16 Ocak 2025 Perşembe

Restore or Enable Admin Shares on Windows

If you want to enable admin shares on Windows, you need to change the parameter value to 1 or delete it:

Set-ItemProperty -Name AutoShareWks -Path HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters -Value 1

How to enable c$ admin share on Windows 10 and Windows Server 2016

The LanmanServer service creates administrative shares on Windows. Remote users cannot access shared resources on this computer if this service is stopped.

Get-Service LanmanServer

check lanmanserver service state

Windows can automatically recreate the hidden admin shares, simply restart the LanmanServer service with the command:

Get-service LanmanServer | restart-service -verbose

28 Aralık 2023 Perşembe

Checking whether SYSVOL and Group Policy are Synchronized on Windows Server DCs using DFSR

 


For /f %i IN ('dsquery server -o rdn') do @echo %i && @wmic /node:"%i" /namespace:\\root\microsoftdfs path dfsrreplicatedfolderinfo WHERE replicatedfoldername='SYSVOL share' get replicationgroupname,replicatedfoldername,state

The state values can be any of:

0 = Uninitialized

1 = Initialized

2 = Initial Sync

3 = Auto Recovery

4 = Normal

5 = In Error





12 Eylül 2022 Pazartesi

How to Backup Windows 10/11 Driver?

Method 1: Backing Up Drivers via Command Line Process

With the DSIM command, in Windows 8 and higher operating systems, you can take backups of all drivers used on the device to a folder you will create on your computer.

You can start the driver backup process by typing "cmd" in the "Run" window and executing the DISM command when Enter is pressed.

dism /online /export-driver /destination:”D:\Drivers Backup”

With this command; drivers are backed up to the previously created Drivers Backup folder on disk D.


Method 2: Backing up drivers in Powershell

When powershell is written in the "Type here for search" section at the bottom left of the screen, select Powershell and select Run as administrator with the right mouse button.

In the Powershell screen,

Export-WindowsDriver -Online -Destination "D:\Drivers Backup"

When the command is run, the computer will back up all the drivers to the Driver Backup folder on the D disk.

Scanning for Empty IP Addresses

Batch Pinging, Finding Empty ip Addresses, Batch Pinging ip Block:

We can say that a simple command directory has been prepared to find out which addresses are empty in an ip block, it is very useful and can be used in many areas.

First of all, let's learn our command:

 for /L %i in (1,1,254) do ping -n 2 -w 250 192.168.1.%i>> C:\ip.txt






 

28 Haziran 2019 Cuma

Uluslararası Sızma Testi Metodolojileri

Sızma Testi metodolojileri çeşitli topluluklar, ilgili kurum ve kuruluşlar tarafından güvenlik denetim testlerinin daha sağlıklı ve tekrar edilebilir sonuçlar üretilmesi için oluşturulmuş ve genel kabul görülmüş standartlardır.

Sızma testi ve güvenlik denetimleri için başlıca standartlar şunlardır;

OWASP (Open Web Application Security Project)
OSSTMM (The Open Source Security Testing Methodology Manual)
ISSAF (Information Systems Security Assessment Framework)
NIST SP800-115
PTES (Penetration Testing Execution Standart)
Fedramp

• OWASP (Open Web Application Security Project)

Bu kılavuz kurum ve kuruluşlara web uygulamalarının denetimi için; test uygulamaları, aşamaları ve kontrol listeleri gibi argüman ve programlar konusunda yardım etmek amacıyla yazılmıştır. Bu kılavuz mevcut pratik bilgiler ve geniş anlatımları ile örnek bir referans ve metodoloji olarak kullanılabilir. Bu çerçevede kuruluşların güvenilir ve güvenli bir yazılım oluşturmak için web uygulamalarını test etmelerinde yardımcı olur.

Owasp Foundation tarafından 2004 yılında “The OWASP Testing Guide v1” adı ile açık kaynak olarak ilk test rehberi kamuoyuna sunulmuştur.

2014 yılında yayınlanan ve web uygulama güvenliği üzerine en kapsamlı kaynak olan OWASP Test Rehberi v.4(The OWASP Testing Guide v4) adı ile yayınlanmıştır.

