Sign in
Michael Howard's Web Log
A Simple Software Security Guy at Microsoft!
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Tags
General
Pages
Personal
Privacy
Rant
Security
Vista
Archive
Archives
September 2009
(1)
July 2009
(1)
May 2009
(2)
March 2009
(1)
December 2008
(2)
November 2008
(3)
October 2008
(3)
September 2008
(7)
August 2008
(5)
July 2008
(3)
June 2008
(1)
May 2008
(1)
April 2008
(5)
March 2008
(5)
February 2008
(4)
January 2008
(9)
December 2007
(4)
November 2007
(4)
October 2007
(6)
September 2007
(1)
August 2007
(2)
July 2007
(4)
June 2007
(13)
May 2007
(6)
April 2007
(8)
March 2007
(11)
February 2007
(4)
January 2007
(8)
December 2006
(4)
November 2006
(15)
October 2006
(5)
September 2006
(6)
August 2006
(6)
July 2006
(2)
June 2006
(7)
May 2006
(8)
April 2006
(2)
March 2006
(5)
February 2006
(6)
January 2006
(10)
December 2005
(2)
November 2005
(2)
October 2005
(1)
September 2005
(4)
August 2005
(5)
July 2005
(5)
June 2005
(3)
May 2005
(9)
April 2005
(8)
March 2005
(5)
February 2005
(9)
January 2005
(7)
December 2004
(7)
November 2004
(9)
October 2004
(11)
August 2004
(13)
July 2004
(4)
June 2004
(12)
May 2004
(17)
April 2004
(2)
March 2004
(2)
February 2004
(3)
January 2004
(2)
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Michael Howard's Web Log
Improve Security with "A Layer of Hurt"
Posted
over 5 years ago
by
Michael Howard
1
Comments
I just wrote a post over on the SDL blog about how to get started with fuzzing,...
Michael Howard's Web Log
Insecure 3rd party software updaters
Posted
over 5 years ago
by
Michael Howard
3
Comments
Gotta love Robert's sarcasm .. but he's right.
Michael Howard's Web Log
SQL Server and the Windows Server 2008 Firewall
Posted
over 5 years ago
by
Michael Howard
8
Comments
SDL alum, Shawn Hernan (now in the SQL Server team), has written an excellent post about SQL Server 2008, Windows Server 2008 and the impact of the firewall being enabled by default in Windows Server 2008, the first time we have enabled a firewall by...
Michael Howard's Web Log
More on Heap Corruption and Process Termination
Posted
over 5 years ago
by
Michael Howard
1
Comments
I just added a post over on the SDL blog about heap corruption and process termination as well as some caveats you should be aware of if you use your own custom heap manager.
Michael Howard's Web Log
Giving SQL Injection the Respect it Deserves
Posted
over 5 years ago
by
Michael Howard
2
Comments
I just posted an article on the SDL blog about the recent news of SQL injection vulnerabilities...
Michael Howard's Web Log
Crispin has a blog!
Posted
over 5 years ago
by
Michael Howard
1
Comments
It had to happen. Since joining Microsoft a few short months ago, Crispin Cowen now has a blog . He's told me some of his ideas for posts... should make for an interesting read! He's never short on opinion.
Michael Howard's Web Log
Oh No! Security Metrics!
Posted
over 5 years ago
by
Michael Howard
1
Comments
I just posted an article over on the SDL blog about security metrics in reponse to an analyst's criticisms of how we measure success/failure/progress. Comments always welcome. UPDATE David Litchfield just made a post on the subjet.
Michael Howard's Web Log
Microsoft Security Development Lifecycle (SDL) 3.2 documentation now available for download
Posted
over 5 years ago
by
Michael Howard
3
Comments
Dave Ladd has just made a (long) post over on the SDL blog announcing the availability of the SDL 3.2 doc suite. This is a big deal.
Michael Howard's Web Log
Internet Explorer 8.0 and Data Execution Prevention (DEP/NX)
Posted
over 5 years ago
by
Michael Howard
4
Comments
Eric Lawrence just posted some commentary about IE8 and DEP/NX. As you may know, IE7 supports DEP/NX, but it's disabled by default owing to compatibility issues. Well, DEP/NX is now enabled by default for IE8 when running on Windows Server 2008 and Window...
Michael Howard's Web Log
When adding security bugs to your code is not your fault!
Posted
over 5 years ago
by
Michael Howard
19
Comments
David LeBlanc and I (and a bunch of others) just had a little email exchange about some fascinating integer overflow vulnerabilities in gcc . Long story made short: the code you add to detect integer overflows might actually be removed by the compiler...
