HOW TO: Check if you have compromised your VMware ESXi 8.0 Hosts if you have added them to Microsoft Active Directory

August 26th, 2024

This video was created in response to Experts Exchange members asking the question “have I compromised my ESXi host be adding to AD?”

In this video presentation which is part of the Hancock’s VMware Half Hour I will show you HOW TO: Check if you have compromised your VMware ESXi 8.0 Hosts if you have added them to Microsoft Active Directory.

In this video demonstration the ESXi servers are ESXi 8.0.3, which have the “fix” detailed below

Secure Default Settings for ESXi Active Directory integration

To demonstrate the differences between a compromised and non-compromised server, I have deliberately changed the default settings on esxi002.cyrus-consultants.co.uk, so the server can be compromised.
HOW NOT TO: Compromise your VMware vSphere Hypervisor ESXi 5.1, 5.5, 6.0, 6.5, 6.7, 7.0, 8.0 by adding to Microsoft Active Directory

On the 29th July 2024, Microsoft  discovered a vulnerability in ESXi hypervisors being exploited by several ransomware operators to obtain full administrative permissions on domain-joined ESXi hypervisors.

this publication is here – https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/

VMware vExperts – Christian Mohn wrote about it here – VMware vSphere CVE-2024-37085 – A Nothing Burger

and Bob Plankers goes into more detail here – Thoughts on CVE-2024-37085 & VMSA-2024-0013

Please have a read of these publications.

Broadcom have issued updates and fixes to vSphere 7.0 and 8.0, and VCF 4.x and 5.x only. There is no security update for 6.7.

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505

HOW TO: Update VMware vSphere vCenter Server 8.0.3 to 8.0.3a using the Reduced Downtime Upgrade (RDU) function

August 26th, 2024

VMware vCenter Server 8.0.3a  Build 24091160 was released on the 17th July 2024.

In this video presentation which is part of the Hancock’s VMware Half Hour I will show you HOW TO: Update VMware vSphere vCenter Server 8.0.3 to 8.0.3a using the Reduced Downtime Upgrade (RDU) function.

This procedure can be used to update any VMware vCenter Server 8.0 update in the future. VMware have released a new feature in later versions of VMware vSphere vCenter 8.0 called the Reduced Downtime Upgrade (RDU), which reduces downtime from over 60, minutes to 10 minutes. We would traditionally use the VAMI method here

HOW TO: Update VMware vSphere vCenter Server 8.0.2 (8.0u2d) 8.0.2 to 8.0.3 using the (VAMI) Appliance Management Interface

but RDU only takes 15 minutes, but it does require the original vCenter Server 8.0.3 iso media!

At the time of this recording, VMware vCenter Server 8.0 Update 3a was the latest version available from VMware.

VMware vCenter Server 8.0 Update 3a Release Notes

HOW TO: Update VMware vSphere vCenter Server 8.0.2 (8.0u2d) 8.0.2 to 8.0.3 using the Reduced Downtime Upgrade (RDU) function

Videos mentioned in this video, this method can be used to backup the vCenter Server database.

HOW TO: Use the vCenter Server 7.0.3 vCenter Server Appliance Management Interface (VAMI) to backup the database and configuration of your vCenter Server

HOW TO: Restore a vCenter Server backup to restore a production vCenter Server 8.0 appliance

HOW TO: Update VMware ESXi 8.0 GA to ESXi 8.0U2 direct from VMware remotely using the ESXCLI tool installed on Windows 10

HOW TO: Remediate a vSphere Cluster VMware ESXi 8.0U2 to ESXi 8.0U3 including adding the HPE OEM Addon for ESXi 8.0.3 – A12 using VMware vSphere Lifecycle Manager (vLCM) from a single image

HOW TO: Migrate physical, virtual and cloud based workloads with real-time replication to VMware vSphere (ESXi) or Microsoft Hyper-V using OpenText Migrate

August 23rd, 2024

In this video presentation which is part of the [url=”https://github.com/CodheadClub/AwesomeResources/blob/master/Virtualisation.md#andrewhancock”]Hancock’s VMware Half Hour[/url] I will show you HOW TO: Migrate physical, virtual and cloud based workloads with real-time replication to VMware vSphere (ESXi) or Microsoft Hyper-V using OpenText Migrate.

Ten years ago I wrote the following article about the product Double-Take MOVE by Vision Solutions. It’s been acquired in the last ten years, by Carbonite, and now is in the hand of OpenText, and is name going forward will be [url=”https://www.opentext.com/en-gb/products/migrate”]OpenText Migrate.[/url]

[url=”https://www.experts-exchange.com/articles/17312/HOW-TO-Migrate-physical-virtual-and-cloud-based-workloads-with-real-time-replication-to-VMware-vSphere-ESXi-using-Double-Take-MOVE.html”]HOW TO: Migrate physical, virtual and cloud based workloads with real-time replication to VMware vSphere (ESXi) using Double-Take MOVE[/url]

In these uncertain times, when you may be required to migrate workloads between platforms, such as VMware vSphere, Microsoft Hyper-V etc I can highly recommend [url=”https://www.opentext.com/en-gb/products/migrate”]OpenText Migrate.[/url] as one of the best products on the market for your Migration Project.

In this video I will demonstrate the migration of an Linux Ubuntu 22.04 LTS Server from Microsoft Hyper-V to VMware vSphere, and concurrently migrate a Microsoft Windows 2022 Server from VMware vSphere to Microsoft Hyper-V, with very little downtime.

Time for a facelift and new branding – Hancock’s VMware Half Hour

August 22nd, 2024
Hancock's VMware Half Hour

Hancock’s VMware Half Hour

It was time for a change! So from today, I’ll be using this new artwork, across the social channels, and for more VMware content to come. It encompasses three things in my life, which I hold true, which is VMware, Experts Exchange and #beekeeping. My Thanks to Devolutions and their graphic designer Stacy Bensa for all the hard work, in creating the design for me. Again Thank You.

HOW NOT TO: Compromise your VMware vSphere Hypervisor ESXi 5.1, 5.5, 6.0, 6.5, 6.7, 7.0, 8.0 by adding to Microsoft Active Directory

August 22nd, 2024

In this video presentation which is part of the Hancock’s VMware Half Hour I will show you HOW NOT TO: Compromise your VMware vSphere Hypervisor ESXi 5.1, 5.5, 6.0, 6.5, 6.7, 7.0, 8.0 by adding to Microsoft Active Directory. I will demonstrate the exposure, and discuss how to avoid it.

In this video demonstration the ESXi servers are ESXi ARM 7.0, but the same functionality has been built into ESXi since 5.1.

On the 29th July 2024, Microsoft  discovered a vulnerability in ESXi hypervisors being exploited by several ransomware operators to obtain full administrative permissions on domain-joined ESXi hypervisors.

this publication is here – https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/

VMware vExperts – Christian Mohn wrote about it here – VMware vSphere CVE-2024-37085 – A Nothing Burger

and Bob Plankers goes into more detail here – Thoughts on CVE-2024-37085 & VMSA-2024-0013

Please have a read of these publications.

Broadcom have issued updates and fixes to vSphere 7.0 and 8.0, and VCF 4.x and 5.x only. There is no security update for 6.7.

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505

He’s like a VMware Yoda! :)

August 21st, 2024

A recent testimonial on Experts Exchange

VMware Yoda

VMware Yoda

A VMware Yoda !

A VMware Yoda !

HOW TO: Fix Synchronous Exception at 0x00000000XXXXXXX on VMware vSphere Hypervisor 7.0 (ESXi 7.0 ARM) on a Raspberry Pi 4

August 20th, 2024

In this video presentation which is part of the Hancock’s VMware Half Hour I will show you HOW TO: Fix Synchronous Exception at 0x00000000XXXXXXX on VMware vSphere Hypervisor 7.0 (ESXi 7.0 ARM) on a Raspberry Pi 4.

It has been well documented that the Raspberry Pi 4 UEFI Firmware Image can cause this fault which renders the UEFI boot image corrupt. See here https://github.com/pftf/RPi4/issues/97

The UEFI firmware imaged used in the lab in this video is v1.37, it is debated as too whether this has been fixed in later releases v1.37, some suggest rolling back to v1.33 !

For the sake of continuity I’ve included previous EE Videos and Articles I’ve created here

Part 51. HOW TO: Update the VMware vSphere Hypervisor 7.0 ARM Edition (ESXi 7.0 ARM edition) from v1.12 to v1.15 on a Raspberry Pi 4

Part 20: HOW TO: Install and Configure VMware vSphere Hypervisor 7.0 (ESXi 7.0 ARM) on a Raspberry Pi 4

Part 23: HOW TO: BOOT VMware vSphere Hypervisor 7.0 (ESXi 7.0 ARM) from an iSCSI LUN for the Raspberry Pi 4

Honey jar labelling Sunday!

August 19th, 2024

So what did you do with your Sunday! I started to label this years (2024) Summer Honey.

The majority of this year’s summer honey which was extracted weeks ago was delivered to pre-paid Wedding Orders as Honey favours.

 

The next batch which was extracted was not ripe – the water content tested at above 20% – which according to the Honey Legislation Act 2015 is technically not honey so it cannot be sold , and there is a risk it can ferment in the jars – so it was all fed back to the bees for them to deal with it correctly and this will be removed and extracted at the end of August!

This is just one of many issues we’ve had this year, see my monthly notes!

January/February 2024 – Feeding fondant – winter far too warm bees too active and ate through their winter stores too quick.

March 2024 – All hives and nucleus colonies went through the winter well – still feeding fondant

April 2024 – Bees expanding very quickly forage available – good hawthorn, blossom on fruit trees although this year no canola in the area! had to start Demeree and putting honey boxes into hives as the bees were expanding very quickly!

May 2024 – Disaster weather turns cold – large colonies need feeding eating 2.5kg a fondant a week! Many reports across the UK of starvation, queens stop laying, failing , colonies that showed signs of swarming have stopped!Majority of reared queens have failed!

June/July 2024 – Weather continued to be poor and a wash out! A few late swarms around

August 2024 – Weather getting warmer – a few honey flows – there could be some summer honey! Extracted honey not ripe! Fed back to bees!

September 2024 – Remove all surplus honey, and feeding and treating for winter, and bringing hives home for winter.

 

Action required: Enable multifactor authentication for your Microsoft Azure tenant by 15 October 2024

August 18th, 2024

This arrived in my inbox, on Saturday, so better check with some Powershell. It produces a nice Excel spreadsheet of users enable for MFA or Single FA 

 

 

 

 

 

 

 

 

 

 

Install-Module MsIdentityTools -Scope CurrentUser

Connect-MgGraph -Scopes Directory.Read.All, AuditLog.Read.All, UserAuthenticationMethod.Read.All

Export-MsIdAzureMfaReport .\report.xlsx

I’m still beekeeping – Andysworld! What else would I do?

August 17th, 2024

It’s time to reboot Andysworld! Blog. I think some of you may have missed tales from Andysworld! Oh if your fedup of this email in you inbox, let me know and I’ll remove you from the list!

I just don’t get much time anymore to keep the Andysworld! blog updated, with all the other social channels, Experts Exchange, VMware vExpert programs and BEEKEEPING which takes up a lot of my time now, over 12 months ago I have up my allotment to spend more time with the bees!

So lets have some bee photographs from this afternoons check, this is a colony of bees, split last year, taken over winter in a small nucleus (6 frames) the nucleus was called N1, so this is H11 (hive 11) which has 11 frames of honey bees, the honey bees are pure Buckfast bees, if you look carefully you will see they are mostly yellow, compared to the native black bees, which has hybridize today with most local strains which are darker. (Hint if you look at the queen in the first photo marked green (for 2024!), you will notice she is yellow/orange/ginger in colour rather than a dark black/brown, this indicates the yellowish colour that the Buckfast strain has, kept because they are easy to work, and non-aggressive H11 is a lovely colony to work compare to those in H3 ! Double gloves for H3 !