News in the Category: Security Subscribe to the rss of this category.

Total posts: 945 | Sort by Views | Sort by Hits

Light Patch Slate Expected on Tuesday

Microsoft Certified Professional Magazine Online | Todays Top Picks, March 4, 2010
Views: 97 | Hits 1

Microsoft is projecting just two "important" fixes in its upcoming security update for March....

Download the Simplified Implementation of the Microsoft SDL

MSDN: BizTalk Server, February 19, 2010
Views: 135 | Hits 13

Understand the core concepts of the Microsoft SDL and learn how to implement it in your organization. The Simplified Implementation of the Microsoft SDL will help you identify which software developme...

Report Profiles Top Software Security Coding Errors

Microsoft Certified Professional Magazine Online | Todays Top Picks, February 18, 2010
Views: 123 | Hits 11

A new study describes the top 25 programming errors that can open up security holes in software....

A good way to handle claim based security in RESTful services

Pablo M. Cibraro (aka Cibrax), February 18, 2010
Views: 187 | Hits 25

Dominick just blogged what I think is one of the best ways to provide claim based security for RESTful services at the moment. The idea of using simple web tokens for RESTful services Ive been in my h...

The system cannot find the file specified error in the WIF FAM module

Pablo M. Cibraro (aka Cibrax), February 17, 2010
Views: 162 | Hits 3

The Federation Authentication Module (FAM) shipped as part of WIF protects by the default the session cookies from being tampered with in passive scenarios using DPAPI. As I mentioned in the past, thi...

Bruce Schneier: Geek of the Week

Simple Talk, February 16, 2010
Views: 22 | Hits 1

If one were to close one's eyes and imagine a BT Executive, one would never conjure up Bill Schneier. He is one of the greatest experts in cryptography, and a well-known mathematician. He even got a b...

Why isnt there a CTRL+ALT+DEL key?

More Whidbey stuff, February 14, 2010
Views: 509 | Hits 31

I vaguely understand why this weird key combination from the 20th century offers some security advantage that somehow justifies that its still present on enterprise versions of Windows, but why does ...

Join a Live Webcast on Detecting and Mitigating Security Issues Using the CAT.NET Tool

MSDN: ASP.NET, February 5, 2010
Views: 143 | Hits 5

In this live Security Talk webcast, discover how CAT.NET includes a set of FxCop security rules that help you identify security flaws in a managed-code (C#, Visual Basic .NET, Visual J#) application y...

SDL Quick Security Reference: Cross-Site Scripting and SQL Injection Attacks

MSDN: ASP.NET, February 2, 2010
Views: 168 | Hits 20

With the SDL Quick Security Reference (QSR), the Security Development Lifecycle (SDL) team introduces a series of basic guidance papers designed to address common vulnerabilities from the perspective ...

Authentication and Authorization Using RIA Services (Article 7 of 7)

peterkellner.net, January 25, 2010
Views: 192 | Hits 25

    This article is very short.  In the actual presentation, there was not much time to talk about this so a brief overview was done.  Basically, its all standard WCF... This si...

SharePoint: The security validation for this page is invalid

Simple Talk, January 5, 2010
Views: 110 | Hits 6

Quite often when developing outside of the parameters of a standard SharePoint customisation I have come across this error message: The security validation for this page is invalid  Its not t...

ActAs in WS-Trust 1.4

Pablo M. Cibraro (aka Cibrax), January 4, 2010
Views: 178 | Hits 5

WS-Trust 1.4 introduced a new feature called as ActAs for addressing common scenarios where an application needs to call a service on behalf of the logged user or a service needs to call another servi...

Windows 7 May Face Attacks in 2010

Microsoft Certified Professional Magazine Online | Todays Top Picks, January 4, 2010
Views: 201 | Hits 14

Windows 7 has the potential to become a security target in 2010, according to researchers, although it's held up so far....

Upgrade of Gemini for http://support.dotnetnuke.com

Joe Brinkman, December 10, 2009
Views: 88 | Hits

Over the past couple of years our issue database has been showing signs of age.  Searches often result in error messages, linking issues can cause server instability, and our general issue workfl...

Increase Your Value as a Professional in the Technical Industry

Simple Talk, November 17, 2009
Views: 117 | Hits 1

It has never been so important to enhance your employability as it is today. Job security can never be taken for granted. Employability, increasing your professional value, means far more than just co...

New! Build More-Secure Applications with the Security Development Lifecycle (SDL) for Agile

MSDN: ASP.NET, November 13, 2009
Views: 258 | Hits 11

Embrace lightweight software security practices with the Security Development Lifecycle for Agile Development, a streamlined approach that melds Agile methods and security....

