Sign In
ACE Team - Security, Performance & Privacy
Translate This Page
Translate this page
Powered by
Microsoft® Translator
October, 2007
Common Tasks
Blog Home
Email Blog Author
About
OK
RSS for comments
RSS for posts
Atom
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
Anti-XSS
BitLocker
CISF
Consulting
cryptoapi
cryptography
dogfooding
Information Technology
InfoSec Assessment & Protection Suite
Infrastructure
management
Performance
Privacy
Risk Tracker
rules
SDL-IT
secure
Security
Security Tools
Solutions
sql injection
SQL Server
Threat Modeling
Tools
waca
Monthly Archives
Archives
October 2010
(1)
February 2010
(1)
January 2010
(1)
December 2009
(1)
November 2009
(2)
October 2009
(5)
September 2009
(5)
August 2009
(2)
July 2009
(2)
June 2009
(3)
May 2009
(6)
April 2009
(5)
March 2009
(7)
February 2009
(3)
January 2009
(4)
December 2008
(3)
November 2008
(3)
October 2008
(1)
September 2008
(2)
August 2008
(2)
July 2008
(1)
June 2008
(2)
May 2008
(6)
April 2008
(2)
March 2008
(1)
February 2008
(1)
January 2008
(1)
December 2007
(1)
November 2007
(1)
October 2007
(10)
September 2007
(4)
August 2007
(1)
May 2007
(1)
February 2007
(3)
January 2007
(1)
November 2006
(1)
October 2006
(2)
September 2006
(1)
July 2006
(4)
June 2006
(3)
May 2006
(2)
April 2006
(3)
March 2006
(3)
February 2006
(2)
January 2006
(2)
December 2005
(1)
November 2005
(1)
October 2005
(2)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
ACE Team - Security, Performance & Privacy
XSSDETECT: Analyzing Large Applications
Posted
over 5 years ago
by
ACE Team
4
Comments
XSSDetect is a static binary analysis tool. In the first step of analysis it reads target binaries to create a directed graph where nodes represent statements while the edges represent flow of data. This graph can get huge for large applications and users...
ACE Team - Security, Performance & Privacy
Update: Some details on how XSSDetect does dataflow analysis
Posted
over 5 years ago
by
ACE Team
2
Comments
Just a brief update, Hassan Khan one of the lead developers of XSSDetect and part of our ACE Engineering team has posted up some technical details on how XSSDetect uses data flow analysis to do its magic. You can read more about it here . Feel free to...
ACE Team - Security, Performance & Privacy
XSSDetect Public Beta now Available!
Posted
over 5 years ago
by
ACE Team
39
Comments
One of the biggest, constant problems we've seen our enterprise customers deal with and we here at Microsoft have to also contend with is that of the XSS (Cross Site Scripting) bug. It's very common and unfortunately, still an issue we have to deal with...
ACE Team - Security, Performance & Privacy
ASP.NET ValidateRequest does not mitigate XSS completely
Posted
over 5 years ago
by
ACE Team
3
Comments
From Eugene Siu's blog: http://blogs.msdn.com/esiu/archive/2007/10/19/asp-net-validaterequest-does-not-mitigate-xss-completely.aspx As a security guy, I can safely say that there is no magic bullet to mitigate any security problems completely, and cross...
ACE Team - Security, Performance & Privacy
Is Microsoft Office Isolated Conversion Environment(MOICE) mocha on ice?
Posted
over 5 years ago
by
ACE Team
4
Comments
From Eugene Siu's blog: http://blogs.msdn.com/esiu/archive/2007/10/19/is-microsoft-office-isolated-conversion-environment-moice-mocha-on-ice.aspx MOICE may sound like mocha on ice, but it is really a strong dark espresso shot offered by Office TWC team...
ACE Team - Security, Performance & Privacy
Given enough eyeballs all bugs are shallow: True or False?
Posted
over 5 years ago
by
ACE Team
3
Comments
From Eugene Siu's blog: http://blogs.msdn.com/esiu/archive/2007/10/11/given-enough-eyeballs-all-bugs-are-shallow-true-or-false.aspx "Given enough eyeballs all bugs are shallow." I do agree if more right-minded folks look at a piece of code, it would help...
ACE Team - Security, Performance & Privacy
System.URI.AbsolutePath Vs Phishing Attack
Posted
over 5 years ago
by
ACE Team
1
Comments
From Eugene Siu's blog: http://blogs.msdn.com/esiu/archive/2007/10/10/system-uri-absolutepath-vs-phishing-attack.aspx Phishing attack can be caused by users inadvertently clicking on malicious links in emails or web pages, which then forward requests...
ACE Team - Security, Performance & Privacy
Web Service Security Guidance
Posted
over 5 years ago
by
ACE Team
1
Comments
From Eugene Siu's blog ( http://blogs.msdn.com/esiu/archive/2007/10/10/web-service-security-guidance.aspx ): I have just published a Technet article. This is geared for administrators and developers as an introduction to web service security. It contains...
ACE Team - Security, Performance & Privacy
Mark Curphey joins Microsoft's ACE Team
Posted
over 5 years ago
by
ACE Team
4
Comments
Mark joined ACE as of Oct. 1st and we're very glad to have him aboard! The following is a note from Mark: As is the tradition around these parts I wanted to introduce myself as the newest member of the ACE Team. My name is Mark Curphey and I’ll be...
ACE Team - Security, Performance & Privacy
More eyeballs for .Net Framework code
Posted
over 5 years ago
by
ACE Team
1
Comments
From Eugene Siu's blog Microsoft will open up source code of .Net Framework to the public. It allows outsiders to review what is under the hood, and enables easier debugging of development projects around .Net Framework. .Net Framework code has been reviewed...
Page 1 of 1 (10 items)