SamSam: 標的型ランサムウェアの攻撃は終わらず
Assertion failed: 200130 (16.0.0.1324)[sem5] Invalid page found in index
Hello all,
I have a problem about database.
I've followed the steps below to repair sem5.db.but the problem is repeated.
- Stop the Symantec Endpoint Protection Manager and Symantec Embedded Database services.
- Rename or delete the current sem5.log
- Click Start > Run and type CMD then click OK
- In the command prompt type CD C:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\ASA\win32\
- For 64-bit: dbsrv16 -f "C:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\db\sem5.db"
- For 64-bit: dbsrv16 -f "C:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\db\sem5.db"
- Press Enter
- Click Start > Run.
- Type services.msc
- Click OK.
- Start the following services:
- Symantec Endpoint Protection Manager
- Symantec Embedded Database
Do you have any other suggestions for solving the problem?
10/26 08:55:19. *** ERROR *** Assertion failed: 200130 (16.0.0.1324)[sem5]
Invalid page found in index
10/26 08:55:22. Fatal error: Internal error.
10/26 10:19:45. *** ERROR *** Assertion failed: 200130 (16.0.0.1324)[sem5]
Invalid page found in index
10/26 10:19:46. Fatal error: Internal error.
10/26 10:46:36. *** ERROR *** Assertion failed: 200130 (16.0.0.1324)[sem5]
Invalid page found in index
10/26 10:46:36. Fatal error: Internal error.
10/26 12:21:47. *** ERROR *** Assertion failed: 200130 (16.0.0.1324)[sem5]
Invalid page found in index
10/26 12:21:47. Fatal error: Internal error.
10/30 00:02:07. *** ERROR *** Assertion failed: 200130 (16.0.0.1324)[sem5]
Invalid page found in index
10/30 00:02:08. Fatal error: Internal error.
10/30 08:50:04. *** ERROR *** Assertion failed: 200130 (16.0.0.1324)[sem5]
Invalid page found in index
10/30 08:50:04. Fatal error: Internal error.
10/30 09:52:04. *** ERROR *** Assertion failed: 200130 (16.0.0.1324)[sem5]
Invalid page found in index
10/30 09:52:04. Fatal error: Internal error.
10/30 10:14:34. *** ERROR *** Assertion failed: 200130 (16.0.0.1324)[sem5]
Invalid page found in index
10/30 10:14:35. Fatal error: Internal error.
10/30 19:34:07. *** ERROR *** Assertion failed: 200130 (16.0.0.1324)[sem5]
Invalid page found in index
10/30 19:34:07. Fatal error: Internal error.
Staying on the software update curve
New software versions and revisions are released periodically, bringing support for new applications, features and functionality, and Operating Systems. This can become an issue to keep up with, depending on your upgrade strategy.
So here is the question...do you upgrade to the latest version of your application, say SEP or GSS, or do you wait it out and possibly see what it brings? Your governance will dicatate which option take, but I'll discuss upgrading and staying up-to-date.
To start, Symantec offers Beta programmes for some of their products, and it's really worth looking into. With the proliferation of options to run a lab locally on your laptop/desktop, you're able to evaluate software in Beta before it is released as a production-ready version. You can see what the changes are, see what an upgrade of your current software will run like, and generally get a feel with the software. best of all, evaluating the Beta this way won't touch your production environment.
From my perspective, I worked on a team looking after a large client in the FMCG field, who were intent in staying on the "bleeding edge". Software had to be as up-to-date as possible, and it made IT life interesting. There wasn't much time between evaluating large version changes, and rolling out application updates to multiple servers and sites. More often than not, this went without a hitch.
Why would you want to keep up-to-date? To stay ahead of competitors, and to keep your applications at the most current state. It has obvious benefits in that support is always current (assuming you have an active maintenance agreement in place with Symantec), and version updates will address any issues between service packs on that application. Ie. minor software changes would include all previous patches and any new ones.
It would also fix an issue you might be experiencing on your site for instance with an application or agent that isn't working like it should.
What should you do before installing the latest version? Well, trial the software at least. Without doing so you're jumping into a big hole if things go wrong and you don't have any proof you had run an evaluation. Read the forums and news to see what is being said about the application, and especially read the release notes. Symantec is very good with changes to the software and what they address. Early adoption might very well fix some issues, but always do your homework before embarking on a new upgrade.
