Eugene Siu's Thoughts on Security
Share my latest security research and techniques
September 2007 - Posts
Anti-Malware and Spyware help for home users
Working for Microsoft means that I become de facto technical support for my friends and family. That should be the experiences of many folks in the computer industry. When I introduce my job title as "senior security consultant" to friends and family,
Read More...
HTTP Header Injection Vulnerabilities
HTTP Response Splitting was discovered several years ago. It allows attackers to split a HTTP response into multiple ones by injecting malicious response HTTP headers. This attack can deface web sites, poison cache and trigger cross-site scripting. Rather
Read More...
Reset Outlook connections without restart
This is a well hidden trick in Outlook. Not sure why this needs to be hidden. You can open Connection Status window by holding CTRL + right-clicking on the Outlook system tray icon on the Task Bar. I want to highlight a couple features: * Reset all connections
Read More...
Silverlight security MSDN magazine article
I have submitted an article proposal to MSDN to write about Silverlight security with my buddy in Silverlight team. If this proposal gets accepted, you will see the article on MSDN magazine soon. Abstract: Silverlight is the latest cross-browser and cross-platform
Read More...
Just learned how to cross-post via MetaWeblog API
I work for ACE team, and want to cross-post from http://blogs.msdn.com/esiu to http://blogs.msdn.com/ace_team . Community Server supports MetaWeblog API, but I am not able to figure out how to configure cross-posting. After a few tries, I am able to cross-post
Read More...
IE Developer Toolbar helps me hack
I was browsing IE blog articles to get research ideas. I came across IE Developer Toolbar , and decided to play with it. I was checking out different options, and it impressed me as a good web client developer tool, as it offers a breakdown of HTML elements,
Read More...
Search
Go
This Blog
Home
About
Email
Tags
<script>alert()</script>
Developer Productivity
Exchange server
IIS
Infoworker Productivity
Mobile Phone
Security
Archives
March 2008 (1)
November 2007 (1)
October 2007 (8)
September 2007 (6)
May 2007 (2)
April 2007 (1)
March 2007 (1)
February 2007 (3)
January 2007 (2)
July 2005 (1)
March 2005 (2)
February 2005 (1)
January 2005 (2)
December 2004 (1)
November 2004 (3)
ACE Team
ACE Team
Syndication
RSS 2.0
Atom 1.0