<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US"><title type="html">Anmol Malhotra : Reading a Hacker's Mind</title><subtitle type="html">Lets Talk about SeCuRiTy</subtitle><id>http://blogs.msdn.com/anmolm/atom.xml</id><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/default.aspx" /><link rel="self" type="application/atom+xml" href="http://blogs.msdn.com/anmolm/atom.xml" /><generator uri="http://communityserver.org" version="2.1.61025.2">Community Server</generator><updated>2007-02-18T10:25:00Z</updated><entry><title>New Security Testing Tool is out called - "Watcher" </title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2009/04/17/new-security-testing-tool-is-out-called-watcher.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2009/04/17/new-security-testing-tool-is-out-called-watcher.aspx</id><published>2009-04-17T23:30:00Z</published><updated>2009-04-17T23:30:00Z</updated><content type="html">&lt;P&gt;Talking to Bryan Sullivan on the SDL team last week, I came to know about a cool new security testing tool - "Watcher". This is a plugin to web debuging proxy &lt;A class="" href="http://www.fiddlertool.com/fiddler/" mce_href="http://www.fiddlertool.com/fiddler/"&gt;Fiddler&lt;/A&gt; and checks for more than 35&amp;nbsp;different vulnerabilites.&amp;nbsp; Yes, its Free!!&lt;/P&gt;
&lt;P&gt;This new plugin can be downloaded from &lt;A href="http://websecuritytool.codeplex.com/"&gt;http://websecuritytool.codeplex.com/&lt;/A&gt;. Be sure to install &lt;A class="" href="http://www.fiddlertool.com/fiddler/" mce_href="http://www.fiddlertool.com/fiddler/"&gt;Fiddler&lt;/A&gt; before you install Watcher. For more details on the tool - &lt;A class="" href="http://blogs.msdn.com/sdl/archive/2009/04/16/watcher-a-new-web-security-testing-tool.aspx" mce_href="http://blogs.msdn.com/sdl/archive/2009/04/16/watcher-a-new-web-security-testing-tool.aspx"&gt;Read this blog post.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Happy bug hunting !!&lt;BR&gt;Anmol Malhotra&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9554618" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author><category term="Security Tools" scheme="http://blogs.msdn.com/anmolm/archive/tags/Security+Tools/default.aspx" /><category term="security" scheme="http://blogs.msdn.com/anmolm/archive/tags/security/default.aspx" /></entry><entry><title>Microsoft IT Information Security (InfoSec) - New Site</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2009/03/09/microsoft-it-information-security-infosec-new-site.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2009/03/09/microsoft-it-information-security-infosec-new-site.aspx</id><published>2009-03-10T01:24:00Z</published><updated>2009-03-10T01:24:00Z</updated><content type="html">&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-height-rule: exactly"&gt;&lt;FONT face="Segoe UI"&gt;We’ve recently launched a site on MSDN.&amp;nbsp; Visit Microsoft IT's Information Security (InfoSec) group &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/security/dd547422.aspx" mce_href="http://msdn.microsoft.com/en-us/security/dd547422.aspx"&gt;&lt;FONT face="Segoe UI"&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Segoe UI"&gt;.&amp;nbsp; On the site, you'll find the latest news on InfoSec including security tools, webcasts and “How do I?” videos.&amp;nbsp; If you’re not familiar with InfoSec, we’re responsible for information security risk management at Microsoft.&amp;nbsp; We’ll let you know as new information is posted to our site.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-height-rule: exactly"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face="Segoe UI"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: white; MARGIN: 0in 0in 0pt; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-height-rule: exactly"&gt;&lt;FONT face="Segoe UI"&gt;Microsoft IT Information Security (InfoSec)&lt;BR&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;A href="http://msdn.microsoft.com/en-us/security/dd547422.aspx" mce_href="http://msdn.microsoft.com/en-us/security/dd547422.aspx"&gt;http://msdn.microsoft.com/en-us/security/dd547422.aspx&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: white; MARGIN: 0in 0in 0pt; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-height-rule: exactly"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: white; MARGIN: 0in 0in 0pt; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-height-rule: exactly"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: white; MARGIN: 0in 0in 0pt; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-height-rule: exactly"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Anmol Malhotra&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: white; MARGIN: 0in 0in 0pt; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-height-rule: exactly"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Information Security&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9468253" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author><category term="security" scheme="http://blogs.msdn.com/anmolm/archive/tags/security/default.aspx" /><category term="Microsoft Information Security" scheme="http://blogs.msdn.com/anmolm/archive/tags/Microsoft+Information+Security/default.aspx" /><category term="MS-IT" scheme="http://blogs.msdn.com/anmolm/archive/tags/MS-IT/default.aspx" /></entry><entry><title>February 25, 2009:  MSDN Webcast  Software Security with Static Code Analysis Using CAT.NET (Level 200)</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2009/02/16/february-25-2009-msdn-webcast-software-security-with-static-code-analysis-using-cat-net-level-200.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2009/02/16/february-25-2009-msdn-webcast-software-security-with-static-code-analysis-using-cat-net-level-200.aspx</id><published>2009-02-16T22:37:00Z</published><updated>2009-02-16T22:37:00Z</updated><content type="html">&lt;P class=MsoNormal style="MARGIN: 9pt 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;A href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032402660&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;CLICK HERE TO REGISTER NOW&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 9pt 0in 0pt"&gt;&lt;B&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Presenter:&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 9pt 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;Andreas Fuchsberger, Senior Software Design Engineer, Microsoft Corporation&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;Summary&lt;/B&gt;:&amp;nbsp; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;In this webcast, we provide an overview of what static code analysis is and typical coding errors that static analysis can and cannot detect. We also look at the recently released CAT.NET tool and how it helps with the detection of security flaws.