11 ana başlık altında değerlendirilen güvenli uygulama geliştirme ve güvenlik kontrol listesinden oluşmaktadır.

Bunlar;

1. Bilgi toplama
2. Yapılandırma ve Dağıtım Yönetimi Testi
3. Kimlik Yönetimi Testi
4. Kimlik Doğrulama Testi
5. Yetkilendirme Testi
6. Oturum Yönetimi Testi
7. Giriş Doğrulama Testi
8. Hata Giderme Testi
9. Zayıf Kriptografi Testi
10. İş Mantığı Testi
11. İstemci Tarafı Testi

•    OSSTMM (The Open Source Security Testing Methodology Manual)

2001 yılının Ocak ayında ISECOM(Güvenlik ve Açık Kaynak Metodoloji Enstitüsü) tarafından yayınlanan OSSTMM açık kaynak bir güvenlik testi metodolojisidir. Operasyonel güvenliği önemli ölçüde arttırabilecek eyleme geçirilebilir bilgiler sunmaktadır. Penetrasyon testi klavuzu yerine ISO 27001 referansını desteklediği söylenilebilir. 2010 yılında OSSTMM versiyon 3 yayınlanmıştır.

Anahtar bölümleri şu şekilde sıralanır.

1. Operasyonel Güvenlik Metrikleri
2. Güven Analizi
3. İş akışı
4. İnsan Güvenliği Testi
5. Fiziksel Güvenlik Testi
6. Kablosuz Güvenlik Testi
7. Telekomünikasyon Güvenlik Testi
8. Veri Ağları Güvenlik Testi
9. Uyum Mevzuatı
10. STAR (Güvenlik Testi Denetim Raporu) ile Raporlama

•    ISSAF(Information Systems Security Assessment Framework)

Bilgi Sistemleri Güvenlik Değerlendirme Sistemi (ISSAF) aktif bir topluluk olmasa da, iyi bir sızma testi referans kaynağıdır . Kapsamlı teknik bir sızma testi rehberliği sağlar. İlk versiyonu 2005’te yayınlamış ve bir güncelleme gelmemiştir.Güvenlik kontrol listeleri ve bilişim güvenliği argümanlarının değerlendirme ölçeklerini sunar.

NIST  SP800-115

Abd Ulusal Standartlar ve Teknoloji Enstitüsü tarafından 2008 yılında yayınlanan NIST SP800-115(Bilgi Güvenliği Test ve Değerlendirme Teknik Kılavuzu) adlı bu kılavuz günümüzde de önemli referans kaynaklarındandır. Kurum ve kuruluşlara teknik anlamda bilgi güvenliği test ve yöntemlerini planlama, yürütme, bulguları analiz stratejileri geliştirme konularında yardımcı olma misyonunu üstlenmiş bir rehberdir. Kılavuz, sızma testi ve inceleme süreçleri ve prosedürlerinin tasarlanması, uygulanması ve sürdürülmesi için pratik öneriler sunar. Bunlar, bir sistemde veya ağda güvenlik açıklarının bulunması ve bir ilkeye veya diğer gereksinimlere uygunluğun doğrulanması gibi çeşitli amaçlar için kullanılabilir.

Beş ana başlıktan oluşur. Bunlar;

1. Hedef Tanımlama ve Analiz Teknikleri
2. Hedef Güvenlik Açığı Doğrulama Teknikleri
3. Güvenlik Değerlendirme Planlaması
4. Güvenlik Değerlendirme Faaliyetleri
5. Test Sonrası Faaliyetler

Penetration Testing Execution Standart (PTES)

Açık kaynak bir proje olan Sızma Testi Yürütme Standardı 2009 yılında sızma testlerindeki konsensus oluşturulması amacıyla ilk versiyonunu kamuoyuna bildirmiştir. 2012 yılında son güncellemesini alan bu rehber yedi ana bölümden oluşmaktadır.