Once you're happy, run through your governance process and install the application.
ATP server unavialable
Hi
In our environment we have implemented SEPM 14.2 and ATP.
ATP-SEP integration is also done but when we check in the computer status report there is a column ATP server which is showing unavailable.
Can anyone please suggest how to fix it.
Thanks
Upgrade Oracle 11g to 12c in two-tier installation with DLP 15
Currently, we are running Symantec DLP 15 with Oracle 11g in two-tier installation and now want to upgrade Oracle to 12c. As per the Upgrade checklist for Oracle 11g which upgrade path, we should follow
https://support.symantec.com/en_US/article.TECH247...
1. Upgrade checklist for Oracle 11g SE1 or Oracle 11g SE on servers with 2 (or fewer) CPU sockets.
2. Upgrade checklist for Oracle 11g SE on servers with more than 2 CPU sockets on a two-tier installation
SEP Client Repair in VDI systems
Hi
We are not able to repairing the SEP client(14.0) in Citrix Environment.
Please share the solution or article.
Thanks
Server Error in '/ICT/administration' Application
Hello all,
I'm trying to access the console. I get this error after entering my credential.
Can you help me? What do I need to check?
Regards.
The client and server cannot communicate, because they do not possess a common algorithm
Description: An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.
Exception Details: System.ComponentModel.Win32Exception: The client and server cannot communicate, because they do not possess a common algorithm
Source Error:
|
Source File: c:\inetpub\wwwroot\ICT\administration\Default.aspx Line: 102
Performance Question
I’ve got a trial version of the PGP Commanline 10.3 software, and in testing it takes around 5 hours to perform encryption for a 30 GB file.
I wanted to ask if this is the performance we should expect, or if the trial version has some limitations that make it slower?
I noticed the encryption was using TripleDES, rather than AES 256. I tried using the --remove-preferred-cipher switch to try and force it to use AES, but it returned an error saying ‘no match for argument “TripleDES”. I’m not sure if this is relevant for asymmetric encryption, or if it’s just for symmetric.
Content Analysis Scanner Sophos Engine 20 Fields
Dear Symantec,
Within the Content Analysis Scanner there is the Sophos anti malware engine.
Our research has found that only the first 20 field within a submitted form are being scanned and in case the form includes more than 20 only the first 20 are scanned.
As a web form can hold many more than 20 items, it would be a very good idea to improve the engine in order to scan all fields but not only the first 20.
The behavior was discovered during Troubleshooting of a F5 -> CAS installation in which the CAS processes traffic from the F5 appliance.
Referenced Ticket: #260101
Kind regards,
Stephan Fleming-Unger
Find Mac OS Computer
Guys,
The sepm only showme computers with Windows , and I like to know if I have any mac os computer,.
Its possible to find for another way?
Impliment a Log Off button for GSS 3.3 Web Console
It would be nice to be able to log off the GSS web console for security reasons. Without the button, I have to delete the cookie files within each browser that I have signed into the GSS web console. I noticed that eventually I was logged out of the web console.
SEE - Web Server Certificate Expiration Notification.
When managing the web server certificate for the SEE management server, having some form of notification, or way to track the expiration of certificates would assist in quick and concise management, and maintenance of certificates, especially in environments without access to internal certificate authorities.
It's been noticed recently in a few scenarios where certificates have expired, unbeknown to the teams managing SEE infrastructure. Because the SEE documentation only specifies high level requirements for server and client side certificates, administration teams and implementation teams are using either self-signed certificates, or unmanaged certificate generation, and as such, the expiration date of certificates are passing, and in turn causing issues with clients losing connective to the management server.
Can the DLP endpoint agent monitor Rightfax clients by exe?
Wondering if it's possible to monitor an endpoint using application monitoring on a Rightfax client in order to see the transmission of the fax request (or attachment upload) to the server that will conduct the actual fax transfer? Our client install path refers to 2 exe's and I wasn't sure which would need to be monitored so i tried both. Neither caught the test faxes (I have all channels in the Application Monitor App for those application checked in case is was print/fax or app mon that caught it). Agent Group I'm in for testing purposes has all channels turned on as well.
