Sign In
Michael Howard's Web Log
A Simple Software Security Guy at Microsoft!
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
General
Pages
Personal
Privacy
Rant
Security
Vista
Archive
Archives
September 2009
(1)
July 2009
(1)
May 2009
(2)
March 2009
(1)
December 2008
(2)
November 2008
(3)
October 2008
(3)
September 2008
(7)
August 2008
(5)
July 2008
(3)
June 2008
(1)
May 2008
(1)
April 2008
(5)
March 2008
(5)
February 2008
(4)
January 2008
(9)
December 2007
(4)
November 2007
(4)
October 2007
(6)
September 2007
(1)
August 2007
(2)
July 2007
(4)
June 2007
(13)
May 2007
(6)
April 2007
(8)
March 2007
(11)
February 2007
(4)
January 2007
(8)
December 2006
(4)
November 2006
(15)
October 2006
(5)
September 2006
(6)
August 2006
(6)
July 2006
(2)
June 2006
(7)
May 2006
(8)
April 2006
(2)
March 2006
(5)
February 2006
(6)
January 2006
(10)
December 2005
(2)
November 2005
(2)
October 2005
(1)
September 2005
(4)
August 2005
(5)
July 2005
(5)
June 2005
(3)
May 2005
(9)
April 2005
(8)
March 2005
(5)
February 2005
(9)
January 2005
(7)
December 2004
(7)
November 2004
(9)
October 2004
(11)
August 2004
(13)
July 2004
(4)
June 2004
(12)
May 2004
(17)
April 2004
(2)
March 2004
(2)
February 2004
(3)
January 2004
(2)
May, 2004
MSDN Blogs
>
Michael Howard's Web Log
>
May, 2004
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Michael Howard's Web Log
Updated info about Threat Modeling tool
Posted
over 8 years ago
by
Michael Howard
5
Comments
If you are getting a user breakpoint when generating a threat model report or using the threat model preview for a threat model with Visio diagrams and you have Visio installed, it may be because stdole’s primary interop assembly (PIA) wasn’t...
Michael Howard's Web Log
Threat Modeling tool now available
Posted
over 8 years ago
by
Michael Howard
7
Comments
Finally, it has been posted - Frank Swiderski's Threat modeling tool is now available for free download on MSDN. From the blurb: The Threat Modeling Tool allows users to create threat model documents for applications. It organizes relevant data...
Michael Howard's Web Log
Why Blaster did not infect Windows Server 2003
Posted
over 8 years ago
by
Michael Howard
10
Comments
I've been meaning to write about this for some time, but while pondering over my very dead laptop (it won't even get to the “Choose an OS to boot' option”, I remembered. The code which Blaster took advantage of was in the released version...
Michael Howard's Web Log
The Antivirus Defense-in-Depth Guide Released to Web
Posted
over 8 years ago
by
Michael Howard
6
Comments
Finally got out of war, and saw this in my inbox... The Microsoft Solutions for Security (MSS) team has released The Antivirus Defense-in-Depth Guide on the Web ( http://go.microsoft.com/fwlink/?LinkId =28734 ) I just had a look at it, and it's...
Michael Howard's Web Log
Hackers Hacked by Hackers (!?)
Posted
over 8 years ago
by
Michael Howard
3
Comments
Here I am, in Windows XPSP2 war again, and there's another debate about how best to binplace some DLLs. So while catching up on some email I saw this funny (as in - “ha ha ha”) story. http://www.theinquirer.net/?article=16050
Michael Howard's Web Log
Do you hate security updates?
Posted
over 8 years ago
by
Michael Howard
5
Comments
I realize the weekend is almost upon us, so I thought I'd share something a little light-hearted. The folks at Microsoft Japan know how to make security bulletins lively and “unboring“. Check this out... www.microsoft.com/japan/security...
Michael Howard's Web Log
Security Management
Posted
over 8 years ago
by
Michael Howard
3
Comments
I'm really not a security infrastructure guy, I leave that to others, from whom I learn a great deal. One such person is my colleague, Jesper Johansson. He now has his own column on TechNet entitled, “Security Management.” If you manage a...
Michael Howard's Web Log
Transmeta chips to support 'NX'
Posted
over 8 years ago
by
Michael Howard
4
Comments
It' 9:55AM and I'm sitting in Windows XP SP2 War; there's a little debate going on which has nothing to do with security, so I thought I'd write this :) As you may be aware Windows XP SP2 will support “No Execute” or “NX”, which...
Michael Howard's Web Log
IT Security at Microsoft Overview
Posted
over 8 years ago
by
Michael Howard
3
Comments
Very, very cool doc. From the document “Overview discussion on what the Microsoft Corporate Security group does to prevent malicious or unauthorized use of digital assets at Microsoft. This asset protection takes place through a formal risk management...
Michael Howard's Web Log
Security Guidance Training for Developers
Posted
over 8 years ago
by
Michael Howard
9
Comments
Over the last few weeks a bunch of security Microsofties have been talking to customers about some of the lessons we have learned, best practices and so on. We have now made that training available through an eLearning center. There are three courses...
Michael Howard's Web Log
How to think about Security
Posted
over 8 years ago
by
Michael Howard
5
Comments
Rewind to Yesterday I remember the early days very well; I’d get an email from someone asking for the best way to do something securely. It would usually be a relatively vague email, like, “how do we protect our network traffic?” or...
Michael Howard's Web Log
Security in Microsoft Products - a chat with Mike Nash
Posted
over 8 years ago
by
Michael Howard
3
Comments
Join me on Thursday (May 13, 2004 9:00am Pacific/12:00pm Eastern) in our monthly security chat with Mike Nash, VP of the Security Business and Technology unit, of which I'm a part. The Chat room is at http://communities2.microsoft.com/home/chatroom.aspx...
Michael Howard's Web Log
Administering Windows Servers through one port
Posted
over 8 years ago
by
Michael Howard
11
Comments
A couple of months ago, I presented at a Financial Services Chief Security Officer’s forum here in Redmond about threat modeling and secure design. One question, totally unrelated to secure design, but still a great question, was how an admin can...
Michael Howard's Web Log
The Spread of the Witty Worm
Posted
over 8 years ago
by
Michael Howard
3
Comments
Thanks to Joel Scambray (coauthor of the Hacking Exposed series of books) for bringing this to my attention. Not many people paid much attention to this worm, because it affected a non-Microsoft product, but the analysis is interesting nevertheless...
Michael Howard's Web Log
Sasser Arrest
Posted
over 8 years ago
by
Michael Howard
2
Comments
Just in case you haven't seen this, there's been an arrest in Germany of an 18yr old accused of creating the Sasser worm. Read an article by Rob Lemos of C|Net here .
Michael Howard's Web Log
An Update on the Windows Server 2003 Vulnerability Count
Posted
over 8 years ago
by
Michael Howard
8
Comments
A few weeks back, I posted an article about some of the progress we had made after 292d of the release of Windows 2000 and Windows Server 2003. One criticism I have heard of these figures is that we measured security bulletins differently in Windows 2000...
Michael Howard's Web Log
Why 'Sasser' does not affect Win2003
Posted
over 8 years ago
by
Michael Howard
16
Comments
As you may be aware, a new worm has emerged named, 'Sasser', and Windows Server 2003 is not infected. Why? Because the RPC interface, which is accessible to anyone (ie; anonymous) on Windows XP and Win2000, was changed in Win2003 so that it requires a...
Page 1 of 1 (17 items)