Sunday, July 14, 2013

Export Active Directory Groups with their Members

Many times I have seen situations when there is a need to audit Active Directory Groups.

In this blog I have included a batch script which will export all AD groups with their members into .csv file which you can open in Microsoft Excel and apply different filters.


:::: Batch Script Start ::::
@ECHO OFF
SETLOCAL EnableDelayedExpansion

SET FileName=C:\Report.csv
SET AG=0
SET EG=0
SET CT=0
SET NE=0
SET GN=

FOR /F %%T IN ('DSQuery * -Filter "(&(objectClass=Group))" -Limit 0') DO SET /a AG+=1 >NUL
FOR /F %%T IN ('DSQuery * -Filter "(&(objectClass=Group)(^!member=*))" -Limit 0') DO SET /a EG+=1 >NUL
SET /a NE=!AG!-!EG!

ECHO Total Groups in Active Directory %AG% out of them %EG% are empty.&&ECHO.
ECHO Group,Members>"!FileName!"
TITLE Exporting !NE! Non-Empty AD Groups.

FOR /F "delims=" %%G IN ('DSQuery * -Filter "(&(objectClass=Group)(member=*))" -Limit 0') DO (
    FOR /F "delims=" %%v IN ('DSQuery * %%G -l -q -Attr Name -Limit 0') DO SET GN=%%v
    SET /a CT+=1 >NUL
    ECHO !CT!. Exporting: !GN!
    FOR /F "delims=" %%M IN ('DSGET Group %%G -Members') DO (
        FOR /F "delims=" %%U IN ('DSQuery * %%M -l -q -Attr displayName') DO (
        ECHO !GN!,%%U>>"!FileName!")))

TITLE Export complete.
ECHO.&&ECHO Export complete, please check '!FileName!' file.
EXIT /B 0
:::: Batch Script End ::::
Copy above script and paste into Notepad and save it with any name having .cmd extension and execute it from command line.

Following one liners can be used to list group members.

To display group's distinguished name:

DSQuery Group -name GroupName


To display Group members:

DSQuery Group -name GroupName |DSGet Group -Members


To list group members's display name or usernames:

DSQuery Group -name GroupName |DSGet Group -Members |DSGet User -c -samID -display


If your group contains any other group (nested) then you might get message like following:

dsget failed: <group distinguished name> :The object class of the target does not match the one specified on the command line.

So to ignore and continue command operation I have included -c switch with above DSGet User statement.

If you want to include members of all nested groups then you can use -expand switch with DSGet Group statement which will recursively expanded list of members of the group.

DSQuery Group -name GroupName |DSGet Group -Members -expand |DSGet User -c -samID -display


To save output into file you can use dos redirection operator > with file name.

DSQuery Group -name GroupName |DSGet Group -Members -expand |DSGet User -c -samID -display >GroupMembers.txt



Wednesday, June 5, 2013

Who Changed Exchange Server Configuration?

Exchange 2010 has introduced new feature called Administrator Audit Logging. This feature keeps track of what, when and who made changes to Exchange organization. 

Microsoft Exchange provides two types of audit logging:
  • Administrator audit logging records any action, based on a Windows PowerShell cmdlet, performed by an administrator. This can help you troubleshoot configuration issues or identify the cause of security- or compliance-related problems.
  • Mailbox audit logging records whenever a mailbox is accessed by someone other than the person who owns the mailbox. This can help you determine who has accessed a mailbox and what they have done.
This blog covers only Administrator Audit Logging.

Audit log keeps record of almost all Cmdlets (except Get-, Search- and Test- Cmdlets) that are either executed directly using Exchange Management Shell or using Exchange Management Console (EMC) or Exchange Web management interface.

You can search the administrator audit logs to discover who made changes to organization, server, and recipient configuration. This can be helpful when trying to track the cause of unexpected behavior, to identify a malicious administrator, or to verify that compliance requirements are being met.

In Exchange 2010 SP1 Administrator Audit Logging is enabled by default and keeps 90 days worth of entries. After 90 days, the audit log entry is deleted. You can change the audit log age limit using the -AdminAuditLogAgeLimit parameter with Set-AdminAuditLogConfig.

Caution: If you set the age limit to 0, Exchange deletes all the entries in the audit log.

Use the Get-AdminAuditLogConfig cmdlet to view the administrator audit logging configuration settings.

Click Start -> All Programs -> Microsoft Exchange Server 2010 -> Exchange Management Shell -> Get-AdminAuditLogConfig


 
If you found administrator audit logging is disabled (AdminAuditLogEnabled :False), then you can always enable it by applying following statement:

Set-AdminAuditLogConfig -AdminAuditLogEnabled:$true



Admin logs can be retrieved using (a) Search-AdminAuditLog cmdlet, (b) New-AdminAuditLogSearch cmdlet and using (C) Exchange Control Panel (ECP) Auditing Reports page. You can't use the EMC to search for audit log entries.

When you run the Search-AdminAuditLog cmdlet, the audit log entries that match the search criteria that you specify are returned. Without any criteria Search-AdminAuditLog returns all Cmdlets entries.  By default it returns 1,000 log entries. You can use ResultSize parameter to specify up to 250,000 log entries.

Click Start -> All Programs -> Microsoft Exchange Server 2010 -> Exchange Management Shell -> Search-AdminAuditLog


 In above search result you can see user Farhan Kazi modified Internet Receive Connector on 3rd June 2013.

ObjectModified: This field contains the object that was modified by the cmdlet specified in the CmdletName field.

CmdletName: This field contains the name of the cmdlet that was run by the user in the Caller field.

ModifiedProperties: This field contains the properties that were modified on the object in the ObjectModified field.

Caller: This field contains the user account of the user who ran the cmdlet in the CmdletName field.

