![]() |
Tags | Domains | Searches | Statistics | Options | Advanced Search |
Michael Howard's Web Log - 22 hours ago
Close on the heels of David Ross' XSS defense in IE8 beta 2, my boss, Steve Lipner just posted an article looking at XSS filter from an SDL perspective. While I'm on the subject of XSS and Dave, if XSS is an area of …
Code Junkie - 24 hours ago
I will be at TechEd Australia speaking on behalf of our team on connected information security and our security tools. You will see more blog entires on the session content and tools in coming days. Our session is …
Also tagged: cisg
Carpe Datum - Aug 28, 2008
I'm working on a Policy that will expose a particularly thorny issue. In SQL Server 2008, you can use a new feature called Transparent Data Encryption (TDE). This feature encrypts the entire database, so you don't have …
Also tagged: sql server, microsoft, administration, encryption, dba
Reed Me - Aug 27, 2008
I always hear Randall's comic voice in my head now shouting "You're doing it wrong!" when I see things like this: "This is believed to be the first reported case of a space station computer getting a virus, but a Nasa …
![]() |
Apple iPhone Security HoleJason Langridge's WebLog - MR Mobile! - Aug 27, 2008 Wired Magazine have just discovered and shared a rather large security hole in the Apple iPhone. This essentially allows you to bypass the PIN security and gain access to the features of the device including the … |
Software Sleuthing - Aug 26, 2008
About three years ago, when the Xbox 360 was getting close to launching, we went through a security pass of the audio and photo playback capabilities. One of the tools that was recommended to us by another employee was …
Also tagged: testing
SQL Server: Service Broker Team Blog - Aug 26, 2008
This sample shows how to set up a secure dialog using certificates. Service broker will always have a level of security at the transport level, which may include encryption, but this is at a server level of …
Also tagged: certificates, dialogs
Code Junkie - Aug 26, 2008
I just posted a blog entry on our team blog site about Microsoft AntiXSS library. Very important for security minded developers, it address one of the top web application security vulnerabilities. Check it out at …
Satisfy Me - Aug 26, 2008
Be alert as you read your mail today: fake ecards with loaded exe's are once again making the rounds... Oooh, look at the mail that's piling up: "You've received a greeting ecard" How exciting. Not. Today, several …
Being Cellfish - Aug 26, 2008
I was recently involved in a discussion where a company was developing an intra-net site using Apache and PHP on a Windows server. All clients were windows and they wanted to know who was connecting to the intra-net …
Also tagged: php