Hope Phones campaign was started in 2009 by Medic Mobile, which works to advance health care in 16 countries by using mobile technology. Individuals, nonprofits, groups, or businesses can host a Hope Phones campaign to donate old phones. They are recycled and valued so the nonprofit can get new technology for the field. Most old models are valued at $5, but newer smartphones are regularly valued at $80, according to the website.

5. Cell Phones for Soldiers

Cell Phones for Soldiers is a nonprofit that works to provide cost-free communication services to active-duty military and veterans. New or gently used mobile phones are accepted and each device valued at $5 turns into 2.5 hours of free talk time for the soldiers.

6. Gazelle

Gazelle is one of the most popular trade-in options for old cell phones. The company is headquartered in Boston, with locations in Louisville, Kentucky and in Texas. Pick your brand, model, carrier, and plug in what kind of shape it’s in, then get an offer. Ship it for free, and receive a check or gift card to Amazon.com or PayPal after they check it out and make sure it’s worth what you say it is.

7. Call2Recycle

Call2Recyle  is a no-cost recycling program for batteries and cell phones in the US and Canada. It has collection boxes that can be placed anywhere, which have shipping permits so mailing them is easy. They also have bulk shipping if there is a large amount of recyclables.

8. Your carrier

AT&T has a trade-in program for unwanted phones and accessories regardless of manufacturer or carrier. The owner gets a “promotion card” which can then be used to take money off a new phone or other purchase. Make sure you erase all your information before you turn them in, though.

Verizon also offers a trade-in program where the owner can receive an electronic gift card once they send in the phone and have it appraised.

9. Local places

Your city undoubtedly has places to recycle old phones. Most local government websites, like New York’s, have directions of where to go to recycle phones. A lot of cities usually have nonprofits that donate old phones as well. The EPA also has an option to find out what electronics you can recycle with mail-in options.

10. Recycling for Charities

This nonprofit features one charity at a time, for which they donate money from recycling old phones. All makes and models are welcome at Recycling for Charities, and the phone condition is not an issue. They make an attempt to refurbish it first, then find recycling centers to ensure the materials won’t go into landfills if the phones cannot be reused.

These 10 services are well-researched and well-known options, but make sure to research on your own where your phone is going to make sure it is going to a certified e-waste recycler, so it doesn’t end up in a landfill despite your efforts.

 

Microsoft Office for iPad is here!

ipad-office

Edit, work, create, and get more done from your iPad, for free

ipad-office3

Four new, free apps are available on your iPad®. With both Microsoft OneDrive and Dropbox access, online storage—and access to your files—is always just a click away on your iPad. The new Microsoft Office apps give you the ability to flat out get more done.

  • With the new Microsoft Word app, you can edit, create, and save your docs, wherever work takes you
  • The new Excel app lets you analyze your data on the fly
  • Build and deliver your presentations—right from your tablet or phone—with the new PowerPoint app
  • The new Microsoft OneNote app helps you work collaboratively and stay organized on the go

With these apps, you can now access, edit, and save directly to your Dropbox account. You can even open and edit files that have already been saved in Dropbox.

Adding Dropbox is easy.  When you are in any of the new apps, follow these simple steps:

1. Tap on the arrow in the top left, then tap Open
2. Tap “Add a Place”
3. Select Dropbox

To get the Office apps for iPad®, open www.appstore.com/microsoftoffice from your iPad’s web browser.

 

Important: Internet Explorer Vulnerability

IEIMPORTANT INFORMATION: US-CERT and UK security agencies warn users to stop using Internet Explorer because of the severity in this security hole that has been used in “limited, targeted attacks”.

United States Computer Emergency Readiness Team released an alert on April 28, 2014 regarding vulnerabilities in Microsoft’s Internet Explorer.  Internet Explorer versions 6 through 11 are susceptible to be victims of attacks to exploit the Remote Code Execution Vulnerability.

US-CERT Vulnerability Note VU#22292

Microsoft Security Advisory 2963983

Workarounds:

Basic protection includes the installation of Anti-malware software, enabling a Firewall and applying all Windows/Microsoft updates.  In addition to basic protection, we recommend taking extra preventative steps listed below.  It is not necessary to apply all of the following workarounds, apply one to help protect your system and data.

