VMware Tools for Windows 12.2.5

VMware Tools for Windows 12.2.5

Andres Bohren
Hi All, VMware has released a Security Advisory for VMware Tools VMSA-2023-0013 VMware Tools update addresses Authentication Bypass vulnerability (CVE-2023-20867) You can download the newest version of VMware Tools here: VMware Tools 12.2.5 After loggin in you need to consent to the general Terms to download the VMware Tools In the downloaded zip File is the ISO File with the VMWare Tools for Windows I’ve extracted the ISO, Renamed it and uploaded it to the Datastore
Azure DevOps Pipeline build number warning

Azure DevOps Pipeline build number warning

Andres Bohren
Hi All, I’ve had a warning in my Azure DevOps Pipeline, that deploys this Blog via Hugo to Azure Static Website. The build number format string Azure Static Web Apps CI/CD generated a build number Azure Static Web Apps CI/CD which contains invalid character(s), is too long, or ends with ‘.’. The maximum length of a build number is 255 characters. Characters which are not allowed include ‘"’, ‘/’, ‘:’, ‘<’, ‘>’, ‘', ‘|’, ‘?
Azure Storage Explorer 1.30.0

Azure Storage Explorer 1.30.0

Andres Bohren
Hi All, Today i’ve seen the notification, that Azure Storage Explorer 1.30.0 has been released The Release notes can be found here Azure Storage Explorer 1.30.0 As already announced it’s now x64 only (no x86 Version available anymore) Several components will use .NET 6 Support for *.avro and *.parquet in Preview I’ve donwloaded the Installer and here are the Screenshots of the Installation Everything went smooth an now i am using Azure Storage Explorer 1.
Microsoft Code 1.79 fixes security issue

Microsoft Code 1.79 fixes security issue

Andres Bohren
Hi All, In Microsoft Code 1.79, there has been an update that fixes a security issue. You can find the details here Closed Issue A information disclosure vulnerability exists in VS Code 1.79.0 and earlier versions on Windows when file system operations are performed on malicious UNC paths. Examples include reading or resolving metadata of such paths. An authorised attacker must send the user a malicious file and convince the user to open it for the vulnerability to occur.
June 2023 Exchange Server Security Updates

June 2023 Exchange Server Security Updates

Andres Bohren
Hi All, Yesterday, Microsoft has released new Exchange Security Updates. Read more at the Blog Post from the Exchange Team Released: June 2023 Exchange Server Security Updates In my case that’s Exchange 2016 CU23 Security Update 8 Security Update For Exchange Server 2016 CU23 SU8 (KB5025903) Description of the security update for Microsoft Exchange Server 2016: June 13, 2023 (KB5025903) Installing the Security Update After the Security Update is installed, it is a good idea to restart the Server.
KeePass 2.54 released

KeePass 2.54 released

Andres Bohren
Hi All, Lately KeePass was in the Press because of the Security Eploit below. Simple Security Exploit Allows Retrieval Of KeePass Master Password, Patch Inbound In short, KeePass 2.53 and earlier loads the master password into memory in plaintext when it is entered via the keyboard. This means all an attacker has to do is get their hands on a memory dump regardless of if that comes from “the process dump, swap file (pagefile.
Microsoft Defender for Office 365 Recommended Configuration Analyzer (ORCA) 2.5 released

Microsoft Defender for Office 365 Recommended Configuration Analyzer (ORCA) 2.5 released

Andres Bohren
Hi All, Just a few Hours ago, the Microsoft Defender for Office 365 Recommended Configuration Analyzer (ORCA) 2.5 was released to the PowerShell Gallery. PowerShell Gallery ORCA 2.5 Seems like some bugs have been closed ORCA Closed Issues Check installed Module and what’s available from the PowerShell Gallery Get-InstalledModule ORCA Find-Module ORCA Uninstall old Module and install the newest one from the PowerShell Gallery Uninstall-Module ORCA Install-Module ORCA Get-InstalledModule ORCA Check what commands are available in the Module
Swiss Domain Security Report Q3 2022

Swiss Domain Security Report Q3 2022

Andres Bohren
Hi All, In 2015 i wanted to know how many SMTP Servers used STARTTLS, SPF, DKIM, DMARC. I’ve programmed a Webspider with PowerShell and collected about 100'000 Domains. Then made another Script that queried those domains and made SMTP Connect to find out if STARTTLS was in the ELHO Response. The Result was a Report of about 100'000 Domains from the .ch Top Level Domain. The Results from 2015: About 90% of the Domains used MX About 75% of the SMTP Servers offered STARTTLS About 28% of the Domains with MX had an SPF Record About 1% or less DKIM and DMARC was barely present In 2022 i have extracted the Open Data of Switch DNS Zone Data for the .
Microsoft Edge Drop

Microsoft Edge Drop

Andres Bohren
Hi All, Do you know the Drop Feature in Microsoft Edge? Use Drop to share files and messages between your phone and desktop devices. Simply drag and drop files to share instantly or send notes to yourself while you browse in Microsoft Edge and stay in the flow. Klick on the little Paperglider icon on the right Navigation and hit “Start” I am already logged in with Edge (see icon on Top) so no furhter Authentication is needed
Microsoft Remote Desktop for AVD and Windows 365

Microsoft Remote Desktop for AVD and Windows 365

Andres Bohren
Hi All, You can use Remote Desktop client for Windows to connect with Azure Virtual Desktop (AVD) od Windows 365. What’s new in the Remote Desktop client for Windows Installation of the Client Default is only for user - i’ve changed it to all users for this computer Click on “Subscribe” Logon with your credentials Now you see the AVD or Windows 365 Machines assigned to you If you click on the Machine you have to login again