Wednesday, August 2, 2017

Tabula Rosa Systems - Blog Of 8/2/2017 - CMDLET -What Is It?




Buy the books at

 www.amazon.com/author/paulbabicki
+++++++++++++++++++++++++++++++++++++++++++++++++++++===================================================








  From whatis.com
cmdlet
A cmdlet (pronounced "command-let") is a lightweight Windows PowerShell script that performs a single function.
A command, in this context, is a specific order from a user to the computer's operating system or to an application to perform a service, such as "Show me all my files" or "Run this program for me." Although Windows PowerShell includes more than two hundred basic core cmdlets, administrators can also write their own cmdlets and share them.
A cmdlet, which is expressed as a verb-noun pair, has a .ps1 extension. Each cmdlet has a help file that can be accessed by typing Get-Help <cmdlet-Name> -Detailed. The detailed view of the cmdlet help file includes a description of the cmdlet, the command syntax, descriptions of the parameters and an example that demonstrate use of the cmdlet.
Popular basic cmdlets include:
Cmdlet
Function
 Get-Location
 get the current directory
 Set-Location
 change the current directory
 Copy-Item
 copy files
 Remove-Item
 remove a file or directory
 Move-Item
 move a file
 Rename-Item
 rename a file
 New-Item
 create a new empty file or directory
++++++++++++++++++++++++++++++++++++++++
     
   
Good Netiquette And A Green Internet To All!  =====================================================================

Tabula Rosa Systems - Tabula Rosa Systems (TRS) is dedicated to providing Best of Breed Technology and Best of Class Professional Services to our Clients. We have a portfolio of products which we have selected for their capabilities, viability and value. TRS provides product, design, implementation and support services on all products that we represent. Additionally, TRS provides expertise in Network Analysis, eBusiness Application Profiling, ePolicy and eBusiness Troubleshooting. 

We can be contacted at:

sales@tabularosa.net  or 609 818 1802.
 ===============================================================
In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” has just been published and will be followed by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

Anyone who would like to review the book and have it posted on my blog or website, please contact me paul@netiquetteiq.com.

In addition to this blog, I maintain a radio show on BlogtalkRadio  and an online newsletter via paper.li.I have established Netiquette discussion groups with Linkedin and  Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and I have been contributing to the blogs Everything Email and emailmonday . My work has appeared in numerous publications and I have presented to groups such as The Breakfast Club of NJ and  PSG of Mercer County, NJ.


Additionally, I am the president of Tabula Rosa Systems, a “best of breed” reseller of products for communications, email, network management software, security products and professional services.  Also, I am the president of Netiquette IQ. We are currently developing an email IQ rating system, Netiquette IQ, which promotes the fundamentals outlined in my book.

Over the past twenty-five years, I have enjoyed a dynamic and successful career and have attained an extensive background in IT and electronic communications by selling and marketing within the information technology market.

Tuesday, August 1, 2017

Tabula Rosa Systems Blog Of 8/1/2017 - The Function of the Prefix



Buy the books at

 www.amazon.com/author/paulbabicki
+++++++++++++++++++++++++++++++++++++++++++++++++++++===================================================






