<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>%41%43%45%20%54%65%61%6d  : links</title><link>http://blogs.msdn.com/hackers/archive/tags/links/default.aspx</link><description>Tags: links</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Weekend Security Reading Round up Links - 10/20/07</title><link>http://blogs.msdn.com/hackers/archive/2007/10/20/weekend-security-reading-round-up-links-10-20-07.aspx</link><pubDate>Sat, 20 Oct 2007 11:40:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5541200</guid><dc:creator>techjunkie</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/hackers/comments/5541200.aspx</comments><wfw:commentRss>http://blogs.msdn.com/hackers/commentrss.aspx?PostID=5541200</wfw:commentRss><description>&lt;P&gt;&lt;A href="http://www.wired.com/gadgets/wireless/news/2007/10/iphone_dev_platform" target=_blank mce_href="http://www.wired.com/gadgets/wireless/news/2007/10/iphone_dev_platform"&gt;Inside the Matrix for Mobiles&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;A pretty interesting concept: hack together a platform for connecting the innards of over one hundred different types of cell phones and then connect them to servers allowing virtual access for testing purposes over the Internet.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.wired.com/science/space/news/2007/10/nigerian_space" target=_blank mce_href="http://www.wired.com/science/space/news/2007/10/nigerian_space"&gt;Nigerian Space Program Isn't a 419 Scam&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;No, really.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.istartedsomething.com/20071019/eric-talk-demo-windows-7-minwin/" mce_href="http://www.istartedsomething.com/20071019/eric-talk-demo-windows-7-minwin/"&gt;Eric Traut talks (and demos) Windows 7 and MinWin&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;What do you guys think of the ASCII Windows Logo?&amp;nbsp; Stay tuned for more... ASCII goodness!&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.forbes.com/feeds/ap/2007/10/19/ap4241444.html" target=_blank mce_href="http://www.forbes.com/feeds/ap/2007/10/19/ap4241444.html"&gt;Comcast Blocks Some Internet Traffic&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The interesting thing is how they're doing it, and to what.&amp;nbsp; Its not to all torrent traffic, they just don't want you to initially seed content or continue seeding after a download completes.&amp;nbsp; &lt;/P&gt;&lt;A href="http://www.msnbc.msn.com/id/21381022/?GT1=10450" target=_blank mce_href="http://www.msnbc.msn.com/id/21381022/?GT1=10450"&gt;Online poker cheating blamed on employee&lt;/A&gt; 
&lt;P&gt;Well so that's a non-good way of proving your point ...eh?&lt;/P&gt;
&lt;P&gt;&lt;A href="http://uk.news.yahoo.com/fc/hacking-hackers.html" target=_blank mce_href="http://uk.news.yahoo.com/fc/hacking-hackers.html"&gt;Yahoo's "hackerwire" news coverage&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/esiu/archive/2007/10/19/asp-net-validaterequest-does-not-mitigate-xss-completely.aspx" mce_href="http://blogs.msdn.com/esiu/archive/2007/10/19/asp-net-validaterequest-does-not-mitigate-xss-completely.aspx"&gt;ASP.NET ValidateRequest does not mitigate XSS completely&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;ACE Team's Eugene Siu has a brief post about why ValidateRequest isn't enough&lt;/P&gt;
&lt;P&gt;&lt;A href="http://xkcd.com/327/" target=_blank mce_href="http://xkcd.com/327/"&gt;Little Bobby Tables (from XKCD.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This is really hilarious... thanks to Spencer Low for forwarding it to me.&lt;/P&gt;
&lt;P&gt;&lt;A title="Mark's Blog" href="http://blogs.technet.com/markrussinovich/default.aspx" mce_href="http://blogs.technet.com/markrussinovich/default.aspx"&gt;Mark's Blog&lt;/A&gt; - Mark Russinovich's blog is required reading.&amp;nbsp; Its just amazing how he'll logically walk through common problems normal users just ignore or get frustrated by and finds the root cause of really common problems like &lt;A href="http://blogs.technet.com/markrussinovich/archive/2007/10/15/2178879.aspx" target=_blank mce_href="http://blogs.technet.com/markrussinovich/archive/2007/10/15/2178879.aspx"&gt;freezing gadgets&lt;/A&gt;, &lt;A href="http://blogs.technet.com/markrussinovich/archive/2007/10/01/2087460.aspx" target=_blank mce_href="http://blogs.technet.com/markrussinovich/archive/2007/10/01/2087460.aspx"&gt;files not copying&lt;/A&gt; or &lt;A href="http://blogs.technet.com/markrussinovich/archive/2007/08/07/1715181.aspx" target=_blank mce_href="http://blogs.technet.com/markrussinovich/archive/2007/08/07/1715181.aspx"&gt;folders not compressing&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;I've been reading Mark since High School when I used to pick up Windows NT Magazine, great stuff!&lt;/P&gt;
