Sign in
MSDN Blogs
Microsoft Blog Images
More ...
Alik Levin's
Clarity, Technology, and Solving Problems |
PracticeThis.com
This Blog
Blog Home
Email Blog Author
RSS for posts
RSS for comments
Atom
OK
Search
Tags
Architecture
Authentication
Deployment
Development
IIS 7
Information Gathering
Inspection
Security
Test
Tools
Archives
Archives
July 2012
(3)
June 2012
(2)
February 2012
(4)
January 2012
(1)
November 2011
(2)
October 2011
(2)
September 2011
(11)
August 2011
(3)
July 2011
(1)
June 2011
(6)
May 2011
(9)
April 2011
(13)
March 2011
(23)
February 2011
(8)
January 2011
(8)
December 2010
(13)
November 2010
(6)
October 2010
(5)
September 2010
(7)
August 2010
(1)
July 2010
(3)
June 2010
(5)
May 2010
(8)
April 2010
(6)
March 2010
(8)
June 2009
(4)
May 2009
(4)
April 2009
(2)
March 2009
(7)
February 2009
(8)
December 2008
(2)
November 2008
(9)
October 2008
(6)
September 2008
(4)
August 2008
(1)
July 2008
(7)
June 2008
(5)
May 2008
(4)
April 2008
(4)
March 2008
(3)
February 2008
(3)
January 2008
(10)
December 2007
(6)
November 2007
(4)
October 2007
(11)
September 2007
(4)
August 2007
(6)
July 2007
(8)
June 2007
(3)
May 2007
(21)
April 2007
(25)
March 2007
(25)
.Net Security How To's
patterns & practices Security How To's Index
ASP.NET 2.0 Security Questions and Answers
Tamper detection
Authentication Hub
VSTS Resources
Architecture and Design checklists
Securing Sites with IP Address Restrictions
WCF - XSD validation for WCF services
WCF - Message Inspectors
Using Credential Management in Windows XP and Windows Server 2003
WCF - Common Security Scenarios
WCF - Authorization
Validating XML Data with XmlReader
Input Validation - XML Data
Validation - Web Client Software Factory
patterns & practices WCF Security Application Scenarios
Microsoft Identity and Access Management Series
Popular
My Favorite Shortcuts
My Pipeline Is My Inbox
Security .Net Code Inspection Using Outlook 2007
Security Code Inspection - Eternal Search For SQL Injection
.Net Assembly Spoof Attack
Code Inspection - First Look For What To Look For
How To Hack WCF - New Technology, Old Hacking Tricks
Generate Documents Out Of Mail Items Directly From Outlook 2007
ARCast With Ron Jacobs - Defending the Application
How to Use Outlook 2007 RSS To Effectively Aggregate And Distill Information
Impactful
Super Size Me
Billy Eliot
The Legend of 1900
The Terminal
The Counterfeiters
Tools
Fiddler2 Web Debugger - Freeware HTTP(S) debugging tool
Microsoft Network Monitor 3
FxCop Team Page
Microsoft Threat Analysis & Modeling
Windows Sysinternals tools
Log Parser 2.2
p&p Practices Checker - performance
Microsoft ® Windows Server ™ 2003 Performance Advisor
Ajax View
WCat 6.3 (x86)
Funnel Web Analyzer 5.0 for Windows
.Net Performance How To's
Improving .NET Application Performance and Scalability
Exceptional Performance
Performance Testing Guidance How-To's
Fiddler PowerToy - Part 2: HTTP Performance
Performance Testing with Fiddler
Bottleneck-Detection Counters
Troubleshooting Performance Problems in SQL Server 2005
Performance Frame - v2
12 Steps To Faster Web Pages With Visual Round Trip Analyzer
. My Personal Blog .
Practice This
Design Patterns
data & object factory
Yahho Design Pattern Library
Sample .Net 3.0 app
Application Architecture for .NET: Designing Applications and Services
Litware HR - A Multitenant sample application
Microsoft .NET Pet Shop 4.0
Responsive Composite Web Client Reference Implementation
Table of Contents: Introduction to CAB/SCSF
ASP.NET Quickstarts
Microsoft Identity and Access Management Series
Software design patterns
Browse by Tags
MSDN Blogs
>
Alik Levin's
>
All Tags
>
sensitive data
Tag Cloud
Architecture
Authentication
Deployment
Development
IIS 7
Information Gathering
Inspection
Security
Test
Tools
Tagged Content List
Blog Post:
Avoid Manipulating Passwords In Memory - It Is Easy To Reveal
Alik Levin
Revealing clear text passwords in memory seems to be a trivial task. This post describes how to reveal clear text passwords and what countermeasures to apply. Summary of steps: Install WinDbg Attach to process or open dump file Load SOS .Net extensions for WinDbg Enumerate threads ...
on
8 Dec 2007
Blog Post:
IIS 7 Configuration File - applicationHost.config - Password Management
Alik Levin
From my learning of IIS7 I understand that IIS7's metabase is actually XML configuration file very familiar to me and similar to ASP.NET's web.config. It is called applicationHost.config and sits in C:\Windows\System32\inetsrv\config My first interest was to see how it manages passwords when specifying...
on
24 Apr 2007
Blog Post:
Code Inspection - First Look For What To Look For
Alik Levin
Reposted from Security Code Inspection - First Look For What To Look For for further reuse on this blog. I found it extremely productive to first look for strings in the code. But what strings to look for? And how to look for the strings? Looking into the source files? My good friend FindStr is of great...
on
20 Mar 2007
Blog Post:
SecureString Class Two Real Usages And Counting!
Alik Levin
SecureString Class "Represents text that should be kept confidential. The text is encrypted for privacy when being used, and deleted from computer memory when no longer needed. This class cannot be inherited. " I first was very excited about SecureString introduced in .Net FX 2.0 but as I tried to learn...
on
19 Mar 2007
Blog Post:
Google Code Search - Different Perspective
Alik Levin
Google launches a special treat just for developers ... I'd like to present it from some different perspective. Imagine you provide search criteria as follows: " Initial Catalog " - try it. What do you see? More like these here Doesn't it make you want to write more secure code ... :) ? Enjoy
on
5 Mar 2007
Page 1 of 1 (5 items)