&lt;/FONT&gt;&lt;/P&gt;&lt;FONT face=Calibri size=3&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;BR&gt;Thanks,&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Anmol Malhotra&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Senior Security Engineer.&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9426359" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author><category term="Security Tools" scheme="http://blogs.msdn.com/anmolm/archive/tags/Security+Tools/default.aspx" /><category term="ACE Team" scheme="http://blogs.msdn.com/anmolm/archive/tags/ACE+Team/default.aspx" /></entry><entry><title>Discover the New HelloSecureWorld Security Resource </title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2008/02/01/discover-the-new-hellosecureworld-security-resource.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2008/02/01/discover-the-new-hellosecureworld-security-resource.aspx</id><published>2008-02-01T09:10:00Z</published><updated>2008-02-01T09:10:00Z</updated><content type="html">&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman','serif'; mso-ansi-language: EN-US; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;
&lt;P&gt;&lt;A href="http://www.hellosecureworld.com/" mce_href="http://www.hellosecureworld.com/"&gt;&lt;FONT color=#777777&gt;www.HelloSecureWorld.com&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;provides a powerful experience for promoting security awareness and education in the developer community by surfacing existing content as well as new.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Well, If you&amp;nbsp;like learning while having FUN then&amp;nbsp;hellosecureworld.com is the resource for you. It brings&amp;nbsp;non traditional ways to&amp;nbsp;provide security awareness and education among the developer community&amp;nbsp;- Virtual lab environment,&amp;nbsp;hands on labs, tutorials, videos, play attack defender games&amp;nbsp;and much more.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy Learning !!&lt;BR&gt;&lt;BR&gt;- Anmol&lt;/P&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=7368487" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author></entry><entry><title>First Line of Defense for Web Applications - Blog series</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2008/01/14/first-line-of-defense-for-web-applications-blog-series.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2008/01/14/first-line-of-defense-for-web-applications-blog-series.aspx</id><published>2008-01-14T10:00:00Z</published><updated>2008-01-14T10:00:00Z</updated><content type="html">&lt;P&gt;Hello folks, &lt;/P&gt;
&lt;P&gt;I just completed my blog series on Input Validation Strategies on our hackers blog - &lt;A href="http://blogs.msdn.com/hackers"&gt;http://blogs.msdn.com/hackers&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;Dan Cornell &lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: EN-US; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;summarized &lt;/SPAN&gt;this series&amp;nbsp;perfectly on his blog &lt;A href="http://denimgroup.typepad.com/denim_group/2008/01/first-line-of-d.html"&gt;http://denimgroup.typepad.com/denim_group/2008/01/first-line-of-d.html&lt;/A&gt;&amp;nbsp;- here is what he had to say - &lt;BR&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;H3 class=entry-header&gt;First Line of Defense for Web Applications - Series of Great MSDN Blog Posts&lt;/H3&gt;
&lt;DIV class=entry-content&gt;
&lt;DIV class=entry-body&gt;
&lt;P&gt;By Dan Cornell&lt;/P&gt;
&lt;P&gt;&lt;A onclick="window.open(this.href, '_blank', 'width=704,height=528,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://denimgroup.typepad.com/.shared/image.html?/photos/uncategorized/2008/01/08/atvsonbeach.jpg"&gt;&lt;IMG title=Atvsonbeach height=281 alt=Atvsonbeach src="http://denimgroup.typepad.com/denim_group/images/2008/01/08/atvsonbeach.jpg" width=375 border=0&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;There is a fantastic set of blog posts over on the &lt;A href="http://blogs.msdn.com/hackers/default.aspx"&gt;&lt;FONT color=#ff9900&gt;Hackers blog on MSDN&lt;/FONT&gt;&lt;/A&gt; taking a deep look at input validation. Input validation is the most important thing you can do to make applications safer from malicious attackers.&amp;nbsp; If input validation is implemented well, you can even have glaring vulnerabilities in your application code but have the validation layer render them unexploitable or at least reduce the impact.&amp;nbsp; This isn't true all the time and input validation won't protect against many classes of attack, but starting with input validation as your foundation puts you in a position to avoid a lot of really silly, easy to find and exploit vulnerabilities.&lt;/P&gt;
&lt;P&gt;The installments are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://blogs.msdn.com/hackers/archive/2007/10/12/first-line-of-defense-for-web-applications-part-1.aspx"&gt;&lt;FONT color=#cc6600&gt;Part 1: Why Bother?&lt;/FONT&gt;&lt;/A&gt; 
&lt;LI&gt;&lt;A href="http://blogs.msdn.com/hackers/archive/2007/10/30/first-line-of-defense-for-web-applications-part-2.aspx"&gt;&lt;FONT color=#cc6600&gt;Part 2: What Should You Validate?&lt;/FONT&gt;&lt;/A&gt; 
&lt;LI&gt;&lt;A href="http://blogs.msdn.com/hackers/archive/2007/10/30/first-line-of-defense-for-web-applications-part-3.aspx"&gt;&lt;FONT color=#cc6600&gt;Part 3: Validation Strategies&lt;/FONT&gt;&lt;/A&gt; 
&lt;LI&gt;&lt;A href="http://blogs.msdn.com/hackers/archive/2007/11/12/first-line-of-defense-for-web-applications-part-4.aspx"&gt;&lt;FONT color=#ff9900&gt;Part 4: Top Bloopers - Cross Site Scripting (XSS)&lt;/FONT&gt;&lt;/A&gt; 
&lt;LI&gt;&lt;A href="http://blogs.msdn.com/hackers/archive/2007/12/16/first-line-of-defense-for-web-applications-part-5.aspx"&gt;&lt;FONT color=#ff9900&gt;Part 5: Top Bloopers - SQL Injection&lt;/FONT&gt;&lt;/A&gt; 
&lt;LI&gt;&lt;A href="http://blogs.msdn.com/hackers/archive/2008/01/06/first-line-of-defense-for-web-applications-conclusion.aspx"&gt;&lt;FONT color=#cc6600&gt;Conclusion: ASP.NET Platform Features&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;My favorite part about this series are the examples in parts &lt;A href="http://blogs.msdn.com/hackers/archive/2007/11/12/first-line-of-defense-for-web-applications-part-4.aspx"&gt;&lt;FONT color=#ff9900&gt;4&lt;/FONT&gt;&lt;/A&gt; and &lt;A href="http://blogs.msdn.com/hackers/archive/2007/12/16/first-line-of-defense-for-web-applications-part-5.aspx"&gt;&lt;FONT color=#ff9900&gt;5&lt;/FONT&gt;&lt;/A&gt;.&amp;nbsp; They go through common, ineffective protection measures that teams implement and provide examples of attack payloads that circumvent these protections.&amp;nbsp; This is great information because a lot of development teams are using these ineffective protection mechanisms ("we replace every ' character with '' to prevent SQL injection...") and think that they are safe.&amp;nbsp; Having a set of clear and concise counter-examples is very useful in being able to see how applications remain exposed.&lt;/P&gt;
