Sign in
Michael Howard's Web Log
A Simple Software Security Guy at Microsoft!
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Tags
General
Pages
Personal
Privacy
Rant
Security
Vista
Archive
Archives
September 2009
(1)
July 2009
(1)
May 2009
(2)
March 2009
(1)
December 2008
(2)
November 2008
(3)
October 2008
(3)
September 2008
(7)
August 2008
(5)
July 2008
(3)
June 2008
(1)
May 2008
(1)
April 2008
(5)
March 2008
(5)
February 2008
(4)
January 2008
(9)
December 2007
(4)
November 2007
(4)
October 2007
(6)
September 2007
(1)
August 2007
(2)
July 2007
(4)
June 2007
(13)
May 2007
(6)
April 2007
(8)
March 2007
(11)
February 2007
(4)
January 2007
(8)
December 2006
(4)
November 2006
(15)
October 2006
(5)
September 2006
(6)
August 2006
(6)
July 2006
(2)
June 2006
(7)
May 2006
(8)
April 2006
(2)
March 2006
(5)
February 2006
(6)
January 2006
(10)
December 2005
(2)
November 2005
(2)
October 2005
(1)
September 2005
(4)
August 2005
(5)
July 2005
(5)
June 2005
(3)
May 2005
(9)
April 2005
(8)
March 2005
(5)
February 2005
(9)
January 2005
(7)
December 2004
(7)
November 2004
(9)
October 2004
(11)
August 2004
(13)
July 2004
(4)
June 2004
(12)
May 2004
(17)
April 2004
(2)
March 2004
(2)
February 2004
(3)
January 2004
(2)
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Michael Howard's Web Log
New hire into our group - James Whittaker
Posted
over 7 years ago
by
Michael Howard
9
Comments
I’m pleased to announce, actually I’m *thrilled* to announce, that James Whittaker has joined our group. James is a well-known author and speaker on software testing and security. He most recently worked as a professor of computer science at Florida Tech...
Michael Howard's Web Log
IIS Auth Diagnostic tool now available
Posted
over 9 years ago
by
Michael Howard
1
Comments
Ages ago, I wrote a little DHTML tool to help people determine the appropriate authentication settings to use with different browsers, servers and Web servers. It helped a good many people, but it was simple. Today, the IIS team has released a much more...
Michael Howard's Web Log
Windows Vista Address Space Layout Randomization – What is Randomized?
Posted
over 7 years ago
by
Michael Howard
7
Comments
A couple of people asked what “on by default” means with regards to ASLR in Windows Vista. The ‘default’ for ASLR in Windows Vista is: • Stacks and Heap are randomized (stack-randomization is on post-Beta 2) • EXEs and DLLs shipping as part...
Michael Howard's Web Log
File Checksum Integrity Verifier utility
Posted
over 8 years ago
by
Michael Howard
0
Comments
Every once in a while I come across an old piece of email, or a document I archived that contains a little nugget; well, I just stumbled on one on a backup DVD. Last year, Microsoft made available a tool named the File Checksum Integrity Verifier (FCIV...
Michael Howard's Web Log
Security Analogies are usually Wrong
Posted
over 7 years ago
by
Michael Howard
30
Comments
I have long believed that if someone makes an argument and uses an analogy, then the argument is often weak. But that’s just me! This is why I usually roll my eyes when I hear statements like, “If [bridges|cars|airplanes] were built like software then...
Michael Howard's Web Log
Some thoughts about Windows Server 2008
Posted
over 5 years ago
by
Michael Howard
11
Comments
Windows Server 2008 has shipped! And a fine product it is, too! Windows Server 2008 is the first Windows Server to go through the full SDL process, making it the most secure version of Windows Server to date. We raised the security bar in Windows Vista...
Michael Howard's Web Log
Threat Modeling tool now available
Posted
over 9 years ago
by
Michael Howard
7
Comments
Finally, it has been posted - Frank Swiderski's Threat modeling tool is now available for free download on MSDN. From the blurb: The Threat Modeling Tool allows users to create threat model documents for applications. It organizes relevant data...
Michael Howard's Web Log
Address Space Layout Randomization for Windows
Posted
over 8 years ago
by
Michael Howard
6
Comments
A small company named Wehnus run by Matt Miller has put together a comprehensive Windows Based host-based intrusion prevention system (HIPS) system called WehnTrust ( http://www.wehnus.com ) that uses Address Space Layout Randomization (ASLR) among other...
Michael Howard's Web Log
“Microsoft Dynamics Writing Secure X++ Code” Paper now available
Posted
over 7 years ago
by
Michael Howard
2
Comments
In June 2006, Microsoft released Dynamics AX 4.0, which was the first full version to be developed in Microsoft using the Security Development Lifecycle (SDL). A key deliverable by this team is a document on security considerations for Dynamics AX development...
Michael Howard's Web Log
A New Way to Detect Integer Overflows?
Posted
over 9 years ago
by
Michael Howard
10
Comments
David LeBlanc and I have written a good deal about Integer Overflow issues, including the following: WSC 2nd Ed: pp620-624. Reviewing Code for Integer Manipulation Vulnerabilities ( http://msdn.microsoft.com/library/en-us/dncode/html/secure04102003.asp...