You can always filter display fields:

Search-AdminAuditLog |fl Caller, CmdletName, ObjectModified



We can specify different search criteria, like following:

Search-AdminAuditLog -Cmdlet Set-ReceiveConnector



Above statement will only query records that includes any modification to Receive Connector.

Search-AdminAuditLog -StartDate "06/03/2013 07:00" -EndDate "06/03/2013 16:00"



Above will search records with date criteria.

Search-AdminAuditLog -Cmdlet Set-ReceiveConnector -StartDate (Get-Date).AddDays(-3) -EndDate (Get-Date)



Above statement will display last 3 days records.

You can use |Out-File to send pipelined output directly to a text file rather than displaying that output on screen.

Search-AdminAuditLog |Out-File C:\ExchAuditLog.txt



By default Out-File saves the data exactly the way that data appears in your Windows PowerShell console. That means that some of the data could end up truncated. To avoid that just include the -width parameter and specify a different line width (in characters) for the text file.

You can also use |Export-Csv cmdlet which makes it easy to export data as a comma-separated values (CSV) file.

Search-AdminAuditLog |Export-Csv C:\ExchAuditLog.csv



You can use New-AdminAuditLogSearch cmdlet to search for audit log entries that meet the criteria you specify, and then send those results to a recipient you specify as an XML file attachment. The results are sent to the recipient within 15 minutes.

After the New-AdminAuditLogSearch cmdlet is run, the report is delivered to the mailboxes you specify within 15 minutes. The log is included as an XML attachment on the report e-mail message. The maximum size of the log that can be generated is 10 MB.

New-AdminAuditLogSearch -Name "Receive Connector Audit" -Cmdlet Set-ReceiveConnector -StartDate "06/03/2013 07:00" -EndDate "06/03/2013 16:00" -StatusMailRecipients "fkazi@techmazter.com"



This example finds all the administrator audit log entries that match the above criteria and sends the results to specified email address.



Once the report has been received, we can save the attached XML file and open it up in an XML Editor.  I chose to use XML Notepad (http://www.microsoft.com/en-au/download/details.aspx?id=7973)



You can also use the Exchange Control Panel (ECP) to export the administrator audit log. On the Auditing tab in the Exchange Control Panel, you can search for and export entries from the administrator audit log and the mailbox audit log.
  1. Log on to Outlook Web App.
  2. Click Options, and then click See All Options.
  3. In the drop-down list box next to Mail > Options, click My Organization from the Select what to manage list.
  4. Click Roles & Auditing from left side panel, and then click Auditing tab.
From there, we can see that we can view some Auditing Reports.You can select "Export the administrator audit log.." - this allows you to search for and export information about configuration changes made in your organization.



The report can take several minutes and even longer depending on how much of a time period we are searching through. Once the report has been received, we can save the attached XML file and open it up in an XML Editor. 

Saturday, April 27, 2013

Creating Custom Active Directory Attributes

This will guide on how to create custom Active Directory attributes where an existing attribute is not available. For example, creating an attribute to hold user's "Medicare Card Number".

Adding custom attributes involves modification in AD schema which requires you to be a member of Schema Administrators and Enterprise Administrators groups. By default, the administrator account is a member of the Schema Administrator group.
 
Or as an alternative to extending the schema there are existing attributes called ExtensionAttribute1 through to ExtensionAttribute15, which can be used for storing custom data without extending the schema.

You can view user object attributes through Attribute Editor tab in user properties.


Before you add attribute into schema you need to register Schema snap-in because by default Active Directory Schema its not available in management console.
  • Navigate to Start > Run >mmc
  • Open File > Add/Remove Snap-in..
 
  • You will notice there is no "Active Directory Schema"
  • To register Schema snap-in type RegSvr32 SchmMgmt.dll in Run text box and hit OK.
  • On successful SchmMgmt.dll registration Windows will show information message box.
  •  Open Schema snap-in. Start > Run > mmc.exe > File >Add/Remove Snap-in >Active Directory Schema > Add
  • Expand Active Directory Schema, right-click Attributes and click on "Create Attribute.."


  • Click on Continue, if you receive schema object creation warning message.

In order to proceed with the next step, you will need to generate an Object Identifier (OID) for the Unique X500 Object ID field.
You can generate OID either using by PowerShell or VBScript.

Generating OID using PowerShell (Microsoft Link):

Navigate to Start >  All Programs > Accessories > Windows PowerShell > Windows PowerShell
Copy and Paste following statements on PowerShell window.


#---
$Prefix="1.2.840.113556.1.8000.2554"
$GUID=[System.Guid]::NewGuid().ToString()
$Parts=@()
$Parts+=[UInt64]::Parse($guid.SubString(0,4),"AllowHexSpecifier")
$Parts+=[UInt64]::Parse($guid.SubString(4,4),"AllowHexSpecifier")
$Parts+=[UInt64]::Parse($guid.SubString(9,4),"AllowHexSpecifier")
$Parts+=[UInt64]::Parse($guid.SubString(14,4),"AllowHexSpecifier")
$Parts+=[UInt64]::Parse($guid.SubString(19,4),"AllowHexSpecifier")
$Parts+=[UInt64]::Parse($guid.SubString(24,6),"AllowHexSpecifier")
$Parts+=[UInt64]::Parse($guid.SubString(30,6),"AllowHexSpecifier")
$OID=[String]::Format("{0}.{1}.{2}.{3}.{4}.{5}.{6}.{7}",$prefix,$Parts[0],$Parts[1],$Parts[2],$Parts[3],$Parts[4],$Parts[5],$Parts[6])
$oid
#---
Copy OID string (dot separated numeric string) and paste into Unique X500 Object ID field.