If the server is doing the actual action of the fax it makes sense that I can't see the web initiated faxes (except over https) as they're performed solely on the server side, but since most of my users leverage the endpoint client I was hoping DLP could see the initiation. Should that theorhetically work or is the action still server side?
Ian
SEP 14.2 "Product Error Requires Attention"
Recently, we upgraded out Windows 10 PCs to SEP 14.2. Some users recieve the following message in the bottom right corner upon login:
My own PC does the same. Upon opening the client, I see on the Status page that it detects an issue with Memory Mitigation. This is disabled and is, in fact, disabled by default when upgrading. When I select "Fix" and restart the error message doesn't pop up in the bottom right and I don't see it on the Status page anymore.
Any idea why this is happening? Does any one know of a way to disable this or to at least do the "Fix" task remotely? A couple other users have complained about this and being about to do this remotely would help.
Windows 10 Enterprise
SEP 14.2.770.0000
Thanks in advance.
Do we need a license from Oracle for Java use with the SEPM Java Remote Console?
I can’t get a straight answer with Symantec’s horrible tier 1 support, therefore hoping a Symantec employee can provide an answer here instead.
Starting January 2019, Oracle is changing Java 8 (and later) licensing requiring non-personal/home-use to purchase a Java licensing to run or use Java 8 or later. Since the SEPM's Java Remote Console requires and uses Java 8 do we (my organization) need to purchase a license? When I contact Symantec support, they referred me to INFO5218 (https://support.symantec.com/content/unifiedweb/en...). I replied nicely that yes, I understand the Symantec Endpoint Protection (“SEP”) client doesn’t use Java, but I was inquiring about the Java Remote Console. Their response was that Java Remote Console didn’t use Java and therefore doesn’t apply. I replied with a screenshot showing that the Java Remote Console requires Java (it’s launched via C:\ProgramData\Oracle\Java\javapath\javaws.exe -localfile -J-Djnlp.application.href=https://sepm.compnay_name.com:8443/servlet/JnlpServlet?osSF=true "C:\Users\<user_name>\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\123a456-78b9b12c) and https://support.symantec.com/en_US/article.TECH236.... Support’s last response was “So we [Symantec] do not require to purchase additional license” but refuses to answer if we (my organization) needs an Oracle Java license to continue to use SEPM’s Java Remote Console. How I read Oracle’s licensing we need to purchase the Oracle Java license for every user of the Java Remote Console. Can a Symantec employee clear this up?
Thanks in advance.
Is there a tool to migrate a configuration on Forcepoint proxy into Symantec's Proxy SG?
Hi;
Is there a tool to migrate a configuration on Forcepoint proxy into Symantec's Proxy SG?
Kindly
Wasfi
Bypass proxy
HI,
I wanted to bypass all proxy operation for one domain. Can you help me how I can bypass that proxy operation on proxy which includes CAS functionality as well.
Thanks in advance.
How to proof that feature predictive analysis on CAS working well for scanning file ?
Hi all,
Please share if you ever testiing feature predictive analysis for the file on CAS ?
if possible for share the file which use to test predictive analysis.
thank you.
How to distribute package to a lot of agent ( 10000 agents )
windows 10 update를 위한 패키지 배포를 하려고합니다. 만약 agent가 1000개 혹은 10000개 이상일 때 동시에 패키지를 배포하면 문제가 발생할 것으로 예상합니다. 이럴 때 agent들을 어떤 방식으로 관리합니까?
정책 아래에 여러개의 태스크를 둬서 각 태스크마다 대상을 할당해줘 분할하려고 했는데
태스크의 대상을 설정할 수 없는 것 같습니다.
많은 에이전트가 있을 때 어떻게 배포하는지 알려주세요.
How to distribute package to a lot of agent ( 10000 agents )
I want to deploy a package for windows 10 update.
If I have 1000 or 10000 agents, distributing the package at the same time will cause problems.
How do you manage agents in this situation?
I tried to put several tasks under the policy, and assign a target for each task.
It seems that can not set the target of the task.
If I have many agents, please let me know about policies that can make deployment way efficient.