|
|
2004年06月10日
If you were on NTBugTraq mailing list, Russ Coppers was presenting his findings about Microsoft Security bulletins and conclude:
IIS 6.0 = 60 vulnerabilities
This is very misleading, after some hot debate and help of few security MVPs, I have blog my findings here.
2004年05月26日
第一本书!Shameless plugs here 谢谢支持,谢谢Grace.
2004年05月20日
2004年05月18日
2004年05月11日
隐藏不是安全保护,最好还是有打上补丁及有防火墙,IDS, 防毒如案件等等。 如何隐藏?点击这。
2004年05月06日
有些日子没上来了。。刚刚贴了个Blog,然后到主页看看其他人的随笔。但突然发现Joy在统计列表不见了? ghj 变第一了 Errr... why ? 是不是又得罪人了? 呵呵!还是 ? why take it off ?
2004年04月01日
I posted this in my English blog, so don't believe whatever you read in product documentation until you have validate it 
Today is April Fool's Day... so don't get tricked by friends....
Two more days before Summmit Trip ! horrayy !!! Those that owe me beers in the community, make sure you buy me when we are there.. Grace ! I will buy for you, don't worry 
2004年03月23日
Well, glad to know many MVPs have the same concerns for my previous post and thanks for everyone who has given their 2cents. I just like to clarify couple of issues here:
a) as pointed, those are my concern in m.p.cn.* newsgroups. it is not related to other community forum or etc. b) if you are rewarded in newsgroups, and you 'think' you did a great job (ask yourself), you have my sincerely apology. I wasn't targeted at 'you', I was indicating those that 'missing' in action c) Grace, wendy, eddie and rest of ccws gang has done a superb job in bring these newsgroups to LIVE and active. d) the point and rating is a 'marketing' push to attract new members - no doubt. but I guess it's been abused, overwhelmingly abused if you ask me.
the cstar + mvp recognition are one of the factor too. well, everyone like to collect 'cert', especially in IT field, myself got couple of certs from MS traincert. Our problem here is user, and we need to 'find' a way somehow to 'brain wash' them, we need to teach them on how to participate in a healthy community. If you in msnews server. comparing with .hk, .tw, .cn.. I mean 'chinese'.. and the rest.. we have more 'junk', we participate newsgroups with 'different' objectives... THAT IS.. get free gift and award...... not the real community spirit of learning and sharing.. it's quite sad if you ask me.
do you guys know who is Sean ? Sean O'Driscoll ?? he is the Director of MVP Program, 微软公司全球MVP项目总监
well, in a lucky or surprise situation, I was chating with him via msn....err couple of weeks ago. I don't know who he was until he reply...
SeanXXXX says: hmmm...who are you? I'm Sean, MVP Program director.
I stunned for awhile, coz I did expect such reply. after that we chat.. around 15-20mins. I remember grace did send message regarding.. 'if you have a chance to ask Sean, what would your question be'... so I ask ..
Bernard says: last one - do you look at quantity or quality ? SeanXXXX says: QUALITY QUALITY QUALITY!!!
------------------ do you read THE message.... 'Quality' in CAPITAL + 3 exclamation marks !!!
Though, I'm nobody here. but I'm proud to be a 'good' MVP and glad to voice out my concern here. Next, we should focus 'solution' rather keep dragging it. It's hard; no doubt. but I guess we can deal with it slowly.
2004年03月22日
Many of you will 'hate' me after you read this post. Well, I think I have to right to voice out my concern and feeling about .cn newsgroups. If I’m not wrong, .cn groups started way back August 2002. It's 2004 March now. So it's been a while. As happy as I was back then to see Chinese newsgroups in ms server, and as sad I'm now to see how it become today.
