Sign In
Michael Howard's Web Log
A Simple Software Security Guy at Microsoft!
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
General
Pages
Personal
Privacy
Rant
Security
Vista
Archive
Archives
September 2009
(1)
July 2009
(1)
May 2009
(2)
March 2009
(1)
December 2008
(2)
November 2008
(3)
October 2008
(3)
September 2008
(7)
August 2008
(5)
July 2008
(3)
June 2008
(1)
May 2008
(1)
April 2008
(5)
March 2008
(5)
February 2008
(4)
January 2008
(9)
December 2007
(4)
November 2007
(4)
October 2007
(6)
September 2007
(1)
August 2007
(2)
July 2007
(4)
June 2007
(13)
May 2007
(6)
April 2007
(8)
March 2007
(11)
February 2007
(4)
January 2007
(8)
December 2006
(4)
November 2006
(15)
October 2006
(5)
September 2006
(6)
August 2006
(6)
July 2006
(2)
June 2006
(7)
May 2006
(8)
April 2006
(2)
March 2006
(5)
February 2006
(6)
January 2006
(10)
December 2005
(2)
November 2005
(2)
October 2005
(1)
September 2005
(4)
August 2005
(5)
July 2005
(5)
June 2005
(3)
May 2005
(9)
April 2005
(8)
March 2005
(5)
February 2005
(9)
January 2005
(7)
December 2004
(7)
November 2004
(9)
October 2004
(11)
August 2004
(13)
July 2004
(4)
June 2004
(12)
May 2004
(17)
April 2004
(2)
March 2004
(2)
February 2004
(3)
January 2004
(2)
May, 2005
MSDN Blogs
>
Michael Howard's Web Log
>
May, 2005
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Michael Howard's Web Log
Hidden Message in Writing Secure Code 2nd Ed
Posted
over 7 years ago
by
Michael Howard
9
Comments
I've been meaning to write about this for a year or so, but for some reason I simply keep forgetting to do it! There's a hidden message in WSC 2nd ed. Since the book's release, only one person has found it. Here's a clue: it's in plain sight :)
Michael Howard's Web Log
File Checksum Integrity Verifier utility
Posted
over 7 years ago
by
Michael Howard
0
Comments
Every once in a while I come across an old piece of email, or a document I archived that contains a little nugget; well, I just stumbled on one on a backup DVD. Last year, Microsoft made available a tool named the File Checksum Integrity Verifier (FCIV...
Michael Howard's Web Log
Writing Secure Web Browsers is Hard
Posted
over 7 years ago
by
Michael Howard
3
Comments
I'm not making excuses, just stating facts. In fact, I just read this from SANS... emphasis is mine. http://www.sans.org/newsletters/newsbites/newsbites.php?vol=7&issue=19 Fixes Not Yet Available for Firefox Vulnerabilities (9 May 2005) Two...
Michael Howard's Web Log
Microsoft unveils details of software security process
Posted
over 7 years ago
by
Michael Howard
0
Comments
My colleague, Window Snyder presented last week at CanSecWest about some of the 'fun' we had getting Windows XP SP2 out the door. You can read some of her comments and analysis at SecurityFocus. http://www.securityfocus.com/news/11115
Michael Howard's Web Log
Comments on recent Firefox security bugs
Posted
over 7 years ago
by
Michael Howard
0
Comments
As you are no doubt aware, a couple of pretty nasty security defects have been found in the latest FireFox bits that allow remote code execution. The IE team has made some very gracious comments here about the issue. The official word about the...
Michael Howard's Web Log
Visio Connector for MBSA available
Posted
over 7 years ago
by
Michael Howard
2
Comments
This is kinda cool - a Visio connector that hooks up to the output from the Microsoft Baseline Security Analyzer (MBSA.) From the blurb: At a glance, you'll be able to: Pinpoint vulnerabilities on the color-coded diagram. Identify solutions...
Michael Howard's Web Log
Microsoft Windows Security Resource Kit, Second Edition Released
Posted
over 7 years ago
by
Michael Howard
0
Comments
Just spotted this while catching up on (lots of) email. So what's new in the Second Edition? In addition to the expected error correction and clarification that always accompanies new versions, coverage of Windows Server 2003, including SP1 and Windows...
Michael Howard's Web Log
More Integer Overflow stuff
Posted
over 7 years ago
by
Michael Howard
2
Comments
I think I've said this a billion times, but I'll say it again. No-one has done more research into integer overflow (and underflow, and truncation and signed-ness) issues than my good friend and co-author, David LeBlanc. So here's the great news - he...
Michael Howard's Web Log
Is Microsoft IIS 6.0 more secure than Apache HTTP Server 2.0?
Posted
over 7 years ago
by
Michael Howard
0
Comments
A couple of months ago I presented at an event called the "Microsoft Technology Summit" to some very smart folks who focus primarily on non-Microsoft technologies. I outlined the security process stuff we're doing here (Security Development Lifecycle...
Page 1 of 1 (9 items)