<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx</link><description>After much blood, sweat and tears, a new software security book, written by me, David LeBlanc and John Viega went to the printers today, and should be available in time for Blackhat :) It has the ever-so catchy title of "The 19 Deadly Sins of Software</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#437876</link><pubDate>Tue, 12 Jul 2005 08:15:26 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:437876</guid><dc:creator>Sushant Bhatia</dc:creator><description>Can we see examples of the 19 sins in C# as an example? </description></item><item><title>re: The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#437877</link><pubDate>Tue, 12 Jul 2005 08:19:50 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:437877</guid><dc:creator>LarryOsterman</dc:creator><description>Ordered :)&lt;br&gt;</description></item><item><title>The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#437887</link><pubDate>Tue, 12 Jul 2005 08:51:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:437887</guid><dc:creator>Dana Epp's ramblings at the Sanctuary</dc:creator><description>Ahhhhh... it was time for me to read a new software security book. I was just thinking about what was next to read. Tonight Michael Howard helped me out and told the world about a new book that he, David LeBlanc and John Viega have finished writing called &amp;amp;quot;The 19 Deadly Sins of Software Security&amp;amp;quot;. The book is carved up into 19 chapters, or Sins, and each is only 10-15pp long. The Sins are: Buffer Overflows Format String problems SQL injection Command injection Failure to handle errors Cross-site scripting Failing to protect network traffic Use of &amp;amp;quot;magic&amp;amp;quot; URLs and hidden forms Improper use of SSL Use of weak password-based systems Failing to store and protect data Information leakage Improper file access Integer range errors Trusting network address information Signal race conditions Unauthenticated key exchange Failing to use cryptographically strong random numbers Poor usability These three guys have contributed to some of my favorite writings. I look forward to getting my hands on a copy....</description></item><item><title>re: The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#437894</link><pubDate>Tue, 12 Jul 2005 09:50:19 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:437894</guid><dc:creator>Ilya</dc:creator><description>Chapter 18 rather should be &amp;quot;Failing to use cryptography in a proper way&amp;quot; though :) Random numbers is a way too narrow spot at the whole subject's blunders. </description></item><item><title>The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#437917</link><pubDate>Tue, 12 Jul 2005 11:52:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:437917</guid><dc:creator>Uwe Hermann</dc:creator><description>Michael Howard, David LeBlanc and John Viega have written a book called The 19 Deadly Sins of Software Security, which is to be published soon.&lt;br&gt;It explains the most important security issues one encounters in the software industry in a Design Patterns-lik</description></item><item><title>re: The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#438209</link><pubDate>Wed, 13 Jul 2005 04:14:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:438209</guid><dc:creator>Brian Lounsberry</dc:creator><description>The work you did on WSC was eye opening and great stuff. However, I like the format you've chosen for this. You guys have this down to a science. I can't wait!</description></item><item><title>The 19 deadly sins of software security.</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#438213</link><pubDate>Wed, 13 Jul 2005 04:25:29 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:438213</guid><dc:creator>Productivity Hacks</dc:creator><description>Michael Howard, Microsoft's security expert, is working on a new book called The 19 deadly sins of software security. Get a copy for your IT guy. Here are Howard's deadly sins: 1. Buffer Overflows 2. Format String problems 3. SQL...</description></item><item><title>Channel 9: 19 deadly sins of software security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#438236</link><pubDate>Wed, 13 Jul 2005 05:57:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:438236</guid><dc:creator>OpsanBlog</dc:creator><description /></item><item><title>New security books from Microsoft security team</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#438401</link><pubDate>Wed, 13 Jul 2005 17:50:17 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:438401</guid><dc:creator>Sergey Simakov blog</dc:creator><description /></item><item><title>New Team System Stuff - 2005-07-14</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#439059</link><pubDate>Fri, 15 Jul 2005 04:35:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:439059</guid><dc:creator>Rob Caron's Blog</dc:creator><description>Visual Studio Team System&lt;br&gt;&lt;br&gt;There’s a new Team System community site – TeamSystemRocks.com! ⊕ &lt;br&gt;Well,...