Wednesday, September 25, 2013

Does your business have a Cyber Security Plan?

Why is a cyber security plan essential for a small business? If you are a small business owner, don’t think that hackers are not interested in you or your data. A recent story in Entrepreneur magazine, relying on data provided by computer security company Symantec, indicated that small businesses with one to 250 employees suffered 30 percent of all cyber crimes this past year.
End point protection is important
Any cyber security plan begins with an anti-virus software. This software is critical for small business owners. Anti-virus isn’t the only protection that is needed today, but companies that don’t have any anti-virus protection are setting themselves up for an extensive hack.
Employee Education
Business owners need to make sure that their employees are aware of the need for deleting suspicious email messages, whether sent by known or unknown sources. Businesses must educate their employees never to click on the links contained in suspicious email messages. Anti-malware, Firewalls, intrusion protection and web filtering are some additional steps that small businesses can take to mitigate the risks that are prevalent today.
DDKinfotech has been helping small businesses mitigate the risks of cyber attacks.   Call us today at 212.997.0600 and speak to an expert regarding your Cyber Security needs.

Thursday, September 19, 2013

A case for Email Archiving - Why your Email Need Protection and Preservation - Today

Why Email Archiving is Important

1. Protecting IP

Businesses today of all sizes need the value of their intellectual property to be maintained in perpetuity. They want to assure that their repository is 100% accurate, even if an employee accidentally or deliberately deletes their email.

2. eDiscovery

Many government agencies and regulations require certain stringent levels of security, permanence and auditability for business email. This includes FRCP, SEC, GLBA, HIPAA, HITECH, SOX, and more.

3. Compliance

Businesses need to cut the risk and costs of complying with discovery requests. They need their emails preserved and protected for the lifetime of the business. They also need it to be simple to produce emails to comply with legal requests or audits.

How Email Archiving Improves Protection

Email Archiving adds layers of protection beyond standard levels


Email security threats

System Downtime & Security, Spam and Viruses, Message Loss (Accidental & Deliberate) are Standard protection that's fundamental to your cloud service. Accidental and Deliberate deletions, Regulations and Litigation are threats that would require Email Archiving. Email Archiving offers protection against legal, regulatory and personnel threats that go beyond the data security and reliability you may already receive.
DDKinfotech specializes in Hosted Exchange Services. DDKinfotech's hosted Exchange 2013 lets your company communicate and collaborate more effectively than with any other email platform. Optionally we offer services that address Compliance and Email archival.
Contact us at 212.997.0600 to discuss how DDKinfotech can customize a Email Archive and compliance solution to meet your specific business needs.

Office 2010 Problems Caused by Microsoft Critical Update KB2589275

On Tuesday, September 10, Microsoft released a critical update that caused Office application files to become disassociated with the actual application. (See Microsoft KB2589275 – Critical Update for Office 2010 update: September 10, 2013)
Issue: Microsoft Office application icons disappear and are replaced by general MS Office orange icon.
If you have installed this update and are experiencing problems, the following three solutions can be used to resolve them:
  1. Right click on the general MS Office icon that replaced the correct icon; select "Open with"; select the correct Office application; select "Always use this application"; the file icon will revert back to the correct Office application icon.
  2. Uninstall the update and hide it on the Windows update website and/or blacklist it on the ITSupport Portal per the article above.
  3. Run the command for MS Word with the /r parameter. Click on Start; Hit Run; Type “winword.exe /r”
Solution 3 should launch the application configuration and temporarily fixes file associations issue without uninstalling this update.
DDKinfotech's Managed Services Clients should not face this issue as we have blacklisted this update from being installed.



