HPE DL360 Gen10Plus BIOS Admin Password

I’ve recently had a problem on some new servers where a BIOS Admin Password had been set by accident, HPE provide this as a solution on their forums: https://community.hpe.com/t5/proliant-servers-ml-dl-sl/how-do-i-disable-the-bios-admin-password-on-a-gen10-dl360/m-p/7166755#M178013 However the Gen10Plus (+) servers appear to be a bit different, upon entering the forward slash “/” on the end of the password to remove it, … Read more

VMware Datastore Showing “Not Consumed”

I had a host that was showing devices with no datastore, saying “Not Consumed”. This is what you’d expect to see for a device where the device has yet to be formatted with VMFS. Now in this case it definitely had a VMFS filesystem created. The fix for this was fairly simple. Essentially the host … Read more

Cheeky PowerShell Hash Script

If you want to check the (MD5/SHA) hash of a file you can do this on Microsoft Windows with “Get-FileHash” within PowerShell. Here is a simple script to take a File, the Hash Algorithm Type and Expected Hash for the file to compare, it hashes the file and then compares it with the expected hash … Read more

Continuing Analysis and Resolution of NetApp and RC4 Issues Caused by (KB5019964) For CVE-2022-37967 and KB5021131 CVE-2022-37966

A long running issue, which I covered in my previous posts: https://geekmungus.co.uk/?p=3532 and https://geekmungus.co.uk/?p=3593, this should be taken as the current status of the problem and the resolution. Issue Following the patch: KB5021131 CVE-2022-37966, which was released November 8th 2022 we’ve continued to have some issues with Kerberos authentication to servers (devices) that use (and … Read more

Calendar Publishing to Internet from Microsoft Exchange (2016+)

Microsoft Exchange provides the capability to allow publishing of user calendars to the Internet, this is different from calendar sharing (which is typically internal, i.e. within our organisation). These instructions explain how to enable publishing by policy and how to apply it your own user mailbox. Calendar Publishing Policy Configuration on Microsoft Exchange These steps … Read more

Further Exploration of KB5019964 Kerberos Changes

NOTE: See https://geekmungus.co.uk/?p=3619 for the most up to date article! The following is my analysis going going deeper into my recent article: https://geekmungus.co.uk/?p=3532, hopefully this will give you a bit more context and information, but also allowed me to work through the issue in my head through documentation. Synopsis The patch KB5019964 changes what the … Read more

PL2303HXA PHASED OUT SINCE 2012. PLEASE CONTACT YOUR SUPPLIER

If you are seeing this issue, you can resolve the problem by downloading and replacing the Windows driver with this one using Device Manager. In my case this was trying to use a USB to Serial (RS232) adapter which just wasn’t working. https://github.com/brucetsao/Drivers/raw/master/FAKE_PL2303/IO-Cable_PL-2303_Drivers-Generic_Windows_PL2303_Prolific.zip Connectix.nl provide a more detailed overview of the solution here.

Internal, External URLs, InternalAuthenticationMethod and ExternalAuthenticationMethod Explained

Within the Microsoft Exchange configuration you’ll see that there is an InternalURL and ExternalURL attribute for each of the key Microsoft Exchange Web Services, e.g. OWA, ECP, ActiveSync etc. Personally i’ve never really used these when they are different, but what it allows is for your internal and external URLs to access the services to … Read more

Have You Got the Multi-Factor?

A big topic at the moment in Information Security is multi-factor authentication(MFA), also known as two factor authentication (2FA). So the first question, what is a “factor”? Put simply a “factor” is element that a principal (i.e. a person trying to logon to a system) can use to prove to the system they are the … Read more