Michael Howard's Web Log
ATL, MS09-035 and the SDL
Posted
over 4 years ago
by
Michael Howard
0
Comments
http://blogs.msdn.com/sdl/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx
Michael Howard's Web Log
Windows Vista Security Enhancements
Posted
over 7 years ago
by
Michael Howard
12
Comments
A paper has just been made available that outlines some of the security improvements in Windows Vista Beta 2.
Michael Howard's Web Log
Hidden Message in Writing Secure Code 2nd Ed
Posted
over 8 years ago
by
Michael Howard
9
Comments
I've been meaning to write about this for a year or so, but for some reason I simply keep forgetting to do it! There's a hidden message in WSC 2nd ed. Since the book's release, only one person has found it. Here's a clue: it's in plain sight :)
Michael Howard's Web Log
Hotmail and SAFER bug
Posted
over 8 years ago
by
Michael Howard
3
Comments
So we've found a small bug in Hotmail when using the SAFER/IE stuff (big thanks to Kody Dickerson to alerting me.) Turns out Hotmail will hang when you start it up if you have Hotmail running under a SAFER context, and MSN messenger running as the "normal...
Michael Howard's Web Log
Office2003/XP Remove Hidden Data tool Available
Posted
over 9 years ago
by
Michael Howard
8
Comments
I've been meaning to write about this for ages. So here goes, better late than never! Many people, quite rightly, are concerned that sensitive or private data can reside in the metadata of documents created by productivity applications, such as Microsoft...
Michael Howard's Web Log
Some of us are *NOT* in Las Vegas!
Posted
over 7 years ago
by
Michael Howard
8
Comments
I suppose someone has to keep the home fires burning! Seriously, it's great to see the Windows Vista presentations were well received at Black Hat 2006: Microsoft gets good reception at Black Hat . That being said, one of the advantages of half the team...
Michael Howard's Web Log
RootkitRevealer from SysInternals
Posted
over 8 years ago
by
Michael Howard
0
Comments
I haven't had a chance to look at it yet, but the good folks at sysinternals have released a tool named RootkitRevealer. It looks like it works by comparing two scans, one very low-level and one high-level which will include the bogus results intercepted...
Michael Howard's Web Log
List of useful security libraries
Posted
over 7 years ago
by
Michael Howard
7
Comments
I was asked last week for a list of "drop-in-and-more-secure" replacements, created at Microsoft, for C/C++ functions and constructs. So here's a list: IntSafe (C safe integer arith library) SafeInt (C++ safe integer arith template class) ...
Michael Howard's Web Log
How to get a US Passport in 1.5h Hours
Posted
over 6 years ago
by
Michael Howard
12
Comments
This is a true story. Last Thursday I flew from RSA in San Francisco back to Seattle. When I got back I helped my wife pack the bags for our trip to New Zealand. At about midnight, after we'd done all the packing, I got the passports out of the safe...
Michael Howard's Web Log
Microsoft Anti-Cross Site Scripting Library V1.0 Available
Posted
over 7 years ago
by
Michael Howard
15
Comments
I like this class library because it looks for "good things" and not "bad things." T he most common method of mitigating XSS issues is to use functions like HtmlEncode that look for "bad things" and escape them. But this library does the right thing...
Michael Howard's Web Log
Administering Windows Servers through one port
Posted
over 9 years ago
by
Michael Howard
11
Comments
A couple of months ago, I presented at a Financial Services Chief Security Officer’s forum here in Redmond about threat modeling and secure design. One question, totally unrelated to secure design, but still a great question, was how an admin can...
Michael Howard's Web Log
My Take on Visual Studio 2005 SP1 and Windows Vista
Posted
over 6 years ago
by
Michael Howard
11
Comments
Over the last couple of days, many people have asked for my take on the fact that Visual Studio 2005 SP1 requires admin privileges to run on Windows Vista, and pops up a dialog saying so when it starts up. So, here’s my take, and I don't work for...
Michael Howard's Web Log
My Recent Spyware Experience
Posted
over 8 years ago
by
Michael Howard
5
Comments
A few months ago a neighbor (the mother of the family) asked me to take a look at their computer running Windows XP. It had slowed noticeably, and they had a nasty case of “pesky popups.” But to make matters worse, they had discovered a stash of really...
Michael Howard's Web Log
Dave G. at Matasano comments on Vista TCP/IP Stack
Posted
over 7 years ago
by
Michael Howard
3
Comments
Very interesting counterpoint to the recent Symantec paper about the TCP/IP stack in Windows Vista.
Michael Howard's Web Log
Updated Errata for Writing Secure Code 2nd Edition
Posted
over 9 years ago
by
Michael Howard
11
Comments
Entire Book Please replace all references to Windows® .NET Server with Windows® Server 2003. Chapter 2, Page 44 There is a small typo: This effect is called the Hawthorn effect. Should read: This effect is called...
Page 3 of 14 (341 items)
1
2
3
4
5
»