&lt;P&gt;-techjunkie&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5541200" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/hackers/archive/tags/security/default.aspx">security</category><category domain="http://blogs.msdn.com/hackers/archive/tags/links/default.aspx">links</category></item><item><title>Weekend Security Reading Round up Links - 10/12/07</title><link>http://blogs.msdn.com/hackers/archive/2007/10/12/weekend-security-reading-round-up-links-10-12-07.aspx</link><pubDate>Sat, 13 Oct 2007 08:55:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5435825</guid><dc:creator>techjunkie</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/hackers/comments/5435825.aspx</comments><wfw:commentRss>http://blogs.msdn.com/hackers/commentrss.aspx?PostID=5435825</wfw:commentRss><description>&lt;P&gt;&lt;A href="http://www.infoworld.com/article/07/10/05/40OPsecadvise-datacentric-worldview_1.html" target=_blank mce_href="http://www.infoworld.com/article/07/10/05/40OPsecadvise-datacentric-worldview_1.html"&gt;&lt;FONT face=verdana,geneva color=#777777&gt;All about the data: IT security starts with a data-centric worldview&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verdana,geneva&gt;ACE Team's Roger A. Grimes has posted a great summary of the importance of having a data-centric way of looking at things for computer/information security to work in an IT environment.&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyId=85F99A70-5DF5-4558-991F-8AEE8506833C&amp;amp;displaylang=en" target=_blank mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyId=85F99A70-5DF5-4558-991F-8AEE8506833C&amp;amp;displaylang=en"&gt;&lt;FONT face=verdana,geneva color=#777777&gt;1st CTP of the SQL Server 2005 Driver for PHP available&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verdana,geneva&gt;Bill Staples &lt;/FONT&gt;&lt;A href="http://www.news.com/underexposed/8300-13580_3-39-0.html?keyword=SQL+Server" mce_href="http://www.news.com/underexposed/8300-13580_3-39-0.html?keyword=SQL+Server"&gt;&lt;FONT face=verdana,geneva color=#777777&gt;announced the imminent release&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt; of the October 2007 Community Technology Preview of the SQL Server 2005 Driver for PHP which is now&amp;nbsp;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyId=85F99A70-5DF5-4558-991F-8AEE8506833C&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyId=85F99A70-5DF5-4558-991F-8AEE8506833C&amp;amp;displaylang=en"&gt;&lt;FONT face=verdana,geneva color=#777777&gt;available for download&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt;.&amp;nbsp;&amp;nbsp; This is an early CTP release and designed&amp;nbsp;to gather feedback from the community to help refine the design of the API, the feature set, and the target scenarios. &lt;/FONT&gt;
&lt;P&gt;&lt;A href="http://searchsecurity.techtarget.com/columnItem/0,294698,sid14_gci1276038,00.html" target=_blank mce_href="http://searchsecurity.techtarget.com/columnItem/0,294698,sid14_gci1276038,00.html"&gt;&lt;FONT face=verdana,geneva color=#777777&gt;Inside MSRC: Microsoft SharePoint flaw explained&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt; &lt;/FONT&gt;
&lt;P&gt;&lt;A href="http://arstechnica.com/journals/microsoft.ars/2007/10/12/top-ten-least-known-features-of-windows-server-2008" mce_href="http://arstechnica.com/journals/microsoft.ars/2007/10/12/top-ten-least-known-features-of-windows-server-2008"&gt;&lt;FONT face=verdana,geneva color=#777777&gt;Top Ten least-known features of Windows Server 2008&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt; &lt;/FONT&gt;
&lt;P&gt;&lt;FONT face=verdana,geneva&gt;WinRS (Windows Remote Shell) looks very interesting.&amp;nbsp; You can read more about it here: &lt;/FONT&gt;
&lt;P&gt;&lt;A title="First Look: WinRM &amp;amp; WinRS" href="http://redmondmag.com/columns/article.asp?editorialsid=2262" target=_blank mce_href="http://redmondmag.com/columns/article.asp?editorialsid=2262"&gt;&lt;FONT face=verdana,geneva color=#777777&gt;First Look: WinRM &amp;amp; WinRS&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt;: &lt;I&gt;Two new tools from Microosft that can drastically help server and workstation management&lt;/I&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/anmolm/archive/2007/10/13/how-to-prove-your-digital-identity.aspx"&gt;&lt;FONT face=verdana,geneva color=#777777&gt;How to prove your Digital Identity&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt; &lt;/FONT&gt;