Cybersecurity Alliance Aims at Network Protection

Microsoft Certified Professional Magazine Online | Todays Top Picks, November 13, 2009
Views: 219 | Hits 1

Thirteen leading technology companies including Microsoft have joined with Lockheed Martin to form a new cybersecurity technology alliance....

MSDN Video: Top 10 Security Pet Peeves

MSDN: BizTalk Server, November 9, 2009
Views: 255 | Hits 17

Michael Howard and Adam Shostack, experts in eecurity engineering at Microsoft, chat about their top 10 security pet peeves....

Criminals Keeping Ahead of Data Breach Laws, Experts Warn

Microsoft Certified Professional Magazine Online | Todays Top Picks, November 9, 2009
Views: 242 | Hits 3

Security experts say that threats to personal data are evolving faster than our responses to them....

CodeRush In The Cloud

The ASPx Blog, November 6, 2009
Views: 279 | Hits 9

Check out this CodeRush in the Cloud screencast with Rory Becker. The video shows you how to use Microsofts free Live Mesh service to synchronize your CodeRush settings across multiple machines. The ...

Patch Tuesday: Expect Six Security Fixes

Microsoft Certified Professional Magazine Online | Todays Top Picks, November 5, 2009
Views: 236 | Hits 7

After a record-breaking Patch Tuesday in October, November's security update promises to be a bit lighter with six scheduled fixes, three deemed "critical" and three "important."...

New! Download the SDL Developer Starter Kit

MSDN: ASP.NET, October 30, 2009
Views: 292 | Hits 25

Educate yourself and your organization on how to build more secure applications. The SDL Developer Starter Kit offers content, labs, and training to help you establish a standardized approach to rolli...

Membership API documentation amended on MSDN

Run Tings Proper, October 27, 2009
Views: 114 | Hits

In preparation for tonight's post I have just added some usage examples to the MSDN Membership API documentation. They are pretty straightforward but if you have any feedback on them then you can just...

Rapid7 Acquires Open Source Metasploit Security Project

Microsoft Certified Professional Magazine Online | Todays Top Picks, October 22, 2009
Views: 278 | Hits 8

An independent security researcher and a prominent figure in open source exploit data collection now has a new commercial home....

Easy default roles for new users with the CreateUserWizard

Run Tings Proper, October 17, 2009
Views: 122 | Hits 7

Here's a scenario for you: You have an admin panel and you want to let the administrators of the site create extra admin accounts when they need to. Your site uses asp.net membership and roles and you...

Connected Information Security Framework: Core Components

MSDN: BizTalk Server, October 16, 2009
Views: 308 | Hits 5

Watch Marius Grigoriu and Vineet Batta, both from Microsoft Information Security, in this short Channel 9 video. They talk about the technical components for the first version of the Connected Informa...

Adding users to a TFS project when youre not on the domain

JonGalloway.ToString(), October 15, 2009
Views: 408 | Hits 18

Visual Studio Team System was obviously designed for user groups who are all members of a Windows Active Directory domain, all working in the same local network. Im able to work remotely (without VPN,...

Content Rewriting through Cisco WebVPN

the telerik blogs, October 13, 2009
Views: 535 | Hits 6

By default, all Cisco security appliances process all WebVPN traffic through a content rewriting engine that includes advanced elements such as JavaScript and Java to proxy HTTP traffic. That is a goo...

ASP.NET Security

The Code Project Latest Articles, October 9, 2009
Views: 347 | Hits 52

ASP.NET Security...

Silverlight 2 Security Interview with Microsoft InfoSec

MSDN: BizTalk Server, October 6, 2009
Views: 315 | Hits 10

Maqbool Malik, from Microsoft Information Security, describes some key features added in the second version of Silverlight to enhance security....

Why Google Chrome and FireFox are a big security risk for anyone using them

ISerializable, October 5, 2009
Views: 395 | Hits 120

Ive stopped using Internet Explorer Too damn slow, memory hogging beast. Ive stopped using FireFox, for the same reasons, funnily enough (until I found out about the security flaw). Im now using Sa...

Microsoft Unmoved by Published SMB Exploit

Microsoft Certified Professional Magazine Online | Todays Top Picks, October 3, 2009
Views: 318 | Hits 9

Microsoft's security team didn't flinch this week, even as a proof-of-concept exploit for Windows Server Message Block Version 2 (SMBv2) was published on Sunday....

ARCast.TV: Perspective and Architectural Insight

MSDN: ASP.NET, October 2, 2009
Views: 291 | Hits 11

Tune in to a recent episode of ARCast.TV to learn more about the next software boom or to watch a video about building line-of-business (LOB) applications in Microsoft Silverlight and Windows Presenta...