&lt;P&gt;The series of articles also does a great job of demonstrating how black-list (negative) validation is a not-very-secure and ultimately brittle approach to validation.&amp;nbsp; They even provide an example of how the &lt;A href="http://www.procheckup.com/Vulner_PR0703.php"&gt;&lt;FONT color=#cc6600&gt;built-in ASP.NET Cross Site Scripting (XSS) protection (based on black-list validation) has been defeated in the past&lt;/FONT&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Even though there are a lot of ASP.NET specific examples, the principles covered in these posts apply to anyone developing applications deployed in a hostile environment - regardless of implementation platform.&lt;/P&gt;
&lt;P&gt;--Dan&lt;BR&gt;dan _at_ denimgroup.com&lt;/P&gt;
&lt;DIV class=entry-content&gt;
&lt;DIV class=entry-body&gt;
&lt;P&gt;PS - I took the photo while riding ATVs on the beaches in Costa Rica last fall.&lt;/P&gt;
&lt;P&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P mce_keep="true"&gt;Thanks &amp;amp; Stay Secure&lt;BR&gt;Anmol Malhotra&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=7105352" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author><category term="XSS" scheme="http://blogs.msdn.com/anmolm/archive/tags/XSS/default.aspx" /><category term="input validation" scheme="http://blogs.msdn.com/anmolm/archive/tags/input+validation/default.aspx" /><category term="security" scheme="http://blogs.msdn.com/anmolm/archive/tags/security/default.aspx" /><category term="web security" scheme="http://blogs.msdn.com/anmolm/archive/tags/web+security/default.aspx" /></entry><entry><title>XSSDetect Public Beta now Available! </title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2007/10/23/xssdetect-public-beta-now-available.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2007/10/23/xssdetect-public-beta-now-available.aspx</id><published>2007-10-23T04:55:00Z</published><updated>2007-10-23T04:55:00Z</updated><content type="html">&lt;H5 class=posthead&gt;XSSDetect is available for download now. It's tool which helps identify Cross Site Scripting Vulnerabilities in .NET code. &lt;/H5&gt;
&lt;P&gt;XSSDetect runs as a Visual Studio plug-in and can detect potential XSS issues in managed code.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Here's a screenshot:&lt;/P&gt;
&lt;P&gt;&lt;IMG title=XSSDetect style="WIDTH: 507px; HEIGHT: 359px" height=359 alt=XSSDetect src="http://blogs.msdn.com/photos/ace_team/images/5611754/original.aspx" width=507 align=middle mce_src="http://blogs.msdn.com/photos/ace_team/images/5611754/original.aspx"&gt;&lt;/P&gt;
&lt;P&gt;More information including link to download available &lt;A class="" title=XSSDetect href="http://blogs.msdn.com/ace_team/archive/2007/10/22/xssdetect-public-beta-now-available.aspx" mce_href="http://blogs.msdn.com/ace_team/archive/2007/10/22/xssdetect-public-beta-now-available.aspx"&gt;&lt;FONT color=#0000cc&gt;here&lt;/FONT&gt;&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Anmol Malhotra&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5613768" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author><category term="Security Tools" scheme="http://blogs.msdn.com/anmolm/archive/tags/Security+Tools/default.aspx" /><category term="Cross site scripting" scheme="http://blogs.msdn.com/anmolm/archive/tags/Cross+site+scripting/default.aspx" /><category term="XSS" scheme="http://blogs.msdn.com/anmolm/archive/tags/XSS/default.aspx" /></entry><entry><title>How to Prove your Digital Identity? </title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2007/10/13/how-to-prove-your-digital-identity.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2007/10/13/how-to-prove-your-digital-identity.aspx</id><published>2007-10-13T08:49:00Z</published><updated>2007-10-13T08:49:00Z</updated><content type="html">&lt;H1 style="MARGIN: 24pt 0in 0pt"&gt;&lt;A class="" title=_Toc166948252 name=_Toc166948252&gt;&lt;/A&gt;&lt;SPAN lang=EN-IN style="FONT-SIZE: 18pt; COLOR: #365f91; FONT-FAMILY: 'Cambria','serif'; mso-ansi-language: EN-IN; mso-bidi-font-family: Arial"&gt;Abstract:&lt;/SPAN&gt;&lt;SPAN style="mso-bookmark: _Toc166948252"&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN-IN style="FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: EN-IN"&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN-IN style="FONT-WEIGHT: normal; FONT-SIZE: 18pt; COLOR: #365f91; FONT-FAMILY: 'Cambria','serif'; mso-ansi-language: EN-IN; mso-bidi-font-family: Arial"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;I&gt;&lt;SPAN lang=EN-IN style="mso-ansi-language: EN-IN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;With the dawn of the internet, online businesses and millions of applications have become part of our lives. But these application and its users does face many challenges. Applications level threats have grown tremendously. Online identity threat, phishing and privacy concerns are on a rise. Almost everyone today has a digital identity and amount of accounts and passwords are getting difficult to track. This paper aims in understanding all you need to know about different ways to prove your identity to authenticate against an application. It discusses present methods like passwords, digital certificates, smart cards to authenticate identities and moves on introducing windows cardspace to manage diverse digital identities effectively. Limitation of each technology and application specific scenarios where these different methods are effective will also be discussed.&lt;/SPAN&gt;&lt;/I&gt;&lt;I&gt;&lt;SPAN lang=EN-IN style="mso-ansi-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;H1 style="MARGIN: 24pt 0in 0pt"&gt;&lt;A class="" title=_Toc166948253 name=_Toc166948253&gt;&lt;/A&gt;&lt;SPAN lang=EN-IN style="FONT-SIZE: 18pt; COLOR: #365f91; FONT-FAMILY: 'Cambria','serif'; mso-ansi-language: EN-IN; mso-bidi-font-family: Arial"&gt;What is a Digital identity?&lt;/SPAN&gt;&lt;SPAN style="mso-bookmark: _Toc166948253"&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN-IN style="FONT-FAMILY: 'Times New Roman','serif'; mso-ansi-language: EN-IN"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-IN style="mso-ansi-language: EN-IN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;There are tons of definitions out there for the word Identity. One of the most interesting one which I observed is the one from Webster’s dictionary which describes identity as “Collective aspect of the set of characteristics by which a thing is recognizable or known.” It is the sameness of essential character, individuality, or the fact of being the same person as one claims to be. So your identity can include your name, age, your social security number, your DNA, birthmarks, fingerprints, or simply characteristics of your body. Just as the word suggests your identity is something by which you can be identified.