Welcome to MSDN Blogs Sign in | Join | Help

Michael Howard's Web Log

A Simple Software Security Guy at Microsoft!

October 2006 - Posts

Something else to look out for when reviewing code
From: The Learning from Mistakes Dept. A few months back eEye found an exploitable buffer overrun in Symantec’s Remote Management software what caught my eye was the nature of the bug, and I think this is coding construct we should all learn from. You’re Read More...
MSDN Yearly Security Edition
It's that time of the year again, when MSDN magazine issues their yearly Security Issue. This year a number of folks from our team wrote content, including myself, Shawn Hernan, Scott Lambert, Tomasz Ostwald, Adam Shostack and Mark Pustilnik. But probably Read More...
Alleged Bugs in Windows Vista’s ASLR Implementation
I've had some people ask me about a paper that was recently published detailing alleged bugs in Address Space Layout Randomization in Windows Vista. It's great to see people looking at and scrutinizing Windows Vista before we ship. With that said, it Read More...
Developing More-Secure Microsoft® ASP.NET 2.0 Applications Now Available
A new book in the Secure Software Development Series, this time from Dominick Baier is now available from Microsoft Press. I reviewed a good number of the draft chapters, and got an early copy last week. What I love about this book is it’s complete. It Read More...
The Sardonic Mr. Jones
If you have not read Jeff Jones' blog recently, you really should. He has a few thought-provoking opinions. I'll just leave it at that! Read More...
Page view tracker