Posts tagged system

Changing your password in Kerio Mailserver

Changing your passwords is very easy.

Under your Windows computer press Crtl + Alt + Del and select change password.

To Change your email password, simply log into your Web Mail  (call us if you don’t know the address)

Then Select change password from the Settings drop down menu as below

settings menu in  kerio webmail

settings menu in kerio webmail

And then enter your old and new passwords in the box below.

kerio password change dialog box

kerio password change dialog box

Remember to make it something secure that no one will guess, no kids, partners or team names and no dictionary words. Random Numbers and letters, remember capitals and lower case combinations are best, or try a sentence like “Why can 1 never remember 555″ you can use spaces. Remember the best passwords are ones that can not be are easy to remember and would not be easily broken using a dictionary or password list attack (this is where a system tires every word in the dictionary or in a common password list, things like Rang3rs or C3lt1c or to easy.

Kerio Mail Server – Feedback and Updates

Kerio have recently introduced a new update for the Kerio MailServer (KMS), which has fast become krayatec’s favoured mail server.

We have now deployed Kerio MailServer 6.2 to most of our clients and despite a handful of teething problems, most are now seeing advantages over Exchange and their previous IMAP based systems.

Feedback from clients has generally been positive, however for two of our clients the switch has not been as pain free as we would have liked and they are still experiencing several issues:

  • VERY Slow connections between the Kerio Outlook connector and the Server.
  • Kerio Outlook Connector seems to consume huge amounts of RAM, particularity on older Systems.
  • Outlook and MS Word Mail merge function seams to fail after installation of Kerio Off-line Outlook connector.  This issue is still under investigation by both our own and Kerio’s Technical teams.
  • IMAP sync issues when using Thunderbird: Kerio and Thunderbird seem to be unable to share junk, sent and deleted folders leading to duplication.
  • Thunderbird and Kerio integration is not perfect in general and Thunderbird is unable to feed back junk mail training data, or rule learning, to the Kerio Mail Server.

The release notes for the new Update to Kerio MailServer 6.7 suggests that this upgrade will fix most of these issues.  The update has now been deployed to our own Kerio system and we are currently testing this in full prior to deployment to our clients systems.  After discussing the updates with the Kerio team, we are very hopeful of resolving the above issues. However, it is indisputable that issues may remain with legacy systems, particularity Windows 2000.

Feedback / comments and suggestions for the above issues are always welcome.

Security Bulletin – Adobe Reader and Acrobat

Below is an update to Security Bulletin – Adobe – April 09

Adobe have published a new Security Bulletin and provided updates for Adobe Reader and Acrobat patches. These updates resolve the previously reported vulnerabilities in Adobe Reader 9.1 and Acrobat 9.1 and earlier versions. This vulnerability (CVE-2009-1492) would cause the application to crash and could potentially allow an attacker to take control of the affected system remotely and install Malicious code.

We have already recommended that user consider using alternatives to Adobe reader, this continues to be our current advice. However users still using Adobe should now update and install these patches as soon as practical.

Adobe recommends users of Adobe Reader 9.1 and Acrobat 9.1 and earlier versions update to Adobe Reader 9.1.1 and Acrobat 9.1.1. Adobe recommends users of Acrobat 8 update to Acrobat 8.1.5, and users of Acrobat 7 update to Acrobat 7.1.2. For Adobe Reader users who can’t update to Adobe Reader 9.1.1, Adobe has provided the Adobe Reader 8.1.5 and Adobe Reader 7.1.2 updates.

Security Bulletin April 2009

This (slightly late) bulletin is a summary of the various security bulletins released by Microsoft for April 2009, a second bulletin for non Microsoft issues will follow next week. This bulletin includes the action Kraya is taking regarding each of these updates and security warnings.

We have now completed Beta Testing of these updates and have commenced pushing these out to your computers in our phased roll out program.

For users that are on Automatic Updates direct from Microsoft these will probably already have been installed. We are in the process of changing that so that all updates will come from Kraya HQ, this allows us to ensure that only the updates we approve are pushed out to your computers and should help prevent any issues caused by configuration changes.

If any of your staff report seeing boxes pop up on their computer screens about updates please tell them to call us and we will advise as to whether the update should be installed.

So here is the list:

MS09-010 Vulnerabilities in WordPad and Office Converters (KB960477) affects Windows 2000, XP and Windows Server 2003

  • This security update fixed a know issue with Microsoft WordPad and Microsoft Office. Previously users had been advised to not open Microsoft Office, RTF, Write, or WordPerfect files from untrusted sources. Whilst this update fixes this issue, the advice still stands.
  • This patch has been tested and determined to be safe, it has now been installed in all of our Windows machines.