Generating OID using VBScript (Microsoft Link):
Open following link in Web browser and copy VB script code and paste into Notepad.

http://gallery.technet.microsoft.com/scriptcenter/56b78004-40d0-41cf-b95e-6e795b2e8a06
Save notepad file with "OIDGen.vbs" (enclosed with double quotes, otherwise it will suffix .txt after .vbs) name on C: drive

Open command prompt and run this script.  Start > Run > Cmd.exe > CScript.exe C:\OIDGen.vbs
Copy OID string (dot separated numeric string) and paste into Unique X500 Object ID field. 

  • In Create New Attribute dialog box enter Common Name (in this case Medicare Number)
  • LDAP Display Name field will automatically populate from Common Name (without space)
  • Paste OID string that we generate in previous steps into Unique X500 Object ID field.
  • Write Description in text box.
  • Choose attribute type (in this case Medicare Number is a numeric value) by selecting appropriate Syntax from drop down list. This could be of a different type and depends on the usage of each attribute)
  • Click OK

Custom attribute medicareNumber is created.

  • We will now add/associate this new attribute to the User class.  Navigate to the Classes leaf and select the User class.
  • Right-click User, click on Properties.
  • Navigate to the Attributes tab. Click on Add.
  • Locate the medicareNumber attribute and click OK, and again OK.
  • Just to confirm that the attribute has been associated with User, right-click User, properties and navigate to the Attributes tab. The medicareNumber attribute should be present in the list of Optional attributes.
This completes the creation of a custom attribute.

Open Active Directory Users and Computers snap-in and check user properties for custom attribute.


 You can set this attribute's value by clicking Edit button and entering appropriate value.


To view all users with Medicare Card number set, you can run following command line statement.
DSQuery * -Filter (medicareNumber=*) -Attr Name, medicareNumber

Monday, February 22, 2010

Find Empty Active Directory Groups

Following one-liners will find Active Directory Groups that have no users.

** To find empty Global Security groups:
Click Start -> Run -> Cmd.exe -> OK -> Copy and Paste following statement

DSQuery * -Filter "(&(sAMAccountType=268435456)(!member=*))" -Limit 0

** You can save the output to a text file by using Dos redirection operator > with file name.

DSQuery * -Filter "(&(sAMAccountType=268435456)(!member=*))" -Limit 0 >C:\EmptyGroups.txt

Above statement will create EmptyGroups.txt file on C: drive root listing all empty security groups.

** To find empty Local Security groups:

DSQuery * -Filter "(&(sAMAccountType=536870912)(!member=*))" -Limit 0

** To find empty Distribution groups:

DSQuery * -Filter "(&(sAMAccountType=268435457)(!member=*))" -Limit 0

 ** To find ALL empty groups (either local, global Security or Distribution groups):

DSQuery * -Filter "(&(objectClass=group)(!member=*))" -Limit 0

Monday, February 15, 2010

Windows 2003 Domain Rename Guide

Domain rename operations are a serious business and involve extensive planning and lab work before implementing this process in production.

Following items must be considered before applying the procedure in production environment:
  • It is extremely important and highly recommended that you test the domain rename procedure 2 to 3 times prior to performing it in a production environment. First, perform the domain rename procedure described in this document in a test environment that has a minimum of two domains and few client machines.
  • You must ensure that you have a functioning and current backup of your Active Directory infrastructure and you have tested the recovery plan in mind if domain domain rename fail.
  • Microsoft cannot guarantee that any third-party software that is installed will function after changing the domain name. You should test and work with third-party application to ensure you understand how product will react to domain name change.
  • A domain rename will work just fine IF you know what you are doing. We have renamed test domain (2 DC's, Trust, child domain and 2 member servers). Please note this is a group project that may require a month with testing, testing and testing.
Downloads:
      1)    Farhan's Guide for Domain Rename
      2)    Step-by-Step Guide to Implementing Domain Rename
      3)    Implementing an Active Directory Domain Rename Operation

Note: If you encounter any problem in downloading the attachments kindly leave comment.

Hope this helps!

Wednesday, February 10, 2010

Servers Shared Folders Auto Backup Batch

Following batch script will make incremental backup of network share folders from different servers to one particular server. The only thing that you need is to list all shares from different servers into a text file (Shares.txt). Script will copy all data with structure to a target server share that you will provide inside the script (TargetPath variable).

Sample shares.txt file:
   \\SRV001\Finance
   \\SRV003\Users\FKazi
   \\MAILSRV001\NSF
   \\LIBSRV\eBooks\

 :: SCRIPT START ::
@ECHO OFF
SETLOCAL EnableDelayedExpansion
TITLE :: Auto Backup Batch ::

SET MM=%DATE:~4,2%
SET DD=%DATE:~7,2%
SET YYYY=%DATE:~10,4%
SET vDate=%DD%_%MM%_%YYYY%.txt

::User Editable Variables - START
SET SLFile=Shares.txt
SET TargetPath=\\DATASRV\DATA_SYNC
:: User Editable Variables - END

IF NOT EXIST "%SLFile%" ECHO ERROR: '"%SLFile%"' file not found. &PAUSE &GOTO DisconnectDrives
IF NOT EXIST "%TargetPath%" ECHO ERROR: '"%TargetPath%"' location does not exist. &PAUSE &GOTO DisconnectDrives
IF NOT EXIST "ExcludeList.txt" ECHO \NONE\>"ExcludeList.txt"

FOR /F "delims=" %%A IN ('TYPE Shares.txt') DO (
    SET LogFile=%%A
    SET LogFile=!LogFile:\\=!
    SET LogFile=!LogFile:\=_!_!vDate!.txt
   
    FOR %%I IN ("%%A") DO ECHO. &ECHO ======== EXECUTING BACKUP JOB FOR %%~nI ======== &ECHO.
    :: Source drive mapping
    CALL :GetFreeDrive
    IF /I !FreeDrv!==FALSE (
        ECHO ERROR: No free drive letter available.
        GOTO :ExitScript
    ) ELSE (SET SDrive=!FreeDrv!)
   