&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-IN style="mso-ansi-language: EN-IN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;In the physical world each and every one of us are uniquely identified and we possess identity proofs for different purposes. Physical identities ranges from your country issued passport, driving licences, to social security number and credit cards, etc. We can’t even imagine a world without identification, if would have been a nightmare if people did not have names and identity proofs in the physical world. Identities have the same importance in the digital world as well.&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN-IN style="mso-ansi-language: EN-IN"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-IN style="mso-ansi-language: EN-IN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;But fact today is that we not only live in our physical world but with the tremendous growth of internet where businesses have grown from leaps and bounds, we all live in this digital world as well. &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-IN style="mso-ansi-language: EN-IN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;When you identify yourself to this digital world with information about who you are is actually a digital identity which is being represented. Digital identity is how you get identified on the World Wide Web. According to Wikipedia Digital identity also has another common usage as the &lt;/SPAN&gt;&lt;SPAN lang=EN-IN style="mso-ansi-language: EN-IN"&gt;&lt;A title=Digital href="http://en.wikipedia.org/wiki/Digital" mce_href="http://en.wikipedia.org/wiki/Digital"&gt;&lt;SPAN style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT color=#0000ff&gt;digital&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN-IN style="mso-ansi-language: EN-IN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt; representation of a set of claims made by one &lt;/SPAN&gt;&lt;SPAN lang=EN-IN style="mso-ansi-language: EN-IN"&gt;&lt;A title="Digital identity" href="http://en.wikipedia.org/wiki/Digital_identity#Digital_subject" mce_href="http://en.wikipedia.org/wiki/Digital_identity#Digital_subject"&gt;&lt;SPAN style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT color=#0000ff&gt;digital subject&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN-IN style="mso-ansi-language: EN-IN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt; about itself or another digital subject. A digital subject is an entity represented or existing in the digital realm which is being described or dealt with. Digital subjects can be living or non living. They can be humans, devices or computers, web servers or digital resources. &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN-IN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;We all have many difficult to manage digital identities as we do in the physical world. Online banking applications, personal and official emails, online communities, blogs and the list goes on and on. &lt;BR&gt;--------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN-IN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;Above is just a glimpse of my&amp;nbsp;new&amp;nbsp;paper&amp;nbsp;around&amp;nbsp;Digital Identities.&amp;nbsp;&lt;BR&gt;&amp;nbsp;&lt;BR&gt;I have started writing&amp;nbsp;on&amp;nbsp;digital identities and various authentication mechanisms&amp;nbsp;available to prove your digital identity- past, present and future.&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN-IN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;Stay tuned for more..... &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN-IN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;- Anmol Malhotra&lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN-IN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-ansi-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;Security Consultant&lt;BR&gt;ACE Services Team&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN lang=EN-IN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5435847" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author><category term="Authentication" scheme="http://blogs.msdn.com/anmolm/archive/tags/Authentication/default.aspx" /><category term="Digital Identity" scheme="http://blogs.msdn.com/anmolm/archive/tags/Digital+Identity/default.aspx" /></entry><entry><title>I am in Redmond now.....</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2007/09/23/i-am-in-redmond-now.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2007/09/23/i-am-in-redmond-now.aspx</id><published>2007-09-24T01:32:00Z</published><updated>2007-09-24T01:32:00Z</updated><content type="html">&lt;P&gt;Hello folks, &lt;/P&gt;
&lt;P&gt;It's been a while since my last blog. Well&amp;nbsp;I have been keeping busy with relocating all the way from India to US. Yes, I have now joined Microsoft -Redmond team. Leaving a country is not all an easy task folks but i am glad things went well.&amp;nbsp; &lt;BR&gt;Well I am liking it here &amp;amp; I will be back in action on my blog with lot of intresting things about security&amp;nbsp; very soon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Stay Tuned........&lt;/P&gt;
&lt;P&gt;Cheers,&lt;BR&gt;Anmol Malhotra&lt;BR&gt;Security Consultant&lt;BR&gt;ACE Services&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5082148" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author><category term="Personal" scheme="http://blogs.msdn.com/anmolm/archive/tags/Personal/default.aspx" /></entry><entry><title>Web Application Security Basics - Strong Naming an Assembly </title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2007/07/02/web-application-security-basics-part-1.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2007/07/02/web-application-security-basics-part-1.aspx</id><published>2007-07-02T17:21:00Z</published><updated>2007-07-02T17:21:00Z</updated><content type="html">&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; COLOR: navy; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt"&gt;&lt;B&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US"&gt;Strong Naming an Assembly:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US"&gt; Assembly should be strongly named &lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US"&gt;à&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US"&gt; Proves the integrity of the Assembly and provides a means using which an Assembly is uniquely identified. &lt;/SPAN&gt;&lt;SPAN lang=EN-US style="mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;Concept: &lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;To&lt;B&gt; &lt;/B&gt;prove the integrity of the assembly, firstly the hash of the assembly is taken and then encrypted with the private key of the publisher. The related public key is kept in the manifest of the assembly along with the assembly name and the name of the algorithm used for hashing. &lt;/SPAN&gt;&lt;SPAN lang=EN-US style="mso-ansi-language: EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 108pt; TEXT-INDENT: -18pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;1) Genrate the key pair using sn utility (sn –k file.key)&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="mso-ansi-language: EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 108pt; TEXT-INDENT: -18pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;2)&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 7pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;Extract the public key (sn –p file.key pub.key)&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="mso-ansi-language: EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 108pt; TEXT-INDENT: -18pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;3)&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 7pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;Make delaysign = true&amp;nbsp;so that the program can use the dll.