Feb 7, 2011

Outlook backup


How to make a backup copy of a .pst 

file

If you do not use Outlook with Microsoft Exchange Server, Outlook stores all its data in a .pst file. You can use the backup copy to restore your Outlook data if the original .pst file is damaged or lost. This section explains how to create a copy of your whole .pst file, with all the default items in the file. 

Follow these steps to back up the whole .pst file:

  1. Close any messaging programs such as Outlook, Microsoft Exchange, or Microsoft Windows Messaging.
  2. Click Start, and then click Run. Copy and paste (or type) the following command in the Open box, and then press ENTER:
    control panel
    Control Panel opens.

    Note If you see the Pick a category screen, click User Accounts, and then go to step 3.
  3. Double-click the Mail icon.
  4. Click Show Profiles.
  5. Click the appropriate profile, and then click Properties.
  6. Click Data Files.
  7. Under Name, click the Personal Folders Service that you want to back up. By default, this service is called Personal Folders. However, it may be named something else.

    Note If you have more than one Personal Folders Service in your profile, you must back up each set of .pst files separately.

    If there are no entries called Personal Folders and you have not yet stored any information such as messages, contacts, or appointments in Outlook, you probably have not yet enabled the Personal Folders Service. Go to the "References" section for information about how to create a .pst file.

    If you have no Personal Folders Services in your profile and you can store information such as messages, contacts, or appointments in Outlook, your information is probably being stored in a mailbox on an Exchange Server. Try using the instructions in the "How to back up .pst file data that is located on a Microsoft Exchange Server" section.
  8. Click Settings, and then note the path and file name that appears.

    Note Because the .pst file contains all data that is stored in the MAPI folders that Outlook uses, the file can be very large. To reduce the size of the .pst file, clickCompact Now in the Settings window.
  9. Close all the Properties windows.
  10. Use Windows Explorer or My Computer to copy the file that you noted in step 8. You can copy the file to another location on the hard disk drive or to any kind of removable storage media, such as a floppy disk, a CD-ROM, a portable hard disk drive, a magnetic tape cassette, or any other storage device.

How to back up .pst file data that is 

located on a Microsoft Exchange 

Server



To know how to back up your data if you use Outlook with a Microsoft Exchange Server, you have to know where the data is stored. The default delivery and storage location for Outlook data is the Exchange Server mailbox. The Exchange Server administrator usually handles backups of the mailboxes on the server. However, some Exchange Server administrators store Outlook data in a .pst file on your hard disk drive. 


Follow these steps to see where Outlook is currently storing your data:

In Outlook 2007:

  1. On the Tools menu, click Options, click the Mail Setup tab, and then click E-mail Accounts.
  2. In the Account Settings window, click the Data Files tab. 

    If the Name field contains the word "Mailbox" followed by an e-mail name, Outlook stores data in folders on the Exchange Server. Contact the Exchange Server administrator for more information about how backups are handled.

    If the field contains the words "Personal Folder" or the name of a set of personal folders or .pst files, Outlook stores new messages, contacts, appointments, and other data in a .pst file on your hard disk. To back up the data, go to the "How to make a backup copy of a .pst file" section.

In an earlier version of Outlook:

  1. On the Tools menu, click E-mail Accounts.

    Note This option might be unavailable on some networks. The network administrator might have removed this option to protect the account information. If you do not see theEmail Accounts option, contact the network administrator for help.
  2. Click View or Change Existing Email Accounts, and then click Next.
  3. Look at the Deliver new e-mail to the following location option. If the option contains the word "Mailbox" followed by an e-mail name, Outlook stores data in folders on the Exchange Server. Contact the Exchange Server administrator for more information about how backups are handled.

    If the field contains the words "Personal Folder" or the name of a set of personal folders or .pst files, Outlook stores new messages, contacts, appointments, and other data in a .pst file on your hard disk. To back up the data, go to the "How to make a backup copy of a .pst file" section.

How to export .pst file data



If you want to back up only some of your Outlook data, you can create a new backup .pst file of only the data that you want to save. This is also known as exporting .pst file data. For example, you might want to use this section if you have important information in only some folders and you have other, less important items in much larger folders. You can export only the important folders or contacts and omit folders like Sent Mail. 