    ECHO Mapping source %%A with drive letter ^(!SDrive!^)
    IF NOT EXIST "%%A" ECHO ERROR: Invalid source ^(%%A^) path. &PAUSE &GOTO DisconnectDrives
    NET USE !SDrive! "%%A" /PERSISTENT:NO
   
    :: Target drive mapping
    CALL :GetFreeDrive
    IF /I !FreeDrv!==FALSE (
        ECHO ERROR: No free drive letter available.
        GOTO :ExitScript
    ) ELSE     (SET TDrive=!FreeDrv!)
   
    ECHO Mapping target !TargetPath! with drive letter ^(!TDrive!^)
    IF NOT EXIST "!TargetPath!\%%~nA" MD "!TargetPath!\%%~nA"
    NET USE !TDrive! "!TargetPath!\%%~nA" /PERSISTENT:NO
           
    :: Copying files
    ECHO Copying files from drive !SDrive! to !TDrive!, please wait...
    XCOPY !SDrive! !TDrive! /D /E /C /S /H /R /Y /EXCLUDE:ExcludeList.txt
   
    ECHO. &ECHO File Copying Finish.
    ECHO Closing Network Connection... &ECHO.
    PING -n 20 -l 5 127.0.0.1 >NUL
    IF EXIST "!LogFile!" (
        FOR %%R IN ("!LogFile!") DO IF %%~zR EQU 0 DEL /F /Q "!LogFile!")
    CALL :DisconnectDrives)
GOTO :ExitScript

:GetFreeDrive
SET FreeDrv=
SET FreeDrv=TRUE
SET DriveLtrs=C,D,E,F,G,H,I,J,K,L,M,N,O,P,Q,R,S,T,U,V,W,X,Y,Z

FOR %%a IN (!DriveLtrs!) DO (
    SET FreeDrv=TRUE
    FOR /F "delims=:" %%b IN ('WMIC LOGICALDISK GET Name ^|FIND ":"') DO IF /I "%%a"=="%%b" SET FreeDrv=FALSE
    IF /I "!FreeDrv!"=="TRUE" (
        SET FreeDrv=%%a:
        EXIT /B 0))
   
:DisconnectDrives
IF EXIST !SDrive! ECHO Disconnecting Mapped Drive (!SDrive!) &NET USE !SDrive! /DELETE /Y
IF EXIST !TDrive! ECHO Disconnecting Mapped Drive (!TDrive!) &NET USE !TDrive! /DELETE /Y
EXIT /B 0

:ExitScript
EXIT /B 0
:: SCRIPT END ::

Thursday, October 8, 2009

Check Internet Explorer Version of Client Computers

Following batch script requires two variables to be set with actual values.
Set 'InputFile' variable with a file name with path from where it will pick computer names.
This file should contain computer name on each line, like:

PC1
PC2
PC3

Set "OutputFile" variable with a file name including path where it will store the results.
So here you go...

:: SCRIPT START::
@ECHO OFF
SET InputFile=C:\Computers.txt
SET OutputFile=C:\IEInfo.txt

IF NOT EXIST "%InputFile%" ECHO **ERROR** "%InputFile%" file does not exist. &GOTO :ExitScript
FOR %%R IN ("%InputFile%") DO IF %%~zR EQU 0 ECHO **ERROR** "%InputFile%" file is empty! &GOTO :ExitScript
FOR /F "delims=" %%C IN ('TYPE "%InputFile%"') Do (
    PING -n 1 -l 10 -w 100 %%C |FIND /I "TTL" >NUL
    IF NOT ERRORLEVEL 1 (
        ECHO Processing: %%C
        FOR /F "tokens=3" %%v IN ('REG QUERY "\\%%C\HKLM\SOFTWARE\Microsoft\Internet Explorer" /v Version ^|FIND /I "REG_SZ"') DO (
            ECHO Computer: %%C    IE Version: %%v>>"%OutputFile%"))ELSE (ECHO **ERROR** Unable to connect %%C))
       
ECHO. &ECHO Script finish, check "%OutputFile%" file for result.

:ExitScript
ECHO.
PAUSE
:: SCRIPT END::

Sunday, September 27, 2009

Default Password List – Networking Devices

Phenoelit-us maybe the simplest and best password list website.

http://www.phenoelit-us.org/dpl/dpl.html

7 Free Default Password List Websites - Something You Need to Bookmark

http://www.smashingpasswords.com/7-free-default-password-list-websites-something-you-need-bookmark

Would you appreciate this information?
Well, I'm sure many would ;-)

Thursday, September 24, 2009

Search Specific User or a Group inside Local Administrators Group of Domain Computers

Following script will search for specific user or a group inside local administrators group of domain computers.

You only have to set 'ObjectName' variable inside a script to the username of a group name.