From www.thoughtco.com
Updated May 05, 2017
In English grammar and morphology, a prefix is a letter or group of letters attached to the beginning of a word that partly indicates its meaning, including such as examples as "anti-" to mean against, "co-" to mean with, "mis-" to mean wrong or bad, and "trans-" to mean across.
The most common prefixes in English are those that express negation like "a-" in the word asexual, "in-" in the word incapable, and "un-" in the word unhappy — these negations immediately alter the meaning of the words the are added to, but some prefixes merely change the form.
Interestingly enough, the word prefix itself contains the prefix "pre-" which means before and the root word fix which means to fasten or place, thus the word itself means "to place before." letter groups attached to the ends of words, conversely, are called suffixes while both belong to the larger group of morphemes known as affixes. 
Prefixes are bound morphemes, which means they can't stand alone. Generally, if a group of letters is a prefix, it can't also be a word. However, prefixation, or the process of adding a prefix to a word, is a common way of forming new words in English.
General Rules and Exceptions to Them
Although there are several common prefixes in English, not all usage rules apply universally, at least in terms of definition. For instance, the prefix "sub-" can either mean "something below" the root word or that the root word is "below something."
James J. Hurford argues in "Grammer: A Student's Guide" that "there are many words in English which look as if they begin with a familiar prefix, but in which it is not clear what meaning to attach either to the prefix or to the remainder of the word, in order to arrive at the meaning of the whole word." Essentially, this means that sweeping rules about prefixes like "ex-" in exercise and excommunicate cannot be applied.
However, there are still some general rules that do apply to all prefixes, namely that they are typically set as part of the new word, with hyphens only appearing in the case of the base word starting with a capital letter or the same vowel that the prefix ends with. In "The Cambridge Guide to English Usage" by Pam Peters, though, the author does posit that "in well-established cases of this type, the hyphen becomes optional, as with cooperate."
Nano-, Dis-, Mis- and Other Oddities
Technology especially utilizes prefixes as our technological and computer worlds get smaller and smaller. Alex Boese notes in the 2008 Smithsonian article "Electrocybertronics," that "lately the prefix trend has been shrinking; during the 1980s, 'mini-' gave way to 'micro-,' which yielded to 'nano'" and that these units of measurement have since transcended their original meaning.
In a similar way, the prefixes "dis-" and "mis-" have come to slightly transcend their original intent. Still, James Kilpatrick claims in his 2007 article "To 'dis,' or Not to 'dis,'" that there are 152 "dis-" words and 161 "mis-" words in contemporary lexicography. However, many of these are never spoken like the word "misact," which starts the "mis- list," as he calls it.
The prefix "pre-" also has a bit of confusion in modern vernacular. George Carlin famously jokes about the everyday occurrence at the airport called "pre-boarding." According to the standard definition of the prefix, "preboarding" should meaning before boarding, but as Carlin puts it "What does it mean to pre-board? Do you get on [a plane] before you get on?"
++++++++++++++++++++++++++++++++++++++++
     
   
Good Netiquette And A Green Internet To All!  =====================================================================

Tabula Rosa Systems - Tabula Rosa Systems (TRS) is dedicated to providing Best of Breed Technology and Best of Class Professional Services to our Clients. We have a portfolio of products which we have selected for their capabilities, viability and value. TRS provides product, design, implementation and support services on all products that we represent. Additionally, TRS provides expertise in Network Analysis, eBusiness Application Profiling, ePolicy and eBusiness Troubleshooting. 

We can be contacted at:

sales@tabularosa.net  or 609 818 1802.
 ===============================================================
In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” has just been published and will be followed by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

Anyone who would like to review the book and have it posted on my blog or website, please contact me paul@netiquetteiq.com.

In addition to this blog, I maintain a radio show on BlogtalkRadio  and an online newsletter via paper.li.I have established Netiquette discussion groups with Linkedin and  Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and I have been contributing to the blogs Everything Email and emailmonday . My work has appeared in numerous publications and I have presented to groups such as The Breakfast Club of NJ and  PSG of Mercer County, NJ.


Additionally, I am the president of Tabula Rosa Systems, a “best of breed” reseller of products for communications, email, network management software, security products and professional services.  Also, I am the president of Netiquette IQ. We are currently developing an email IQ rating system, Netiquette IQ, which promotes the fundamentals outlined in my book.

Over the past twenty-five years, I have enjoyed a dynamic and successful career and have attained an extensive background in IT and electronic communications by selling and marketing within the information technology market.

Sunday, July 30, 2017

Tabula Rosa Systems Blog Of 7/30/2017 - What is an Echo Word?


Buy the books at

 www.amazon.com/author/paulbabicki
+++++++++++++++++++++++++++++++++++++++++++++++++++++===================================================






What is an Echo Word?
Updated April 09, 2017
In linguistics and composition, the term echo word has more than one meaning:
  1. An echo word is a word or phrase (such as buzz and cock a doodle doo) that imitates the sound associated with the object or action it refers to: an onomatope. Also called an echoic word. 
  2. An echo word is a word or phrase (such as shilly shally and click and clack) that contains two identical or very similar parts: a reduplicative.
  1. An echo word is a word or phrase that recurs in a sentence or paragraph.
Examples and Observations (#1 and #2)
  • "Sound alone is the basis of a limited number of words, called echoic or onomatopoeic, like bang, burp, splash, tinkle, bobwhite, and cuckoo. Words that are actually imitative of sound, like meow, bowwow, and vroom--though these differ from language to language--can be distinguished from those like bump and flick, which are called symbolic. Symbolic words regularly come in sets that rime (bump, lump, clump, hump) or alliterate (flick, flash, flip, flop) and derive their symbolic meaning at least in part from other members of their sound-alike sets. Both imitative and symbolic words frequently show doubling, sometimes with slight variation, as in bowwow, choo-choo, and pe(e)wee."
    (John Algeo and Thomas Pyles, The Origins and Development of the English Language, 5th ed. Thomson Wadsworth, 2005)
Examples and Observations (#3)
  • "Repetitions help to echo key words, to emphasize important ideas or main points, to unify sentences, or to develop coherence among sentences. Skillful repetitions of important words or phrases create 'echoes' in the reader's mind: they emphasize and point out key ideas. You can use these 'echo words' in different sentences--even in different paragraphs--to help 'hook' your ideas together. . . .
  • "[E]cho words may come any place in the sentence: with the subjects or the verbs, with the objects or the complements, with prepositions or other parts of speech. You need not always repeat the word exactly; think of other forms the word may take, such as freak, freakiness, freakishness (nouns), freaking (participle), freaky and freakish (adjectives), and freakishly and freakily (adverbs)." (Ann Longknife and K. D. Sullivan, The Art of Styling Sentences, 4th ed. Barron's, 2002)
Echo-Pairs 