&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="mso-ansi-language: EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 108pt; TEXT-INDENT: -18pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;4)&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 7pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;To push it in GAC use register verification skipping option (sn –Vr dll)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 108pt; TEXT-INDENT: -18pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 108pt; TEXT-INDENT: -18pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: red; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;Best Practices / checklist &lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 54pt; TEXT-INDENT: 18pt"&gt;&lt;B&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: red; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;&lt;/SPAN&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 108pt; TEXT-INDENT: -18pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Wingdings; mso-ansi-language: EN-US"&gt;þ&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 7pt; COLOR: navy; mso-ansi-language: EN-US"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;Check for the [assembly: AssemblyKeyFile (@ “C:\Key\xyz.snk”)] directive in the assembly.cs file. &lt;/SPAN&gt;&lt;SPAN lang=EN-US style="mso-ansi-language: EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 108pt; TEXT-INDENT: -18pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Wingdings; mso-ansi-language: EN-US"&gt;þ&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 7pt; COLOR: navy; mso-ansi-language: EN-US"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;Check for the size of xyz.snk file it should be of just 160 bytes (if it consists just the public key). If it is of 596 bytes( it contains both public and private key).&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="mso-ansi-language: EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 108pt; TEXT-INDENT: -18pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Wingdings; mso-ansi-language: EN-US"&gt;þ&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 7pt; COLOR: navy; mso-ansi-language: EN-US"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;Recommend for delay signing the assembly while in the Test UAT. &lt;/SPAN&gt;&lt;SPAN lang=EN-US style="mso-ansi-language: EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 108pt; TEXT-INDENT: -18pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Wingdings; mso-ansi-language: EN-US"&gt;þ&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 7pt; COLOR: navy; mso-ansi-language: EN-US"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-ansi-language: EN-US"&gt;Recommend to keep the Private key in a folder properly ACL’d while resigning it during shipping the assembly into production. (sn –R dll file.key).&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="mso-ansi-language: EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2012264" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author><category term="Application Security" scheme="http://blogs.msdn.com/anmolm/archive/tags/Application+Security/default.aspx" /></entry><entry><title>TechMela'07 My Threat Modeling Session details........</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2007/06/09/techmela-07-my-threat-modeling-session-details.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2007/06/09/techmela-07-my-threat-modeling-session-details.aspx</id><published>2007-06-09T13:44:00Z</published><updated>2007-06-09T13:44:00Z</updated><content type="html">&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;Folks,&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;Here are my session details for TechMela 2007&lt;BR&gt;&lt;BR&gt;My deep dive session is scheduled for &lt;STRONG&gt;16th June : 11:00 AM to 12:00 PM &lt;/STRONG&gt;: Threat Modeling Strategy for LOB applications.&lt;BR&gt;&lt;BR&gt;You can checkout more details here... &lt;A href="http://www.techmela.com/speaker.htm"&gt;http://www.techmela.com/speaker.htm&lt;/A&gt;&amp;nbsp;&amp;amp; detailed agenda from &lt;A href="http://www.techmela.com/tec_agenda.htm"&gt;http://www.techmela.com/tec_agenda.htm&lt;/A&gt;&amp;nbsp;link.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;See you,&lt;BR&gt;Anmol Malhotra&lt;BR&gt;Security Consultant&lt;BR&gt;ACE Services &lt;BR&gt;anmol(dot)malhotra(at)microsoft.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3181857" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author><category term="TechMela" scheme="http://blogs.msdn.com/anmolm/archive/tags/TechMela/default.aspx" /></entry><entry><title>ACE is Hiring again ................ Security Folks in Hyderabad India</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2007/06/06/ace-is-hiring-again-security-folks-in-hyderabad-india.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2007/06/06/ace-is-hiring-again-security-folks-in-hyderabad-india.aspx</id><published>2007-06-06T12:44:00Z</published><updated>2007-06-06T12:44:00Z</updated><content type="html">&lt;P&gt;Hi Guys,&lt;BR&gt;&lt;BR&gt;We are Hiring in Microsoft ACE- Application Consulting and Engineering Team. Positions are based out of Hyderabad, India campus. We are looking for folks with profile something similar to this- &lt;A href="http://blogs.msdn.com/ace_team/archive/2006/07/14/666013.aspx"&gt;http://blogs.msdn.com/ace_team/archive/2006/07/14/666013.aspx&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are passionate about Security &amp;amp; have the zeal, we would like to hear from you. &lt;BR&gt;&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;Keep it secure,&lt;/P&gt;