</description></item><item><title>re: The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#441265</link><pubDate>Thu, 21 Jul 2005 10:43:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:441265</guid><dc:creator>michaelsilk</dc:creator><description>how can you say it's aimed a 'all languages' and then put the #1 'sin' as &amp;quot;buffer overflow&amp;quot; and #2 as format string!!&lt;br&gt;&lt;br&gt;not really that language independant (so don't try to be ..?!).&lt;br&gt;&lt;br&gt;jmo.</description></item><item><title>re: The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#443537</link><pubDate>Tue, 26 Jul 2005 22:39:57 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:443537</guid><dc:creator>SATISH BHARDWAJ</dc:creator><description>Congratulations to the writer of the book &amp;quot;19 deadly sins&amp;quot;. I'm probably wasting my time making my comments which are not an attack on his book or on his idea. My comments are basically on the refusal of everypne to recognize that the hackers operate not because of the foolishness of anyone as the book implies. It is because the present system of browsing the net gives to much power who has money to buy any personal coputer that is powered by any browser. The web surfer can use any security system he can find on the net. If he is clever like the writer of the &amp;quot;19 deadly sins&amp;quot; he will device his own security software and market it through Amazon like our friend Michael does and become rich. May be not overnight but eventually.&lt;br&gt;&lt;br&gt;Unless this power is taken away from the Hackers the security systems will do no good. The hackers job is relatively easy. It is to convince the servers that the request for any information is legitemate. There are no holds barred by the request for inormation. Perhaps Michael would agree with me that this is the job of the server. Send the files to the clients. But may be Michael would not agree with me. In that case I'd ask him to tell me and others what, in his view, is the job of the server?&lt;br&gt;&lt;br&gt;Unless the job of the server is changed, basically by the rewriting of the code, there is no hope for the people who keep their files on the internet.&lt;br&gt;&lt;br&gt;&amp;lt;a href=&amp;quot;&lt;a rel="nofollow" target="_new" href="http://www.hackers10.blogspot.com/&amp;quot;&amp;gt;STOP"&gt;http://www.hackers10.blogspot.com/&amp;quot;&amp;gt;STOP&lt;/a&gt; THE HACKER&amp;lt;/a&amp;gt;&lt;br&gt;&lt;br&gt;Perhaps I should have called my blog &amp;quot;ONLY ONE WAY TO STOP THE HACKERS.</description></item><item><title>re: The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#445658</link><pubDate>Sun, 31 Jul 2005 14:18:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:445658</guid><dc:creator>Sergey Kostrukov</dc:creator><description>Bla, Bla, Bla...&lt;br&gt;&lt;br&gt;I has read &amp;quot;Writing Secure Code&amp;quot; book, and was interested. - thanks, Michael, for the good book.&lt;br&gt;&lt;br&gt;I'll keep waiting, when this book will be published in Russian.</description></item><item><title>Drop My Rights</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#446698</link><pubDate>Tue, 02 Aug 2005 20:09:31 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:446698</guid><dc:creator>Stuart Celarier</dc:creator><description>Here's an invaluable resource...an article by Michael Howard titled Browsing the Web and Reading E-mail Safely as an Administrator. The article includes a great application called DropMyRights that lets a user who is running as administrator run applications in the much safer context of a non-administrator...</description></item><item><title>Michael Howard does it again: The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#449618</link><pubDate>Wed, 10 Aug 2005 00:05:19 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:449618</guid><dc:creator>Yves Hanoulle: Project Complete</dc:creator><description /></item><item><title>Michael Howard does it again: The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#449620</link><pubDate>Wed, 10 Aug 2005 00:08:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:449620</guid><dc:creator>Yves Hanoulle: Project Complete</dc:creator><description /></item><item><title>Michael Howard does it again: The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#449623</link><pubDate>Wed, 10 Aug 2005 00:14:33 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:449623</guid><dc:creator>Yves Hanoulle: Project Complete</dc:creator><description /></item><item><title>Michael Howard does it again: The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#449626</link><pubDate>Wed, 10 Aug 2005 00:16:05 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:449626</guid><dc:creator>Yves Hanoulle: Project Complete</dc:creator><description /></item><item><title>Michael Howard does it again: The 19 Deadly Sins of Software Security</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#449628</link><pubDate>Wed, 10 Aug 2005 