Tuesday 31 January 2012

Kick off your Windows 7 and Internet Explorer Deployment – with Microsoft and Quest at Old Trafford

Kick off your Windows 7 deployment with a little coaching from the experts at Quest Software and Microsoft. They’ll show you how to red card IE 6 and accelerate migration. And where better for a master class than Old Trafford, home to Manchester United.

With expert guidance on managing applications, virtualisaing IE 6, and migrating off Notes, Groupwise, and legacy Exchange, you’ll tackle all your IT challenges with ease. Plus, you’ll get to experience all the benefits Windows 7 provides, including its easy-to-use desktop, intelligent search, faster performance, and much more.

Space is limited for this exclusive event on the 21st February 2012, so review the agenda and sign up today!

Agenda:

09:30 – 10:00      Registration
10:00 – 10:45      IE6 Migration: What Makes A Successful Deployment Plan (Microsoft)
10:45 – 11:30      Applications: Package, Assess, and Fix (Quest)
11:30 – 11:45      Coffee
11:45 – 12:30      Fixing What Can’t Be Fixed: Virtualising IE6 (Quest)
12:30 – 13:00      Moving off Notes, Groupwise, or Legacy Exchange (Microsoft and Quest)
13:00 – 14:00      Lunch and Networking
14:00                   Stadium Tour – Email Emily Jones to Reserve Your Place
Register now

If you have questions, or are interested in more information about this solution, contact Neil Sanderson.

Thursday 26 January 2012

The ChangeBASE team is getting bigger...

To kick start 2012, the ChangeBASE professional services team has been introducing our automated application compatibility tool to the wider team at Quest Software. They’ve been running technical enablement training in Europe and North America for pre-sales, professional services and support team across the organisation. There is now a large network of technical staff at Quest who are certified in the ChangeBASE technology and enabled in helping customers both new and old to accelerate their application migration and management projects.

The core ChangeBASE specialist team is still working across the globe to bring expertise to a range of leading organisations. Here's a bit about each team member and their work with ChangeBASE so far...

Sophie Tidman - Head of Professional Services
Sophie has 14 years’ commercial experience in IT with 10 years’ experience in application management, application compatibility and desktop migration solutions. Sophie has been with ChangeBASE since the early days (2007) and has developed the Professional Services organization since then to cover everything from pre-sales to training, consultancy and Project Management of ChangeBASE implementations. Since being part of the Quest family, Sophie has run the pre-sales initiative to win deals in excess of $400K as well as securing  orders within a week of her initial onsite visits!

Ben Nel - Senior Consultant
Ben Nel has over 10 years’ experience in application packaging, desktop migrations and application compatibility. Ben has been with ChangeBASE since June 2009 and has been instrumental in many of our strategic implementations. Ben has run training courses across the globe and since the acquisition of ChangeBASE by Quest Software has been heavily involved with joint pre-sales engagements, as well as helping to run the wider Quest enablement programme to train our Quest colleagues on ChangeBASE technology.

Ben Cook - Senior Consultant
For the past ten years Ben has focused on application packaging and deployment, specialising in MSI packaging. Starting out on Windows XP migration projects, he has worked on large-scale desktop deployments in both the public and private sectors. Ben is an expert in SCCM and App-V and joined ChangeBASE in early 2011 where he holds the position of Senior Consultant and is the Subject Matter Expert for Virtualization. Since ChangeBASE has been a part of Quest Software, Ben has run several very successful pre-sales engagements across Europe, partner seminars for PDS as well as various POCs, and training and implementation consultancy for some ChangeBASE’s existing large customers. Ben Cook will be running the EMEA ChangeBASE Enablement training in Maidenhead, UK.

Mike Russell - Solutions Engineer
Mike has over 15 years’ commercial IT experience and in the past 7 years has specialized in compliance & entitlement management, application compatibility and desktop migration. Mike joined ChangeBASE in early 2011 focusing in pre-sales, but also running training and consulting as well as partner seminars.  Mike is comfortable at all levels within an enterprise, helping organizations to solve business problems, and is extremely adept at conveying the value proposition and benefits from both a business and technical standpoint. Recently, Mike has helped ChangeBASE win significant deals in Canada and the United States.

Charlotte Mulcare - Project Manager
Charlotte has 20 years IT experience working as a Project Manager for large corporations and smaller companies. The assignments have included working for and with major FTSE companies in the banking and financial services sector, including Lloyds Banking Group, First Data International, HSBC, American Express and MasterCard. The projects encompassed a variety of deliveries ranging from enhancements to multi-million pound projects, these being client facing, development, operational and infrastructure. Charlotte joined ChangeBASE in early 2011 as Project Manager for pre and post sales and has also been assisting with Development projects such as the integration of ChangeBASE into the Quest Software portfolio.