Enable Enhanced Protection Mode

    1. Open IE 10 or IE 11.
    2. Click the Tools menu and select Internet Options.
    3. In the Internet Options window, click the Advanced tab.
    4. Scroll down the list of options until you see the Security section, click the checkbox to Enable Enhanced Protected Mode.  For IE 11 in a 64-bit version of Windows, you also need to click the checkbox to “Enable 64-bit processes for Enhanced Protected Mode”.
    5. Restart IE to force the new settings.

Change Access Control List and unregister VGX.DLL:

32-Bit Systems:

      1. Open elevated Command Prompt (Run as Administrator)
      2. Run the following command:
        “%SystemRoot%\System32\regsvr32.exe” -u “%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll”
      3. Click OK to close Dialog Box confirming un-registration has succeeded.

64-Bit Systems:

      1. Open elevated Command Prompt (Run as Administrator)
      2. Run the following command(s) separately:
        “%SystemRoot%\System32\regsvr32.exe” -u “%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll” “%SystemRoot%\System32\regsvr32.exe” -u “%CommonProgramFiles(x86)%\Microsoft Shared\VGX\vgx.dll”
      3. Click OK to close Dialog Box confirming un-registration has succeeded.

Windows XP and all other users.

For all user(s) that cannot follow recommendations from Microsoft are urged to use a different web browser.  For secure download(s) of Google Chrome or Mozilla Firefox, please follow the links provided.

For assistance with Changing IE Settings or Install a new Browser

 please contact us 856-745-9990 or click here.

 

Top Smartphones for 2013 Holiday Season

2013smartphone2

iPhone 5s

The iPhone 5S was launched with iOS7.  The updated camera with iPhone 5S has become popular against competitors. Also, the iOS 7 includes many new features including fingerprint identification on the home button, control center, multitasking, enhanced Siri and many more.

The iPhone 5S is available with all major carriers.  Contract prices are $199-399 or without Contract prices are $649-$849.

HTC One

The HTC One runs Android 4.3, a quad-core processor, 2 GB of RAM, 1080p LCD displays and an ultra mega pixel camera.  The most popular feature with HTC One is the front facing speakers and dual microphones.

The HTC One is available with all major carriers.  Contract prices are as low as $50 or without Contract price is $550.

Samsung Galaxy Note 3

The Samsung Galaxy Note 3 is the most prevailing Android device on the market.  The Galaxy Note 3 includes many features, such as, the S Pen, 13 mega pixel camera (rear), microSD storage, a removable battery, LTE and many more.

The Samsung Galaxy Note 3 is available with all major carriers.  Contract price is$299.99 or without Contract price is $699.99.

Nokia Lumia 1520

The Nokia Lumia 1520 runs Windows Phone 8 OS.  The 1520 offers a larger display, faster processor, and lower resolution camera than the Lumia 1020.  Features of the Lumia 1520 include integrated Microsoft Office, 20 mega pixel camera, HD 1080p display and many more.

The Nokia Lumia is only available through AT&T.  Contract price is $199.99 or without Contract price  is$584.99.

Google Nexus 5

The Nexus 5 runs Android 4.4.  The Nexus 5 includes a Snapdragon 800 processor, 8 mega pixel camera, HDR+, wireless charging and many more.

The Nexus 5 prices are $349 (16GB) and $399 (32GB).

Moto X

The Moto X runs Android 4.4.  The Moto X includes many features, such as, 10 mega pixel camera with quick capture, touch-less control, face unlock and many more.

The Moto X is available with all major carriers. Contract price is $99 or without Contract price is $499.

LG G2

The LG G2 runs Android 4.2.2.  The LG G2 has 1080p IPS display, 13 mega pixel camera, power and volume rear keys , clip tray, knock on and many more features.

The LG G2 is available with all the major carriers.  Contract price is $199.99 or without Contract price is $603.99.

Samsung Galaxy S4

The Samsung Galaxy S4 runs Android 4.2.  The Galaxy S4 has a 13 mega pixel camera with Dual shot and Drama Shot, Air View that allows you to control your phone with hovering instead of touch, WatchON, S Health and many more.

