Archive for September, 2013

New Microsoft Surface preview September 2013

September 14th, 2013

Microsoft will launching its next-generation Surface devices and peripherals on September 23 in New York City, according to an invitations Microsoft is sending out to press today.

Expect to see the Haswell-based Surface 2 Pro and the Tegra-based Surface 2 –Microsoft’s rumored 7- to 8-inch Surface device I doub we will see as part of the September 23 unveiling.

Expect sales release to coincide with Windows 8.1 mid October.

Vodaphone hack raises security questions

September 14th, 2013

Personal details of about 2 million Vodafone Germany customers were exposed in a hack making international headlines. Hackers tapped into an information pool of: addresses, bank account numbers and dates of birth.
“…This attack was highly complex and conducted with inside knowledge of our most secure internal systems,” the company said in a statement.

Many criminals might try to use this information offline as well as online, so be extra cautious of any suspicious activity, like incoming phone calls or emails e.g claiming to be your bank.

In these days of spcial media interaction it begs the quesiton whether servers that contain critical data, such as personally identifiable information that was stolen in the Vodafone hack, should be accessible on the public Internet.

Can organizations really expect to keep up with the ever-changing set of vulnerabilities, patches, and zero-day exploits that leave this kind of information at risk? Vodpahone is hardly IT llliterate, and if they can be hit then the rest of us need to take notice and think again about our data protection strategies.

September 12th, 2013

ERP Project Recovery

Unfortunately, not all ERP projects go as planned. Indeed the majority still fail as a recent survey comfirms that not much has improved since the same survey last year. The relaity is that the situation may be worse, some users don’t even realise they have a bad system, or have learned to live with it rather than tell mangement it is not quite what they promised.

Synergy is regularly invited to help turn around problem implementations.

Sometimes project scope creeps, the ERP project team decides to customize too much, or the enterprise software vendor or system integrator simply isn’t able to get the job done.

Further, ERP failure can take many forms: from complete operational disruption to a lack of alignment or user buy-in that negatively affects the organization’s return on its ERP investment.

A frequent problem in this expatriate market is labour turnover of both customer and consultant staff, excerbated by short term expediency to offshore work which in the long run proves more expensive when it either has to be redone or no-one is around to support it. There is usually little evidence of documentation, or best practise checking in such cases.

Synergy Software Systems is one of the longest established enterprise solution practises in the region, and bases all its staff in Dubai. We have a low staff turnover relative to the industry and in most cases more senior and better certified consultants. Experienced senior consultants cost more, but they do better quality work in less time, add value and don’t cut corners.

Typical errors we find;

Incorrect set up of server, raid, windows and sql
Code not compiled and not to best practise.
Systems unpatched
Inappropriate configuraiton settings
Inappropriate data structures
Opening balances unreconciled
Duplicate data
Inventory not closed
Month ends not closed
Year ends not closed
Users unaware of basic navigation features, inquiries and reports
Unnecessary customisation
Unused modules
Many unresolved issues
Poor response time
Little use of workflows, alerts, BI
No management of database, table sizes, log files, data retention, etc.

If you need to reboot your projects and to get a firm foundation then give us a call – better still ask our customers about the value such an exercise brings.

Dynamics CRM 2013-early preview

September 11th, 2013

Reimagined User Experience
With an entirely new user experience, Microsoft Dynamics CRM allows you to view everything you
need in one spot – fast and fluid, and relevant to the work at hand. No pop-ups. No flipping from
one application to the next. What you need, where you need it. Get in, get going and get done.
So you can focus on what is most important – your customers.

Patch Tuesday- 11 Sep 2013

September 11th, 2013

Microsoft had projected 14 security bulletins for today, but only 13 were released.

For SharePoint, an attacker could abuse the ViewState mechanism on two specific web pages and gain control over the server. By default, the pages require authentication, which limits the attack vector. If you have reconfigured authentication, this bulletin should be high on your list. Note that the bulletin contains work-around steps that you can configure immediately even if you cannot apply the patch right away.

