Welcome to MSDN Blogs Sign in | Join | Help

Michael Howard's Web Log

A Simple Software Security Guy at Microsoft!

May 2005 - Posts

Hidden Message in Writing Secure Code 2nd Ed
I've been meaning to write about this for a year or so, but for some reason I simply keep forgetting to do it! There's a hidden message in WSC 2nd ed. Since the book's release, only one person has found it. Here's a clue: it's in plain sight :) Read More...
File Checksum Integrity Verifier utility
Every once in a while I come across an old piece of email, or a document I archived that contains a little nugget; well, I just stumbled on one on a backup DVD. Last year, Microsoft made available a tool named the File Checksum Integrity Verifier (FCIV) Read More...
Writing Secure Web Browsers is Hard
I'm not making excuses, just stating facts. In fact, I just read this from SANS... emphasis is mine. http://www.sans.org/newsletters/newsbites/newsbites.php?vol=7&issue=19 Fixes Not Yet Available for Firefox Vulnerabilities (9 May 2005) Two vulnerabilities Read More...
Microsoft unveils details of software security process
My colleague, Window Snyder presented last week at CanSecWest about some of the 'fun' we had getting Windows XP SP2 out the door. You can read some of her comments and analysis at SecurityFocus. http://www.securityfocus.com/news/11115 Read More...
Comments on recent Firefox security bugs
As you are no doubt aware, a couple of pretty nasty security defects have been found in the latest FireFox bits that allow remote code execution. The IE team has made some very gracious comments here about the issue. The official word about the bugs is Read More...
Visio Connector for MBSA available
This is kinda cool - a Visio connector that hooks up to the output from the Microsoft Baseline Security Analyzer (MBSA.) From the blurb: At a glance, you'll be able to: Pinpoint vulnerabilities on the color-coded diagram. Identify solutions in the detailed Read More...
Microsoft Windows Security Resource Kit, Second Edition Released
Just spotted this while catching up on (lots of) email. So what's new in the Second Edition? In addition to the expected error correction and clarification that always accompanies new versions, coverage of Windows Server 2003, including SP1 and Windows Read More...
More Integer Overflow stuff
I think I've said this a billion times, but I'll say it again. No-one has done more research into integer overflow (and underflow, and truncation and signed-ness) issues than my good friend and co-author, David LeBlanc. So here's the great news - he's Read More...
Is Microsoft IIS 6.0 more secure than Apache HTTP Server 2.0?
A couple of months ago I presented at an event called the "Microsoft Technology Summit" to some very smart folks who focus primarily on non-Microsoft technologies. I outlined the security process stuff we're doing here (Security Development Lifecycle Read More...
Page view tracker