IT人在工廠日記 – 煙花消逝二十年

昨天看到新聞,關於香港回歸20年的成就,使我感到可笑和可悲。另外,新聞報導李源潮說:香港回歸20年,一國兩制取得舉世公認成功。事實上,香港已接近一國一制了。老董說過:中國好,香港更好。其實,中國需要香港時,香港才會好,但是中國好時,便不需要香港,香港又怎會好呢 !

現時,我覺得香港的地位,只是大陸的一個普通城市,比不上北京、上海、廣州等地…,很令我這香港仔感觸。

忽然想起一個網台節目特輯,叫 “煙花消逝十五年”,現時亦可應景地叫 “煙花消逝二十年”。希望各位回味,所以抄到本頁分享,資料來源為 http://www.ourradio.hk/ 網站,但現時已下架了 ,希望他們不介意分享。

工務員 I

工務員 II

金融 I

金融 II

工作轉型 I

工作轉型 II

传媒 I

传媒 II

地產 I

地產 II

國內生育 I

教育 I

教育 II

運輸 I

運輸 II

視聽制作 I

視聽制作 II

六四

IT人在工廠日記 – 念六四

道念六四,尤其是六四或英魂! 想忘記,不能忘,這是慘痛的中國近代歴史!願早日平反六四!

硬漢子李旺陽慘死

 

坦克人王维林(下落不明)

 

Wanna Cry 勒索病毒

近日熱門的網络安全話題是WannaCry勒索病毒,所以我也搜索一些相關文章和解決方法,分享出來。

香港微軟官方最新消息 (13/5 11:59pm)

Microsoft掌握到這個勒索軟件 “WannaCrypt” 和網路攻擊已經影響數個區域的不同行業。我們的安全團隊已迅速採取行動來保護我們的客戶,並已經增修最新偵測與防護功能以避免新的勒索軟件威脅(例如: 知名病毒軟件:Win32.WannaCrypt.) 。

今年3月份,我們已經發布了一個安全更新 (security updates),堵塞了這些攻擊所利用的漏洞。啟用Windows Update的用戶可以防止對此漏洞的攻擊。對於尚未應用安全更新的組織,我們建議您立即部署Microsoft安全公告MS17-010。對於已經安裝我們免費提供的防毒軟件,對該勒索軟件應可以有效偵測並清除,我們強烈建議用戶執行Windows Update 並持續更新,以降低被惡意攻擊的風險。

對於使用Windows Defender的客戶,我們今天稍早時間發布了一個檢測到Ransom:Win32 / WannaCrypt的威脅的更新。作為額外的“深度防禦”措施,請保持安裝最新反惡意軟件軟件。目前Windows Defender已經可以針對發作中的惡意程式,有效的偵測並清除;使用者可以從下列位置下載 Windows Defender: https://support.microsoft.com/zh-hk/help/14210/security-essentials-download

此外,我們正為所有客戶提供額外安全更新,以保護適用於早期Windows 軟件包括Windows Windows XP,Windows 8和Windows Server 2003的Windows平台。請使用以下連結下載安全更新: Windows Server 2003 SP2 x64, Windows Server 2003 SP2 x86,Windows XP SP2 x64, Windows XP SP3 x86, Windows XP Embedded SP3 x86,Windows 8 x86, Windows 8 x64

據我們瞭解,這個勒索軟件攻擊並沒有針對Windows 10,只要有下載3月份安全更新已能夠有效地防禦這次攻擊。我們藉此再次呼籲客户盡快升級Windows 10 ,並積極考慮落實部署Microsoft 企業級雲端服務,以時刻確保保安措施是最新版本,為客户提供最強大的防禦。企業用戶可以隨時聯繫Microsoft的客戶經理查詢。

客戶如有任何查詢,可致電Microsoft 香港客戶服務中心電話:+852 2388 9600

解決方案 from –> Youtube video as below

解決方案 from –> https://unwire.hk/2017/05/13/wannacry-wcry/tech-secure/

未中伏前解決方案:

Step 0 :

甚麼都不用說,先斷網絡進行備份!

星期一上班,我可以開電腦嗎 ?

先切斷網絡,移除 lan 線 /關掉 wifi ,用你的方法停止電腦接上網絡。開機後立即備份重要檔案,緊記別備份在本機或網絡磁碟上。

 

(免責聲明 : 修改 Windows 有風險請先備份,如因以下方法導致任何損失,本網恕不負責)

 

Step 1: 鎖埠

透過路由器 / 防火牆封鎖 139 及 445 埠

 

A)路由器 : 

B) Windows 防火牆

如果你無法更改公司伺服器設定可以設定 Windows 防火牆,安全的話可以考慮先移除 LAN 線 / 關閉 Wifi

 

Step 1:

按 WIN + R 鍵 ,鍵入 firewall.cpl 按 enter

Step 1:
如果你 Firewall 未開啟,請按「請用建議的設定」去開啟

Step 2:

如已開啟了(綠色),請按左邊進階設定

 

Step 3:

左側按 輸入規則 > 右側按 新增規則

 

Step 4 :

選擇 通訊協定及連接埠,選 連接埠

 

Step 5 :

如下圖選擇 TCP , 特定本機連接埠選 445 ,139 ,下一步

Step 6:

選擇封鎖連線,下一步

 

Step 7:

套用所有規則,下一步

 

Step 8 :

隨意命名,完成

Step 9 

重覆 Step 3 至 4 , 今次我們選擇 UDP , 特定本機連接埠選 445 ,139 ,下一步。重覆 Step 6 至 8

 

XP 用家可參考這個方法

改成阻檔 TCP 及 UDP 445 , 139

Step 2 :

你應該快安裝修正檔 !

 

Windows 10 

去 Windows 更新便可

 

Windows 8.1 64:

http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/05/windows8.1-kb4019215-x64_d06fa047afc97c445c69181599e3a66568964b23.msu

Windows 8.1 32:
http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/05/windows8.1-kb4019215-x86_fe1cafb988ae5db6046d6e389345faf7bac587d7.msu

Windows 7 64:
http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/05/windows6.1-kb4019264-x64_c2d1cef74d6cb2278e3b2234c124b207d0d0540f.msu

Windows 7 32:
http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/05/windows6.1-kb4019264-x86_aaf785b1697982cfdbe4a39c1aabd727d510c6a7.msu

==

其他舊版 Windows 已推出安全性更新

 

Windows Server 2003 SP2 x64,

Windows Server 2003 SP2 x86,

Windows XP SP2 x64,

Windows XP SP3 x86,

Windows XP Embedded SP3 x86,

Windows 8 x86,

Windows 8 x64

 

 

<官方修正檔網址>

 

 

======

如以上方法失效,你可以..

 

 手動停止 Windows  SMBv1 服務

如何你無法修改路由器設定,你可以通用系統管理員權限修改以下設定

 

Windows 7/Sever 2008 / Vista 用家:

Step 1

以系統管理員登入,執行regedit

 

Step 2 

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesLanmanServerParameters
找空白處按右鍵新增 DWORD key SMB1, 其數值為 0 (日後成功執行修正檔的話,可把數值由 0 改回 1 )

 

 

 

 

Windows 8 或以上 :

Step 1

右按以管理員執行 CMD

Step 2

鍵入powershell (Enter)

set-ExecutionPolicy Unrestricted   (Enter)

set-SmbServerConfiguration -EnableSMB1Protocol $false (Enter)

看到提示後選 Y

 

成功後重新開機便成功

(日後成功執行修正檔的話,照以上方法,最後一次由 $false 改為 $true )

=====

為何我之前一直有更新,一樣中伏 ?

因為資料顯示此病毒有潛伏期,設定為 5  月 12 附近的日子爆發 ! 因此有可能在你電腦自動更新前已中招潛服在內,以下圖片顯示就算你電腦無連網絡,潛伏於電腦內的病毒照樣爆發。

中伏後解決方案 :

檔案已被加密了怎算 ?

1) 修復檔案

由於加密的過程是這樣的 :

1. 從原檔產生新的加密檔

2. 把原檔刪除

理論上,我們可以利用平時「undelete」的軟件把刪除的檔案救回來,只要那個區域未被新資料覆寫上去就有機會救回。如發現你的硬碟已被感染,請即關機。把硬碟取出搬到「無毒」的電腦上進行修復,方法可以參考 <這裡>的「救 DATA 篇」,不過有心理準備,只有部份檔案可 100% 救回來。

 

2) WNcry@2ol7 非解鎖密碼

Twitter 瘋傳 WNcry@2ol7 是解鎖密碼 ,但其實只是病毒一部份既解壓碼,用來解壓自己其中的 module繼續攻擊,有部份防毒軟件掃瞄不到有密碼的 zip 檔,所以部份病毒會用法方法加密自己的文件。

 

3)付款不等於會收到解密 

由於今次 BITCOIN 收款的地址是統一的,因此開發者無法證明支付者身份,任何人都可以冒認你跟病毒開發者說已付了帳,理論上會提供解密密碼機會很低。話雖如此,Bitcoin 追蹤資料顯示直到現時為止已有 23 單個交易,開發者收取了4.26616859 BITCOIN (現價計算的話,總值 7,210 美元)

 

4)勿亂安裝不明來歷的破解工具

Wanna Decrytor 暫時未有任何通用解密方法,可是中國網上已有很多所謂的破解工具,但其實檔案被加密後,那隨機密碼不可能用你自家電腦的運算力於短時間內破解,因此這類破解檔很多時是木馬程式,安裝後找尋 PC 內銀行或信用咭密碼,讓你受二次傷害

 

 

智云ERP

智云ERP是由OSCG面向广大小微型企业所研发的云端ERP系统,它是目前全球增长速度最快的企业系统odoo (OpenERP) 衍生出的最新产品。智云ERP提供了最便捷安全的系统环境以及配套服务。只需要三分钟,您的企业就能够享用最先进的企业管理软件。

智云ERP包含了所有Odoo的最新模块,如销售管理,采购管理,库存管理,项目管理,财务管理,人力资源管理以及不断更新的OSCG本地化和行业化模块。

  • 享用真正的云端ERP-无需安装,不限用户
    • 快速启用
      • 只需三分钟,就可以享用属于自己的智云ERP
    • 收费合理
      • 打破传统ERP价格昂贵的现状,适合小微型企业
    • 安全可靠
      • 多层加密及备份措施,确保系统数据安全
    • 随时随地使用
      • 只需要浏览器,就可以使用智云ERP
  • 体验专业的ERP服务-多年经验,快速上手
    • 专业的顾问团队
      • 经验丰富的讲师,资源丰富的支持团队
    • 易懂的用户手册
      • 通过实际案例设计的用户手册,用户更易理解和掌握
    • 完整的技术文档
      • 即使普通用户,也能使用ERP高端功能
    • 二次开发服务
      • 提供专业的ERP开发团队,让智云ERP随公司发展而变化

SAP S/4HANA

工業 4.0解決方案及物聯網(IoT)是製造業的業務驅動因素。根據 IDC 的報告顯示,全球的物聯網市場將於 2020 年達到 3.04 兆美元,當中有 30 億台連網裝置。現在經過多年的創新及不斷的發展,物聯網相關的科技更趨成熟,使工業 4.0 的目標更容易實現。

另一方面,「中國製造2025」是一個更廣泛的倡議,力求推動中國製造業的全面升級。而香港製造商可以帶領智能製造,綠色製造的行業發展。香港製造業可以透過應用資訊科技,抓住數碼轉型的機遇。

為了把企業收益增長達到最高,您需要一個能夠降低成本,加速生產週期,減少浪費和再加工,以及加快獲利的解決方案。選用 SAP S/4HANA 於IBM Power Systems,你會體驗到如何透過使用合適平台,在內存數據庫運用實時分析的裨益。

Agenda of FDA Inspection

FDA-logoRecently, FDA conducted audit to my company. FDA is known as Food and Drug Administration whereas US has FDA organization and China also has CFDA organization. Its official web site is https://www.fda.gov.

I would like to post their 3 days inspection agenda for your reference. To pass FDA audit is essential for export medical product; let’s well prepare for it.

Day 1
·         Introduction
·         Opening meeting.
·         Introduction/Presentation
·         Plant Overview (Warehouse, Manufacturing and Quality control areas).
·         Tour on facilities.
Lunch
·         Quality Manual.
·         Company Organization Chart.
·         Document Control / Records.
·         Change Control of Documents
·         Human Resources (job description, hiring, training).
·         Quality System Management Review.
Day 2
·         Daily wrap up.
·         Environment Control (Clean rooms, ESD and other applicable).
·         Design Control / History File.
·         Risk Management.
·         Device Master Record (DMR).
·         Change Control of Projects.
Lunch
·         CAPA.
·         Complaint Handling.
·         Field Actions / Recall.
·         Incoming Inspections.
·         Purchasing / Incoming Goods/Warehouse Activities.
Day 3
·         Daily wrap up.
·         Device History Record (DHR).
·         Internal Audits.
·         Validation Activities.
·         Non Conforming Product.
Lunch
·         Quality control (in process and final inspections).
·         Packaging / labeling.
·         Handling / Distribution/ Shipping.
·         Final Release.
·         Identification and Traceability.
Day 4
·         Daily wrap up.
·         Calibration / Maintenance program.
·         Field service/Technical assistance.
·         Decontamination / Returned Products.
Lunch
·         Housekeeping (Cleaning, pest control, building maintenance).
·         Statistical Techniques.
·         Pending Points.
·         Inspector’s findings Discussion.
·         Closing meeting.

Recommend Computer Room Temperature

What temperature is right?

tempatureGeneral recommendations suggest that you should not go below 10°C (50°F) or above 28°C (82°F). Although this seems a wide range these are the extremes and it is far more common to keep the ambient temperature around 20-21°C (68-71°F). For a variety of reasons this can sometimes be a tall order.

How do you maintain the right temperature?

Purpose built server rooms are well insulated for fire precaution reasons and air conditioning is essential. In many companies however the maintenance of the air conditioning is separate from the running of the servers. If the air conditioning fails you might not be the first to know. You may even be the last.

Even if everything is working the temperature may fluctuate during the day, from season to season, and there is always the possibility of localized hot-spots around equipment giving off lots of heat.

Don’t be tempted to think that just because you have an air conditioning unit that is up to the job that you are safe. People working in the server room sometimes switch the air conditioning off and forget to turn it on again. Sometimes they leave doors open. Servers run hotter at some times of the day than at others, air conditioning systems sometimes run at lower power at night etc.

What if it’s night time, your air conditioning is running at low power, and your webserver suddenly starts to work hard because the west coast has woken up? Now your machine heats up and your air conditioning can’t cool it enough. Exactly this scenario has been know to happen. Many intermittent faults and slow downs can be traced to overheating.

Replacing old equipment can introduce a new set of problems. Newer machines run faster and often run hotter as well, increasing the burden on the air conditioning systems even more. If you’ve recently introduced new servers or modern switches, it might be time to examining your air conditioning unit to make sure it can still keep up.

Another thing to look out for is the scenario where you turn up the air conditioning unit during the day, in order to ensure the right environment in your server room, but then don’t switch it down during the night or weekends. During the day there might be a lot of activity into and out of the server room. The server room door being opened all of the time lets warmer air into the server room thus necessitating the air conditioning system to be turned up high. At night and at the weekend, without the same level of activity, you may be running up large energy bills for no reason.

How are you going to monitor the temperature?

You need to monitor the temperature in your server room all of the time, especially at night and weekends when nobody is around. A number of systems are available for this purpose, the Temperature Monitor range from OPENXTRA offer good products at reasonable prices. You need to measure temperatures at different points in the room to get an idea of where the hot spots might be. You need temperature measurement to be automated and reliable, so a network attached device is ideal. The device must support alarms, via a number of different methods like email or SMS. You should be able to set the system up and then be alerted when something is wrong.

Information Source: https://www.openxtra.co.uk/kb/environment-monitoring/recommended-server-room-temperature.html

SQLite database management tool

SQLite is the primary database of python. SQLite is a simple and easy to use database. We can also easy to manage SQLite database by using SQLite Studio, which is a freeware and you can download from https://sqlitestudio.pl/index.rvt?act=download.

SQLiteStudio is a SQLite database manager with the following features:

  • Portable – no need to install or uninstall. Just download, unpack and run.
  • Intuitive interface,
  • Powerful, yet light and fast,
  • All SQLite3 and SQLite2 features wrapped within simple GUI,
  • Cross-platform – runs on Windows 9x/2k/XP/2003/Vista/7, Linux, MacOS X and should work on other Unixes (not tested yet).
  • Exporting to various formats (SQL statements, CSV, HTML, XML, PDF, JSON),
  • Importing data from various formats (CSV, custom text files [regular expressions]),
  • Numerous small additions, like formatting code, history of queries executed in editor windows, on-the-fly syntax checking, and more,
  • Unicode support,
  • Skinnable (interface can look native for Windows 9x/XP, KDE, GTK, Mac OS X, or draw widgets to fit for other environments, WindowMaker, etc),
  • Configurable colors, fonts and shortcuts.
  • Open source and free – Released under GPLv3 license.

Difference for moving AP/AR transaction to history mode in Great Plain/Dynamic system

In Receivables module, a AR transaction document is moved to ‘history’ status when the said document is fully applied and then the Paid Transaction Removal (PTR) routine is processed (i.e. run “Paid Transaction Removal” Option under “Routines”). It is different from AP, whereas In Payables module, a document is auto moved to ‘history’ status when the said document is fully applied.