The Samsung Galaxy S4 is available with all the major carriers.  Contract price is $199.99 or without Contract price is $627.99.

Motorola Droid Maxx

The Motorola Droid Maxx has outlasting power with a 3,500 mAh capacity battery.  The Droid Maxx features include active notifications, always-on listening, Command Center, wireless charging, 10 mega pixel camera and many more.

The Droid Maxx is only available at Verizon Wireless.  Contract price is $199.99 or without Contract price is $499.99.

Sony Xperia Z1

The Sony  Xperia Z1 is waterproof and dust resistant.  The Xperia Z1 has man features that include 20.7 mega pixel camera, full HD TRILUMINOUS display, quad-core processor, 2GB RAM, microSD card slot, and many more.

The Sony Xperia Z1 is available without a contract for $649.99.

 

Second Generation Surface Tablets

mss2_1

Microsoft has offically announced that the release date for the second generation surface tablets, Surface 2 and Surface Pro 2, will be October 22, 2013.  Pre-order for Surface 2 and Surface Pro 2 is available.

Both new Surface tablets will have a dual-angle kickstand and multiple connectivity options such as Bluetooth 4.0, Wi-Fi 802.11, USB 3.0, micro-SD expansion and HD video-out port.

The new Type and Touch Covers will be released with both tablets.  Both Covers include backlighting and additional sensors.  Also, Microsoft has designed a Power cover that is designed to add additional battery life to both Tablets.

mss21

The Surface 2 has a 10.6 Clear Type Full HD (1920×1080) Display and will run Windows RT 8.1 Operating System on an nVidia Tegra 4 Processor. The Surface Pro 2 has two storage options including, 32 GB and 64 GB.  Surface 2 is priced at $449.

sur2

Pre-order a Surface 2 Tablet.

mss22

The Surface Pro 2 has a 10.6 Clear Type Full HD (1920×1080) Display and will run Windows 8.1 Pro Operating System on an Intel Core i5 Processor. The Surface Pro 2 has multiple storage options including 64 GB, 128 GB, 256 GB and 512 GB.  Surface Pro 2 is priced at $899.  

surp2

Pre-order a Surface Pro 2 Tablet.

American Red Cross – Mobile Apps

Untitled

September is National Preparedness Month sponsored by the Federal Emergency Management Agency in the US Department of Homeland Security.  American Red Cross now offers Mobile Apps that include a Volunteer App, First Aid App, Shelter Finder App and multiple natural disaster Apps.  Prepare your company and family for emergency situations using ‘Make a Plan’ feature in each App.

vaVolunteer App

Team Red Cross wants you! Join Team Red Cross to help provide care and comfort to your local community when the unthinkable occurs. Team Red Cross is looking for people with various backgrounds, talents, and skill levels. Make a difference, support your community and join Team Red Cross!

taTornado App

Get your family and home ready for a tornado with the official Tornado App from the American Red Cross. The Tornado app puts everything you need to know prepare for a tornado – and all that comes with it – in the palm of your hand.

haHurricane App 

Monitor conditions in your area or throughout the storm track, prepare your family and home, find help and let others know you are safe even if the power is out – a must have for anyone who lives in an area where a hurricane may strike or has loved ones who do. 

sfaShelter Finder App 

The Red Cross Shelter Finder is available in the iTunes store and works on iOS devices. The Shelter Finder displays open Red Cross shelters and their current population on an easy to use map interface.

faaFirst Aid App

The official American Red Cross First Aid app puts expert advice for everyday emergencies in your hand. The official American Red Cross First Aid app offers videos, interactive quizzes and simple step-by-step advice it’s never been easier to know first aid. 

eaEarthquake App 

Be ready for an earthquake with Earthquake by American Red Cross. Get notified when an earthquake occurs, prepare your family and home, find help and let others know you are safe even if the power is out – a must have for anyone who lives in an earthquake-prone area or has loved ones who do.

wfaWildfire App 

Be ready for wildfires with the official Red Cross wildfire app. Blaze Warnings, Blaze Alerts” and Blaze Path Tracker are tools included with the Wildfire App. You can also let loved ones know that you are safe even if the power is out and learn what steps you should take to prepare your family, home and pets – all from the palm of your hand.

Download these Apps:  Android and Apple