These 3 are the ones that demanded my immediate attention:

MS13-067 addresses ten vulnerabilities in SharePoint server, and affects SharePoint 2003, 2007, 2010, and 2013, along with Office Web Apps 2010. The patch addresses multiple elevations of privilege vulnerabilities that could allow an attacker to execute code in the context of another SharePoint user. In certain situations where the default authentication mechanism has been changed, an attacker may be able to take control of the server. Safeguarding sensitive data is critical, so get this patch rolled out as soon as possible.
***

MS13-068 / KB2756473 – Vulnerability in Microsoft Outlook Could Allow Remote Code Execution

MS13-068 fixes a critical privately reported vulnerability in Outlook, which an attacker could use to execute arbitrary code in the context of the current user. It affects both Outlook 2007 and 2010. Attackers can exploit this without specific user interaction by crafting malicious S/MIME messages and sending those to target users. When the malicious message is opened, the exploit is triggered, and the vulnerable system is compromised – enabling the attacker to run code in the context of the user. The attack vector makes it urgent to apply this patch as soon as possible
***

MS13-069 / KB2870699 – Cumulative Security Update for Internet Explorer

MS13-069 is the latest cumulative security update for the Internet Explorer Web browser. The update applies to all supported versions of Internet Explorer, but none of the underlying flaws affects all versions of the browser. This patch should be deployed as quickly as possible, though, because any of these vulnerabilities can be used in drive-by exploits allowing the attacker to execute code in the context of the current user.

Security in the digital world – how about in Dubai? ask Synergy Software Systems

September 10th, 2013

There has been a lot of concern this year about how safe is the data you put on line- e.g with facebook, or in your corporate cloud, or just your personal emails, message and phone calls monitored by big brother government snooping?

Synergy Software Systems offers several solutions both against internal threats and external ones e.g.penetration testing, secure collaboration, end point security, network monitoring. We also offer digital signature solutions. See the infographic below and if you are interested to understand more about the issues then there is a list of informative links at the end.

To discuss your requirements or to learn more about our solutions, then please contact us or meet us at Gitex.

online signature

Dynamics Ax Schools Admission Module for the U.A.E. from Synergy Software Systems

September 9th, 2013

This was developed and implemented in several schools in the U.A.E.to manage the complete back office functions of a major U.K. public school.

Some Key features include:

Enquiry,
Registration,
Admissions,
Waiting list management
Sibling management
Enrolment of students,
Assignment of students to class and year groups, house etc.
Re-enrollment,
Promotions,
Billing for academic(tuition) and non-academic fees .
Collection of fees
Debentures
Withdrawal process of Students based on the KHDA and ADEC rules, Refund process
Generation of transfer Certificate
KHDA reporting and compliance and ADEC requirements and compliance.
Integration into Access control, ID card generation, Schools portal in SharePoint, integration into a Library Management System
Implementing HR for Teaching, Admin and non Admin staff.

And of course the full suite of Dynamics Ax modules are available including : Financials, Purchasing, inventory, HR, CRM, Service module, Project Accounting, Document Management, Case Management, Alerts, Management Reporter, Retail POS, Questionnaire, Customer Portal

We also offer complimentary solutions for the Education sector for example: specialist School management software, rfid cards for self service library kiosks, cashless payment, and access control, Mimosa timetable software etc.

Call Bikram for more information: 00971 4 3365589

Management Reporter Web Viewer-Ask Synergy Software Systems Dubai

September 9th, 2013

Management Reporter Web Viewer has been the default viewer since Management Reporter RU5.
You can still either open the desktop viewer and browse to the report download the report from within the web viewer.

Microsoft critical new patches- switch off Outlook preview for now

September 8th, 2013

Microsoft said it will ship 14 security updates this week to patch vulnerabilities in Internet Explorer (IE), Windows, Office, and SharePoint. Microsoft flgas four as critical, the company’s most severe rating.

The IE update, affects every supported version, from the soon-to-be-retired IE6 to the newest IE10, Microsoft has patched IE every month so far this year.

“Bulletin 2,” will quash one or more bugs in Outlook 2007 and Outlook 2010, critical Office vulnerabilities have usually been through the preview pane the only way to get into Outlook without user interaction, which is a Microsoft criteria for a critical rating. The Outlook update we consider as important as the one for IE, because next to the browser, your email reader is just as popular and important.

We recommend that users disable the preview pane in Outlook 2007 and 2010 until more is known of Bulletin 2’s vulnerabilities.

Microsoft ends its advanced certificates

September 8th, 2013

MCM, MSA, and renamed versions of those certifications are no longer being offered after Oct 1, 2013. The announcement was made in email, late on Friday night is the US, which was Saturday morning for those of us living in European/Middle East/African timezones.

This decision, along with the recent ending of TechNet subscriptions sends a poor message about how Microsoft views their Enterprise server products and the need for people with deep technical knowledge of their products. Their focus is not on deployment on-premise. Microsoft want to encourage everyone in the cloud.

There has been lot of midtrust caused by these announcements – two of the more reasoned blog articles that provides more insight:
http://www.stevieg.org/2013/08/are-microsoft-losing-friends-and-alienating-it-pros/
http://www.devinonearth.com/2013/08/defending-a-bad-decision/