@ECHO OFF
SET ObjectName=Domain Users

SET Counter=0
SET OutputFile=GroupInfo.txt
FOR /F "delims=\\ " %%c IN ('NET VIEW ^|FIND "\\"') DO (
    PING -n 1 -l 10 -w 100 %%c |FIND /I "TTL" >NUL
    IF NOT ERRORLEVEL 1 (
        ECHO Processing: %%c
        WMIC /NODE:"%%c" PATH Win32_GroupUser WHERE ^(GroupComponent="win32_group.name=\"Administrators\",Domain=\"%%c\""^) GET PartComponent |FIND /I "%ObjectName%" >NUL
        IF NOT ERRORLEVEL 1 (
            SET /A Counter+=1
            ECHO =============================>>"%OutputFile%"
            ECHO Machine: %%c >>"%OutputFile%"
            ECHO =============================>>"%OutputFile%"
            ECHO Date: %DATE%  Time: %TIME% >>"%OutputFile%"
            ECHO Administrators group members:>>"%OutputFile%"
            WMIC /OUTPUT:TmpResult.txt /NODE:"%%c" PATH Win32_GroupUser WHERE ^(GroupComponent="win32_group.name=\"Administrators\",Domain=\"%%c\""^) GET PartComponent /FORMAT:CSV
            FOR /F "Tokens=5 Delims==," %%u IN ('TYPE TmpResult.txt') DO ECHO %%~u >>"%OutputFile%"
            ECHO. >>"%OutputFile%"
            ECHO ALERT: '%ObjectName%' exists in Administrators group of %%c computer.)))

IF EXIST TmpResult.txt DEL /F /Q TmpResult.txt
IF %Counter% GTR 0 (
    ECHO. &ECHO SUMMARY: Found %Counter% machine^(s^) having '%ObjectName%' in Administrators Group.
    ECHO For more info check '%OutputFile%' file on %CD%) ELSE (
    ECHO. &ECHO SUMMARY: No machine found having '%ObjectName%' in Administrators Group.)

:ExitScript
ECHO.
PAUSE

Wednesday, September 23, 2009

Automatically Add Default Route for VPN Connection

One common problem that most of the users face after connecting to VPN server is ROUTING.
To enable VPN users to access network resources that are on a different subnet you need to have gateway a address that routes data packets.

We usually remove "Use default gateway on remote network” check in advanced properties on TCP/IP setting while creating VPN connection. This setting enforces to add route to remote subnet manually.
This configuration leads to the problem when RRAS server assigns IP addresses dynamically, which mean that VPN users will get different IP address each time when they connect to the RRAS server!

In Windows you can view routing table by applying following statement from command line:
Click Start -> Run -> Cmd -> OK

ROUTE PRINT

 Following batch script will help network admins to provide users with a batch file that will automatically set route to the corporate network.

You only have to set two variables inside a script. Set ‘NetSubnet’ with a network subnet address and ‘SubnetMask’ with the subnet mask.

:: ************ Method -1 ************ ::
@ECHO OFF
COLOR 8F

SET NetSubnet=172.16.0.0
SET SubnetMask=255.255.0.0

ECHO.
ECHO ###########################################################
ECHO            PLEASE DO NOT CLOSE THIS WINDOW     
ECHO This window will automatically disappear after 10 seconds.
ECHO ###########################################################
ECHO.
FOR /F %%I IN ('ROUTE PRINT ^|FIND "WAN (PPP/SLIP)"') DO SET IFindex=%%I
ECHO Updating Routing Table, please wait....
ECHO.
ROUTE DELETE %NetSubnet% >NUL
ROUTE ADD %NetSubnet% MASK %SubnetMask% 0.0.0.0 IF %IFindex%
ROUTE PRINT %NetSubnet%
PING -n 10 -w 1 -l 1 127.0.0.1 >NUL
EXIT /B 0

:: ************ Method -2 ************ ::

@ECHO OFF
COLOR 8F
SET NetSubnet=172.16.0.0
SET SubnetMask=255.255.0.0
ECHO.
ECHO ###########################################################
ECHO            PLEASE DO NOT CLOSE THIS WINDOW      
ECHO This window will automatically disappear after 10 seconds.
ECHO ###########################################################
ECHO.
SET cWMIC=WMIC NICCONFIG WHERE "ServiceName='NdisWan'" GET IPAddress /FORMAT:CSV
FOR /F "tokens=2 delims=,{}" %%i IN (' %cWMIC% ^|FIND "."') DO SET IPAddress=%%i
ECHO Obtained IP address: %IPAddress%
ECHO.
ECHO Updating Routing Table, please wait....
ECHO.
ROUTE DELETE %NetSubnet% >NUL
ROUTE ADD %NetSubnet% MASK %SubnetMask% %IPAddress% METRIC 1
ROUTE PRINT %NetSubnet%
PING -n 10 -w 1 -l 1 127.0.0.1 >NUL
EXIT /B 0

Optionally if you want this batch script to dial VPN connection then you can use following batch script. It will dial VPN connection and will set route for the remote subnet.

:: ************ Method -1 ************ ::

@ECHO OFF
COLOR 8F
SET NetSubnet=172.16.0.0
SET SubnetMask=255.255.0.0
ECHO.
ECHO ###########################################################
ECHO            PLEASE DO NOT CLOSE THIS WINDOW     
ECHO This window will automatically disappear after 20 seconds.
ECHO ###########################################################
ECHO.
ECHO Dialing VPN, please wait....
RASDial ConnectionName MyUsername MyP@ssw0rd
PING 127.0.0.1 -n 15 -l 0 -w 0 >NUL
FOR /F %%I IN ('ROUTE PRINT ^|FIND "WAN (PPP/SLIP)"') DO SET IFindex=%%I
ECHO.
ECHO Updating Routing Table, please wait....
ECHO.
ROUTE DELETE %NetSubnet% >NUL
ROUTE ADD %NetSubnet% MASK %SubnetMask% 0.0.0.0 IF %IFindex%
ROUTE PRINT %NetSubnet%
PING -n 5 -w 1 -l 1 127.0.0.1 >NUL
EXIT /B 0