Todd Mera – New Recruit
The ChangeBASE specialist technical team has also brought on a new recruit in the United States. Todd Mera has been in Information Technology for over 15 years and has worked in Asia, Europe and the USA on behalf of major corporate clients such as Nissan, Adidas, Merrill Lynch, KMPG, Siemens, Honeywell, Boeing, Microsoft, Delta Airlines and Expedia.  Todd worked for enterprise IT Services company, Aelita Software, where he was a practice leader for Windows and Messaging.  Aelita was acquired by Quest Software in March of 2004. Todd received his B.S. in Biochemistry from Western Washington University, and enjoys winemaking, whitewater kayaking and travel.  His favorite quote:  “It takes a big man to cry…it takes a bigger man to laugh at that man :)”

The whole team will continue to blog about their activities and discoveries in the application compatibility space, so look out for some very interesting stuff as we move into 2012!

Thursday 19 January 2012

Check out Greg Lambert, Chief Technical Architect of the ChangeBASE solution, on his Application Compatibility blog.
 
Here's an excerpt from his latest look into Microsoft's plan for Windows 8:
 
"Microsoft has recently announced that Windows 8 Server and then Windows 8 (desktop?) will support a new file system called ReFS or Resilient File System. This will be the first low-level update of the desktop and server platform file systems for just over 10 years with the introduction of NTFS (New Technology File System) in 2000.

Some of the key benefits of this new FileSystem will include;
  • Maintain a high degree of compatibility with a subset of NTFS features that are widely adopted while deprecating others that provide limited value at the cost of system complexity and footprint.
  • Verify and auto-correct data. 
  • Optimize for extreme scale. 
  • Never take the file system offline.
  • Provide a full end-to-end resiliency architecture when used in conjunction with the Storage Spaces feature, 
Some great ideas and once again,  Microsoft has a strong focus on backward compatibility, and so compatibility deserves a space at the top of the new system's feature list."
 
To read the full article, and more from Greg Lambert, visit his blog now.

Tuesday 17 January 2012

Application Compatibility News

Carl Bennett, Technical Specialist for ChangeBASE at Quest Software, has carefully selected all the best bits of what's new in the application compatibility space. And just for fun, check out Carl's Ye Olde Computer History Corner - time to reminisce...

Platform News
Windows 8’s recovery mode in detail
Windows 8 storage spaces allow volumes to span disks
Windows 8 introduces picture passwords
How to prevent pending updates from installing when shutting down Windows
Do you need to reboot but have lots of Outlook and Word windows open? If you want all your windows restoring after the reboot, go to the Run box and type Shutdown /g
Ice and Globes Windows desktop themes

Compatibility News
Brian Madden reviews both ChangeBASE and its competitor
Don’t miss the Microsoft, Quest ChangeBASE and Flexera Software webcast on Tools to Accelerate Windows 7 Deployment on January 18th

Virtualisation News
VMWare Workstation 8’s new features in detail

Browser News
For the first time, Microsoft are about to push major IE updates to get XP on IE8 and everyone else on IE9.  Chris Jackson shows how you can block it from happening.
IE6 usage is now less than 1% in The US. Microsoft celebrate with a T-shirt, mug and cake.
The Evolution of Search, google’s story.

Packaging News
Advanced Installer now supports ThinApp.
Improved (hacked) version of resource hacker for modifying PE files.  You can use it to cheat in Minesweeper.
InstallAware and their Delphi tale of adventure.

Mobile News
Windows Phone now has 50,000 apps, Android has 400,000, Apple has over 500,000
3.7 million people got an Android for Christmas and 3.8 million got an iPhone/iPad
The Courier Tablet and the story of how Microsoft killed it.

Ye Olde Computer History Corner
The Apple Collection 1986/87 (I like the windsurfing sail but the shorts are horrible)
Triumph of the Nerds, documentary about Microsoft, Apple and all the other contributors to the story of modern computing

Tuesday 10 January 2012

Microsoft Patch Tuesday Report - January 10th 2012

Application Compatibility Update
By: Greg Lambert

Executive Summary

With this January Microsoft Patch Tuesday update, we see a set of 7 updates; 1 with the rating of Critical and 6 with the rating of Important. This is a moderately sized update from Microsoft and the potential impact for the updates is likely to be low.

As part of the Patch Tuesday Security Update analysis performed by the ChangeBASE team, we have seen a small number of potential compatibility issues, including some which caused by the fifth update in this release, MS12-005, where vulnerabilities in Microsoft Windows could allow Remote Code Execution.

Given the nature of the changes and updates included in each of these patches, most systems will require a reboot to successfully implement any and all of the patches and updates released in this January Patch Tuesday release cycle.

