Eugene Siu's Thoughts on Security
Share my latest security research and techniques
Browse by Tags
All Tags
»
Security
(RSS)
Developer Productivity
Exchange server
IIS
(In)Security of MultiByteToWideChar and WideCharToMultiByte (Part 2)
Part 1 of this installment discussed the unsafe nature of MultiByteToWideChar and WideCharToMultiByte. They do not guarantee terminating strings properly. In this installment, I want to focus on the count parameters. There are three
Read More...
(In)Security of MultiByteToWideChar and WideCharToMultiByte (Part 1)
There are a few well-known unsafe APIs in the standard C library, such as strcpy and memcpy. These routines are unsafe as buffer and destination buffer size are not taken into consideration. Buffer overflows may take place because destination
Read More...
My favorite security blogs and podcasts
What are your favorite security blogs or podcasts? Here are mine. Please leave yours in the comment section. Podcasts Security Now ( http://www.grc.com/securitynow.htm ) CNet Security Bites ( http://securitybites.cnet.com ) Blogs Schneier
Read More...
“Out of Band” security patch MS08-067
Out of Band security patch MS08-067 is released today. Microsoft strives to keep our monthly patch Tuesday release cycle so that enterprise administrators can plan ahead for their testing and deployment. When out of band is released, it must
Read More...
What is unique about patch Tuesday of October 2008?
Technorati Tags: Security Every second Tuesday, MSRC releases security patches for Microsoft products that have fixed vulnerabilities. The best is to have no patches for patch Tuesdays, and many administrators can take a break from installing patches
Read More...
ASP.NET ValidateRequest does not mitigate XSS completely
As a security guy, I can safely say that there is no magic bullet to mitigate any security problems completely, and cross-site scripting(XSS) bugs are not exceptions. Since ASP.NET 1.1, ValidateRequest can be configured in web.config to check and reject
Read More...
Is Microsoft Office Isolated Conversion Environment(MOICE) mocha on ice?
MOICE may sound like mocha on ice, but it is really a strong dark espresso shot offered by Office TWC team to jolt up security. Microsoft Office Isolated Conversion Environment (MOICE) is a new security tool that helps protect Office users from malicious
Read More...
True test of a security geek
If you chuckle at this comic strip, congratulations! You are a security geek. If you don't chuckle, it is never too late to become one. Read my blog more, and you will become one. Thanks TechJunkie for forwarding.
Read More...
System.URI.AbsolutePath Vs Phishing Attack
Phishing attack can be caused by users inadvertently clicking on malicious links in emails or web pages, which then forward requests to malicious websites. A common phishing technique is to fake emails sent by well-known banks or merchants,, which contain
Read More...
Web Service Security Guidance
I have just published a Technet article. This is geared for administrators and developers as an introduction to web service security. It contains lots of references that allow you to deepend your knowledge of web service security. Please visit http://www.microsoft.com/technet/community/columns/sectip/st1007.mspx
Read More...
Anti-Malware and Spyware help for home users
Working for Microsoft means that I become de facto technical support for my friends and family. That should be the experiences of many folks in the computer industry. When I introduce my job title as "senior security consultant" to friends and family,
Read More...
HTTP Header Injection Vulnerabilities
HTTP Response Splitting was discovered several years ago. It allows attackers to split a HTTP response into multiple ones by injecting malicious response HTTP headers. This attack can deface web sites, poison cache and trigger cross-site scripting. Rather
Read More...
IE Developer Toolbar helps me hack
I was browsing IE blog articles to get research ideas. I came across IE Developer Toolbar , and decided to play with it. I was checking out different options, and it impressed me as a good web client developer tool, as it offers a breakdown of HTML elements,
Read More...
Exchange 2007 RPC interfaces are locked down
Exchange 2007 RPC interfaces have retired support of various legacy RPC bindings, including AppleTalk, SPX and Banyan Vines. This exemplifies the philosophy of reducing attack surface area in the design of Exchange 2007.
Read More...
My first passphrase
I have read many articles about the benefits of using passphrases in contrast to passwords. For more details, you can read http://blogs.technet.com/robert_hensing/archive/2004/07/28/199610.aspx . I have always been convinced about the use of passphrases.
Read More...
More Posts
Next page »
Search
This Blog
Home
About
Email
Tags
<script>alert()</script>
Developer Productivity
Exchange server
IIS
Infoworker Productivity
Mobile Phone
Security
Archives
November 2008 (2)
October 2008 (3)
March 2008 (1)
November 2007 (1)
October 2007 (8)
September 2007 (6)
May 2007 (2)
April 2007 (1)
March 2007 (1)
February 2007 (3)
January 2007 (2)
July 2005 (1)
March 2005 (2)
February 2005 (1)
January 2005 (2)
December 2004 (1)
November 2004 (3)
ACE Team
ACE Team
Syndication
RSS 2.0
Atom 1.0