:: ************ Method -2 ************ ::
@ECHO OFF
COLOR 8F
SET NetSubnet=172.16.0.0
SET SubnetMask=255.255.0.0
ECHO.
ECHO ###########################################################
ECHO            PLEASE DO NOT CLOSE THIS WINDOW      
ECHO This window will automatically disappear after 20 seconds.
ECHO ###########################################################
ECHO.
ECHO Dialing VPN, please wait....
RASDial ConnectionName MyUsername MyP@ssw0rd
ECHO.
ECHO Obtaining IP Address, please wait....
PING 127.0.0.1 -n 15 -l 0 -w 0 >NUL
SET cWMIC=WMIC NICCONFIG WHERE "ServiceName='NdisWan'" GET IPAddress /FORMAT:CSV
FOR /F "tokens=2 delims=,{}" %%i IN (' %cWMIC% ^|FIND "."') DO SET IPAddress=%%i
ECHO Obtained IP address: %IPAddress%
ECHO.
ECHO Updating Routing Table, please wait....
ECHO.
ROUTE DELETE %NetSubnet% >NUL
ROUTE ADD %NetSubnet% MASK %SubnetMask% %IPAddress% METRIC 1
ROUTE PRINT %
NetSubnet%
PING -n 5 -w 1 -l 1 127.0.0.1 >NUL
EXIT /B 0


In above script beside setting ‘NetSubnet’ and ‘SubnetMask’ variables and you have to provide required information to RASDial command.
RASDial command syntax is

              RASDial entryname [username [password|*]] [/DOMAIN:domain]

 Here 'entryname' is the connection name (shown in image below) that have created under 'Network Connections' for dialing VPN connection.


Monday, September 21, 2009

Searching Network for Specific Process Running Machines

Following batch script will help system administrators to find machines on a network with a specific running process.

You only have to set 'ProcessName' variable inside a script with the process name (i.e. calc.exe) that you want to find.

@ECHO OFF
SET ProcessName=calc.exe

SET Counter=0
FOR /F "delims=\\ " %%c IN ('NET VIEW ^|FIND "\\"') DO (
PING -n 1 -l 10 -w 100 %%c |FIND /I "TTL" >NUL
IF NOT ERRORLEVEL 1 (
    ECHO Processing: %%c
    TASKLIST /S %%c /V /FI "IMAGENAME eq %ProcessName%" /FO LIST |FIND /I "PID" >NUL
    IF NOT ERRORLEVEL 1 (
        SET /A Counter+=1
        ECHO =================================>>ProcessInfo.txt
        ECHO Machine: %%c >>ProcessInfo.txt
        ECHO =================================>>ProcessInfo.txt
        ECHO Date: %DATE%  Time: %TIME% >>ProcessInfo.txt
        FOR /F "tokens=3" %%u IN ('REG QUERY "\\%%c\HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v DefaultUserName ^|FIND /I "REG_SZ"') DO (
            ECHO Logged-in username: %%u >>ProcessInfo.txt)
        TASKLIST /S %%c /V /FI "IMAGENAME eq %ProcessName%" /FO LIST >>ProcessInfo.txt
        ECHO.>>ProcessInfo.txt)))

IF %Counter% GTR 0 (
    ECHO. &ECHO Found %Counter% machine^(s^) with running '%ProcessName%' process.
    ECHO For more info check 'ProcessInfo.txt' on %CD%) ELSE (
    ECHO. &ECHO No machine found with '%ProcessName%' running.)

:ExitScript
ECHO.
PAUSE
 

Tuesday, September 15, 2009

Getting Dell Service Tag from Command Line


Now you don't need to switch off your PC and search in BIOS for system Service Tag! Service Tag is a unique five- to seven- digit alphanumeric (letter and number) code, which is found on a white bar-coded label affixed to your Dell computer or peripheral. Entering the service tag of your Dell computer or peripheral helps Dell deliver solutions tailored to the products you own.

Try following one-liners to get local or remote system service tag:

Click Start -> Run -> Cmd.exe -> now try one of the following statement:

Local System

WMIC SYSTEMENCLOSURE GET SerialNumber
                                      OR
WMIC BIOS GET SerialNumber

Remote System

WMIC /NODE:ComputerName SYSTEMENCLOSURE GET SerialNumber
                                       OR
WMIC /NODE:ComputerName BIOS GET SerialNumber

Remote System with Credentials

WMIC /USER:"DOMAIN\Username" /NODE:ComputerName SYSTEMENCLOSURE GET SerialNumber
                                       OR
WMIC /USER:"DOMAIN\Username" /NODE:ComputerName BIOS GET SerialNumber
                                      OR
WMIC /USER:"DOMAIN\Username" /PASSWORD:"P@ssw0rd" /NODE:ComputerName SYSTEMENCLOSURE GET SerialNumber
                                      OR
WMIC /USER:"DOMAIN\Username" /PASSWORD:"P@ssw0rd" /NODE:ComputerName BIOS GET SerialNumber

Monday, August 31, 2009

AYATS AND AHADITHS THAT PROVE HIJAB OF FACE NOT ONLY EXISTS BUT IS FARZ

Allaah says (interpretation of the meaning):
“O Prophet! Tell your wives and your daughters and the women of the believers to draw their cloaks (veils) all over their bodies (i.e. screen themselves completely except the eyes or one eye to see the way). That will be better, that they should be known (as free respectable women) so as not to be annoyed. And Allaah is Ever Oft‑Forgiving, Most Merciful”
[al-Ahzaab 33:59]

In the Sunnah there are many ahaadeeth, such as: the Prophet (peace and blessings of Allaah be upon him) said: “The woman in ihraam is forbidden to veil her face (wear niqaab) or to wear the burqa’.” This indicates that when women were not in ihraam, women used to cover their faces.

