Monday, August 20, 2007

Ninja - Turn off Outlook's junk e-mail filtering

From: AgCompSupport [mailto:AgCompSupport@psu.edu]
Sent: Monday, August 20, 2007 4:26 PM

Subject: Turning off Junk E-mail and Rules in Outlook

With the configuration of Ninja moving along, we are now ready to turn off junk e-mail and rules in Outlook.
Turn off Junk E-mail filtering in Outlook 2003
1. Open Outlook.
2. Under Actions on the menu bar, pull down to Junk E-mail, then pull down to Junk E-mail Options.
3. A new window will open up. Choose No Automatic Filtering.
4. Click OK.
5. Quit and re-open Outlook.

Turn off Specific Rules and Alerts in Outlook 2003 and 2007
1. Open Outlook
2. Under Tools menu, choose Rules and Alerts. A new window will open
3. If present, Uncheck rule: X-Spam-Flag: YES
4. click OK.
5. Quit and re-open Outlook.

Thanks,
Mike Leiter, Support Coordinator

Ninja installed on August 8

Ninja, an antispam/antivirus software, was installed on the College’s Exchange servers on Wed, August 8. [Update: Ninja was not installed on Aug 8th. The planned install was postponed and Ninja was installed on Aug 15th - vcv]. It will help block and actually delete known Spam messages before they even hit our mailboxes. You should now see a Spam folder in your Outlook folder list. In that folder, there are 3 folders: Allowed Senders, Blocked Senders, and Quarantine.

As we work to get the filter levels correct, we still need to know from you if you are getting good mail in the Quarantine folder. Please send an AgCompSupport@psu.edu a note if you receive a good message in this Quarantine folder. You can move this good message to your inbox simply but clicking and dragging to Inbox. There are many filter settings so we can adjust them as needed. We hope to eventually get all the spam/junk messages going to the Quarantine folder or perhaps not even making it to our mailboxes at all!

You may actually notice that you are getting MUCH less spam arriving in your Junk E-mail or Spam folders. This is because Ninja is deleting messages that are 100% obvious spam and it never arrives to our mailboxes. As we adjust the settings we hope to delete more and quarantine less of these spam messages.

Once we get more of the filter settings adjusted, we will be providing directions on how to turn off the Junk E-mail folder provided by Outlook. It won’t be needed with Ninja fully functioning.

So you may be asking what do I do with the other folders under Spam – the Allowed Senders and Blocked Senders. These folders allow you to “personalize” what messages you receive or don’t receive if they end up in your Inbox or your Quarantine folder.

  • The Allowed Folder Use the Allowed folder to create a list of email addresses from which you always want to receive messages. Any message you drop in the Allowed folder will not be quarantined. If you want an email to get through, to but do not want to add it to your contact list (i.e. a list to which you subscribe), simply drop one message from this sender into the Allowed folder. Future messages from this address should then appear in your In mailbox.
  • The Blocked Folder You can use the Blocked folder to create a list of users from whom you do not want to receive messages. There is no need to maintain a large list in the Blocked folder since most unsolicited spam emails are caught by Ninja before they reach your inbox. However, if you receive messages that still slip, simply drop one of these messages into your Blocked folder and you will not receive another message from that sender.

How does the Quarantine Folder work?Any messages that meet the preset spam criteria are automatically placed into this folder. Our System Administrators have determined the selection criteria in your spam detection settings. We recommend that you delete individual messages or the entire contents of the folder on a regular basis to keep the size of the folder low and make sure your mailbox is free of spam.

You can also drag messages from this folder to any other folder. If you want to continue receiving messages from a sender, drag the current messages into the Allowed folder. If you want to block future messages from a sender, drag them into the Blocked folder.
In addition, you can delete the Quarantine folder anytime, erasing the entire contents of spam messages in one easy step. The next time you receive a message containing spam, the system automatically rebuilds the folder and places the new spam message into it.

And finally, one final tip from Ninja on making their Spam Filtering work better for you – Keep your Contacts list Current. Any email address or user in your contact list will not be quarantined. Keep your Contacts list is up-to-date by adding or deleting contacts as needed.

Stay tuned for more information about Ninja.

Thursday, July 19, 2007

Flash Player update available to address security vulnerabilities

Critical vulnerabilities have been identified in Adobe Flash Player that could allow an attacker to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit these potential vulnerabilities. Users are recommended to update to the most current version of Flash Player available for their platform.

To see what version of Macromedia Flash Player you have, go to this Adobe Flash Player page. Wait for the page to load. The version will be displayed in a box called "Version Information." If it says "You have version 9,0,47,0 installed" then you have the newest version.

Adobe recommends all Flash Player 9.0.45.0 and earlier upgrade to the new version, which can be downloaded from the Player Download Center.