I've been busy.. well ! who is not busy in this world, right ? but I still manage to have little to time for newsgroups these recent months... overall grade: FAIL. I still remember back then, we have many 'good' ppl ! or those err so called 'mvp'. Not sure if they still awarded by now... you name it we got it. we have ppl answering post 24*7... where r those ppl now ? don't get personal with this blog. I'm just expressing my feeling about the china communities - especially in NNTP newsgroups. The rest like csdn and etc, I have no idea. coz I don't hang out there. and I'm sure if you are not what I said, you should be happy that I bring out this topic and not you.
Many mvp 'disappear' after they got rewarded well, mission accomplished ! so why stay ! well. maybe you move on with life and have been busy.. so you 'fall out' from the group. understandable ! but from my observation for 2 damn years. I think 'we' are not ! we just... or should I say - you guys.. just run away.... I'm sure MS have lot of statistic recording user posting.. still remember the old 'top 10' posting in ms/community site.... there was one time. I see user's posting just for the sake of getting higher position... the 'point' system also encouraging junk post...
I've been in both english and chinese groups for year. Look at ENGLISH group ! look at those mvp and user... and LOOK at .cn groups.. put it in a bad way - heaven and hell sorry, Grace! this is not your part.. you did well. It's the user that we need to educate.
For now.. you will see 'new batch' of hardworking user.. working so damn hard to answer thousand of post each day.. some is even 24*7 if you ask me. well. for what u ask me ? well.. err first community star ! then mvp..... then missing.. then new ppl come in.. then cycle repeat again..... and again.
if you go to netscan @ microsoft research site.. look at the .cn traffic ! increase tremendous everyday ! and look at the content.. 80% crap ! well, as forum admin I felt helpless as well. coz no point keep on deleting... it just too many. and for those new batch of ppl, they will just answer the post even it's already answered !
For example: a) i have see active poster answering the same question over and over again. b) some user just simply say 'reinstall the product or OS' c) some even give wrong answer ! believe me if you like me .. reading news everyday, you will get sick soon. say now - iis 500 err. an user reply - your machine problem... format it' damn ! and what the hell is that ! if you don't know the answer.. just shut up ! and read and learn d) active poster always repeat the answer. if it's answer.. just shut up ! and wait of OP to reply the thread. i have seen 1 simple question with 10 same anwsers !!! why they do this ? err. for point and mvp or whatever.. e) junk / flame post ! everyone get excited and keep on posting crap.... f) multipost / crosspost ! .cn groups has the most crosspost message that I ever seen in ms news server. and the best part is everyone like to be part of it !!!!! and most of question were so lame or non related at all. and I have seen so many personal attacks. it is so shame if you ask me how i feel about it.
well, this post is not that organize in a way.. coz I'm just letting it all out. initialy i have subscribe to all .cn groups.. but because of all these crap.. I think I have err 6 or 7 now. And some active posters are so full of themselves, I felt that it just not right. You participate in newsgroups because you want to learn new things and share your knowledge. of coz at the same time if you can pickup nice award.. why not ! but be humble ! be nice.. be like a professional ! or should I said be an adult !
arrrghhhhh.. what else ? when you are not calm.. you tend to forget what you wanted to say .. so anyway, I think .cn newsgroups has it position now.. and many users are aware of it. we should deal with the 'quality' now ! before we are known ! we look for 'quantity'.. after that we should look at how well we have done it.. I would like to suggest drop the point and rating system.... what's the point ! there's no point of having points if every user are posting crap just to get the point ! and then ... do a internal clean up and kill those ghost 'mvp'...
You can hate me as much as you may like. I'm just doing my part here, that's how we shape our future for a better tomorrow.