Michael Howard's Web Log
"How Do I?" Videos for Security
Posted
over 5 years ago
by
Michael Howard
6
Comments
These are pretty cool - I'm a big fan of highly focused, short education like this... http://msdn2.microsoft.com/en-us/security/bb896640.aspx
Michael Howard's Web Log
IE8 Activity to lookup CVEs and Microsoft bulletins
Posted
over 5 years ago
by
Michael Howard
2
Comments
Update: Added Microsoft bulletin stuff. I'm always looking up CVEs so I want to get to the data as quickly as possible, especially if I'm digging through a load of them. Three years ago I posted some code to perform CVE lookup using Smart Tags in...
Michael Howard's Web Log
Protecting Your Code with Visual C++ Defenses
Posted
over 5 years ago
by
Michael Howard
6
Comments
MSDN Magazine has just published an article I wrote that collects many of the various C and C++ defenses in the current Visual C++ compiler suite, all of these defenses are SDL requirements or recommendations.
Michael Howard's Web Log
The impact of the SDL on Microsoft SQL Server
Posted
over 5 years ago
by
Michael Howard
1
Comments
Following on from my recent post about Windows Vista security and the SDL, a number of people have indicated to me that obvioulsy it's a fluke. It's important to point out that the reason I talk about Windows Vista so much is because I work in the Windows...
Michael Howard's Web Log
Some thoughts about Windows Server 2008
Posted
over 5 years ago
by
Michael Howard
11
Comments
Windows Server 2008 has shipped! And a fine product it is, too! Windows Server 2008 is the first Windows Server to go through the full SDL process, making it the most secure version of Windows Server to date. We raised the security bar in Windows Vista...
Michael Howard's Web Log
The First Step on the Road to More Secure Software is admitting you have a Problem
Posted
over 5 years ago
by
Michael Howard
9
Comments
I just wrote an article over on the SDL blog about my observations from the industry to Jeff Jones' vulnerability analysis and the lack of security progress by our competitors.
Michael Howard's Web Log
FAQ about HeapSetInformation in Windows Vista and Heap Based Buffer Overruns
Posted
over 5 years ago
by
Michael Howard
6
Comments
2/19 - Added some Minor Tweaks Perhaps it's the phase of the moon or something, but over the last few weeks I have received more email about correctly using the HeapSetInformation function than any other topic. I really don't know why! This was added...
Michael Howard's Web Log
Introducing SAFECode
Posted
over 5 years ago
by
Michael Howard
6
Comments
Today SAFECode , the Software Assurance Forum for Excellence in Code, introduced its first white paper, "Software Assurance: An Overview of Current Industry Best Practices." The organization was founded by Microsoft, Symantec, EMC, SAP and Juniper...
Michael Howard's Web Log
More trustworthy election systems via SDL?
Posted
over 5 years ago
by
Michael Howard
1
Comments
My colleague Eric Bidstrup has just posted a thought provoking article on the SDL blog about elections software and the SDL.
Michael Howard's Web Log
New NX APIs added to Windows Vista SP1, Windows XP SP3 and Windows Server 2008
Posted
over 5 years ago
by
Michael Howard
27
Comments
In the interests of helping secure the platform, we want more people to opt-in to using Data Execution Prevention (aka DEP aka NX), and we have lowered the barrier to entry for application developers in Windows Vista SP1, Windows XP SP3 and Windows Server...
Michael Howard's Web Log
My Daughter will never be a Spy
Posted
over 5 years ago
by
Michael Howard
2
Comments
My kids are desperate for pets; my six-year old son wants a dog (note, a dog, not a puppy!) and my 4-year old daughter wants a cat. The worse part is my wife keeps egging the kids on, and says she'll get the a pet when I'm next out of town. Tonite...
Michael Howard's Web Log
Windows Vista Crypto Modules now FIPS 140-2 Certified
Posted
over 5 years ago
by
Michael Howard
2
Comments
The standard crypto providers such as DSSENH and RSAENH are now certified FIPS 140-2 on Windows Vista. http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/1401val2008.htm has all the info.
Michael Howard's Web Log
Crispin Cowan joins the Windows Security Team!
Posted
over 5 years ago
by
Michael Howard
18
Comments
I am delighted to announce that Crispin Cowan has joined the core Windows Security Team! For those of you who don’t know Crispin, Crispin is responsible for a number of very well respected Linux-based security technologies such as StackGuard, the...
Michael Howard's Web Log
Timely Microsoft Office 2003 SP3 Advice from David LeBlanc
Posted
over 5 years ago
by
Michael Howard
1
Comments
http://blogs.msdn.com/david_leblanc/archive/2008/01/16/a-good-reason-to-install-sp3.aspx
Michael Howard's Web Log
Cry or Smile? You Decide...
Posted
over 5 years ago
by
Michael Howard
9
Comments
On Wednesday Mark Curphey emailed me about a conversation his team had with a customer. I see he has now blogged about the conversation. Here's an excerpt. When a customers [sic, you need to learn some simple grammar, Curphey!] development team...
Page 2 of 14 (341 items)
1
2
3
4
5
»