&lt;P&gt;Cheers,&lt;BR&gt;Anmol Malhotra&lt;BR&gt;Security Consultant&lt;BR&gt;ACE Services&lt;BR&gt;anmolm(at)microsoft(dot)com&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3113385" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author><category term="ACE Team" scheme="http://blogs.msdn.com/anmolm/archive/tags/ACE+Team/default.aspx" /></entry><entry><title>I am gonna Rock TechMela 2007 [13th - 16th June]</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2007/06/01/i-am-gonna-rock-techmela-2007.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2007/06/01/i-am-gonna-rock-techmela-2007.aspx</id><published>2007-06-01T14:35:00Z</published><updated>2007-06-01T14:35:00Z</updated><content type="html">&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;Hi guys,&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;IMG title=www.techmela.com style="WIDTH: 425px; HEIGHT: 62px" height=62 alt=www.techmela.com src="http://blogs.msdn.com/photos/anmolm/images/3023272/425x62.aspx" width=425 mce_src="http://blogs.msdn.com/photos/anmolm/images/3023272/425x62.aspx"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;I am going to present deep dive session on Threat Modeling Process and our very own &lt;A class="" href="http://www.microsoft.com/downloads/details.aspx?familyid=59888078-9daf-4e96-b7d1-944703479451&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?familyid=59888078-9daf-4e96-b7d1-944703479451&amp;amp;displaylang=en "&gt;Threat&amp;nbsp;analysis and modeling Tool&lt;/A&gt; - TAM in TechMela 2007 in Mumbai [13th - 16th June]&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;For more information on the event registerations, sessions or speakers check out &lt;A href="http://www.techmela.com/"&gt;http://www.techmela.com&lt;/A&gt; &lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;See&amp;nbsp;you in mumbai.........&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;Here is the&amp;nbsp;my session title and abstract...&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;Session Title&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="COLOR: #1f497d"&gt; :&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Threat Modeling Strategy for Line Of Business applications.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: #1f497d"&gt;Abstract&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="COLOR: #1f497d"&gt; :&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;To protect your applications and build a secure system, it is imperative that you identify and understand all of the potential threats to your applications. Threat modeling is an increasingly valuable discipline, and one that should form part of your application design phase.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The process of threat modeling is built on a simple principle: in order to feasibly build a secure system, one must understand all the threats in that system. The challenge, however, has been to make threat modeling easily adoptable by and beneficial for non-security information technology professionals (business owners, architects, developers, testers, etc.). With over 3 years of experience in threat modeling, Microsoft has developed and refined a threat modeling process to a point where minimal input (non-security related!) is used to produce a feature rich threat model used to manage the risk to software applications during the SDLC and beyond.&amp;nbsp; Using the Microsoft Threat Analysis &amp;amp; Modeling v2.1 tool, application development teams can create a threat model that helps detect security flaws and evaluate application threats and vulnerabilities.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;BR&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;This session will go over this threat modeling process, outline its benefits, showcase the Threat Analysis &amp;amp;&amp;nbsp; Modeling tool [TAM] and show how threat modeling fits into the Microsoft Security Development Lifecycle (SDL) for IT.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;Cheers&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;Anmol Malhotra&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;Security Consultant&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;anmol(dot)malhotra(at)microsoft.com &lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&lt;IMG title=www.techmela.com style="WIDTH: 200px; HEIGHT: 100px" height=100 alt=www.techmela.com src="http://blogs.msdn.com/photos/anmolm/images/3023323/original.aspx" width=200 mce_src="http://blogs.msdn.com/photos/anmolm/images/3023323/original.aspx"&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 36pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3023233" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author><category term="TechMela" scheme="http://blogs.msdn.com/anmolm/archive/tags/TechMela/default.aspx" /><category term="Threat Modeling" scheme="http://blogs.msdn.com/anmolm/archive/tags/Threat+Modeling/default.aspx" /></entry><entry><title>Cross – Site Scripting Test Case - </title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2007/05/08/cross-site-scripting-test-cases.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2007/05/08/cross-site-scripting-test-cases.aspx</id><published>2007-05-08T17:26:00Z</published><updated>2007-05-08T17:26:00Z</updated><content type="html">&lt;P class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 36pt; TEXT-INDENT: -18pt; mso-list: l0 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol; mso-fareast-language: EN-IN"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-IN"&gt;Check for&amp;nbsp;persistent Cross attack-Site Scripting bugs through the input form fields&lt;BR&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 36pt; TEXT-INDENT: -18pt; mso-list: l0 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-IN"&gt;Steps: &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 72pt; TEXT-INDENT: -18pt; mso-list: l0 level2 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 72.0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'; mso-fareast-language: EN-IN"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-IN"&gt;Identify entry points that collect user input such as Form inputs [e.g text boxes], query string parameters, etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 72pt; TEXT-INDENT: -18pt; mso-list: l0 level2 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 72.0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'; mso-fareast-language: EN-IN"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-IN"&gt;Check if the user input saved to database and same data is fetched back and rendering back to screen.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;UL type=circle&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l0 level2 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 72.0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-IN"&gt;Enter this : &amp;lt;Script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt; , "&amp;gt;&amp;lt;script&amp;gt;('XSS')&amp;lt;/script&amp;gt; , ;alert('XSS') , ');alert('XSS') , javascript:alert('XSS')&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l0 level2 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 72.0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-IN"&gt;In data rendering page, If this pops up an alert box saying “XSS” attack was successful.