This does not mean that if a woman takes off her niqaab or burqa’ in the state of ihraam that she should leave her face uncovered in the presence of non-mahram men. Rather she is obliged to cover it with something other than the niqaab or burqa’, on the evidence of the hadeeth of ‘Aa’ishah (may Allaah be pleased with her) who said: “We were with the Prophet (peace and blessings of Allaah be upon him) in ihraam, and when men passed by us, we would lower the khimaar on our heads over our faces, and when they moved on we would lift it again.”

He also said:
It is OK to cover the face with the niqaab or burqa’ which has two openings for the eyes only, because this was known at the time of the Prophet (peace and blessings of Allaah be upon him), and because of necessity. If nothing but the eyes show, this is fine, especially if this is customarily worn by women in her society. 

Ibn Taymiyah (may Allaah have mercy on him) said:
“Allaah commands women to let the jilbaab come down (over their faces) so that they will be known (as respectable women) and not be annoyed or disturbed. This evidence supports the first opinion. ‘Ubaydah al-Salmaani and others stated that the women used to wear the jilbaab coming down from the top of their heads in such a manner that nothing could be seen except their eyes, so that they could see where they were going. It was proven in al-Saheeh that the woman in ihraam is forbidden to wear the niqaab and gloves. This is what proves that the niqaab and gloves were known among women who were not in ihraam. This implies that they covered their faces and hands.”

Allaah says (interpretation of the meaning):
“And tell the believing women to lower their gaze (from looking at forbidden things), and protect their private parts (from illegal sexual acts) and not to show off their adornment except only that which is apparent (like both eyes for necessity to see the way, or outer palms of hands or one eye or dress like veil, gloves, headcover, apron), and to draw their veils all over Juyoobihinna (i.e. their bodies, faces, necks and bosoms)…”
[al-Noor 24:31]

Ahmad said: the adornment which is apparent is the clothing. And he said: every part of a woman is ‘awrah, even her nails. It was narrated in the hadeeth, ‘The woman is ‘awrah,’ This includes all of the woman. It is not makrooh to cover the hands during prayer, so they are part of the ‘awrah, just like the feet. Analogy implies that the face would be ‘awrah were it not for the fact that necessity dictates that it should be uncovered during prayer, unlike the hands.”
Sharh al-‘Umdah, 4/267-268.

It was narrated that ‘Aa’ishah (May Allah be Pleased with her) said: “The riders used to pass by us when we were with the Messenger of Allaah (peace and blessings of Allaah be upon him) in ihraam. When they came near, each of us would lower her jilbaab from her head over her face, and when they passed by we would uncover (our faces).”
Narrated by Abu Dawood, 1833; Ahmad, 24067

It is well known that a woman should not put anything over her face when she is in ihraam, but ‘Aa’ishah and the Sahaabiyaat (women of the Sahaabah) who were with her used to lower part of their garments over their faces because the obligation to cover the face when non-mahrams pass by is stronger than the obligation to uncover the face when in ihraam.

It was narrated that ‘Aa’ishah (may Allaah be pleased with her) said: “May Allaah have mercy on the women of the Muhaajireen. When Allaah revealed the words (interpretation of the meaning)
 ‘and to draw their veils all over Juyoobihinna (i.e. their bodies, faces, necks and bosoms)…”
[al-Noor 24:31], they tore their aprons and covered their faces with them.”
(Narrated by al-Bukhaari, 4480)

It was narrated from ‘Aa’ishah (May Allah be Pleased with her) … that Safwaan ibn al-Mu’attal al-Sulami al-Dhakwaani was lagging behind the army. He came to where I had stopped and saw the black shape of a person sleeping. He recognized me when he saw me, because he had seen me before hijaab was enjoined. I woke up when I heard him saying ‘Inna Lillaahi wa inna ilayhi raaji’oon (verily to Allaah we belong and unto Him is our return),’ when he saw me, and I covered my face with my jilbaab.”
(Narrated by al-Bukhaari, 3910; Muslim, 2770)

It was narrated from ‘Abd-Allaah that the Prophet (peace and blessings of Allaah be upon him) said: “The woman is ‘awrah and when she goes out the Shaytaan gets his hopes up.”
(Narrated by al-Tirmidhi, 1173)

Verily Allah give strength to all those who follow his commands. He open doors of the Hearts of the people He loves. May Allah Give us a chance to follow what ever He said truely, faithfully and completely.


Fataawa al-Mar’ah al-Muslimah, 1/399

Allaah says (interpretation of the meaning):
“And tell the believing women to lower their gaze (from looking at forbidden things), and protect their private parts (from illegal sexual acts) and not to show off their adornment except only that which is apparent (like both eyes for necessity to see the way, or outer palms of hands or one eye or dress like veil, gloves, headcover, apron), and to draw their veils all over Juyoobihinna (i.e. their bodies, faces, necks and bosoms) and not to reveal their adornment except to their husbands, or their fathers, or their husband’s fathers, or their sons, or their husband’s sons, or their brothers or their brother’s sons, or their sister’s sons, or their (Muslim) women (i.e. their sisters in Islam), or the (female) slaves whom their right hands possess, or old male servants who lack vigour, or small children who have no sense of feminine sex. And let them not stamp their feet so as to reveal what they hide of their adornment. And all of you beg Allaah to forgive you all, O believers, that you may be successful”
[al-Noor 24:31]

The evidence from this verse that hijab is obligatory for women is as follows:


(a)       Allaah commands the believing women to guard their chastity, and the command to guard their chastity also a command to follow all the means of doing that. No rational person would doubt that one of the means of doing so is covering the face, because uncovering it causes people to look at it and enjoy its beauty, and thence to initiate contact. The Messenger of Allaah (peace and blessings of Allaah be upon him) said: “The eyes commit zina and their zina is by looking…” then he said, “… and the private part confirms that or denies it.” Narrated by al-Bukhaari, 6612; Muslim, 2657.