  • "Echo-words are crucially different from straight reduplicated words in that they have rules sensitive to the reduplicated configuration, 'detaching melodic elements from the affixal skeleton' and replacing them with an invariant onset (McCarthy and Prince 1986, 86). This accounts for the ban on auto-reduplication of echo-words themselves. Yiddishized English shm-initial words undergoing echo-pairing (such as shmaltz) have to be echo-paired with something else (usuall shp-: shpaltz) or else with nothing (no echo-pair can be formed), but certainly not with a direct repeat (**shmaltz-shmaltz is disallowed)." ( Mark R. V. Southern, Contagious Couplings: Transmission of Expressives in Yiddish Echo Phrases. Praeger, 2005)


+++++++++++++++++++++++++++++++++++++++++        
Good Netiquette And A Green Internet To All!  =====================================================================

Tabula Rosa Systems - Tabula Rosa Systems (TRS) is dedicated to providing Best of Breed Technology and Best of Class Professional Services to our Clients. We have a portfolio of products which we have selected for their capabilities, viability and value. TRS provides product, design, implementation and support services on all products that we represent. Additionally, TRS provides expertise in Network Analysis, eBusiness Application Profiling, ePolicy and eBusiness Troubleshooting. 

We can be contacted at:

sales@tabularosa.net  or 609 818 1802.
 ===============================================================
In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” has just been published and will be followed by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

Anyone who would like to review the book and have it posted on my blog or website, please contact me paul@netiquetteiq.com.

In addition to this blog, I maintain a radio show on BlogtalkRadio  and an online newsletter via paper.li.I have established Netiquette discussion groups with Linkedin and  Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and I have been contributing to the blogs Everything Email and emailmonday . My work has appeared in numerous publications and I have presented to groups such as The Breakfast Club of NJ and  PSG of Mercer County, NJ.


Additionally, I am the president of Tabula Rosa Systems, a “best of breed” reseller of products for communications, email, network management software, security products and professional services.  Also, I am the president of Netiquette IQ. We are currently developing an email IQ rating system, Netiquette IQ, which promotes the fundamentals outlined in my book.

Over the past twenty-five years, I have enjoyed a dynamic and successful career and have attained an extensive background in IT and electronic communications by selling and marketing within the information technology market.

Saturday, July 29, 2017

Tabula Rosa Security Bulletin National Cyber Awareness System: TA17-181A: Petya Ransomware all You need To Know Or Do




Buy the books at

 www.amazon.com/author/paulbabicki
+++++++++++++++++++++++++++++++++++++++++++++++++++++===================================================







National Cyber Awareness System:


07/01/2017 01:41 AM EDT

Original release date: July 01, 2017 | Last revised: July 28, 2017

Systems Affected

Microsoft Windows operating systems

Overview

This Alert has been updated to reflect the National Cybersecurity and Communications Integration Center's (NCCIC) analysis of the "NotPetya" malware variant.
The scope of this Alert’s analysis is limited to the newest Petya malware variant that surfaced on June 27, 2017. This malware is referred to as “NotPetya” throughout this Alert.
On June 27, 2017, NCCIC [13] was notified of Petya malware events occurring in multiple countries and affecting multiple sectors. This variant of the Petya malware—referred to as NotPetya—encrypts files with extensions from a hard-coded list. Additionally, if the malware gains administrator rights, it encrypts the master boot record (MBR), making the infected Windows computers unusable. NotPetya differs from previous Petya malware primarily in its propagation methods. 
The NCCIC Code Analysis Team produced a Malware Initial Findings Report (MIFR) to provide in-depth technical analysis of the malware. In coordination with public and private sector partners, NCCIC is also providing additional indicators of compromise (IOCs) in comma-separated-value (CSV) form for information sharing purposes.
Available Files:

Description

NotPetya leverages multiple propagation methods to spread within an infected network. According to malware analysis, NotPetya attempts the lateral movement techniques below:
  • PsExec - a legitimate Windows administration tool
  • WMI - Windows Management Instrumentation, a legitimate Windows component
  • EternalBlue - the same Windows SMBv1 exploit used by WannaCry
  • EternalRomance - another Windows SMBv1 exploit
Microsoft released a security update for the MS17-010 SMB vulnerability on March 14, 2017, which addressed the EternalBlue and EternalRomance lateral movement techniques.
Technical Details
NCCIC received a sample of the NotPetya malware variant and performed a detailed analysis. Based on the analysis, NotPetya encrypts the victim’s files with a dynamically generated, 128-bit key and creates a unique ID of the victim. However, there is no evidence of a relationship between the encryption key and the victim’s ID, which means it may not be possible for the attacker to decrypt the victim’s files even if the ransom is paid. It behaves more like destructive malware rather than ransomware.
NCCIC observed multiple methods used by NotPetya to propagate across a network. The first and—in most cases—most effective method, uses a modified version of the Mimikatz tool to steal the user’s Windows credentials. The cyber threat actor can then use the stolen credentials, along with the native Windows Management Instrumentation Command Line (WMIC) tool or the Microsoft SysInternals utility, psexec.exe, to access other systems on the network. Another method for propagation uses the EternalBlue exploit tool to target unpatched systems running a vulnerable version of SMBv1. In this case, the malware attempts to identify other hosts on the network by checking the compromised system’s IP physical address mapping table. Next, it scans for other systems that are vulnerable to the SMB exploit and installs the malicious payload. Refer to the malware report, MIFR-10130295, for more details on these methods.
The analyzed sample of NotPetya encrypts the compromised system’s files with a 128-bit Advanced Encryption Standard (AES) algorithm during runtime. The malware then writes a text file on the “C:\” drive that includes a static Bitcoin wallet location as well as unique personal installation key intended for the victim to use when making the ransom payment and the user’s Bitcoin wallet ID. NotPetya modifies the master boot record (MBR) to enable encryption of the master file table (MFT) and the original MBR, and then reboots the system. Based on the encryption methods used, it appears unlikely that the files could be restored, even if the attacker received the victim’s unique key and Bitcoin wallet ID.
The delivery mechanism of NotPetya during the June 27, 2017, event was determined to be the Ukrainian tax accounting software, M.E.Doc. The cyber threat actors used a backdoor to compromise M.E. Doc’s development environment as far back as April 14, 2017. This backdoor allowed the threat actor to run arbitrary commands, exfiltrate files, and download and execute arbitrary exploits on the affected system. Organizations should treat systems with M.E.Doc installed as suspicious, and should examine these systems for additional malicious activity. [12]

Impact

According to multiple reports, this NotPetya malware campaign has infected organizations in several sectors, including finance, transportation, energy, commercial facilities, and healthcare. While these victims are business entities, other Windows systems are also at risk, such as:
  • those that do not have patches installed for the vulnerabilities in MS17‑010, CVE-2017-0144, and CVE-2017-0145, and
  • those who operate on the  shared network of affected organizations.
Negative consequences of malware infection include:
  • temporary or permanent loss of sensitive or proprietary information,
  • disruption to regular operations,
  • financial losses incurred to restore systems and files, and
  • potential harm to an organization’s reputation.

Solution

NCCIC recommends against paying ransoms; doing so enriches malicious actors while offering no guarantee that the encrypted files will be released. In this NotPetya incident, the email address for payment validation was shut down by the email provider, so payment is especially unlikely to lead to data recovery.[1] According to one NCCIC stakeholder, the sites listed below sites are used for payment in this activity. These sites are not included in the CSV package as IOCs.
hxxp://mischapuk6hyrn72[.]onion/
hxxp://petya3jxfp2f7g3i[.]onion/
hxxp://petya3sen7dyko2n[.]onion/
hxxp://mischa5xyix2mrhd[.]onion/MZ2MMJ
hxxp://mischapuk6hyrn72[.]onion/MZ2MMJ
hxxp://petya3jxfp2f7g3i[.]onion/MZ2MMJ
hxxp://petya3sen7dyko2n[.]onion/MZ2MMJ