Note: If you visit this page, you should uncheck the installation for the Google Toolbar!

Wednesday, July 18, 2007

Sun Releases Java(TM) 6 Update 2

As of July 18, 2007, the current version of Sun's Java client is 1.6.0_2.

If you have previous versions of this Plugin installed, you should remove them. If you have installed Sun's Java client, please follow our "How To Update Sun's Java 2 Runtime Environment Plug-in" to update your Java software.

http://ict.cas.psu.edu/Training/howto/util/sun_java_update.htm

Thursday, July 05, 2007

Startup Message: Computer must be restarted before updating can continue

Each time you start your computer you see the following message:
The Computer must be restarted before updating can continue. Would you like to restart now?
Your choices are Yes or No. If you click Yes, the computer is forced into a reboot, but the message returns. If you click No, you can work normally.

ISSUE: You may have a failed Adobe Reader 8 update. This updater places an entry in a Registry RUN key for the "AdobeUpdater.exe" application. The "AdobeUpdater.exe" application is located here: C:\Program Files\Common Files\Adobe\Updater5

If you open these folders and double-click on the "AdobeUpdater.exe" application, you should see the same message as above.

To test if you need to do the Workaround, do this first. Open Adobe Reader 8. From the Help menu choose Check for Updates. If the program checks for updates and finds them, apply. This may solve the issue. But if you see the same error message after a restart, you should do the Workaround steps are provided in our eNews article.

Switching displays on a Laptop takes time

From the Microsoft Knowledge Base Article KB 937930, You may be unable to switch between displays on a portable computer that is running Windows XP.

The article is listed as applying to Microsoft Windows XP Professional, not to Microsoft Windows XP Professional with Service Pack 2. So, this may be a moot point for our College Enterprise machines. But I found it interesting that the article lists the "wait for a full minute before you try to switch displays" as a workaround.

If you have this issue on your machine, you can at least try that.

Fake Greeting Card E-mails and Sites

In last year's eNews, we ran an article called eCard Sites To Stay Away From. If you go to some of these sites to send a virtual greeting card, you ran the risk of becoming infected with malware.

Normally, when you use sites like AmericanGreetings.com or Hallmark.com to send a virtual birthday, anniversary, etc. to friends or family, the process works like this. You pick a card, create a message, and enter the person's email address. You add your own email address and you can send the E-card. Your friend or family member is notified to pick up the card on the web site via email. They will need to click on a link in the message to see the greeting. Pretty standard stuff.

Recently, phishers have begun to exploit this common service in a new way. You might RECEIVE a fake card with URLs that, when clicked on, take you to a malicious site. The computer can then be infected with malware that attempts to steal information to be used for identity theft.

Most of the real greeting card services give you, in the email notice, the name or email address of the sender. If the message simply says "a friend sent you a card," with no identifying info, as in the above example, DELETE the message without clicking on the link.

Friday, June 22, 2007

Adding Signatures in Outlook 2003 with Word as the E-mail Editor

If you have enabled Word to be the editor of Outlook 2003 E-mail messages, you may have "lost" a common Outlook function. You appear to lose the toolbar icon to add/delete/change signatures in an e-mail message. Here's the alternate process to add a signature to a message.
In Outlook 2003, create a new signature, but put nothing in it - no text at all. Name it something obvious - "empty" or "blank" etc.

Now, when creating a new message, you will have the opportunity to right-click on the default signature appearing in the new message. Right-clicking presents a list of all signatures for selection -including the blank signature.

If you would like the message sent without a signature, select "blank" and the mail will be sent without appearing to have a signature line.

Java problems in QuickTime

Apple is recommending that QuickTime users download its update for Version 7.1.6 to fix a pair of security glitches.
One of the first two problems, in QuickTime for Java, can lead users to having their systems hijacked if they visit a malicious site. If a user visits a site containing a maliciously crafted Java applet, an attacker can trigger the vulnerability and take over the target system. The second glitch, like the first, a user has to visit a site with a maliciously crafted Java applet. The attacker can take advantage of the vulnerability and may be able to read sensitive information off your system.
See our How To for steps in installing QuickTime 7.1.6.http://ict.cas.psu.edu/training/howto/util/QuickTimeInstall.htm

Penn State to add DNS Security on July 9, 2007

In an effort to enhance Domain Name Server (DNS) security and improve resource usage on the Penn State Network, ITS (http://its.psu.edu/) will restrict a function called "Recursive DNS lookups" in the University's domain name service on July 9, 2007.

Don't panic. College Enterprise computers should be set to use College DNS numbers or be set to Obtain DNS server address automatically. In these cases, the PSU DNS numbers will not be used and you can continue to access Internet sites as expected.