(b)      Allaah says (interpretation of the meaning): “…and to draw their veils all over Juyoobihinna (i.e. their bodies, faces, necks and bosoms)  …”. The jayb (pl. juyoob) is the neck opening of a garment and the khimaar (veil) is that with which a woman covers her head. If a woman is commanded to draw her veil over the neck opening of her garment then she is commanded to cover her face, either because that is implied or by analogy. If it is obligatory to cover the throat and chest, then it is more appropriate to cover the face because it is the site of beauty and attraction.

(c)       Allaah has forbidden showing all adornment except that which is apparent, which is that which one cannot help showing, such as the outside of one's garment. Hence Allaah says (interpretation of the meaning): “…except only that which is apparent …” and He did not say, except that which they show of it. Some of the salaf, such as Ibn Mas’ood, al-Hasan, Ibn Sireen and others interpreted the phrase “except only that which is apparent” as meaning the outer garment and clothes, and what shows from beneath the outer garment (i.e., the hem of one’s dress etc.). Then He again forbids showing one’s adornment except to those for whom He makes an exception. This indicates that the second adornment mentioned is something other than the first adornment. The first adornment is the external adornment which appears to everyone and cannot be hidden. The second adornment is the inward adornment (including the face). If it were permissible for this adornment to be seen by everyone, there would be no point to the general wording in the first instance and this exception made in the second.

(d)      Allaah grants a concession allowing a woman to show her inward adornments to “old male servants who lack vigour”, i.e. servants who are men who have no desire, and to small children who have not reached the age of desire and have not seen the ‘awrahs of women. This indicates two things:

1 – That showing inward adornments to non-mahrams is not permissible except to these two types of people.
2 – That the reason for this ruling is the fear that men may be tempted by the woman and fall in love with her. Undoubtedly the face is the site of beauty and attraction, so concealing it is obligatory lest men who do feel desire be attracted and tempted by her.

(e)       The words (interpretation of the meaning): “And let them not stamp their feet so as to reveal what they hide of their adornment” mean that a woman should not stamp her feet so as to make known hidden adornments such as anklets and the like. If a woman is forbidden to stamp her feet lest men be tempted by what they hear of the sound of her anklets etc., then what about uncovering the face?

Which is the greater source of temptation – a man hearing the anklets of a woman whom he does not know who she is or whether she is beautiful, or whether she is young or old, or ugly or pretty? Or his looking at a beautiful youthful face that attracts him and invites him to look at it?
Every man who has any desire for women will know which of the two temptations is greater and which deserves to be hidden and concealed.

Allaah says (interpretation of the meaning):
“And as for women past childbearing who do not expect wedlock, it is no sin on them if they discard their (outer) clothing in such a way as not to show their adornment. But to refrain (i.e. not to discard their outer clothing) is better for them. And Allaah is All‑Hearer, All‑Knower”
[al-Noor 24:60]

The evidence from this verse is that Allaah states that there is no sin on old women who have no hope of marriage because men have no desire for them, due to their old age (if they discard their outer clothing), subject to the condition that their intention in doing so is not to make a wanton display of themselves. The fact that this ruling applies only to old women indicates that the ruling is different for young women who still hope to get married. If the ruling on discarding the outer clothing applied to all, there would be no point in singling out old women here.

The phrase “in such a way as not to show their adornment” offers further proof that hijab is obligatory for young women who hope to marry, because usually when they uncover their faces the intention is to make a wanton display (tabarruj) and to show off their beauty and make men look at them and admire them etc. Those who do otherwise are rare, and the ruling does not apply to rare cases. 

When the Prophet (peace and blessings of Allaah be upon him) commanded that women should be brought out to the Eid prayer place, they said, “O Messenger of Allaah, some of us do not have jilbaabs.” The Prophet (peace and blessings of Allaah be upon him) said, “Let her sister give her one of her jilbaabs to wear.” Narrated by al-Bukhaari and Muslim.
This hadeeth indicates that the usual practice among the women of the Sahaabah was that a woman would not go out without a jilbaab, and that if she did not have a jilbaab she would not go out. The command to wear a jilbaab indicates that it is essential to cover. And Allaah knows best.

Complied By: Bushra Meraj

Sunday, August 23, 2009

Improve System Performance

There are several small things that you should do to tune up your PC performance.

The one that I presenting for improving your system performance painlessly is through disabling Windows Performance Counters.

Microsoft Windows 2000 and Windows XP have a built-in performance monitor that essentially monitor performance on your machine.

Performance counters are the tools used by Windows to monitor and track the errors and bottlenecks in the speed and performance of Windows. But they are TOO technical in nature and are difficult to be used by a common Windows user. They can, generally be used by an IT administrator or a developer to tweak the performance related to CPU, Memory, Disk, Network, Processes Exchange and many other things. They keep on gathering their data from Windows in the background but in the process eat up precious system resources.

You can safely consider disabling Performance Counters without loosing anything. This will surely help to speedup your Windows and make it run faster.

To disable follow the steps below.

1. Download and install Extensible Performance Counter List (615kb) from Microsoft’s website [http://download.microsoft.com/download/win2000platform/exctrlst/1.00.0.1/nt5/en-us/exctrlst_setup.exe]
2. Run the program which resides in "C:\Program Files\Resource Kit\exctrlst.exe"
3. Clear the "Performance Counters Enabled" check box for each counter listed.



Note: Do realize that a lot of the information collected by the performance counters can be very helpful in analyzing problems on your computer. If your PC shows errors or maybe sometimes you face problem while installing any program that requires perticular performance counter enabled then in such situation make sure to enable all counters then install that program and then you can disable all the counters again.

Once I encountered likewise problem while installing Microsoft Visual Studio, then I have to enable "PerfOS" performance counter (shown in image below) to proceed with the installation.