<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Threat Modeling Again, What does STRIDE have to do with threat modeling?</title><link>http://blogs.msdn.com/larryosterman/archive/2007/09/07/threat-modeling-again-what-does-stride-have-to-do-with-threat-modeling.aspx</link><description>In my last couple of posts , I've talked about the STRIDE categories. As I mentioned, STRIDE provides a convenient classification mechanism for threats, and threat modeling is all about trying to identify the threats to your feature/component/whatever.</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Threat Modeling Again, What does STRIDE have to do with threat modeling?</title><link>http://blogs.msdn.com/larryosterman/archive/2007/09/07/threat-modeling-again-what-does-stride-have-to-do-with-threat-modeling.aspx#4820128</link><pubDate>Sat, 08 Sep 2007 05:14:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4820128</guid><dc:creator>Cheong</dc:creator><description>&lt;p&gt;Regarding &amp;quot;Data Stores&amp;quot;, it's fairly common for database applications to also store the &amp;quot;right assignment&amp;quot; for users into tables. Doesn't exploiting it be possible for &amp;quot;Elevation of Privilege&amp;quot;?&lt;/p&gt;
&lt;p&gt;For example, the user information of MySQL is stored in the database named &amp;quot;mysql&amp;quot;. If someone find their way to modify &amp;quot;mysql.user&amp;quot; table then execute &amp;quot;flush privileges&amp;quot; or just wait until the next time the server is restarted, the attacker can gain access to all databases - not just the database that the buggy application runs on - and can feel free to drop any of them.&lt;/p&gt;</description></item><item><title>Threat Modeling Again, STRIDE per Element</title><link>http://blogs.msdn.com/larryosterman/archive/2007/09/07/threat-modeling-again-what-does-stride-have-to-do-with-threat-modeling.aspx#4855017</link><pubDate>Mon, 10 Sep 2007 20:31:05 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4855017</guid><dc:creator>Larry Osterman's WebLog</dc:creator><description>&lt;p&gt;As I mentioned the other day , we had three huge big realizations as we've been doing more and more threat&lt;/p&gt;
</description></item><item><title>Threat Modeling Again, STRIDE per Element</title><link>http://blogs.msdn.com/larryosterman/archive/2007/09/07/threat-modeling-again-what-does-stride-have-to-do-with-threat-modeling.aspx#4855193</link><pubDate>Mon, 10 Sep 2007 20:54:24 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4855193</guid><dc:creator>Noticias externas</dc:creator><description>&lt;p&gt;As I mentioned the other day , we had three huge big realizations as we&amp;amp;#39;ve been doing more and more&lt;/p&gt;
</description></item><item><title>STRIDE chart</title><link>http://blogs.msdn.com/larryosterman/archive/2007/09/07/threat-modeling-again-what-does-stride-have-to-do-with-threat-modeling.aspx#4882931</link><pubDate>Wed, 12 Sep 2007 21:09:14 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4882931</guid><dc:creator>The Security Development Lifecycle</dc:creator><description>&lt;p&gt;Adam Shostack here. I've been meaning to talk more about what I actually do, which is help the teams&lt;/p&gt;
</description></item><item><title>Some final thoughts on Threat Modeling...</title><link>http://blogs.msdn.com/larryosterman/archive/2007/09/07/threat-modeling-again-what-does-stride-have-to-do-with-threat-modeling.aspx#5246386</link><pubDate>Tue, 02 Oct 2007 21:54:40 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5246386</guid><dc:creator>Larry Osterman's WebLog</dc:creator><description>&lt;p&gt;I want to wrap up the threat modeling posts with a summary and some comments on the entire process. Yeah,&lt;/p&gt;
</description></item></channel></rss>