Standart bir sızma testi yürütmek için temel olarak tanımlanan ana bölümler şunlardır:

1. Ön Sözleşme
2. İstihbarat toplama
3. Tehdit Modellemesi
4. Güvenlik Açığı Analizi
5. İstismar Süreci
6. İleri Sömürü Aşaması
7. Raporlama

FedRamp Penetration Test Guidance

Federal Risk ve Yetkilendirme Yönetimi Programı (FedRAMP), Federal Bilgi Güvenliği Yönetimi Yasası’nın (FISMA) bulut bilişim hizmetlerine nasıl uygulandığını standartlaştırmak için oluşturulan ABD hükümet programıdır. İlk versiyonu 2015’te yayınlanan “FedRAMP  PENETRATION TEST GUIDANCE” 2017 yılında ikinci versiyonunu yayınlamıştır. Fedramp ile bulut tabanlı hizmetlerin güvenlik değerlendirmesi, yetkilendirilmesi ve sürekli izlenmesi için standartlaştırılmış bir yaklaşım sunar. Bu rehber kuruluşlara, Sızma Testi’nin planlanması ve yürütülmesi ile ilgili bulguların analiz edilmesi ve raporlanması konusunda rehberlik sağlamaktır.

Ana bölümleri şunlardır:

1. Bilgi Toplama ve Keşif  Aşaması
2. Web Uygulama ve Api Test Bilgisi Toplama ve Keşif Aşaması
3. Mobil Uygulama Bilgi Toplama ve Keşif Aşaması
4. Ağ Bilgi Toplama ve Keşif Aşaması
5. Sosyal Mühendislik Bilgi Toplama ve Keşif Aşaması
6. İç Ağ Bilgi Toplama ve Keşif Aşaması
7. İstismar Aşaması
8. İleri Sömürü Aşaması
9. Raporlama

10 Ocak 2018 Çarşamba

Disable Java auto updater script




dim wsh
set wsh = createobject("WScript.Shell")
wsh.run("REG.EXE DELETE ""HKLM\SOFTWARE\JavaSoft\Java Update"" /f")
wsh.run("REG.EXE DELETE ""HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"" /v SunJavaUpdateSched /f")
wsh.run("REG.EXE DELETE ""HKLM\SOFTWARE\WOW6432Node\JavaSoft\Java Update"" /f")
wsh.run("REG.EXE DELETE ""HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run"" /v SunJavaUpdateSched /f")
set wsh = nothing

JAVA Direct connection to Internet without Proxy Batch






Windows 7-8-10


(
  (echo(deployment.proxy.type=0)
)>>"%userprofile%\AppData\LocalLow\Sun\Java\Deployment\deployment.properties"




Windows XP


(
  (echo(deployment.proxy.type=0)
)>>"%userprofile%\Application Data\Sun\Java\Deployment\deployment.properties"



Clear All Windows EventLog

You can apply the extension by rotating * .bat.


@echo off
FOR /F "tokens=1,2*" %%V IN ('bcdedit') DO SET adminTest=%%V
IF (%adminTest%)==(Access) goto noAdmin
for /F "tokens=*" %%G in ('wevtutil.exe el') DO (call :do_clear "%%G")
echo.
echo Event Logs have been cleared!
goto theEnd
:do_clear
echo clearing %1
wevtutil.exe cl %1
goto :eof
:noAdmin
echo You must run this script as an Administrator!
echo.
:theEnd

8 Ağustos 2016 Pazartesi

Windows Server 2016 Lisanslama

Microsoft Windows Server 2016 işletim sistemi ile birlikte, lisans ücretlendirmesini de çekirdek seviyesine indiriyor.

Windows Server 2012 R2 sürümünden bu yana sunucularda kullandıkları işlemci başına lisans bedeli ödeniyordu. Windows Server 2016 işletim sistemi ile birlikte işlemci ve çekirdek başına belirlenmiş yeni bir ücretlendirme hayata geçirilecek.

Örneğin çift çekirdekli bir işlemci ile çalışan sunucunun en az 8 çekirdekli lisans bedeline başvurması gerekiyor. Veya 2 çekirdekli 4 adet işlemci ile çalışan sunucuların en az 16 çekirdek lisansını satın alması gerekiyor.