MS09-013 Vulnerabilities in Windows Web Services affects Windows 2000, XP and Windows Server 2003

  • This update resolves an issue with Microsoft Windows HTTP Services (WinHTTP) which could allow malicious software to be installed on a computer remotely.
  • This patch has been tested and determined to be safe, it has now been installed in all of our Windows machines. However it has been associated with a slowing of the system however the security vulnerability
    is to severe to neglect.

MS09-011 Vulnerability in Microsoft DirectX 8.1 & 9.0 affects Windows 2000, XP and Windows Server 2003 (KB961373)

  • This update resolves an issue with Microsoft DirectX on non older systems. The vulnerability could allow malicious software to be installed on a computer remotely if user opened a specially infected Movie file.
  • This patch has been tested and determined to be safe, it has now been installed in all of our Windows machines. However Windows 2000 users seem to experience some slowing of graphics drivers after this update. Unfortunately again the security vulnerability
    is to severe to neglect.

MS09-014 Security Update for Internet Explorer 6 & 7 (KB963027)

  • Resolves Six different vulnerabilities in Internet Explorer 6 & 7. These vulnerabilities could again allow malicious software to be installed on a computer remotely if a user were to view a specially crafted Web page or advert. This is one of the many reasons we recommend that users use Firefox rather than Microsoft Internet Explorer.
  • This patch has been tested and determined to be safe, it has now been installed in all of our Windows machines.

MS09-009 Fix for Issues with Microsoft Office Excel (KB968557, KB959964, KB959988, KB959995, KB959997, KB968694, KB959993, KB960000, KB960003) affects Microsoft office 2000, XP, 2003, 2007 on Mac and Windows, also affected are Microsoft Office Excel Viewer and Microsoft Office Converter / Compatibility Packs

  • This security update resolves a vulnerability that I have previously contacted you all about in Excel that could allow, allow malicious software to be installed on a computer if you opened a specially crafted Excel file.
  • However, this update does not replace the standing advice, do not to open files from un-trusted sources or if you receive and unexpected attachment to an email i.e. email from a trusted source, but the email content is out of character for that sender. You should also be very careful with Email forwards such as games embedded in excel and Power point presentations of pretty pictures or half naked girls on motor bikes, these are all classic ways to infect your computer with malicious software.
  • This patch has been tested and determined to be safe, it has now been installed in all of our Windows machines.

MS09-012 Security flaw in Microsoft Windows allowing Elevation of user Privileges (KB959454, KB952004, KB956572) affects Windows 2000, XP, Vista and Windows Server 2003 & 2008

  • This security update resolves a security flaw in Microsoft Windows which could allow a user who has gained access to your system, legitimately or otherwise to elevate their security privilege to an administrator. An attacker who successfully exploited any of these vulnerabilities could take complete control over the affected system.
  • This patch has been tested and determined to be safe, it has now been installed in all of our Windows machines.

MS09-016 Vulnerabilities in Microsoft ISA Server (KB961759, KB960995, KB968078)

  • This security update resolves an issue with Microsoft Internet Security and Acceleration (ISA) Server and Microsoft Forefront Threat Management Gateway (TMG), Medium Business Edition (MBE). This could create a denial of service attack if specifically designed data is passed over a network to the affected system, or the disclosure of confidential information if a user visits a Web site that contains content controlled by the attacker.
  • This patch does not affects most of our clients but will be installed on those affected.

MS09-015 Blended Threat Vulnerability in Search Path Could Allow Elevation of Privilege (KB959426) affects Windows 2000, XP, Vista and Windows Server 2003 & 2008

  • This security update resolves a security flaw in Microsoft Windows which could allow a user who has gained access to your system, legitimately or otherwise to elevate their security privilege to an administrator. An attacker who successfully exploited any of these vulnerabilities could take complete control over the affected system.
  • This patch has been tested and determined to be safe, it has now been installed in all of our Windows machines.

There are a long list of other updates already deployed the only ones of note are Microsoft Internet Explorer 8 Release Candidate 1 (RC1) and its subsequent updates despite testing ok there have been wide spread reports of IE8 slowing computers down. Therefore no more computers will be upgraded at this time and I would reiterate my advice to use Firefox rather than IE. If IE 8 has already been installed on your computer, uninstalling it and reverting back to IE 7 does not seem to help speed it back up.

We will continue to monitor the situation and await further updates from Microsoft.

As ever any questions please let me know.