October 2006 - Posts

Something else to look out for when reviewing code
30 October 06 10:04 AM
From: The Learning from Mistakes Dept. A few months back eEye found an exploitable buffer overrun in Symantec’s Remote Management software what caught my eye was the nature of the bug, and I think this is coding construct we should all learn from. You’re Read More...
Postedby michael_HOWARD | 5 Comments    
Filed under:
MSDN Yearly Security Edition
18 October 06 02:34 PM
It's that time of the year again, when MSDN magazine issues their yearly Security Issue. This year a number of folks from our team wrote content, including myself, Shawn Hernan, Scott Lambert, Tomasz Ostwald, Adam Shostack and Mark Pustilnik. But probably Read More...
Postedby michael_HOWARD | 0 Comments    
Filed under:
Alleged Bugs in Windows Vista’s ASLR Implementation
04 October 06 12:26 PM
I've had some people ask me about a paper that was recently published detailing alleged bugs in Address Space Layout Randomization in Windows Vista. It's great to see people looking at and scrutinizing Windows Vista before we ship. With that said, it Read More...
Postedby michael_HOWARD | 13 Comments    
Filed under: ,
Developing More-Secure Microsoft® ASP.NET 2.0 Applications Now Available
04 October 06 09:40 AM
A new book in the Secure Software Development Series, this time from Dominick Baier is now available from Microsoft Press. I reviewed a good number of the draft chapters, and got an early copy last week. What I love about this book is it’s complete. It Read More...
Postedby michael_HOWARD | 0 Comments    
Filed under:
The Sardonic Mr. Jones
02 October 06 09:12 PM
If you have not read Jeff Jones' blog recently, you really should. He has a few thought-provoking opinions. I'll just leave it at that! Read More...
Postedby michael_HOWARD | 0 Comments    
Filed under:
Page view tracker