Sign in
ACE Team - Security, Performance & Privacy
Common Tasks
Blog Home
Email Blog Author
About
OK
RSS for comments
RSS for posts
Atom
Search Form
Tag Cloud
Anti-XSS
BitLocker
CISF
Consulting
cryptoapi
cryptography
dogfooding
Information Technology
InfoSec Assessment & Protection Suite
Infrastructure
management
Performance
Privacy
Risk Tracker
rules
SDL-IT
secure
Security
Security Tools
Solutions
sql injection
SQL Server
Threat Modeling
Tools
waca
Monthly Archives
Archives
October 2010
(1)
February 2010
(1)
January 2010
(1)
December 2009
(1)
November 2009
(2)
October 2009
(5)
September 2009
(5)
August 2009
(2)
July 2009
(2)
June 2009
(3)
May 2009
(6)
April 2009
(5)
March 2009
(7)
February 2009
(3)
January 2009
(4)
December 2008
(3)
November 2008
(3)
October 2008
(1)
September 2008
(2)
August 2008
(2)
July 2008
(1)
June 2008
(2)
May 2008
(6)
April 2008
(2)
March 2008
(1)
February 2008
(1)
January 2008
(1)
December 2007
(1)
November 2007
(1)
October 2007
(10)
September 2007
(4)
August 2007
(1)
May 2007
(1)
February 2007
(3)
January 2007
(1)
November 2006
(1)
October 2006
(2)
September 2006
(1)
July 2006
(4)
June 2006
(3)
May 2006
(2)
April 2006
(3)
March 2006
(3)
February 2006
(2)
January 2006
(2)
December 2005
(1)
November 2005
(1)
October 2005
(2)
Browse by Tags
MSDN Blogs
>
ACE Team - Security, Performance & Privacy
>
All Tags
>
security tools
Tagged Content List
Blog Post:
XSSDetect FAQ
ACE Team
Hi! This is Hassan Khan. As promissed, here the FAQs on XSSDetect: Q. What is XSSDetect? A. XSSDetect is stripped down version of the Code Analysis Tool for .NET used by the ACE team to help find security vulnerabilities in software applications. It has been made available for free on Microsoft downloads...
on
11 Dec 2007
Blog Post:
XSSDETECT: Analyzing Large Applications
ACE Team
XSSDetect is a static binary analysis tool. In the first step of analysis it reads target binaries to create a directed graph where nodes represent statements while the edges represent flow of data. This graph can get huge for large applications and users can sometimes run into the “out of memory exception...
on
24 Oct 2007
Blog Post:
Update: Some details on how XSSDetect does dataflow analysis
ACE Team
Just a brief update, Hassan Khan one of the lead developers of XSSDetect and part of our ACE Engineering team has posted up some technical details on how XSSDetect uses data flow analysis to do its magic. You can read more about it here . Feel free to leave additional questions and I'm sure he'll follow...
on
24 Oct 2007
Blog Post:
XSSDetect Public Beta now Available!
ACE Team
One of the biggest, constant problems we've seen our enterprise customers deal with and we here at Microsoft have to also contend with is that of the XSS (Cross Site Scripting) bug. It's very common and unfortunately, still an issue we have to deal with in many web applications. Internally, the ACE Team...
on
22 Oct 2007
Blog Post:
ACE's interview with Scoble on Channel 9 - part II & III now up
ACE Team
Hey Folks, part II and III of the Channel 9 interviews are up! You can check out part II here and part III here . Ahmad Mahdi Security Technologist Microsoft – ACE Team ahmad.mahdi
on
29 Oct 2006
Blog Post:
What would you like the ACE team to discuss on Channel 9?
ACE Team
The ACE Team is going to be doing a Channel 9 video with Robert Scoble! (Thanks Robert! :) We’ll get a chance to discuss what we do and how we do it. We’ll also be spending time talking about our threat modeling process and tool (more info as always on our threat modeling blog ). But the real reason...
on
1 May 2006
Blog Post:
Crypto Key Generation & Management
ACE Team
Ever wondered how strong your crypto keys are and whether they are secure against the ever growing threat of being compromised? The threat continues to grow daily in a world where hackers are mounting more sophisticated and complex attacks against a constantly increasing attack surface. The attacks vectors...
on
5 Apr 2006
Blog Post:
What’s the difference between IOSEC and the Microsoft Anti-Cross Site Scripting Library?
ACE Team
Some users who have been using IOSEC, our internal library for defending against cross-site scripting (XSS) attacks, may be wondering what’s the difference between that library and the Microsoft Anti-Cross Site Scripting Library V1.0 at http://www.microsoft.com/downloads/details.aspx?FamilyID=9A2B9C92...
on
19 Mar 2006
Blog Post:
ACE Team Tools and Libraries Part I - IOSEC
ACE Team
Update [3/16/06, 4:56PM] There has been some confusion between what IOSEC does and what the Microsoft Anti-Cross Site Scripting Library does (linked to below). The Anti-XSS library currently has a subset of the functionality of IOSEC. Over the coming weeks and months, we will be porting over additional...
on
13 Mar 2006
Blog Post:
Threat Analysis & Modeling Launch
ACE Team
Over the past several years, the ACE Team has developed and matured a threat modeling methodology for the implementation of software. We've recently started a separate blog for threat modeling & I'd like to invite you to check it out and keep watching it for more details as we get ready to launch...
on
26 Feb 2006
Page 1 of 1 (10 items)