Bununla birlikte 8 çekirdekli 4 adet işlemci ile çalışan sunucular 16 çekirdek lisansı öderken, 40 veya daha fazla çekirdekle çalışan sunucularda ekstra ücretlendirme olacak.


14 Nisan 2016 Perşembe

Skype for Business Server Topology Builder encountered an issue and cannot publish this topology.



ERROR

The error message given below mostly appears when you trying to publish the topology for the very first time.

Topology Builder encountered an issue and cannot publish this topology.

SQL store \rtc is not defined in the topology. You must ensure that the SQL store that is used for the Central Management Store is part of the defined topology and that the SQL store is associated with a Front End Pool.

SOLUTION

1. Open Skype for Business Server Shell on the new Skype for Business Server role that you have deployed

2. Run Get-CsConfigurationStoreLocation. This cmdlet reports back the location of the Active Directory service control point for the Central Management store.

If the output of the above cmdlet is same as that of the SQL server and instance shown in the error above,

3. Run Remove-CsConfigurationStoreLocation cmdlet. The account running the cmdlet must be a member of RTCUniversalServerAdmins group.

4 Aralık 2015 Cuma

Remotely lock computer psexec


psexec.exe -accepteula \\[IPAddress_or_ComputerName] -i -s %windir%\system32\rundll32.exe user32.dll,LockWorkStation

Psexec LOGOFF Remote user / computer and administrators

Remotely Logoff User

Use it when you want to logoff a remote admin because you hate using the Windows Terminal Services Console or because sometimes it crashes.


C:\psexec.exe \\[IPaddress_or_ComputerName] -u DomainName\UserName cmd.exe

PsExec v1.94 - Execute processes remotely
Copyright (C) 2001-2008 Mark Russinovich
Sysinternals - www.sysinternals.com

Password: ********

Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\WINDOWS\system32>query session

SESSIONNAME USERNAME ID STATE TYPE DEVICE
>console Administrator 0 Active wdcon
rdp-tcp 65536 Listen rdpwd
rdp-tcp#4 User1 1 Active rdpwd
rdp-tcp#5 User2 2 Active rdpwd

C:\WINDOWS\system32>logoff 1

C:\WINDOWS\system32>logoff 2

12 Kasım 2015 Perşembe

Windows Server 2012 Enable Desktop Icons

Open Run


Copy and paste the line below into the Open: field, then click OK

"%Systemroot%\system32\rundll32.exe" shell32.dll,Control_RunDLL desk.cpl,,0

8 Haziran 2015 Pazartesi

ESX Host currently has no management network redundancy

When admitting a host to a HA cluster, or enabling HA on an existing cluster you may receive the "Host currently has no management network redundancy" warning message.


This happens due to requirements in a HA cluster where the management network (that is the service console or VMkernel port for management) is required to have two physical NICs.

If this requirement is not met the above error message is displayed. While I recommend you always, always ensure the management network has two pNICs and is redudant (including via seperate physical switches), it might not be possible in a demo/test environment.
In which case you may want to disable this warning message.


This can be done as follows...

1. Go to "Edit" the cluster settings

2. Click "VMware HA"

3. Click "Advanced Options"




4. Add "das.ignoreRedundantNetWarning" and set the value to "True", Click Ok



5. If there error still shows you need to select the host and click "Reconfigure for HA"

11 Mart 2015 Çarşamba

Disable users account move them to different OU PowerShell

Disable users account move them to different OU

Powershell Commands

Search-ADAccount –AccountDisabled –UsersOnly –SearchBase “DC=domain, DC=local” |Move-ADObject –TargetPath “OU=Disable Account, DC=domain,DC=local”

10 Mart 2015 Salı

Old Disabled Users list last logon date With Powershell

Old Disabled Users list last logon date With Powershell

12 month old

Search-ADAccount -accountdisabled | where {$_.lastlogondate -lt (get-date).addmonths(-12)} | FT Name,samaccountname,LastLogonDate | out-file -filepath C:\export.txt –noclobber

23 Aralık 2014 Salı

How Do I Set a Group Policy to Lock a PC After Minutes

1- Click "Start." Type "Gpedit.msc" into the search box at the bottom of the Start menu. Press "Enter."