Sample Results


Here is a sample of the results for two applications tested for compatibility with these updates:

MS12-005: Vulnerabilities in Microsoft Windows Could Allow Remote Code Execution.

MS12-006: Vulnerabilities in SSL/TLS Could Allow Information Disclosure.

And here is a sample ChangeBASE Summary report for a sample database where the ChangeBASE Patch Impact team has run the latest Microsoft Updates against a small application portfolio:

Testing Summary

MS12-001
Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615)
MS12-002
Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381)
MS12-003
Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524)
MS12-004
Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391)
MS12-005
Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146)
MS12-006
Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584)
MS12-007
Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664)

Security Update Detailed Summary

MS12-001
Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615)
Description
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow an attacker to bypass the SafeSEH security feature in a software application. An attacker could then use other vulnerabilities to leverage the structured exception handler to run arbitrary code. Only software applications that were compiled using Microsoft Visual C++ .NET 2003 can be used to exploit this vulnerability.
Payload
Ntdll.dll, Wntdll.dll, Updspapi.dll
Impact
Important - Security Feature Bypass

MS12-002
Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381)
Description
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file with an embedded packaged object that is located in the same network directory as a specially crafted executable file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Payload
No specific files affected
Impact
Important - Remote Code Execution

MS12-003
Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524)
Description
The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. The attacker could then take complete control of the affected system and install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability can only be exploited on systems configured with a Chinese, Japanese, or Korean system locale.
Payload
Winsrv.dll, Updspapi.dll
Impact
Important - Elevation of Privilege

MS12-004
Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391)
Description
This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited the vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Payload
Mciseq.dll, Winmm.dll, Updspapi.dll
Impact
Critical - Remote Code Execution

MS12-005
Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146)
Description
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file containing a malicious embedded ClickOnce application. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Payload
Packager.exe, Updspapi.dll
Impact
Important - Remote Code Execution

MS12-006
Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584)
Description
This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. This vulnerability affects the protocol itself and is not specific to the Windows operating system. The vulnerability could allow information disclosure if an attacker intercepts encrypted web traffic served from an affected system. TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected.
Payload
Schannel.dll, Winhttp.dll, Updspapi.dll
Impact
Important - Information Disclosure





MS12-007
Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664)
Description
This security update resolves one privately reported vulnerability in the Microsoft Anti-Cross Site Scripting (AntiXSS) Library. The vulnerability could allow information disclosure if a an attacker passes a malicious script to a website using the sanitization function of the AntiXSS Library. The consequences of the disclosure of that information depend on the nature of the information itself. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker's user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system. Only sites that use the sanitization module of the AntiXSS Library are affected by this vulnerability.
Payload
No specific files affected
Impact
Important - Information Disclosure

*All results are based on an ChangeBASE Application Compatibility Lab’s test portfolio of over 1,000 applications.
For more info, please visit www.quest.com/changebase

Wednesday 4 January 2012

Quest Software's CTO, Carl Eberling, on Virtualization & VKernal

Here's a second snippet from Bruce Hoard's interview with Carl Eberling, discussing how recently acquired VKernal expands Quest Software's virtualization management offering. To read Carl's views on the exciting new capabilities that ChangeBASE adds to the Quest Software portfolio, please check out yesterday's post.


Virtualization Reveiw: Turning to Quest's acquisition of VKernel, what attracted you to them, and how will that acquisition impact your customers?

Carl Eberling: With VKernel, we had recently rolled out some new capabilities for capacity management. When we looked at VKernel, we felt like it could accelerate what we'd already planned even further. We were pretty excited about it, because we had been looking at them for some time, and that' the quick summary.

Again, how customer-driven was that?

Eberling: That was less customer-driven than it was strategy-driven. About a year and a half ago, we laid out a strategy where we were looking at not only the capabilities that exist in a comprehensive performance management solution, but also ways we could officially deliver both point solutions as well as enterprise platforms.

How do Quest and VKernel benefit by selling vFoglight and other products -- say relating to capacity management -- to vSphere customers?

Eberling: We knew there was going to be multiple hypervisors. We're starting to see it now pretty aggressively across customers, especially since the last pricing change on the VMware side. We're finding more Hyper-V in the dev and test environments -- maybe not production yet -- but certainly more of a mix in the datacenter, and what Quest with vFoglight and VKernel offers is the ability to manage and capacity-plan across hypervisor environments, and we're also adding additional support for hypervisors like (Citrix) Xen and KVM as well.

Do you think Quest is competitive enough against VMware to draw new virtualization users away from them and to you?

Eberling: Yes, absolutely. I think it's all about our focus. When it comes to systems management, we have a rich history of success over 20 years. I love to ask people if after they provision their environments, do they just turn them over to their end users, or are they layering in applications and building something that is a utility for end users? When you look back at our history, you can see that we didn't start making a hypervisor, wake up a couple years later, and say yes we also want to be a systems manager. From the beginning we said it's how technology is applied and how it's put to use for the end user that's really important.