Follow these steps to export a specific folder:

  1. Open Outlook.
  2. On the File menu, click Import And Export. If the menu item is not available, hover your pointer over the chevrons at the bottom of the menu, and then click Import and Export.
  3. Click Export To File, and then click Next.
  4. Click Personal Folder File (.pst) , and then click Next.
  5. Click the folder that you want to export the .pst file to, and then click Next.
  6. Click Browse, and then select the location where you want the new .pst file to be saved.
  7. In the File Name box, , type the name that you want to use for the new .pst file, and then click OK.
  8. Click Finish.
Note Folder design properties include permissions, filters, description, forms, and views. If you export items from one .pst file to another, no folder design properties are maintained.

How to import .pst file data into Outlook

You can use the backup copy of your .pst file to restore your Outlook data if the original .pst file is damaged or lost. Everything that is saved in the .pst file is returned to Outlook. 

Follow these steps to restore, or import, your data into Outlook:

  1. If the .pst file that you want to import is stored on a removable device, such as a floppy disk, a portable hard disk drive, a CD-ROM, a magnetic tape cassette, or any other storage medium, insert or connect the storage device, and then copy the .pst file to the hard disk drive of the computer.

    When you copy the .pst file, make sure that the Read-Only attribute is not selected. If this attribute is selected, you might receive the following error message:
    The specified device, file, or path could not be accessed. It may have been deleted, it may be in use, you may be experiencing network problems, or you may not have sufficient permission to access it. Close any application using this file and try again.
    If you receive this error message, clear the Read-Only attribute, and then copy the file again.
  2. Open Outlook.
  3. On the File menu, click Import And Export. If the command is not available, rest the pointer over the chevrons at the bottom of the menu, and then click Import and Export.
  4. Click Import from another program or file, and then click Next.
  5. Click Personal Folder File (.pst), and then click Next.
  6. Type the path and the name of the .pst file that you want to import, and then click Next.
  7. Select the folder that you want to import. To import everything in the .pst file, select the top of the hierarchy.
  8. Click Finish.

How to transfer Outlook data from 

one computer to another computer



You cannot share or synchronize .pst files between one computer and another computer. However, you can still transfer Outlook data from one computer to another computer. 

Use the instructions in the "How to make a backup copy of a .pst file" section to copy the .pst file to a CD or DVD-ROM or other portable media, or copy the file to another computer over a LAN/WAN link. 

Note Connecting to .pst files over LAN/WAN links is not supported and problems connecting to .pst files over such links can occur. See the following article for more information:

297019  Personal folder files are unsupported over a LAN or over a WAN link 

You might also want to create a new, secondary .pst file that is intended for transferring data only. Save the data that you want to transfer in this new .pst file and omit any data that you do not want to transfer. If you need to make a secondary .pst file to store data for transfer between two different computers, or for backup purposes, use the following steps:

  1. On the File menu, point to New, and then click Outlook Data File.
  2. Type a unique name for the new .pst file, for example, type Transfer.pst, and then click OK.
  3. Type a display name for the Personal Folders file, and then click OK.
  4. Close Outlook.
Follow these steps to copy an existing .pst file:
  1. Use the instructions in the "How to make a backup copy of a .pst file" section to make a backup copy of the .pst file that you want to transfer. Make sure that you copy the backup .pst file to a CD-ROM or other kind of removable media.
  2. Copy the backup .pst file from the removable media to the second computer.
  3. Follow the steps in the "How to import .pst file data into Outlook" section to import the .pst file data into Outlook on the second computer.


How to back up Personal Address 

Books



Follow these steps to locate your Personal Address Book file:
  1. If you are running Windows Vista: Click Start.

    If you are running Windows XP: Click Start, and then click Search.

    If you are running Microsoft Windows 95 or Microsoft Windows 98: Click Start, point toFind, and then click Files or Folders.

    If you are running Microsoft Windows 2000 or Microsoft Windows Millennium Edition (Me): Click Start, point to Search, and then click For Files or Folders.
  2. Type *.pab, and then press ENTER or click Find Now.

    Note the location of the .pab file. Use My Computer or Windows Explorer to copy the .pab file to the same folder or storage medium that contains the backup of the .pst file.
You can use this backup to restore your Personal Address Book to your computer or transfer it to another computer. Follow these steps to restore the Personal Address Book:
  1. Close any messaging programs such as Outlook, Microsoft Exchange, or Windows Messaging.
  2. Click Start, and then click Run. Copy and paste (or type) the following command in the Open box, and then press ENTER:
    control panel
    Control Panel opens.