Microsoft, Others Earn Single Sign-On Cert

Microsoft Certified Professional Magazine Online | Todays Top Picks, September 30, 2009
Views: 284 | Hits 12

Eight identity management products from seven vendors have earned interoperability certification for the Security Assertion Markup Language (SAML 2.0) in this summer's round of interoperability testin...

Virtual Lab: Windows Forms Security

MSDN: BizTalk Server, September 24, 2009
Views: 411 | Hits 30

This lab is intended to show experienced .NET Windows Forms developers how to secure Windows Forms applications. In this lab, you will work with cryptography, implement custom authentication and autho...

Microsoft Sues Alleged 'Malvertisers'

Microsoft Certified Professional Magazine Online | Columns, September 22, 2009
Views: 180 | Hits 10

Plus: an SMB flaw stopgap measure; Security Essentials on the release horizon....

Webserver Security Check

The Code Project Latest Articles, September 17, 2009
Views: 399 | Hits 32

This article contains a security check script and describes how to secure Windows and Linux webservers against hackers....

Scenarios for WS-Passive and OpenID

Pablo M. Cibraro (aka Cibrax), September 14, 2009
Views: 394 | Hits 9

I was wondering these days what would be the point in using WS-Passive when there is another simple sign-on solution, OpenID, that works really well and its getting a great adoption in the community. ...

Welcoming a new member of the Security team

Shaun Walker, September 11, 2009
Views: 209 | Hits 3

The DotNetNuke security team would like to give a long overdue public welcome to our newest team member, Brandon Haynes.More......

Microsoft Warns of Another Server Message Block Bug

Microsoft Certified Professional Magazine Online | Todays Top Picks, September 9, 2009
Views: 329 | Hits 18

The all-critical patch release of hotfixes served up by Redmond Tuesday hadn't even cooled off yet when Microsoft issued yet another security advisory on late Tuesday night....

Client Configuration in WCF 4.0

Pablo M. Cibraro (aka Cibrax), September 8, 2009
Views: 427 | Hits 34

As Dr Nick announced in this post, WCF 4.0 will ship with a new feature to configure a client channel from a configuration source other than the traditional section in the application configuration fi...

Addressing Vulnerabilities in JavaScript in ASP.NET Web Sites

The Code Project Latest Articles, September 8, 2009
Views: 339 | Hits 41

This describes some of the potential security concerns caused by common programming techniques and how to get around them...

New: Security Developer Starter Kit

MSDN: BizTalk Server, September 8, 2009
Views: 411 | Hits 44

The Microsoft SDL - Developer Starter Kit offers 14 modules of content, labs, and training to help you establish a standardized approach to rolling out security development policies and industry best ...

Windows Auto Sign On In Locked Mode

Steven Smith, September 4, 2009
Views: 411 | Hits 31

Earlier this week, after enduring yet another windows update, I came up with a feature request for Windows that would make me a much happier user.  Weve all heard about requests for speeding up b...

Updated: !exploitable Crash Analyzer Tool

MSDN: ASP.NET, September 4, 2009
Views: 306 | Hits 9

View more information on the Windows debugging extension (Windbg) that provides automated crash analysis and security risk assessment....

'Critical' Windows Fixes Expected on Patch Tuesday

Microsoft Certified Professional Magazine Online | Todays Top Picks, September 3, 2009
Views: 315 | Hits 7

Microsoft is forecasting a rare Patch Tuesday next week, with all of the September security bulletins expected to be deemed "critical."...

Luca Cardelli: Geek of the Week

Simple Talk, September 2, 2009
Views: 284 | Hits 9

Luca Cardelli is probably best known for Polyphonic C# and Biocomputing, but he has designed a number of experimental languages and published a variety of papers on Theoretical Computing subjects such...

Topeka Dot Net User Group (DNUG) Meeting – September 24, 2009

Fervent Coder, September 1, 2009
Views: 221 | Hits 4

Topeka DNUG is free for anyone to attend! Mark your calendars now! SPEAKER: Rob Reynolds has been programming in .NET since the early days of 1.0. He is a .NET Developer at FHLBank Topeka, a bank w...

How Do I: Use the SDL Process Template Documentation and Reporting?

MSDN: ASP.NET, September 1, 2009
Views: 338 | Hits 16

This 5-minute video will help you learn how to use the new SDL Process Template's document templates and security metrics reporting. The built-in SDL document templates will help you jump start your u...

SSA Testing Microsoft HealthVault

Microsoft Certified Professional Magazine Online | Todays Top Picks, August 31, 2009
Views: 343 | Hits 10

The Social Security Administration will to test Microsoft's HealthVault software for its disability determination process....

Product Spotlight