<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7678477895190931490</id><updated>2011-07-30T21:40:22.066-07:00</updated><title type='text'>Byte Size Tech</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://bytesizetech.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7678477895190931490/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://bytesizetech.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/02825135300837599803</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://3.bp.blogspot.com/_PUK85CxO7yI/S2maDyDY5ZI/AAAAAAAAK4k/3Vo4X0sXQgc/S220/jeffhead.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7678477895190931490.post-2786005251032419231</id><published>2010-02-22T04:54:00.000-08:00</published><updated>2010-02-22T05:45:31.612-08:00</updated><title type='text'>Nails everywhere I look....</title><content type='html'>The other day a colleague asked me what tools I use on a daily basis for the troubleshooting I do. My first reaction was 'my brain', but that didn't sound very nice and I got concerned he would take me literally and we would have a 'Silence of the Lambs' thing happening and I would end up in some well strangling some little poodle to save my life.  Anywho, the tools I use pretty much on a daily basis are comprised of freeware from several different developers as well as built-in applications. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The first set of tools will not be that much of a surprise to most Windows admins, &lt;a href="http://technet.microsoft.com/en-us/sysinternals/default.aspx"&gt;Sysinternals&lt;/a&gt; (Mark Russinovich, you're my hero). These tools are so awesome that Microsoft bought the company and &lt;a href="http://blogs.technet.com/markrussinovich"&gt;Mark&lt;/a&gt; is now a technical fellow there. There are about 65 different utilities, some are great (process explorer) and some aren't (RegJump). The main ones I use are:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;u&gt;&lt;b&gt;Process Explorer&lt;/b&gt;&lt;/u&gt;&lt;/div&gt;&lt;div&gt;This one is my favorite. Think of it as Task Manager on steroids. It will show everything you could ever want to know about a process including all handles and dlls that are in use.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;u&gt;&lt;b&gt;Process Monitor&lt;/b&gt;&lt;/u&gt;&lt;/div&gt;&lt;div&gt;Shows real-time FS, Registry, TCP/UDP, and Thread/Process for all processes. This is a must if you ever want to know what a process is actually doing.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;u&gt;&lt;b&gt;AutoRuns&lt;/b&gt;&lt;/u&gt;&lt;/div&gt;&lt;div&gt;Shows you what programs are configured to run during system bootup or login, and shows you the entries in the order Windows processes them. I have found some many compromised servers using this tool.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;u&gt;Strings&lt;/u&gt;&lt;/div&gt;&lt;div&gt;This is used to display all strings contained within a  file. This is also handy for compromised systems.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;As I said there are over 60 tools and these are just the tip of the iceberg, so check them out.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Another tool set I use are from &lt;a href="http://www.nirsoft.net"&gt;NirSoft&lt;/a&gt;. These guys have some great tools that I can't ever seem to replace.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;u&gt;Currports&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;This is network monitoring software that displays the list of all currently opened TCP/IP and UDP ports on your local computer and the executable listening.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;u&gt;OpenedFilesView&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;Displays the list of all opened files on your system. For each opened file, additional information is displayed: handle value, read/write/delete access, file position, the process that opened the file.  You can also close one or more opened files, or close the process that opened these files.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;u&gt;RegDllView&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;This tools shows all the object that are registered on the system. Is a must for anyone responsible for a web environment&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;NirSoft also has a full line for password recovery utilities that have saved me more than once.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;As for built-in commands I use the following everyday (i'll let you Google them):&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;netstat&lt;/div&gt;&lt;div&gt;tasklist&lt;/div&gt;&lt;div&gt;taskkill&lt;/div&gt;&lt;div&gt;findstr&lt;/div&gt;&lt;div&gt;netsh&lt;/div&gt;&lt;div&gt;sc&lt;/div&gt;&lt;div&gt;net&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I hope these tools can help you find the cause of any issues that you are trying to resolve as they have helped me for years.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Jeff&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7678477895190931490-2786005251032419231?l=bytesizetech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bytesizetech.blogspot.com/feeds/2786005251032419231/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bytesizetech.blogspot.com/2010/02/nails-everywhere-i-look.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7678477895190931490/posts/default/2786005251032419231'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7678477895190931490/posts/default/2786005251032419231'/><link rel='alternate' type='text/html' href='http://bytesizetech.blogspot.com/2010/02/nails-everywhere-i-look.html' title='Nails everywhere I look....'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/02825135300837599803</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://3.bp.blogspot.com/_PUK85CxO7yI/S2maDyDY5ZI/AAAAAAAAK4k/3Vo4X0sXQgc/S220/jeffhead.