It has become essential to take measures to protect your business PCs from numerous threats encountered these days. Threats to your business and business productivity are more pervasive than ever. Hackers use various techniques that make Malware protection extremely difficult.
1. Use Endpoint Protection:  Use antivirus software from a reputable company.  Also, make sure that Endpoint protection you are using has Malware protection and Spyware protection built in.  As long as you have a valid subscription, your antivirus will automatically update from the Internet. Most Virus Protection companies push updates several times a day. Malware on the Internet entices users to download free Security software, so make sure that you are downloading  Security software from a reputable company and not some malware that poses itself as Security software. If you are not sure you should discuss this with your IT department or someone knowledgeable.
2. Keep your Operating Systems up to date: Operating System vulnerabilities are released on a regular basis and most are addressed through regular updates. You should regularly check for updates for your operating systems. At work check with your techs to see how they handle this. Most IT departments use Management software to push Operating system updates to all the computers.
3. Remove all Unnecessary software: Remove software that is unnecessary or not needed. This will reduce the attack surface, this is extremely important on servers. Make sure you backup any data before removing any programs.
4. Backup your data: Make sure you have current backup all the time. In case you were attacked by a virus, or your system crashed or a piece of hardware in your computer failed, you will have a backup to revert to.
5. Be very Wary of Unexpected Emails and Attachments:  Be very very wary of emails from people you know and you don't know. If you receive an email from someone you don't know, especially if it is sent to a group of people, immediately delete it. If the email is coming from a source you do know but it is unexpected and has attachment and or links that you don't recognize or are not expecting, more than likely that person's email account has been compromised and the hacker is trying to spread the attack to you, as your contact was in the person's email account.
6. Don't click on Internet Links you don't recognize:  Web links can connect you to websites and webpages that may be hosting malicious software which will infect your system without your knowledge. Only click on links from a source you know and trust. The easiest way to find out whether a link may be illegitimate is to hover your mouse over the link to see where it is taking you. Most email programs offer a preview of the actual link when you hover over.
7. Passwords: Enable passwords and use strong passwords. Do not use same passwords for all the services that you use. If you use different passwords for different services at least not all your accounts will get compromised if a hacker was to get hold of one of your passwords.
8. Keep Applications Updated: All PCs have software such as Java, Flash, Adobe Reader installed these days. These software are essential to carry out transactions and activities on the Internet. There have been known vulnerabilities in these software. Keeping these applications up-to-date is essential and will protect you from many vulnerabilities.
DDKinfotech specializes in Managed Services. Our Managed Services lets you focus on growing your business, instead of worrying about IT. Our Managed Service Offering comes with Antivirus, Spyware, Malware protection, OS Patch Management, 3rd Party Patch Management, Asset Management and system monitoring. Also, included is our secure remote access to your office desktop.
Contact Us to schedule no obligation, free Assessment, Click here

Monday, June 17, 2013

Shoretel DID hitting Voicemail Directly

I was experiencing an issue with a phone where when someone called a user's DID it would hit their Voicemail.  Checked all the settings and the Call handling and everything was setup correctly where the the call should hit the Voicemail after 5 rings.... Confusing!!

Workaround to fix the issue, was to create a new Route Point in the Director.   First I had to remove the DID from the user's profile.  Then I created a Route Point for the DID and under Call handling I Call Forwarded the DID to the user's extension.  This seemed to have resolved the issue.

Steps

  1. Login into the Director
  2. Under Call Control Go to Route Point
  3. Click on Add New 
  4. Type in a name for the Route Point
  5. Accept the default extension number or type one that is not in use
  6. Enter the user's DID that is giving trouble
  7. Under Call Handling  Call Forward Always to the User's internal Extension.


Please note, this is a workaround to get the problem resolved.

How to Telnet into a Shoretel Phone

Yes, there is a way to telnet into a shoretel phone?  Well, when would you ever use this useless piece of information?  Probably never.  I had to do just this yesterday at a site where the phones were setup using Static IP addresses as there is no DHCP server.   User complained that the date and time on the phone was wrong and I just knew that the tech who setup the phone probably put the wrong IP address for SNTP server, so i had to figure out how to fix the issue without standing in front of the physical phone.

When you need to telnet into the phone it has to be done from the ShoreTel HQ server.  You will also need to have the IP address of the phone that you need to telnet into.  This information can easily be gathered from the Director.  Login into the Director and on the Navigation go to IP Phones => Individual IP Phones.

Once you have the IP address of the phone that you need to Telnet into

1.  Login into the ShoreTel Server
2.  Open up a Command Prompt, and change the directory to x:\Program Files\Shoreline Communications\shoreware server  (x is the drive letter where your Shoretel Software is installed to)
3.  Type "phonectl -pw 1234 -telneton xxx.xxx.xxx.xxx".  If you kept  the default password then it is 1234, otherwise type the password that you are using in your environment.   (Please note xxx.xxx.xxx.xxx is the IP address of the phone that you are trying to telnet into.
4.  You should now be telnetted into the phone, if the telnet fails try Steps 1 through 3 again.

If you found this Post useful please use like button below ( is that too much to ask) and or +1 on Google+.  Thank you!!

Unfortunately, I was not able to set the SNTP server on the phone via telnet, there is no command for it.  If anyone knows a command to set or change a parameter via telnet please post here.   If you just want to simply view the configuration on the phone, after you follow steps above and have telnet connection type:

printsysInfo, this will show you the running config of the phone.


Thursday, September 20, 2012

Sophos detecting itself as Virus Shh/Updater-B

Starting Wednesday evening we received numerous phone calls and also automatic alerts regarding Sophos antivirus detecting its own update as malware.

All the PCs running Sophos started throwing alerts generating false positives reporting SHH/Updater-B malware.  We were getting slammed with alerts by email regarding the issue. In panic we called Sophos support but I guess we were not alone as every single Sophos customer was hit with this issue and their phone lines were hijacked with these customers.  We could not get through to them.

Sophos later posted an apology and a  knowledgebase article on how to resolve this problem which can be read here.