To verify whether or not a particular computer is currently configured to use the Penn State DNS servers, see our How To. You may need to remove one Penn State DNS number: 128.118.25.3. This How To has complete steps to verify your network settings and includes pictures.

For More information, see our eNews article: http://ict.cas.psu.edu/NewsLetters/enews72.html#Article1

Monday, June 11, 2007

Yahoo! Messenger software needs Upgrade

Two critical vulnerabilities reside in Yahoo! Messenger versions 8.1.0.249 and earlier. Computers running earlier versions of the Yahoo IM software could be hijacked by visiting a malicious Web page.

The company has pushed out a fix to plug two newly discovered security holes. Yahoo! Messenger users should download and install the latest version immediately.

http://messenger.yahoo.com/download.php

Thursday, March 15, 2007

Office 07 & Vista Deployment Plans

It's been in the news and we've received emails - Microsoft Office 2007 and Microsoft Vista operating system are available!! What's happening with these two different software packages in the College of Ag Sciences? Read on about each one…

The deployment of Office 07 will begin September 2007 - November 2007. (Enterprise computers shipped after October 2007 will be shipped with Office 2007).

There are several reasons why we feel this is the best time to deploy Office 2007:
  • Timing of the upgrade is important - if all staff do not upgrade to Office 2007 at the same time, those still using Office 2003 wouldn't be able to open any Office 2007 documents without downloading a file converter.
  • Breeze (Adobe Connect Pro) Web Conferencing is not able to convert PowerPoint 2007 presentations yet. We expect this to be corrected by September.
    Penn State technology classrooms and computer labs will have Office 2007 installed during the summer of 2007.
  • Training issues - training materials for Office 2007 are not yet completely developed. Office 2007 has a very different interface. Our goal is to minimize the impact on productivity by providing thorough training opportunities.
  • There will never be a "good" time to upgrade, but by doing this over a couple months you should be able to work around busy schedules. Also, by working in the fall we can avoid county fair season, the beginning of the semester, and before winter meetings and conferences.

Now, comes the fun part. If you would like to be part of the CoAS Office 2007 Pilot, please email us as the Project contacts. After reviewing the emails, we will select a sampling of different office environments, up to 25. If you are selected, we will send you an email with all the details. Vista operating system WILL NOT be part of this pilot.

The Vista operating system deployment will begin in September 2008 (not a typo this IS NEXT YEAR). By that date, we expect that some of the initial adjustments (new features, drivers, and compatibility issues) will have been worked out and the first service release packs will have been made available. This is consistent with the university's deployment approach for the computer labs and technology classrooms. Right now there is no "must have" reason to switch to the next generation Vista operating system. Enterprise computers will NOT be shipped with Vista operating system until September 2008. ICT will not be supporting Vista operating system machines on the Enterprise network until after Sept 2008. We will keep you up to date with our plans with both of these products via eNews, ICT Tech Alerts, and our ICT Web site.

If you have questions or would like to sign up for the CoAS Office 2007 Pilot, please email Jacki (jweikert@psu.edu) or Peg (pshuffy@psu.edu).

Tuesday, January 30, 2007

Clock continues to TICK on Password Change Deadline

Penn State's initiative to foster a safer computing environment requires that all Access Account holders change their passwords on an annual cycle. Note: any university password changed after August 1, 2006 will expire exactly 365 days from the date and time of change. The College of Ag Sciences is following the same initiative in regards to AG account passwords.

College of Ag Science faculty and staff will normally have TWO accounts. They will have a PSU Access Account and a College of Ag Sciences' AG account. Note, some have more and other faculty/staff have less. Also note that county email accounts are AG accounts and also need their passwords changed by April 2.

This means that you need to change your password, in most cases, 2 places. Our How To provides directions on How To Change your PSU Access Account password and your AG password. This How To also gives you a list of which services use your AG password and which one use your PSU password. For example, if you use Dreamweaver for web development on the college's web server, you will need to update the AG password in Dreamweaver's settings.

For more infromation, including deadlines in the University's campaign to have all Penn State community members change their Access Account passwords, see the following eNews article from Jan 18, 2007.

Change your Password - no April Fool's (or Groundhog Day Eve) joke!

Monday, January 22, 2007

Install IE7 Phishing Filter Update

The new IE7 Phishing Filter evaluates an entire Web page when the page is opened. If a page contains a number of frames, the Phishing Filter may prevent it from loading. One example we have seen was a web based video conference using streaming QuickTime. The page never loaded with the Phishing Filter enabled. On Dec 12, 2006, Microsoft released an update to Internet Explorer 7. The update is designed to resolve slowdowns for Web pages containing a number of frames.

See these Install Phishing Filter Update steps from the How To Install Internet Explorer 7 for Windows XP. They are written for College Enterprise computers that are using Windows XP Service Pack 2.