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l0 level2 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 72.0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'; mso-fareast-language: EN-IN"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-IN"&gt;Depending on the context of the output this payload might need more tweaking. Do a View Source to find where &amp;amp; how the input was echoed back. &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l0 level2 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 72.0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-IN"&gt;&lt;o:p&gt;Cheers,&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l0 level2 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 72.0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-IN"&gt;&lt;o:p&gt;Anmol Malhotra&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l0 level2 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 72.0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-IN"&gt;&lt;o:p&gt;Security Consultant&lt;BR&gt;ACE Services&lt;BR&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2012313" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author></entry><entry><title>Is there a Firewall for Humans ?? </title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2007/04/02/social-engineering-at-its-best.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2007/04/02/social-engineering-at-its-best.aspx</id><published>2007-04-02T15:05:00Z</published><updated>2007-04-02T15:05:00Z</updated><content type="html">&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;&amp;lt;Alice&amp;gt; Good Morning, this is Company’s Technical Support, I am Alice speaking, how can I help you?&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;&amp;lt;Bob&amp;gt; Hi Good Morning Alice, this is Bob Davis- Head of Marketing and sales. I am in the middle of a presentation with one of the biggest customers in our state, but I am unable to access my account remotely. Can you please reset my password?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;&amp;lt;Alice&amp;gt; uuuh, Sir I am not sure I can do that now&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;&amp;lt;Bob&amp;gt; I need to demo our latest emailing system or we will lose this opportunity. Do you want our company should lose this million dollar contract for a stupid password? I am unable to RAS in right now &amp;amp; I can’t let my customer waiting any more. Our company reputation is at stake. Now can you get this thing done for me??? &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;&amp;lt;Alice&amp;gt;hmm ohh ok sir, give me a minute &amp;amp; I will reset your password&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;&amp;lt;Bob&amp;gt; Thanks a ton! Appreciate your help Alice. My account name is smartbob &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;&amp;lt;Alice&amp;gt; Your password has been reset. Please try connecting now. it is Qa89%500&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;&amp;lt;Bob&amp;gt; Got that. Thanks again.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;Above is a typical case of a social engineering attack. This kind of attack can only be mitigated by User Educations and awareness. Technology can aid in protection but it has its own limits. Vista has some cool features to protect users falling in attackers trap. &lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;
&lt;P&gt;Learning how to spot social engineering techniques is the next step and the new Windows Vista operating system makes that easier to do:&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;
&lt;TABLE class="" cellSpacing=0 cellPadding=0 border=0&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class=listBullet vAlign=top class="listBullet"&gt;•&lt;/TD&gt;
&lt;TD class=listItem class="listItem"&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/athome/security/online/ie7.mspx" mce_href="http://www.microsoft.com/athome/security/online/ie7.mspx"&gt;Internet Explorer 7&lt;/A&gt; is available for Windows Vista and has a &lt;A href="http://www.microsoft.com/athome/security/online/phishing_filter.mspx" mce_href="http://www.microsoft.com/athome/security/online/phishing_filter.mspx"&gt;Phishing Filter&lt;/A&gt; built in that scans and alerts users to potentially harmful phishing sites.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=listBullet vAlign=top class="listBullet"&gt;•&lt;/TD&gt;
&lt;TD class=listItem class="listItem"&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/windows/products/windowsvista/features/details/parentalcontrols.mspx" mce_href="http://www.microsoft.com/windows/products/windowsvista/features/details/parentalcontrols.mspx"&gt;Windows Vista Parental Controls&lt;/A&gt; offer parental controls for children to help prevent kids &lt;A href="http://www.microsoft.com/athome/security/spyware/kidsspyware1.mspx" mce_href="http://www.microsoft.com/athome/security/spyware/kidsspyware1.mspx"&gt;from downloading unwanted software&lt;/A&gt;.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=listBullet vAlign=top class="listBullet"&gt;•&lt;/TD&gt;
&lt;TD class=listItem class="listItem"&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/athome/security/spyware/software/default.mspx" mce_href="http://www.microsoft.com/athome/security/spyware/software/default.mspx"&gt;Windows Defender&lt;/A&gt; helps you avoid spyware and other malicious software that can be part of a social engineering scam. &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=listBullet vAlign=top class="listBullet"&gt;•&lt;/TD&gt;
&lt;TD class=listItem class="listItem"&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/windowsvista/features/foreveryone/security.mspx#more" mce_href="http://www.microsoft.com/windowsvista/features/foreveryone/security.mspx#more"&gt;User Account Control &lt;/A&gt;built into Windows Vista requires your consent before allowing a potentially dangerous program to run. This helps reduce the impact of viruses, spyware, and other threats you might encounter through social engineering. &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-bidi-font-size: 12.0pt"&gt;More information @ &lt;A href="http://www.microsoft.com/athome/security/email/socialengineering.mspx" mce_href="http://www.microsoft.com/athome/security/email/socialengineering.mspx"&gt;http://www.microsoft.com/athome/security/email/socialengineering.mspx&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=1676258" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author></entry><entry><title>Security Tools for Testers- Part II</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/anmolm/archive/2007/02/18/security-tools-for-testers-part-ii.aspx" /><id>http://blogs.msdn.com/anmolm/archive/2007/02/18/security-tools-for-testers-part-ii.aspx</id><published>2007-02-18T13:25:00Z</published><updated>2007-02-18T13:25:00Z</updated><content type="html">&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;Welcome to the Security Tools for Testers Part