You guys claim to be the leader in virtualization management. How do you define virtualization management?

Eberling: We use third-party validation mostly. IDC has put out stuff in the past couple of years that said we are number three in virtualization management -- we're the first ISV, but that they list us right behind VMware and Microsoft in this space, so that's how we claim our title as leader in systems management. In addition, we put a lot credence in the feedback we get from our customers.

Going forward, what specific goals must Quest meet to thrive as a company?

Eberling: We've got several initiatives that span our solutions. Last year we embarked on an effort to really educate both our companies, and even our employees in some cases, about the general solution area that Quest participates in. We've got this rich portfolio of a hundred and some products, and nobody could ever know them all. People generally relate to a smaller set of solution areas, so we settled on six solution areas, which is great. Now, as we go into 2012 we're looking at things like identity management and access management along with end-user workspace. These are things that certainly can be entire platforms, but they also can be point solutions if the user is wondering, how do I get that one application or point solution in place to solve the problem I have today, and then how do I also leverage that to build for a better tomorrow? 


For more information how Quest's ChangeBASE solution set makes getting your applications ready for deployment on a virtual infrastructure simpler, faster and less costly, please visit the website.

Tuesday 3 January 2012

A Q&A with Quest Software's CTO Carl Eberling

A few weeks ago, Bruce Hoard, Virtualization Review Editor-in-Chief, interviewed Quest Software CTO Carl Eberling about the impact that recently acquired ChangeBASE and VKernel will have on customers. Here's what Carl had to say about the exciting new capabilities that ChangeBASE brings to the Quest Software portfolio.


Virtualization Review: What are the solutions offered by ChangeBASE that led to the Quest acquisition of this company?

Carl Eberling: About a year ago, we laid out a strategy relative to what we had going on with vWorkspace in server-based desktop computing, where we've got VDI, Terminal Services, and the ability to manage VoIP as well. That in and of itself didn't cover enough of the evolving user and client management challenges that are hitting IT, so we started looking at how we could apply some of our monitoring and performance management technologies. We were also interested in including some of our security and identity access management pieces, and one of the things that we saw that was a bit of an opportunity for us related to desktop migration. That is, when people typically have to go from one operating system to another, it tends to be a major event within IT. There are a whole lot of great solutions out there that can help customers make that transition in a cost-effective way. We felt like Quest had a rich history in the migration business -- look at what we do with our e-mail migration, what we do with AD and SharePoint -- so we set about looking at this issue of desktop migration, and I came across a great company called ChangeBASE.

Were Quest customers pressing you to acquire or develop the capabilities offered by ChangeBASE?

Eberling: They weren't pressuring us, but we were finding that frequently during an upgrade event a customer would sit back and say, "Is there a different way for me to do desktop computing for the enterprise?" And so it seemed like it a good opportunity for us to get involved with the conversation sooner rather than later. We also thought we could apply some of our other assessment technologies that we've got with VDI, so not only can we figure out how best to get you upgraded to Windows 7, but now we can also look at all your applications and how you're using them, and give you some recommendations on what could be on Terminal Services, what could be app virtualization, and what could actually be going nicely into VDI. It was more looking at the workflow that occurs within IT that led us to feel we would be better suited to get involved.

Do you see your customers gravitating to a desktop virtualization approach that leans more toward Terminal Services and remote desktop services, as opposed to a VDI model based on datacenter connectivity?

Ebering: Yes, you know, people talk about VDI, but they implement Terminal Services. You get much greater density. For the purposes of what they're trying to solve in terms of making sure end users can get to their applications, get their job done and get the best control, they tend to gravitate more to that with the desktop experience. I would say VDI is growing in the sense that maybe it's become 10 percent or 15 percent of the mix.

How will the acquisition of ChangeBASE impact your customers?

Eberling: A couple of ways. One, we believe it brings to the discussion a technology and set of capabilities that I find an alarming number of customers don't even know exist. Even during our due diligence prior to buying ChangeBASE we found that over half of the customers we talked to had no awareness that this kind of tooling was available to them. There were only two players in this game, and both of them spent a fair amount of time talking more to the application packaging experts, and talking to big outsourcing shops, rather than getting the message out to the enterprise.

Who were those two players?

Eberling: ChangeBASE and App-DNA.

So you consider App-DNA to be direct competition now?

Eberling: In a way. What App-DNA does is very different. They're big on the reporting aspect, but they don't necessarily help much with the actual fixing of the problems once you find them. There is certainly the opportunity to catch up over time, but right now, sure, they are a competitor.


For more information on how Quest's ChangeBASE solution can make your migration project faster, simpler and less costly, please visit the website.