00:17:06 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:449628</guid><dc:creator>Yves Hanoulle: Project Complete</dc:creator><description /></item><item><title>Register Domain WebLog  &amp;raquo; Blog Archive   &amp;raquo; BNA's Web Watch -Data Security - April 2005</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#3939949</link><pubDate>Wed, 18 Jul 2007 19:27:30 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3939949</guid><dc:creator>Register Domain WebLog  » Blog Archive   » BNA's Web Watch -Data Security - April 2005</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://blogsseek.com/register-domain/2007/07/17/bnas-web-watch-data-security-april-2005/"&gt;http://blogsseek.com/register-domain/2007/07/17/bnas-web-watch-data-security-april-2005/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>Os formatadores de strings da Granja do Solar &amp;laquo; sec::h0p /* by Alberto Fabiano */</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#5972247</link><pubDate>Thu, 08 Nov 2007 03:03:29 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5972247</guid><dc:creator>Os formatadores de strings da Granja do Solar « sec::h0p /* by Alberto Fabiano */</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://sechop.wordpress.com/2007/11/05/os-formatadores-de-strings-da-granja-do-solar/"&gt;http://sechop.wordpress.com/2007/11/05/os-formatadores-de-strings-da-granja-do-solar/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>Os formatadores de strings da Granja do Solar &amp;laquo; Inno::Blog /* by Alberto Fabiano */</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#5972486</link><pubDate>Thu, 08 Nov 2007 03:15:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5972486</guid><dc:creator>Os formatadores de strings da Granja do Solar « Inno::Blog /* by Alberto Fabiano */</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://techberto.wordpress.com/2007/11/07/os-formatadores-de-strings-da-granja-do-solar/"&gt;http://techberto.wordpress.com/2007/11/07/os-formatadores-de-strings-da-granja-do-solar/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>Os formatadores de strings da Granja do Solar  &amp;laquo; sec::h0p /* by Alberto Fabiano */</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#5972703</link><pubDate>Thu, 08 Nov 2007 03:31:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5972703</guid><dc:creator>Os formatadores de strings da Granja do Solar  « sec::h0p /* by Alberto Fabiano */</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://sechop.wordpress.com/2007/11/07/os-formatadores-de-strings-da-granja-do-solar/"&gt;http://sechop.wordpress.com/2007/11/07/os-formatadores-de-strings-da-granja-do-solar/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>  Michael Howard&amp;#8217;s Web Log : The 19 Deadly Sins of Software Security at Restaurants</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#6913898</link><pubDate>Mon, 31 Dec 2007 09:35:03 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6913898</guid><dc:creator>  Michael Howard’s Web Log : The 19 Deadly Sins of Software Security at Restaurants</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://restaurants.247blogging.info/?p=468"&gt;http://restaurants.247blogging.info/?p=468&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>A szoftver minőségbiztosítási eszközök valós lehetőségei és korlátai</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#9394606</link><pubDate>Wed, 04 Feb 2009 08:04:20 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9394606</guid><dc:creator>Termékinformációk fejlesztőknek</dc:creator><description>&lt;p&gt;[Nacsa S&amp;#225;ndor, 2009. janu&amp;#225;r 13. – febru&amp;#225;r 3.]&amp;amp;#160; A minős&amp;#233;gbiztos&amp;#237;t&amp;#225;s k&amp;#233;rd&amp;#233;sk&amp;#246;re szinte alig ismert&lt;/p&gt;
</description></item><item><title> Michael Howard s Web Log The 19 Deadly Sins of Software Security | Paid Surveys</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#9653821</link><pubDate>Fri, 29 May 2009 19:16:09 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9653821</guid><dc:creator> Michael Howard s Web Log The 19 Deadly Sins of Software Security | Paid Surveys</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://paidsurveyshub.info/story.php?title=michael-howard-s-web-log-the-19-deadly-sins-of-software-security"&gt;http://paidsurveyshub.info/story.php?title=michael-howard-s-web-log-the-19-deadly-sins-of-software-security&lt;/a&gt;&lt;/p&gt;
</description></item><item><title> Michael Howard s Web Log The 19 Deadly Sins of Software Security | pool toys</title><link>http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx#9774155</link><pubDate>Thu, 18 Jun 2009 11:37:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9774155</guid><dc:creator> Michael Howard s Web Log The 19 Deadly Sins of Software Security | pool toys</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://pooltoysite.info/story.php?id=8291"&gt;http://pooltoysite.info/story.php?id=8291&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>