2004年03月11日
原本Rating只有Important的MS04-009, 今天提升到Critical, 请赶快打上补丁。 更多资料及微软中国TechNet安全通告。建议大家定阅微软安全公告(好像有点问题,没有显示如何定阅?)或TechNet中文速递邮件。
2004年03月10日
。。 很久都没在这blog,很多计划要在这月底实行,又要安排好一些工作(当我在美国时)。另外又在帮Syngress Publishing 写一本Securing IIS 6.0书。累得要命!还有我今年还不知'鹿死谁手' 希望可以和大家一样在有Grace做MVP Lead. 另外,更新了很多关于IIS的资料在英文Blogs, 希望大家可以建议一下。。
刚刚看完大家在Grace的帖字讨论一起去Seattle回帖,正是羡慕死人。 我这可能有另外一个MVP一起去,连我只有两个,我看再多几年国内的MVPs, 可以把整架飞机都做满,那就更好玩了。。
最后,今天是补丁天 (Patch Day),每个月的第二个星期二(美国). 幸好没有Critical Updates, 到 Jerry's security blgos 看看
2004年02月21日
2004年02月18日
Well, I went for the interview this morning, here's the whole story, I'm not sure about procedures in Mainland but I guess should be similar.
a) Apply online first - check your local embassy url: Over here we got 2 forms - DS156 and 157. 157 is supplement (if you fit their age category), submit 156 online and printout at confirmation page, you will see your application form been 'bar coded', then print out 157, fill it out with black pen.
b) Get a 2 x 2 inch photo 1 piece, white background with errr grey or black shirt possible
c) Prepare the following items to show that you have strong local committment, hence you are not going to 跳飞机. 1) Marriage certificate (if you married) 2) Sales and purchase agreement (if you have property) 3) Bank loan document (if you have owe some bank money) 4) Old and new passport (if you got many) 5) Employement letter (if you working ) 6) MS invitation letter (you don't have ? are you sure you a mvp ?) 7) Summit registration email (print that out after MVP sent you the confirmation detail)
Now, the best part.. woke up 7:30am, get there around 9am after terrible traffic jam, after few round of security check, get yourself a number and wait...... at 10:45am (I was standing all the time as there is NO chair available for you to sit), it's my turn '4286' what a number, so I walked to the correct counter, the guy was a white guy, and question goes like: a) so you going to US, huh ? > of coz, I say 'yes' b) what is MVP, how do you get that ? > err. it stand for Microsoft Most Valuable Professional, I was awarded base on my expertise in Microsoft product and contribution to their communities. c) so you going to settle, everything pay by microsoft except air ticket, so who will pay for the ticket ? > the middle part “pay by microsoft” is what I filled in the form, so I say, yes and I will pay myself for the air fare d) what product you working on? > IIS - the microsoft errr web server e) Microsoft web server security is not good, right? > well, it was in the past, it depend on how you configure it, but with the latest version 6, you got secure by design, deployment and default. f) he smile... and ask ... “what about database”, does it encrypt database, oracle do that.. > I replied, well, I'm sure you can encrypt it too, you will see more features in Yukon - the next version MSSQL. g) so you going to be in seattle for 4 days, do you like 'biking' ? (err. something like that, bike...'ing) > yes, coz MS only pay 4 days hotel and I like computer and xbox only.. not the 'bike' thing.. h) do you like coffee ? > err.. sometime..... and he replied.. 'seattle has some nice coffee, go try it' and I answered 'thanks man, will do that'. i) Mm... I think that's it... you can collect your passport tomorrow..... > at first I was stumped, and ask myself 'that fast ?' ..... then he pass me the collecting ticket.. and say 'have a nice trip' I replied 'sure... thanks man...' and go out.. after picking up my car keys and handphone.. I'm done.!
wow ! hehehe... does he really know Microsoft product that well ? hahah.. maybe just a little I guess. but I was surprised that the interview is only about 5mins... I see other talk so long and still have to come back the next day... I guess I'm just lucky.. .or he like microsoft stuff..... and he doesn't even check my other documents as well...
anyway.. I still have to plan for the trip.. my freaking CEO ask me not to go....... screw and double W him I'll see how the ticket arrangement goes..... hopefully I get to go this time.
good luck if you going to apply for visa..
2004年01月30日
|