August 2006 - Posts

Miscellaneous Windows Vista Security Stuff
31 August 06 03:32 PM
I just noticed these blog posts related to Windows Vista security that may interest y'all. Built-in Administrator Account Disabled Sidebar Security Elevations Are Now Blocked in the User's Logon Path Read More...
Postedby michael_HOWARD | 2 Comments    
Filed under: ,
New Security Resources Available
25 August 06 12:28 PM
These papers are aimed at IT type folks and non-technical users. Skip this blog post if you're a developer! Protecting Clients from Network Attacks Securing Remote Clients and Portable Computers How to Configure Windows Firewall in a Small Business Environment Read More...
Postedby michael_HOWARD | 4 Comments    
Filed under:
Protecting against Pointer Subterfuge (Redux)
16 August 06 09:44 AM
In a prior post, " Protecting against Pointer Subterfuge (Kinda!) " I described the algorithm we used to encode and decode long-lived pointers in memory to make them harder to exploit after a buffer overrun. A couple of days after the post, I received Read More...
Postedby michael_HOWARD | 3 Comments    
Filed under:
“Microsoft Dynamics Writing Secure X++ Code” Paper now available
10 August 06 08:35 AM
In June 2006, Microsoft released Dynamics AX 4.0, which was the first full version to be developed in Microsoft using the Security Development Lifecycle (SDL). A key deliverable by this team is a document on security considerations for Dynamics AX development. Read More...
Postedby michael_HOWARD | 2 Comments    
Filed under:
Some of us are *NOT* in Las Vegas!
03 August 06 10:27 PM
I suppose someone has to keep the home fires burning! Seriously, it's great to see the Windows Vista presentations were well received at Black Hat 2006: Microsoft gets good reception at Black Hat . That being said, one of the advantages of half the team Read More...
Postedby michael_HOWARD | 5 Comments    
Filed under:
A Process for Performing Security Code Reviews
01 August 06 09:19 PM
I wrote an article about performing security code reviews that appears in the July/August 2006 edition of IEEE Security & Privacy . Oh, and by the way, there's a little typo in the article; my name is Michael Howard, not Michael A. Howard. Unlike Read More...
Postedby michael_HOWARD | 9 Comments    
Filed under:
Page view tracker