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7678477895190931490.post-5292320437228043480</id><published>2010-02-03T11:36:00.000-08:00</published><updated>2010-02-03T12:11:46.901-08:00</updated><title type='text'>Troubleshooting. It ain't just a river in Egypt.</title><content type='html'>&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;Working as a sysadmin I use my troubleshooting ability on a daily basis.  I also see a lot of other techs really struggle with troubleshooting. I have never had any formal training on troubleshooting, I think it is one of those skills I was just born with and I am happy I was. It makes my life easier. But I do realize that not everyone has this skill and I want to share a basic troubleshooting methodology that anyone can follow for any troubleshooting they need to do.&lt;/span&gt;&lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;Troubleshooting typically consists of the following steps:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;1) Define &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; "&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;2) Analyze&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; "&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;3) Implement&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;&lt;i&gt;Define&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;Problem Statement:&lt;/b&gt;  Create a clear, concise statement of the  problem.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;Identify the symptoms:&lt;/b&gt;  What works?   What doesn't?&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;Identify Differences and Changes:&lt;/b&gt;  What has changed recently? What is unique about this system?&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;&lt;i&gt;Analyze&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;Brainstorm:  &lt;/b&gt;Gather Hypotheses:  What might have caused the problem?&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;Identify Likely Causes:  &lt;/b&gt;Which hypotheses are most likely?&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;Test Possible Causes:  &lt;/b&gt;Schedule the testing for the most likely hypotheses.  Perform any non-disruptive testing immediately.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;&lt;i&gt;Implement&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;Implement the Fix:   &lt;/b&gt;Complete the repair.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;Verify the Fix:   &lt;span class="Apple-style-span" style="font-weight: normal;"&gt;Is the problem really fixed?&lt;/span&gt;&lt;/li&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;&lt;/li&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;Document the Resolution:  &lt;span class="Apple-style-span" style="font-weight: normal;"&gt;What did we do?  &lt;/span&gt;&lt;/li&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;b&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;b&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;Using this basic formula will provide a smooth, timely troubleshooting path. &lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;I'll focus on more real world examples in my next post.&lt;/span&gt;&lt;/li&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;b&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: verdana; font-size: medium; "&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;b&gt;&lt;b&gt;&lt;li style="display: inline !important; "&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;Jeff&lt;/span&gt;&lt;/li&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7678477895190931490-5292320437228043480?l=bytesizetech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bytesizetech.blogspot.com/feeds/5292320437228043480/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bytesizetech.blogspot.com/2010/02/troubleshooting-it-aint-just-river-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7678477895190931490/posts/default/5292320437228043480'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7678477895190931490/posts/default/5292320437228043480'/><link rel='alternate' type='text/html' href='http://bytesizetech.blogspot.com/2010/02/troubleshooting-it-aint-just-river-in.html' title='Troubleshooting. It ain&apos;t just a river in Egypt.'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/02825135300837599803</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://3.bp.blogspot.com/_PUK85CxO7yI/S2maDyDY5ZI/AAAAAAAAK4k/3Vo4X0sXQgc/S220/jeffhead.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7678477895190931490.post-6013436313200162722</id><published>2010-02-03T08:03:00.000-08:00</published><updated>2010-02-03T08:07:29.261-08:00</updated><title type='text'>Intro...</title><content type='html'>Well I decided to follow my colleagues and but a blog online with interesting things as I find them.   I should tell you a bit about myself so you can decide on whether or not you want to actually ready this. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I am a systems engineer with over 15 years IT experience. My current job is focused on Windows but I have touched a lot of things in the industry.  AS I run into interesting things or cool sysadmin stuff I'll be putting it here.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Jeff&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7678477895190931490-6013436313200162722?l=bytesizetech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bytesizetech.blogspot.com/feeds/6013436313200162722/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://bytesizetech.blogspot.com/2010/02/intro.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7678477895190931490/posts/default/6013436313200162722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7678477895190931490/posts/default/6013436313200162722'/><link rel='alternate' type='text/html' href='http://bytesizetech.blogspot.com/2010/02/intro.html' title='Intro...'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/02825135300837599803</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://3.bp.blogspot.com/_PUK85CxO7yI/S2maDyDY5ZI/AAAAAAAAK4k/3Vo4X0sXQgc/S220/jeffhead.jpg'/></author><thr:total>0</thr:total></entry></feed>