II, in Part I we looked at security tools available for developers which can enable them to indentify security issues upfront in the development cycle. Let’s move up the chain and see what tools testers can leverage when they&amp;nbsp;test web applications. &lt;/SPAN&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;STRONG&gt;&lt;SPAN lang=EN-US style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN-US; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi"&gt;1. HTTP Debuggers type tools&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;Fiddler -&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Public version V1.2 is available at&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN lang=EN-US style="mso-ansi-language: EN-US"&gt;&lt;A href="http://www.fiddlertool.com/fiddler" mce_href="http://www.fiddlertool.com/fiddler"&gt;&lt;FONT color=#0000ff&gt;http://www.fiddlertool.com/fiddler&lt;/FONT&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;Single liner = Fiddler allows you to fiddle with HTTP traffic :) &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;Basically it is an HTTP debugging proxy that logs all HTTP traffic between your computer and the Internet. Fiddler enables you to inspect all HTTP traffic, set breakpoints, and "fiddle" with incoming or outgoing data.&amp;nbsp;Fiddler can investigate SSL&amp;nbsp;http connections&amp;nbsp;as well. &amp;nbsp;Fiddler is a tool to be used by security testers who are looking for vulnerabilities in Web applications or client applications that integrate with the Web. &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;it has powerful features where you can intercept a request, change it &amp;amp; send it to the server OR you can intercept a response , change it &amp;amp; then send it to the client. You can even replay a captured session by hand crafting a custom request. very cool feature.....&amp;nbsp; now let’s hit the nail question -&amp;nbsp;What all security issues can fiddler help me indentify?&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l2 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: Arial"&gt;Input validation issues - specifically bypassing client side validations&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l2 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: Arial"&gt;Cross site scripting issues - fiddle with Query string, forms fields etc to verify this&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l2 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: Arial"&gt;SQL injection issues&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l2 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: Arial"&gt;Authorization issues &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l2 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: Arial"&gt;Information disclosure&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l2 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: Arial"&gt;Many more.....&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;IMO if testers while conducting functional testing on the web applications, can also test for these low hanging fruits security issues&amp;nbsp;, using tools like fiddler, we can really decrease&amp;nbsp;the number of security issues which pass on to our productions systems.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;&lt;IMG title=Fiddler style="WIDTH: 500px; HEIGHT: 324px" height=421 alt=Fiddler src="http://blogs.msdn.com/photos/anmolm/images/1704532/original.aspx" width=547 mce_src="http://blogs.msdn.com/photos/anmolm/images/1704532/original.aspx"&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman','serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;2. Network Analyzers &lt;/SPAN&gt;&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;STRONG&gt;&lt;SPAN lang=EN-US style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN-US; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi"&gt;NetMon 3.0&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt; has been released&amp;nbsp; &amp;amp; i am in love with this tool:) specially&amp;nbsp;with the powerful filter feature&amp;nbsp;which allows you to&amp;nbsp;filter captured or displayed packets. It has got a brand new User interface and many cool features. Network monitor is a sniffer tool which can help you analyze network traffic.&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;With Network Monitor, you can: &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l0 level1 lfo2; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: Arial"&gt;Capture frames (packets) directly from the network.&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l0 level1 lfo2; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: Arial"&gt;Display and filter the captured frames&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l0 level1 lfo2; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: Arial"&gt;Much more&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;Network monitor 3.0 &amp;nbsp;has a command line tool as well to capture traffic. You can use the ‘Nmcap.exe’ tool to capture frames without the GUI. This tool is available in the Network Monitor 3 installation directory.&lt;BR&gt;From a testing perspective, netmon can help you identify -&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman','serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l1 level1 lfo3; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: Arial"&gt;verify if the communication channel is in clear or encrypted text (very important)&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l1 level1 lfo3; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: Arial"&gt;identify performance bottlenecks&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-list: l1 level1 lfo3; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list 36.0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: Arial"&gt;This tool will come in handy when you are reviewing a third party thick client &amp;amp; are not sure of the communication channel (clear or encrypted) it is talking on.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;Where to find Network Monitor 3.0 ? -- simply click the link below....:)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;A title=http://blogs.technet.com/netmon/default.aspx href="http://blogs.technet.com/netmon/default.aspx"&gt;http://blogs.technet.com/netmon/default.aspx&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;Cheers,&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;SPAN lang=EN-US style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN-US"&gt;&lt;FONT face=Calibri size=3&gt;Anmol Malhotra&lt;/FONT&gt;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=1703259" width="1" height="1"&gt;</content><author><name>anmolm</name><uri>http://blogs.msdn.com/members/anmolm.aspx</uri></author><category term="Security Tools" scheme="http://blogs.msdn.com/anmolm/archive/tags/Security+Tools/default.aspx" /></entry></feed>