    Note If you see the Pick a category screen, click User Accounts.
  3. Double-click the Mail icon.
  4. Click Show Profiles.
  5. Click the appropriate profile, and then click Properties.
  6. Click Email Accounts.
  7. Click Add a New Directory or Address Book, and then click Next
  8. Click Additional Address Books, and then click Next.
  9. Click Personal Address Book, and then click Next.
  10. Type the path and the name of the Personal Address Book file that you want to restore, click Apply, and then click OK.
  11. Click Close, and click then OK.
Note The Outlook Address Book is a service that the profile uses to make it easier to use a Contacts folder in a Mailbox, Personal Folder File, or Public Folder as an e-mail address book. The Outlook Address Book itself contains no data that has to be saved.


Your Personal Address Book might contain e-mail addresses and contact information that is not included in an Outlook Address Book or contact list. The Outlook Address Book can be kept either in an Exchange Server mailbox or in a .pst file. However, the Personal Address Book creates a separate file that is stored on your hard disk drive. To make sure that this address book is backed up, you must include any files that have the .pab extension in your backup process.

Jan 23, 2011

Web App Attacks: Sneaking in the Front Door


Anatomy of an ARP Poisoning Attack

by Corey Nachreiner, WatchGuard Network Security Analyst
Hackers lie. Skillful hackers lie well. And well-rounded hackers can lie both to people and to machines.
Lying to people, known as "social engineering," involves tactics (detailed at length by convicted hacker Kevin Mitnick) such as posing as a company's employee so the company's real employees will blab secrets freely. Lying to machines involves lots of different techniques, and a commonly used one -- ARP Cache Poisoning -- is the focus of this article. ARP poisoning enables local hackers to cause general networking mayhem. Because it's mostly "incurable," every administrator should be aware of how this attack works.

ARP Refresher

In Foundations: What Are NIC, MAC, and ARP?, we explained that Address Resolution Protocol (ARP) is how network devices associate MAC addresses with IP Addresses so that devices on the local network can find each other. ARP is basically a form of networking roll call.
ARP, a very simple protocol, consists of merely four basic message types:
  1. An ARP Request. Computer A asks the network, "Who has this IP address?"
  2. An ARP Reply. Computer B tells Computer A, "I have that IP. My MAC address is [whatever it is]."
  3. A Reverse ARP Request (RARP). Same concept as ARP Request, but Computer A asks, "Who has this MAC address?"
  4. A RARP Reply. Computer B tells Computer A, "I have that MAC. My IP address is [whatever it is]"
All network devices have an ARP table, a short-term memory of all the IP addresses and MAC addresses the device has already matched together. The ARP table ensures that the device doesn't have to repeat ARP Requests for devices it has already communicated with.
Here's an example of a normal ARP communication. Jessica, the receptionist, tells Word to print the latest company contact list. This is her first print job today. Her computer (IP address 192.168.0.16) wants to send the print job to the office's HP LaserJet printer (IP address 192.168.0.45). So Jessica's computer broadcasts an ARP Request to the entire local network asking, "Who has the IP address, 192.168.0.45?" as seen in Diagram 1.
All the devices on the network ignore this ARP Request, except for the HP LaserJet printer. The printer recognizes its own IP in the request and sends an ARP Reply: "Hey, my IP address is 192.168.0.45. Here is my MAC address: 00:90:7F:12:DE:7F," as in Diagram 2.
Now Jessica's computer knows the printer's MAC address. It sends the print job to the correct device, and it also associates the printer's MAC address of 00:90:7F:12:DE:7F with the printer's IP address of 192.168.0.45 in its ARP table.

Hey ARP, Did You Know Gullible Is Not in the Dictionary?

The founders of networking probably simplified the communication process for ARP so that it would function efficiently. Unfortunately, this simplicity also leads to major insecurity. Know why my short description of ARP doesn't mention any sort of authentication method? Because in ARP, there is none.
ARP is very trusting, as in, gullible. When a networked device sends an ARP request, it simply trusts that when the ARP reply comes in, it really does come from the correct device. ARP provides no way to verify that the responding device is really who it says it is. In fact, many operating systems implement ARP so trustingly that devices that have not made an ARP request still accept ARP replies from other devices.
OK, so think like a malicious hacker. You just learned that the ARP protocol has no way of verifying ARP replies. You've learned many devices accept ARP replies before even requesting them. Hmmm. Well, why don't I craft a perfectly valid, yet malicious, ARP reply containing any arbitrary IP and MAC address I choose? Since my victim's computer will blindly accept the ARP entry into its ARP table, I can force my victim's gullible computer into thinking any IP is related to any MAC address I want. Better yet, I can broadcast my faked ARP reply to my victim's entire network and fool all his computers. Muahahahahaa!
Back to reality. Now you probably understand why this common technique is called ARP Cache Poisoning (or just ARP Poisoning): the attacker lies to a device on your network, corrupting or "poisoning" its understanding of where other devices are. This frighteningly simple procedure enables the hacker to cause a variety of networking woes, described next.