Network Signatures
NCCIC recommends that organizations coordinate with their security vendors to ensure appropriate coverage for this threat. Given the overlap of functionality and the similarity of behaviors between WannaCry and NotPetya, many of the available rulesets can protect against both malware types when appropriately implemented. The following rulesets provided in publically available sources may help detect activity associated with these malware types:
  • sid:2001569, “ET SCAN Behavioral Unusual Port 445 traffic Potential Scan or Infection”[2]
  • sid:2012063, “ET NETBIOS Microsoft SRV2.SYS SMB Negotiate ProcessID? Function Table Dereference (CVE-2009-3103)”[3]
  • sid:2024297, “ET CURRENT_EVENTS ETERNALBLUE Exploit M2 MS17-010”[4]
  • sid:42944,"OS-WINDOWS Microsoft Windows SMB remote code execution attempt"[11]
  • sid:42340,"OS-WINDOWS Microsoft Windows SMB anonymous session IPC share access attempt"[11]
  • sid:41984,"OS-WINDOWS Microsoft Windows SMBv1 identical MID and FID type confusion attempt"[11]
Recommended Steps for Prevention
Review US-CERT’s Alert on The Increasing Threat to Network Infrastructure Devices and Recommended Mitigations [6], and consider implementing the following best practices:
  • Ensure you have fully patched your systems, and confirm that you have applied Microsoft’s patch for the MS17-010 SMB vulnerability dated March 14, 2017.[5]
  • Conduct regular backups of data and test your backups regularly as part of a comprehensive disaster recovery plan.
  • Ensure anti-virus and anti-malware solutions are set to automatically conduct regular scans.
  • Manage the use of privileged accounts. Implement the principle of least privilege. Do not assign administrative access to users unless absolutely needed. Those with a need for administrator accounts should only use them when necessary. 
  • Configure access controls, including file, directory, and network share permissions with the principle of least privilege in mind. If a user only needs to read specific files, they should not have write access to those files, directories, or shares. 
  • Secure use of WMI by authorizing WMI users and setting permissions.
  • Utilize host-based firewalls and block workstation-to-workstation communications to limit unnecessary lateral communications.
  • Disable or limit remote WMI and file sharing.
  • Block remote execution through PSEXEC.
  • Segregate networks and functions.
  • Harden network devices and secure access to infrastructure devices.
  • Perform out-of-band network management.
  • Validate integrity of hardware and software.
  • Disable SMBv1 and block all versions of SMB at the network boundary by blocking TCP port 445 with related protocols on UDP ports 137-138 and TCP port 139; this applies to all boundary devices.
Note: Disabling or blocking SMB may create problems by obstructing access to shared files, data, or devices. Weigh the benefits of mitigation against potential disruptions to users.
Recommended Steps for Remediation
  • NCCIC strongly encourages organizations contact a local Federal Bureau of Investigation (FBI) field office upon discovery to report an intrusion and request assistance. Maintain and provide relevant logs.
  • Implement a security incident response and business continuity plan. Ideally, organizations should ensure they have appropriate backups so their response is simply to restore the data from a known clean backup. 
Report Notice
DHS encourages recipients who identify the use of tools or techniques discussed in this document to report information to DHS or law enforcement immediately. To request incident response resources or technical assistance, contact NCCIC at NCCICcustomerservice@hq.dhs.gov or 888-282-0870. You can also report cyber crime incidents to the Internet Crime Complaint Center (IC3) at https://www.ic3.gov/default.aspx.
+++++++++++++++++++++++++++++++++++++++++++       Good Netiquette And A Green Internet To All!  =====================================================================

Tabula Rosa Systems - Tabula Rosa Systems (TRS) is dedicated to providing Best of Breed Technology and Best of Class Professional Services to our Clients. We have a portfolio of products which we have selected for their capabilities, viability and value. TRS provides product, design, implementation and support services on all products that we represent. Additionally, TRS provides expertise in Network Analysis, eBusiness Application Profiling, ePolicy and eBusiness Troubleshooting. 

We can be contacted at:

sales@tabularosa.net  or 609 818 1802.
 ===============================================================
In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” has just been published and will be followed by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

Anyone who would like to review the book and have it posted on my blog or website, please contact me paul@netiquetteiq.com.

In addition to this blog, I maintain a radio show on BlogtalkRadio  and an online newsletter via paper.li.I have established Netiquette discussion groups with Linkedin and  Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and I have been contributing to the blogs Everything Email and emailmonday . My work has appeared in numerous publications and I have presented to groups such as The Breakfast Club of NJ and  PSG of Mercer County, NJ.


Additionally, I am the president of Tabula Rosa Systems, a “best of breed” reseller of products for communications, email, network management software, security products and professional services.  Also, I am the president of Netiquette IQ. We are currently developing an email IQ rating system, Netiquette IQ, which promotes the fundamentals outlined in my book.

Over the past twenty-five years, I have enjoyed a dynamic and successful career and have attained an extensive background in IT and electronic communications by selling and marketing within the information technology market.