Sign in
Michael Howard's Web Log
A Simple Software Security Guy at Microsoft!
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Tags
General
Pages
Personal
Privacy
Rant
Security
Vista
Archive
Archives
September 2009
(1)
July 2009
(1)
May 2009
(2)
March 2009
(1)
December 2008
(2)
November 2008
(3)
October 2008
(3)
September 2008
(7)
August 2008
(5)
July 2008
(3)
June 2008
(1)
May 2008
(1)
April 2008
(5)
March 2008
(5)
February 2008
(4)
January 2008
(9)
December 2007
(4)
November 2007
(4)
October 2007
(6)
September 2007
(1)
August 2007
(2)
July 2007
(4)
June 2007
(13)
May 2007
(6)
April 2007
(8)
March 2007
(11)
February 2007
(4)
January 2007
(8)
December 2006
(4)
November 2006
(15)
October 2006
(5)
September 2006
(6)
August 2006
(6)
July 2006
(2)
June 2006
(7)
May 2006
(8)
April 2006
(2)
March 2006
(5)
February 2006
(6)
January 2006
(10)
December 2005
(2)
November 2005
(2)
October 2005
(1)
September 2005
(4)
August 2005
(5)
July 2005
(5)
June 2005
(3)
May 2005
(9)
April 2005
(8)
March 2005
(5)
February 2005
(9)
January 2005
(7)
December 2004
(7)
November 2004
(9)
October 2004
(11)
August 2004
(13)
July 2004
(4)
June 2004
(12)
May 2004
(17)
April 2004
(2)
March 2004
(2)
February 2004
(3)
January 2004
(2)
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Michael Howard's Web Log
Threat Modeling tool now available
Posted
over 9 years ago
by
Michael Howard
7
Comments
Finally, it has been posted - Frank Swiderski's Threat modeling tool is now available for free download on MSDN. From the blurb: The Threat Modeling Tool allows users to create threat model documents for applications. It organizes relevant data...
Michael Howard's Web Log
Integer Overflow and operator::new
Posted
over 8 years ago
by
Michael Howard
7
Comments
As Raymond Chen pointed out last year ( http://blogs.msdn.com/oldnewthing/archive/2004/01/29/64389.aspx ), there is a potential integer overflow when calling operator::new. The C++ compiler in Visual Studio 2005 automatically generates defensive code...
Michael Howard's Web Log
Clinic 2806: Microsoft Security Guidance Training for Developers
Posted
over 8 years ago
by
Michael Howard
7
Comments
I'd totally forgotten about this, but Microsoft eLearning has made available, "Clinic 2806: Microsoft Security Guidance Training for Developers" It's a free on-line clinic that lasts about 6 hours aimed squarely at developers. It covers, among other things...
Michael Howard's Web Log
"How can I Trust Firefox" blog by Torr
Posted
over 9 years ago
by
Michael Howard
7
Comments
Peter Torr has joined our group, working with development teams to help them through the Security Development Lifecycle and Final Security Review processes. He just posted an interesting comment about downloading and running Firefox. http://blogs.msdn...
Michael Howard's Web Log
Matt Miller Joins the Security Science Team!
Posted
over 5 years ago
by
Michael Howard
7
Comments
Good news! Matt Miller, author of plenty of cutting-edge security research, including my fave “ A Brief History of Exploitation Techniques and Mitigations on Windows ” has joined the Security Science team to work on improved ways to find security vulnerabilities...
Michael Howard's Web Log
Ken Johnson (Skywing) joins Microsoft
Posted
over 4 years ago
by
Michael Howard
7
Comments
Following close on the heels of security experts Matt Miller , Adam Shostack and Crispin Cowan joining Microsoft, I am pleased to announce that Ken Johnson, AKA Skywing, has joined our group. Ken brings an enormous amount of reverse engineering...
Michael Howard's Web Log
Overlong UTF-8 Escapes Bite
Posted
over 5 years ago
by
Michael Howard
6
Comments
Every once in a while a security bug pops up that really piques my interest, and a new directory traversal bug that affects Apache Tomcat (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2938) most certainly made me take notice because I haven...
Michael Howard's Web Log
"How Do I?" Videos for Security
Posted
over 5 years ago
by
Michael Howard
6
Comments
These are pretty cool - I'm a big fan of highly focused, short education like this... http://msdn2.microsoft.com/en-us/security/bb896640.aspx
Michael Howard's Web Log
Introducing SAFECode
Posted
over 5 years ago
by
Michael Howard
6
Comments
Today SAFECode , the Software Assurance Forum for Excellence in Code, introduced its first white paper, "Software Assurance: An Overview of Current Industry Best Practices." The organization was founded by Microsoft, Symantec, EMC, SAP and Juniper...
Michael Howard's Web Log
FAQ about HeapSetInformation in Windows Vista and Heap Based Buffer Overruns
Posted
over 5 years ago
by
Michael Howard
6
Comments
2/19 - Added some Minor Tweaks Perhaps it's the phase of the moon or something, but over the last few weeks I have received more email about correctly using the HeapSetInformation function than any other topic. I really don't know why! This was added...
Michael Howard's Web Log
Protecting Your Code with Visual C++ Defenses
Posted
over 5 years ago
by
Michael Howard
6
Comments
MSDN Magazine has just published an article I wrote that collects many of the various C and C++ defenses in the current Visual C++ compiler suite, all of these defenses are SDL requirements or recommendations.