2- Click "Yes" in the User Account Control prompt window, if one appears.

3- Navigate to the "User Configuration\Administrative Templates\Control Panel\Personalization" folder in the left pane of the Group Policy window.

4- Double-click the "Password Protect the Screen Saver" setting in the right pane of the Group Policy Editor window.

5- Click "Enabled." Click "OK."

6- Double-click the "Screen Saver Timeout" setting in the right pane.

7- Click "Enabled."

8- Type the number of seconds you want to lock the PC after into the "Seconds" box. For example, type "600" if you want to lock the PC after 10 minutes.

9- Click "OK."

12 Aralık 2014 Cuma

Event ID 2042 Active Directory Replikasyon Problemi


Active Directory içerisinde uzun zamandır kapalı tuttuğunuz ya da replikasyonu kesilmiş bir Domain Controller’ı devreye aldığınızda replikasyonla ilgili tombstone lifetime süresi geçti replike yapılamadı gibi uyarılar almanız muhtemeldir. Bu problemi çözmek için;
Yeni açmış olduğunuz sunucuda regedit.exe çalıştırılarak aşağıdaki registry kaydı girilir.
regedit çalıştırıldıktan sonra

“HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters” path’ine ulaşılır.

Sağ tıklayıp “New – DWORD value” seçtikten sonra aşağıdaki parametre ismi verilir.
“Allow Replication With Divergent and Corrupt Partner”

Parametrenin üzerine sağ tıklayıp “Modify” dedikten sonra Value “1” olarak girilir.

Replikasyon başlatılır ve tamamlandığını gördükten sonra bu parametrenin değerini “0” olarak değiştirmemiz gerekmektedir.

28 Kasım 2014 Cuma

Group Policy Slow Links Detection Nedir ?

Computer GPO ayarları bilgisayar yeniden başlatıldığında, User GPO ayarları ise log-on sürecinde uygulanmaktadır.Kullanıcı policy değişiklikleri için log-off ve log-on istenir.Makine GPO değişikliklerinin uygulanması için bilgisayarın yeniden başlatılması.

Bunların dışında birde GPO refresh süresi dediğimiz ve 90 - 120 dakika arasında kullanıcı ve makine policyleri tazelenir. Eğer GPO tarafında bir değişiklik var ise bu değişiklik uygulanır. Eğer bir değişiklik yok ise uygulanmaz.
GPO tarafında, kullanıcının daha hızlı logon olması ve bu tür yavaş bağlantılarda tüm GPO ayarlarının yüklenmesi yerine sadece kritik olan ayarların yüklenmesini sağlayan bu özellik “Slow link detection” olarak adlandırılmaktadır.

Aşağıdaki yolu izleyerek bir GPO için bu ayara ulaşabilirsiniz.




Computer Configuration\Policies\Administrative Templates\System\Group Policy altında
“Group Policy slow link detection”

Varsayılan olarak 500kbps olan bu değeri “0” sıfır yaparsanız eğer bu ayarı devre dışı bırakmış olursunuz. Yani aradaki network bant genişliği ne olursa olsun mutlaka tüm GPO ayarları uygulanmak için çalışır.

22 Ağustos 2014 Cuma

How to remove auto-mapping in Exchange 2010

I took the following steps on our Domain Controller server to remove the auto-mapping feature.
1. Open the tool ‘ADSI Edit’ from the Administrative Tools.
2. Browse to the offending user(mailbox) that you would no longer like to be automatically mapped to particular users.
3. Right-click the account and select Properties.
4. In the Attribute Editor, select ‘Filter’ in the bottom right corner.
5. Ensure ‘Show only attributes that have values’ is ticked.

6. Browse in the list attributes and select ‘msExchDelegateListLink’. These are the list of users that the account will automatically map to (populated by those with Full Access to the mailbox).


7. 7. Select Edit, click on the user you would like to no longer auto-map to and select Remove.

8. 8. Press Ok then Apply.