&lt;P&gt;&lt;FONT face=verdana,geneva&gt;ACE Team's Anmol Malhotra has a short post on his blog about digital identities.&amp;nbsp; Anmol's also contributed a great whitepaper on Input Validation for Application Security which we'll be syndicating on this blog very soon, thanks Anmol!&lt;/FONT&gt;&lt;/P&gt;&lt;A class="" href="http://blogs.msdn.com/anmolm/archive/2007/10/13/how-to-prove-your-digital-identity.aspx" target=_blank mce_href="http://blogs.msdn.com/anmolm/archive/2007/10/13/how-to-prove-your-digital-identity.aspx"&gt;&lt;/A&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5435825" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/hackers/archive/tags/security/default.aspx">security</category><category domain="http://blogs.msdn.com/hackers/archive/tags/links/default.aspx">links</category></item><item><title>Weekend Security Reading Round up Links - 10/5/07</title><link>http://blogs.msdn.com/hackers/archive/2007/10/05/weekend-security-reading-round-up-links-10-5-07.aspx</link><pubDate>Fri, 05 Oct 2007 21:37:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5298439</guid><dc:creator>techjunkie</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/hackers/comments/5298439.aspx</comments><wfw:commentRss>http://blogs.msdn.com/hackers/commentrss.aspx?PostID=5298439</wfw:commentRss><description>&lt;P&gt;&lt;A href="http://searchwindowssecurity.techtarget.com/tip/0,289483,sid45_gci1275094,00.html?track=sy201&amp;amp;asrc=RSS_RSS-23_201"&gt;&lt;FONT color=#777777&gt;What's hot in Microsoft security: White lists; Blue hats&lt;/FONT&gt;&lt;/A&gt;&lt;B&gt;&lt;/B&gt; 
&lt;P&gt;A discussion on Symantec’s proposal to whitelist everything on a Windows box as well as a summary of &lt;A href="http://blogs.technet.com/bluehat"&gt;&lt;FONT color=#777777&gt;Microsoft’s Bluehat&lt;/FONT&gt;&lt;/A&gt; 
&lt;P&gt;&lt;A href="http://www.bestsecuritytips.com/news+article.storyid+341.htm"&gt;&lt;FONT color=#777777&gt;10 Microsoft Security Links to Blow Your Mind&lt;/FONT&gt;&lt;/A&gt; 
&lt;P&gt;Pretty self explanatory, no? :) 
&lt;P&gt;&lt;A href="http://blogs.msdn.com/esiu/archive/2007/10/04/more-eyeballs-for-net-framework-code.aspx"&gt;&lt;FONT color=#777777&gt;More eyeballs for .Net Framework code&lt;/FONT&gt;&lt;/A&gt;&lt;B&gt;&lt;/B&gt; 
&lt;P&gt;Our own Eugene Siu talks about Microsoft’s decision to open up the .NET framework for review by developers under a shared source license 
&lt;P&gt;&lt;A href="http://blogs.msdn.com/ace_team/archive/2007/09/19/asp-net-file-upload-how-to-prevent-network-clogging.aspx"&gt;&lt;FONT color=#777777&gt;ASP.NET File Upload: How to prevent network clogging&lt;/FONT&gt;&lt;/A&gt; 
&lt;P&gt;Varun from ACE has posted a great little post developers accepting file uploads should take a look at 
&lt;P&gt;&lt;A href="http://channel9.msdn.com/ShowPost.aspx?PostID=345524#345524"&gt;&lt;FONT color=#777777&gt;ARCast.TV - Security Chat from Slovenia&lt;/FONT&gt;&lt;/A&gt; 
&lt;P&gt;Channel 9 has a great video conversation on security recorded in Slovenia earlier in the year but just now posted up 
&lt;P&gt;&lt;A href="http://blogs.msdn.com/shawnfa/archive/tags/Silverlight/default.aspx"&gt;&lt;FONT color=#777777&gt;Silverlight Security Series&lt;/FONT&gt;&lt;/A&gt; 
&lt;P&gt;Shawn Farkas has a great series of posts on Silverlight security starting from &lt;A href="http://blogs.msdn.com/shawnfa/archive/2007/05/09/the-silverlight-security-model.aspx"&gt;&lt;FONT color=#777777&gt;part I&lt;/FONT&gt;&lt;/A&gt;, then going on to &lt;A href="http://blogs.msdn.com/shawnfa/archive/2007/05/10/silverlight-security-ii-what-makes-a-method-critical.aspx"&gt;&lt;FONT color=#777777&gt;part II&lt;/FONT&gt;&lt;/A&gt; and finally, &lt;A href="http://blogs.msdn.com/shawnfa/archive/2007/05/11/silverlight-security-iii-inheritance.aspx"&gt;&lt;FONT color=#777777&gt;part III&lt;/FONT&gt;&lt;/A&gt;! And of course, the obligatory &lt;A href="http://blogs.msdn.com/shawnfa/archive/2007/05/14/silverlight-security-cheat-sheet.aspx"&gt;&lt;FONT color=#777777&gt;cheatsheet&lt;/FONT&gt;&lt;/A&gt; as well :)&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Updated: Removed some of the HTML gunk, oops.&lt;/EM&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5298439" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/hackers/archive/tags/security/default.aspx">security</category><category domain="http://blogs.msdn.com/hackers/archive/tags/links/default.aspx">links</category></item></channel></rss>