Friday, December 08, 2006

Adobe Download Manager 2.1 and earlier should be removed

A critical vulnerability has been identified in Adobe Download Manager 2.1 and earlier. Adobe is recommending that users uninstall these versions of Adobe Download Manager.

Note: Adobe Download Manager is a stand-alone application that improves the process of downloading files from Adobe. Customers who have downloaded software from Adobe, including Adobe Reader, may have Adobe Download Manager installed.

To verify if a vulnerable version of Adobe Download Manager is installed, and to uninstall Adobe Download Manager if necessary, please follow these steps.

Note: These steps are written for College of Ag Sciences Enterprise computers with Windows XP Service Pack 2.

1. Open My Computer. Open Local Disk (C:). Open the Program Files folder.
2. Open the Common Files folder. Open the Adobe folder.

Note: If you don't see an ESD folder, you don't have Adobe Download Manager installed. Stop here.

3. If you see an ESD folder, open the ESD folder.
4. Right-click on the AdobeDownloadManager.exe file and select Properties.
5. Click on the Version tab.
6. If the version is 2.1.x or higher, your version is not affected. Click OK. Close all windows. If the version 2.1.x or lower, you need to uninstall Adobe Download Manager. Click OK. Close all windows.
7. Download the Adobe uninstaller and save it to your Desktop.
8. Double click on the DLMUninst_001.exe file to remove the Adobe Download Manager.
9. Click OK.
10. You can now delete the DLMUninst_001.exe file.

Update available for potential vulnerabilities in Adobe Reader and Adobe Acrobat 7

Critical vulnerabilities have been identified in Adobe Reader 7.0 through 7.0.8 that could allow an attacker to take control of your machine. Adobe is recommending that users update to Adobe Reader 8. For complete steps please see our How To Install and Configure Adobe Reader for Windows.

If you have installed the FULL version of Adobe Acrobat 7 (software that allows you to create PDF documents), Adobe has workaround steps to update the AcroPDF.dll on your machine. This will allow you to keep Adobe Acrobat 7 Professional on your machine and be safe as well. Follow Steps 1 - 5 from the Solution section of this Adobe Security bulletin.

Again, folks who just have Adobe READER installed, should upgrade to Adobe Reader 8.

Monday, November 20, 2006

ITS download site changes

ITS has changed their policies and permissions on their downloads site (http://downloads.its.psu.edu/) depending on if you are a full-time PSU employee vs an access account holder.

Only full-time PSU employees can get the "complete" list of installers (including SAV, Office)

In most cases this means that only full-time PSU employees and extension educators can use this site to access these installers. Extension support staff will need to ask educators to download these installers for them.

-jsw

Friday, November 03, 2006

Unable to load Penn State Newswire's live.psu.edu webpage in IE6

For the latest Penn State news and information, you can visit http://live.psu.edu/

When you attempt to visit the page, you are asked to run an ActiveX control. The screen goes blank and your only option is to click OK in the dialog box. When you do, Internet Explorer locks up and crashes.

Issue
The live.psu.edu page has a strip of video's on the left side that use ActiveX to be displayed. If you have an older version of QuickTime installed on your computer, these controls can't be shown in the window.

Fix
Update to the most recent version of QuickTime. Use these How To steps.

Install QuickTime for Windows using the Standalone Installer

Friday, October 27, 2006

New IE7 How To install and Configure

How To Install Internet Explorer 7 for Windows XP

http://ict.cas.psu.edu/training/howto/comm/ie7/installie7.htm

Last week Microsoft released version 7 of the Internet Explorer web browser (IE7). Internet Explorer updates are included as part of the regular Windows update process so you will automatically receive this update in the near future. IE7 offers a number of benefits and a streamlined interface.

Some of the important changes include:

  • tabbed browsing - browse multiple web pages within a single IE window
  • integrated search - a search box always available to the right of the address bar
  • improved printing - IE scales text appropriately so you won't end up with one line of text on your last page (usually)
  • improved security features - many under the hood changes as well as a new phishing filter
  • RSS feed support - stay up to date with basic RSS support right in your browser

Take a quick tour or view a more complete feature list for more information. FYI...IE7 is the version of Internet Explorer that will be included with Windows Vista when it releases later this year, so working with IE7 on XP now will give you a head start on Vista. PS, we will not be upgrading to Vista when it is released!

- jsw

Wednesday, September 27, 2006

Picture Manager Slow to Open

Opening a Picture Manager is extremely slow, taking a couple minutes to open a 100K file...
The solution is to edit the OIScatalog.cag (just an XML file) located in C:\Documents and Settings\\Local Settings\Application Data\Microsoft\OIS.
Locate tags that begin with "mru path". Delete any that point to bad or slow locations.