Michael Howard's Web Log
Russinovich and the WMF Flaw (MS06-001)
Posted
over 7 years ago
by
Michael Howard
6
Comments
I'm not 100% sure why no-one seems to have picked up on this, Russinovich decided to do his own analysis of the WMF flaw to see if Gibson's belief that WMF/SetAbortProc() is an intentional backdoor. Of course, it's not! Here's Mark's analysis: http...
Michael Howard's Web Log
Address Space Layout Randomization for Windows
Posted
over 8 years ago
by
Michael Howard
6
Comments
A small company named Wehnus run by Matt Miller has put together a comprehensive Windows Based host-based intrusion prevention system (HIPS) system called WehnTrust ( http://www.wehnus.com ) that uses Address Space Layout Randomization (ASLR) among other...
Michael Howard's Web Log
Comments from Gartner about Microsoft's Security Work
Posted
over 8 years ago
by
Michael Howard
6
Comments
I just read this very interesting article in Information Week about the recent Cisco 'issue' at Blackhat. What caught my eye is a comment from John Pescatore, a senior security researcher at Gartner. Emphasis is mine... Microsoft , said Pescatore...
Michael Howard's Web Log
The Antivirus Defense-in-Depth Guide Released to Web
Posted
over 9 years ago
by
Michael Howard
6
Comments
Finally got out of war, and saw this in my inbox... The Microsoft Solutions for Security (MSS) team has released The Antivirus Defense-in-Depth Guide on the Web ( http://go.microsoft.com/fwlink/?LinkId =28734 ) I just had a look at it, and it's...
Michael Howard's Web Log
Microsoft Security Bulletin RSS Feed
Posted
over 9 years ago
by
Michael Howard
6
Comments
From the “Well-waddya-know Dept.” I just found out this morning there's an RSS feed for Microsoft Security bulletins. You learn something every day! Point your reader at http://www.microsoft.com/technet/security/bulletin/secrss.aspx...
Michael Howard's Web Log
An Update on David LeBlanc
Posted
over 7 years ago
by
Michael Howard
6
Comments
As you probably all know, David is a very good friend of mine and we have authored some popular security books together, and will probably write some more too (but that’s another story.) Some of you know that David left Microsoft to join Webroot in...
Michael Howard's Web Log
Wresting free from a software straitjacket
Posted
over 7 years ago
by
Michael Howard
6
Comments
There's an interesting article over at C|Net about security in general, and Microsoft and the SDL in particular. One thing the author points out as important is BillG's Trustworthy Computing memo. IMHO, here's why such an email is so important. If...
Michael Howard's Web Log
Microsoft hosts OEM partners for a crash-course in SDL (Day One)
Posted
over 7 years ago
by
Michael Howard
6
Comments
As part of our ongoing SDL efforts, we are hosting a 2.5 day event here in Redmond for our OEM partners – over 50 senior technical experts from the biggest names in the computer industry. Out of respect for our partners I won’t name names, but the “usual...
Michael Howard's Web Log
Microsoft hosts OEM partners for a crash-course in SDL (Day Two)
Posted
over 7 years ago
by
Michael Howard
6
Comments
Day two of the SDL training session for OEMs went well. James Whittaker led the discussion for the first half of the morning, discussing security testing. His main point was that testing for security requires a diffferent mind set - you still have to...
Michael Howard's Web Log
Whatever Happened to sprintf(..., “%n”,...)?
Posted
over 7 years ago
by
Michael Howard
6
Comments
You may have noticed that if your code calls functions in the sprintf family and the format template string uses the %n parameter, then it fails to run correctly after it is compiled with Visual Studio 2005. Why? Well, it's pretty simple, by default we...
Michael Howard's Web Log
From the Mouths of Babes
Posted
over 6 years ago
by
Michael Howard
6
Comments
A few weeks ago someone in my group suggested I blog about more than security. I asked, "Why?" He said, "So people will realize you're not a droid!" So here is my first post that has nothing to do with security, it's about parenting. More to the point...
Michael Howard's Web Log
The Most Complex SAL annotation
Posted
over 6 years ago
by
Michael Howard
5
Comments
While working on " Writing Secure Code for Windows Vista " I spent a good deal of time spelunking the new crypto stuff, CNG . One of the APIs is BCryptResolveProviders , and the last argument is pretty complex: If you pass NULL, it fails and...
Michael Howard's Web Log
News Items that Interested me this Week
Posted
over 6 years ago
by
Michael Howard
5
Comments
Each week (ok, mostly every week!) I'll post news items that interested me... Security analysis of Checkpoint firewall Of interest is the way around RedHat's ExecShield buffer overflow defense. http://www.pentest.es/checkpoint_hack.pdf Abusing chroot...
Michael Howard's Web Log
Windows Live OneCare v1.5 is released to manufacturing
Posted
over 6 years ago
by
Michael Howard
5
Comments
This is great news. OneCare is one of my all-time-fave products. I love it because it was built knowing that the target user is no security expert. It wasn't built by geeks for geeks. Everyone in my immediate family uses OneCare because (to quote my...
Page 5 of 14 (341 items)
«
3
4
5
6
7
»