All Your ARP Are Belong To Us!

The ability to associate any IP address with any MAC address provides hackers with many attack vectors, including Denial of Service, Man in the Middle, and MAC Flooding.

Denial of Service

A hacker can easily associate an operationally significant IP address to a false MAC address. For instance, a hacker can send an ARP reply associating your network router's IP address with a MAC address that doesn't exist. Your computers believe they know where your default gateway is, but in reality they're sending any packet whose destination is not on the local segment, into the Great Bit Bucket in the Sky. In one move, the hacker has cut off your network from the Internet.

Man in the Middle

A hacker can exploit ARP Cache Poisoning to intercept network traffic between two devices in your network. For instance, let's say the hacker wants to see all the traffic between your computer, 192.168.0.12, and your Internet router, 192.168.0.1. The hacker begins by sending a malicious ARP "reply" (for which there was no previous request) to your router, associating his computer's MAC address with 192.168.0.12 (see Diagram 3).
Now your router thinks the hacker's computer is your computer.
Next, the hacker sends a malicious ARP reply to your computer, associating his MAC Address with 192.168.0.1 (see Diagram 4).
Now your machine thinks the hacker's computer is your router.
Finally, the hacker turns on an operating system feature called IP forwarding. This feature enables the hacker's machine to forward any network traffic it receives from your computer to the router (shown in Diagram 5).
Now, whenever you try to go to the Internet, your computer sends the network traffic to the hacker's machine, which it then forwards to the real router. Since the hacker is still forwarding your traffic to the Internet router, you remain unaware that he is intercepting all your network traffic and perhaps also sniffing your clear text passwords or hijacking your secured Internet sessions.

MAC Flooding

MAC Flooding is an ARP Cache Poisoning technique aimed at network switches. (If you need a reminder about the difference between a hub and a switch, see this sidebar.) When certain switches are overloaded they often drop into a "hub" mode. In "hub" mode, the switch is too busy to enforce its port security features and just broadcasts all network traffic to every computer in your network. By flooding a switch's ARP table with a ton of spoofed ARP replies, a hacker can overload many vendor's switches and then packet sniff your network while the switch is in "hub" mode.

Scared? Good, Now Calm Down!

This is scary stuff. ARP Cache Poisoning is trivial to exploit yet it can result in very significant network compromise. However, before you jump to Defcon-7, notice the major mitigating factor: only local attackers can exploit ARP's insecurities. A hacker would need either physical access to your network, or control of a machine on your local network, in order to deliver an ARP Cache Poisoning attack. ARP's insecurities can't be exploited remotely.
That said, hackers have been known to gain local access to networks. Good network administrators should be aware of ARP Cache Poisoning techniques.
Since ARP Cache Poisoning results from a lack of security in a protocol that is required for TCP/IP networking to function, you can't fix it. But you can help prevent ARP attacks using the following techniques.

For Small Networks

If you manage a small network, you might try using static IP addresses and static ARP tables. Using CLI commands, such as "ipconfig /all" in Windows or "ifconfig" in 'NIX, you can learn the IP address and MAC address of every device in your network. Then using the "arp -s" command, you can add static ARP entries for all your known devices. "Static" means unchanging; this prevents hackers from adding spoofed ARP entries for devices in your network. You can even create a login script that would add these static entries to your PCs as they boot.
However, static ARP entries are hard to maintain; impossible in large networks. That's because every device you add to your network has to be manually added to your ARP script or entered into each machine's ARP table. But if you manage fewer than two dozen devices, this technique might work for you.

For Large Networks

If you manage a large network, research your network switch's "Port Security" features. One "Port Security" feature lets you force your switch to allow only one MAC address for each physical port on the switch. This feature prevents hackers from changing the MAC address of their machine or from trying to map more than one MAC address to their machine. It can often help prevent ARP-based Man-in-the-Middle attacks.

For All Networks

Your best defense is understanding ARP Poisoning and monitoring for it. I'd highly recommend deploying an ARP monitoring tool, such as ARPwatch, to alert you when unusual ARP communication occurs. This kind of vigilance is still the greatest weapon against all kinds of attack -- for, as Robert Louis Stevenson wrote, "The cruelest lies are often told in silence."

Resources: