Addsum web site and general info

Postings here will focus mainly on Advanced Accounting software updates, tips, and related topics. They will also include general comments relating to troubleshooting PC/Windows/network problems and may also include reference to our other software products and projects including any of our various utilities, or to the TAS Premier programming language. We considered setting up separate blogs for different topics so that users/others could subscribe to topics mostly aligned with their interests, but decided that it would be better to keep things simple since some topics cross over into others. We would nonetheless welcome your feedback/input in this regard. Our web site URL is www.addsuminc.com. Call us at 800-648-6258 or 801-277-9240. We also maintain www.advancedaccounting.us so that older Business Tools users in particular have a greater chance to find us. White list noreply@follow.it to ensure you receive notifications once you subscribe.

Wednesday, May 17, 2017

Microsoft catalog link for WannaCry

The direct Microsoft catalog update link for installing the WannaCry (aka "WannaCrypt") security update or patch (i.e. KB4012598, vulnerability MS17-010) can be found here:

http://www.catalog.update.microsoft.com/Search.aspx?q=KB4012598

You might wonder why Windows 7 is not referenced in the KB4012598 update.  This is because the updates for Windows 7 came out in March under a different KB reference (KB4012212 and others) to address the MS17-010 vulnerability.  See this link for the list:

https://blogs.technet.microsoft.com/sudheesn/2017/05/17/patches-that-fix-the-vulnerability-for-ms17-010/

See also:

http://www.infoworld.com/article/3196825/microsoft-windows/how-to-make-sure-your-windows-pc-wont-get-hit-by-ransomware-like-wannacrypt.html


U.S. users have thus far not been impacted to the same degree as elsewhere but more "WannaCry" variants are expected.

 While these updates first became available in March for most operating systems, updates for non-supported Windows XP (both 32 and 64 bit versions) only became available on May 13, 2017 (and was rather surprising since MS has not been issuing free updates for XP for some time now).  

 Users still running XP should immediately install the appropriate update from the catalog link.  Installing the update takes only a few minutes.  It does require a reboot    Even if your PC typically does not have direct Internet access, it is advisable to install this update since it would help to stop the spread of this latest  ransomware virus from spreading from one PC (that might have Internet access) to others (that might not) on the same network.  The security patch can be downloaded to a shared folder on your network or to a thumb or external drive, and then run on other PC's on your network or in your office without their having any web access.

While we are not a fan of automatic updates, some updates are from time to time important to install regardless of how careful users are with inbound e-mail, anti-virus protection, and in the web sites they visit.

There is some amount of misinformation about this virus and how it spreads.  Your greatest vulnerability is once again by opening e-mail attachments from unsavory sources, often disguised to look like it is from someone you know and/or that purports to contain an attached invoice or purchase order, etc.   End user education remains critical.

It is indeed unfortunate that there are individuals that would choose to spend their time and resources spreading malware rather than on pursuits that would benefit society and/or the health of the planet.  It is also highly unfortunate how the NSA handled this situation in terms of both safeguarding its information, in developing unsavory methods of hacking into computer systems in the first place, and not promptly acting to notify Microsoft and others of the threat so that these security updates could have been made available sooner.

Note:  If infected, do not pay the ransom.  Even if you pay it, you may still not receive an unencrypt key, more so this time around than ever.  Immediately consult your IT support if you receive any pop-up messages or if you start to see file extensions of .WCRY.



Additional information:


https://support.microsoft.com/en-us/help/4012598/title

http://www.npr.org/sections/thetwo-way/2017/05/15/528451534/wannacry-ransomware-what-we-know-monday

http://www.nbcnews.com/news/world/why-wannacry-malware-caused-chaos-national-health-service-u-k-n760126

https://www.wired.com/2017/05/wannacry-ransomware-hackers-made-real-amateur-mistakes/

https://www.ft.com/content/e2786cbe-3a97-11e7-821a-6027b8a20f23






Thursday, April 27, 2017

Keyhelp.ocx vulnerability relating to Actian PSQL 12 install

A TAS Premier 7i runtime user relating to a third party vertical market software system (for which we provide support assistance as well as programming) has reported receiving a notice from their security vulnerability analysis software relating to a file installed by Actian/Pervasive version 12 as follows:

Description: The remote host has KeyWorks KeyHelp ActiveX control installed, which is affected by multiple vulnerabilities 

- Multiple stack-based buffer overflows exist that could allow an
attacker to execute arbitrary code. (CVE-2012-2515)

- An unspecified command injection vulnerability. (CVE-2012-2516)


KEYHELP.OCX is a part of the PSQL 12 install and is not harmful.  It is also, however, a non-essential control with respect to the Pervasive engine.

See:

https://supportactian.secure.force.com/help/articles/Technical_Document/Keyhelp-ocx-reported-as-a-security-vulnerability-by-security-analyzer-utilities

https://supportactian.secure.force.com/help/articles/Bug_Document/Actian-Security-Vulnerabilities-NoticePSQL/




Note that Actian recommends the removal of this control (which is only used when running the Pervasive System Analyzer aka PSA tool).   It will not be shipping with future updates to the v12 engine starting with service pack 1,  i.e. 12.10.  

For users with older installations of version 12 (i.e prior to 12.10), the instructions in the second link above is repeated below:


You can prevent the installation of this file by using the 'Custom' Setup Type option, and changing the installation option for the optional utility to 'This feature will not be available' during the installation.  Alternatively, it can be removed from an existing PSQL installations by modifying the installation to remove the optional utility by selecting 'Uninstall/Change' from Programs and Features, selecting the default 'Modify' option and removing the utility from the installation. 











Forced Windows 10 updates causing damage to external drives

Based on now numerous reports, many Windows 10 users have experienced total data loss and even hardware damage with USB-connected devices that are being accessed when a Windows 10 "forced update" occurs.

This discussion relating to damage caused by a Windows 10 forced update is just the tip of the iceberg of reported problems.  We have had other reports of the same issue experienced recently by IT professionals.

Automatic updates that slow computers used for business purposes down to a crawl and that can only be marginally controlled are simply an unacceptable approach and must change or else business PC users will ultimately either start to migrate to something else and/or stay far, far away from Windows 10 to the greatest extent possible.  The current level of control with respect to these updates remains dismal at best making Windows 10 the least stable operating system that Microsoft has released perhaps in its history.

While our software runs on everything released by Microsoft to date, we cannot recommend the use of Windows 10 (Professional) because of its overall poor performance in multiple respects and because of the lost time and potential havoc its forced updates create.   Your maintenance and supports costs will be higher with Windows 10 and for marginal benefit.



See also:

http://addsuminc.blogspot.com/2017/04/windows-10-update-kb4015217-creates.html







Monday, April 17, 2017

Windows 10 update KB4015217 creates havoc

The Tuesday April 11, 2017 Windows 10 update started to create numerous problems for users trying to install it and then has had other unfortunate impacts.

Our first call was from a user who experienced a loss of network connectivity after the update.  Both PC's were Windows 10 Home (the Home version works with our software, but is generally discouraged).  The update also caused at least one of the PC's to be significantly slower.   This update does require a reboot and apparently in the case of this user, the update brought about a weakness in the way the two PC's had previously been configured (but which was otherwise working prior to the update).  In this case it may have been a Homegroup versus Workgroup setup issue.

Problems simply in installing the update have been somewhat widely reported including being stuck and/or taking several hours to complete.  Another example.   Problems with respect to PC's "freezing" after installing the update have also been experienced.  Prior cumulative updates have sometimes simply failed to install.    An example would be the prior KB4015438 cumulative update (which was intended to fix problems with yet another prior cumulative update; see more below).  This has also been the case with 4015217 update.

Example of issues with the KB4015438 update:


KB4015438 failing to install repeatedly



After installation, there have been reports of slowness and black screens.

As of April 14, 2017 there are reports of more esoteric issues such as with the VB ADODB.Recordset filter  property (which a related Windows 7 update has also apparently caused).   This problem does not impact our software in any way, but is nonetheless alarming.  Users have had to uninstall the update to solve the recordset filter problem (however depending on your settings and particularly if you have Windows 10 Home, users will have difficulty preventing the update from trying to install itself again in the future).

Security updates that came out last week for other versions of the Windows operating systems, including server versions, have caused widespread issues, particularly slowness.

While it may be too late for most, our recommendation would be, at least for now, to avoid this update if possible.  Windows 10 Home users, unless they are solely connected via Wi-Fi and can set that connection to 'metered' may not be able to avoid or defer it (other than to not connect those devices to the Internet at all!).

Windows 10 Professional users may be able to prevent updates through the group policy editor (but there are indications that after this cumulative "anniversary" install, this may no longer be possible).

Some pertinent links in terms of turning off and/or managing Windows 10 updates:

http://www.pcworld.com/article/3085136/windows/two-ways-to-control-or-stop-windows-10-updates.html

http://www.thewindowsclub.com/turn-off-windows-update-in-windows-10

http://www.howto-connect.com/stop-windows-10-update-in-progress/





















Friday, March 31, 2017

Unpost AR payment and DDF creator enhancements

This past month we have made many important Advanced Accounting enhancements including to two utility options.

Unpost AR payment

Accessed via the Addsum utilities (via UT-G and in the Accounts receivable section) from the Advanced Accounting 7i menu, the unpost AR payment (aka "Unpost customer payment")  utility allows an end user to reverse an accounts receivable customer payment where that payment might have been applied to the wrong customer or was for the wrong amount or was applied to the wrong invoices, etc.   While it does remove the payment record from customer transaction and related files, it nonetheless leaves an audit trail in the general ledger. Payments not fully applied can also be unposted.  

For various technical reasons, something that was not previously allowed by the utility was the ability to unpost a payment for the same amount on the same date for the same customer.  Yet, the entry of a duplicate (or even triplicate) payment for the same customer on the same date and for the same amount is one of the reasons why a payment may sometimes in fact need to be unposted. This ability now exists. The program as enhanced however does require user interaction to determine which invoices the duplicate payment was applied to when it involves the same date and amount.  So users should first determine what those invoices were before attempting to unpost such payments.  There are at least two ways to do this, the best one being the AR-O credit analysis/customer payment history report which is referenced in the utility option itself.


Unpost AR/customer payment - 7i version

Whether an errant duplicate payment  was applied to one or twenty or more invoices doesn't matter:  the user will be asked to confirm which invoices were involved and ensure that they add up to the duplicate payment amount to be unposted, followed by the normal confirmation screen.

The payment could even have been made in triplicate or quadruplicate on the same date for the same amount for the same customer but can still now be unposted as long as the program is first told which one of those to unpost, and then second, which invoices were errantly applied in connection with that payment.

This updated option will be standard with the Adv 8 add-on and will include support in that release for the expanded invoice numbers and the new GL audit file.   A version compatible with Adv 7i will also in the interim be available for users who have these utilities and that may have need of this capability. 

The Addsum utilities collection is an add-on option for Advanced Accounting.

DDF creator

Data dictionary files (DDF's) are needed to be able to access your Advanced Accounting data via ODBC through other programs such as Crystal Reports or Microsoft Access or via our SQL query tool or via the Actian/Pervasive Control Center to make SQL queries of your data thru any desired means including web site integration (via PHP for example). This software category is sometimes referred to as a "DDF builder."  The DDF files are Pervasive format files which provide structure for outside access.   (You must be using the Pervasive record manager/database engine which installs the required ODBC driver.)

This option has been dramatically changed compared to the older DDF option as released by Business Tools prior to 1997.  This version which allows you to select only desired files for outside access and it also remembers your prior selections, and has also been extensively modernized to comply with newer Pervasive requirements.  It first started to become available in 2003-2004 with significant enhancements that followed in 2007, 2008 and 2010.

The latest enhancements involve an improved interface, updates for pathing defaults, and an improved searching capability when attempting to find data files ("tables") to be included in the DDF's.


DDF creator Adv7i

This updated version is now standard for Adv 7i and will become the new standard add-on option for Adv 8.


The DDF creator is an add-on option for Advanced Accounting and when installed is available from the accounting software menu under UT-P ("Create DDF files").















Tuesday, February 28, 2017

Using Gmail with Advanced Accounting

Some background information:

SMTP (Simple Mail Transfer Protocol)  is the Internet standard protocol for sending and receiving messages between mail servers.   These servers use internally assigned ports to facilitate various communications and provide other services.  Standard (aka "well-known") ports for Internet services developed over time.  The standard port that your ISP's own mail servers use for  communication with other mail servers is port 25 (just like port 80 is used for http: web browsing, ports 20 and 21 are used for file transfer protocol (FTP), port 23 is used for telnet and so forth).

For end users wanting to send and receive e-mail using a mail client of some kind, e-mails are relayed to an actual mail server using SMTP protocol. But e-mails are instead received/delivered to mail clients using a different protocol (typically POP3 or IMAP).

 In an application like Advanced Accounting, the most typical need is the ability to send e-mail out of the software most often with an attachment (sales order, sales invoice, quote, purchase order, statement and so forth).  Therefore, in setting up a user's e-mail settings to accomplish the relay of the outbound e-mail, SMTP settings must be established including the name of the  SMTP server.   

Port 25 remained the common port for use with mail clients for much of the first 25 years since the development of Internet networking standards. Some mail server providers still provide that capability.   Increasingly however over  the past decade in an attempt to control spam, port 25 started to be blocked for use by mail clients and is now typically blocked by most providers.   At first the approach was to simply use other ports such as 2525.  Authentication started to also become routine often with the alternative port approach (or with the standard port) which basically requires that a user log-in (typically an e-mail address) with a password in order to successfully send an e-mail.

Authenticated e-mails however were still commonly being sent as plain text until so-called secure or encrypted methods were developed and started to become common practice (particularly as a result of leaked, illegal NSA surveillance techniques).  These methods, most commonly SSL/TLS (collectively "secure socket layers"), use authentication combined with more private means of communication and are most often also used in connection with ports 465 and 587.  Web-based mail clients (aka "webmail") running on web servers typically require SSL/TLS support.

With two factor authentication now becoming more common, the complexity of successfully communicating with mail servers is becoming even more complex.

Some traditional mail providers are now also requiring that your "sender" e-mail address matches your authentication user ID, and often make sudden changes to their authentication or other requirements without advance notification leading to authentication failures and "unable to send e-mail" responses.   (Troubleshoot these by clicking on the "Trace" check box on the e-mail send form, and e-mail us the results if you require assistance.)

Advanced Accounting's support for e-mail:  The Advanced Accounting 6.x series was the first version to support outbound e-mail and provide therefore SMTP communication capabilities.  Version 6, while also providing the ability to authenticate, only supported standard port 25.   Starting with a release of the Advanced Accounting 7 series in 2009, a user could specify any SMTP port.  Towards the end of 2013, SSL/TLS support was available in version 7.  

Note: in Advanced Accounting, we are only primarily concerned with sending, not receiving, e-mails.  POP3 support is however available if needed in custom program situations, and has been since version 6.

Choosing an SMTP provider

Many options exist in terms of selecting an SMTP mail services provider typically at either no or low cost.

Normally your Internet Service Provider (ISP) or other third party provider that already provides your SMTP mail services is your first contact of choice and should be able to provide SMTP services to you without charge.  If your ISP is either not also hosting your web site or providing mail services, they should still be a strong option to first consider. They will have SMTP mail servers. Another option might be your web site's hosting provider or some third party provider including providers of webmail.

It is important to note that your domain based return e-mail address does not have to correspond to a mail server that belongs to your hosting provider in most, but not all, cases.  So while normally your SMTP server might most often also be the server through which you also receive incoming mail, it does not have to be.

Your mail server provider will have other required settings and port usage and authentication requirements that must be established in order to send outbound e-mails.  You will need to determine what those are before being able to establish appropriate e-mail settings for you and/or your other users of Advanced Accounting.  

 We do highly recommend the use of separate Advanced Accounting logons so that you can create separate e-mail profiles for each user, and so that each user can use their own reply/sender e-mail address. In your Advanced Accounting settings, we highly recommend using the BCC: default and therein specifying your own e-mail address so that you will automatically receive a copy of every e-mail that is sent, and which can be archived for follow-up or future reference as desired.

Using Gmail as your SMTP provider:

Even though your incoming mail may be routed to you some other way, if you have a Gmail account, then you can use a Google SMTP server for your outbound e-mail.

Steps you will need to take:

(1)  You will need the last Adv 7i rel. 7f updates some of which occurred in Feb. 2014 when we changed how we launch the SSL/TLS capable extension.  If you are on that release but don't have those updates, we will provide and install them at no charge.  These updates will be needed for any provider that requires SSL/TLS.

(2)  Because of newer security requirements, your normal Google/Gmail password will not likely be sufficient as it once was.  Instead:

  • Go to: https://myaccount.google.com/apppasswords
  • Sign in with you usual credentials if required.
  • In the first drop down box ("Select app") choose "Mail" and in the second ("Select device") choose "Windows computer."






  • Finally, click on the Generate button (will become visible after choosing "Windows Computer").   Copy/paste this password into the password below.

(3) Establish or complete your Advanced Accounting e-mail setting under SY-C-A (System Maintenance, Enter/Chg User Security,  Maintain Logon Codes) by highlight the logon code, click on Edit, and click on the E-mail settings button.





As indicated in the example above:


  • SMTP server:  smtp.gmail.com
  • SMTP port:   587
  • Click the Use TLS check box
  • SMTP user ID: insert your user ID, the same one used in step (3) above
  • SMTP Password:  paste the "app password" generated in step (3) above
  • Sender name:  Your name or other text you want recipients to see when receiving your e-mail
  • Sender E-mail address:  The address you wish to use for the sender/reply e-mail address.  It does NOT need to be the same as your gmail address.  You will only be relaying outbound e-mail via a Gmail SMTP server, nothing more.



After saving these settings, test sending an e-mail via the Adv user logon for whom you have establish these settings. The easiest way to do that is via Tools (across the top of the menu to the right of File and Module in the full screen mode) and then E-mail 

Keep in mind that security measures are constantly changing and the steps that need to be taken in the future may differ from those outlined above.




Additional related information:

ISPs Removing Their Customers' Email Encryption (Nov 2014)

SSL versus TLS (July 2016)















Tuesday, January 3, 2017

Advanced Accounting 2017 payroll updates

In late November of 2016 we posted some initial information about upcoming 2017 payroll changes and new due dates for federal W-2 filings.  On the last day of the year, we published more information on our "year end" page including federal tax tables with new and updated screen shots, and our annual printable PDF outlining the most important changes that need to be made.

Since then we have added either updated tax tables and/or new required program logic for 15 states that have made state income withholding changes as of January 1. 

Here is the link to the year end page:

http://www.addsuminc.com/advyearend.html

Some of the states with rather significant changes include Maine, Minnestoa, South Carolina (the first time in 25 years that South Carolina has made any changes), and  Rhode lsland.


States with tax table or other changes as of January 1, 2017:

California (all of the various tax codes require updating)

Indiana

Kentucky

Maine

Maryland

Minnesota

Missouri 

Nebraska

New York

North Dakota

Oklahoma

Oregon 

Rhode Island

South Carolina

Vermont

There will no doubt be a few more to follow.

Advanced Accounting has user-maintainable payroll tax codes allowing users to make changes themselves for many of these states (as well as federally).   However, some states have had standard deduction changes or they use an approach to withholding calculation that does not follow the norm and that therefore requires program modifications whenever that state makes to its withholding formulas (examples would be Oregon and Indiana).

Advanced Accounting 7i users with employees in Indiana, Kentucky, Maryland, Missouri, Oregon or South Carolina will need the 2017 payroll update (which assumes that the prior 2015/2016 update has also been previously installed) going forward into 2017.   

Users in other states may will want to obtain the payroll update to avoid their having to update federal tables and any tables updating relating to their state.