Friday, July 16, 2010

Protecting the Edge Server Against DoS and Password Brute Force Attacks in Office Communications Server

Some of my good OCS friends (Kjeld and Kenneth) pointed me to this great article from RUI Maximo on protecting your Edge/OCS from DoS.

In some company’s users will actually be looked out after 3-5 bad  login attempts, and stay looked out until they are unlocked, in most company's they will reopen automatically after 5-15 min and then they will have 3-5 login attempts again.

But no matter if it’s 5 min or 30 min that users are looked out, it’s could give load on the helpdesk, and loss of productivity .

DoS attacks can be done from self made applications/scripts . I have not heard of customers that have had attack yet, but if you have customers that have concerns on this topic, please read Rui Maximo great article and maybe use the filter on your Edge server.

Link : http://technet.microsoft.com/en-us/ff706687.aspx

Wednesday, July 14, 2010

Important update: Microsoft Office Communicator Mobile 2007 R2

This is actully not just a fix/patch, it’s an update, I have missed the “call via work” from the normal dialpad for a long time, now this works on Windows 6.5, sorry dont know for all other mobiles.

Download here and description here: and remember that you always can download directly from the phone here http://getcomo.com

New version is:6906.29

Issues that this hotfix package fixes
  • Provides home screen support for new home screens in Windows Mobile 6.5+ phones.
  • Provides integration within the phone dialer for Windows Mobile 6.5+ phones.
  • Enables Communicator Mobile 2007 R2 to recognize when the phone is roaming and by default prevents Communicator Mobile 2007 R2 from signing in to roaming networks.
  • Provides additional support for joining conference calls from a Windows Mobile appointment. To do this, press Menu, and then press Join Conference.
  • Lets users log on by using a user name in the user@example.com format, in addition to the domain\user format.
  • Enables the functionality by which callbacks are now automatically accepted when the user uses the Call via Work option.
  • Resolves the problem in which the Microsoft Installer (.msi) installation fails on a Windows XP Service Pack 3 (SP3)-based computer. In this situation, users should install Communicator Mobile 2007 R2 by using a (.cab) installation.
  • Fixes the problem in which AT&T FUZE devices that are set for a High-Speed Downlink Packet Access (HSDPA) connection cannot handle voice and data at the same time. In this situation, calls that use the Call via Work option fail unless the device is reverted to 3rd Generation (3G) by disabling HSDPA.