Welcome to MSDN Blogs Sign in | Join | Help

Mike Ormond's Blog

In my world, things would be simpler than this...

News

  • Add to Technorati Favorites

    These postings are provided "AS IS" with no warranties, and confer no rights. The use of any script / code samples is subject to the terms specified here.

Browse by Tags

All Tags » Security
Dominick Baier on Identity, Geneva and OpenID
And following on from Dominick on DevWeek and WCF we also chat to Dominick about Identity, Geneva and OpenID. Technorati Tags: geneva , devweek , identity , openid Read More...
Trouble connecting to the Visual Studio webserver this week?
Quite a few people started reporting having issues connecting to Cassini earlier in the week. I’ve seen blog posts , tweets and internal mail threads as people who had a working environment one day found the could no longer connect the next. The solution Read More...
IE8 Cross Site Scripting (XSS) Protection
I’ve been doing a little bit of XSS work and, in particular, have been testing a website for XSS vulnerabilities. It was clear the site had a reflected (Type 1) vulnerability from simply typing some script code into a suitable input and submitting the Read More...
Macs, Viruses and the Gadget Show
Love it or loathe it (and I do both at times), I regularly indulge myself by watching a bit of The Gadget Show . It's hardly Top Gear / Fifth Gear / any other car show on TV which I can watch all day on Dave and would do if only my wife would let me (and Read More...
Windows Vista & Windows Server 2008 SP 2 Preview
I see we've announced broader availability of SP2 Beta on the Windows team blog . With immediate effect, MSDN and TechNet subscribers can access Service Pack 2 Beta and from 4th December it will be available to everyone via the Customer Preview Program Read More...
PDC 2008 Session Video Downloads
If you want to watch any of the PDC 2008 sessions, you can simple peruse the session list at: http://sessions.microsoftpdc.com/public/timeline.aspx select the session you want to watch and click the "Watch Session Recording" icon. On the other Read More...
Even More on Securing Entities in ASP.NET Dynamic Data
I should mention (as I failed to do so in my last post ) that some of the information (in particular the use of the location element) came from David Ebbo and his answers to questions in the forums. If you want to take things even further and implement Read More...
More on Securing Entities in ASP.NET Dynamic Data
In the last post I talked about how to expose or hide specific tables in ASP.NET Dynamic Data. What if you want to this based on authorization rules, eg whether a user is authenticated or a member of a particular role. ASP.NET offers a powerful set of Read More...
Securing Entities in ASP.NET Dynamic Data
This first post is about controlling which tables get exposed through Dynamic Data. It's important to remember you have complete control over this and there are essentially two approaches: The "demo friendly" approach (which you'll see me using Read More...
Securing Against SQL Injection
Anything that can be done to make it easier to build more secure applications has to be a good thing. I spotted that yesterday we announced three new tools to help protect and identify potential SQL injection issues with ASP.NET and classic ASP applications. Read More...
ASP.NET Routing and Authorization
I got a great question on Tuesday night at the .NET Developer Network where I was talking about some of the upcoming ASP.NET features such as MVC and Dynamic Data. The question was, how do I go about preventing access to pages when using the new ASP.NET Read More...
Developer Day Scotland - 10th May 2008
Technorati Tags: event , community , scotland , microsoft event , community , scotland , microsoft Read More...
UK MSDN Roadshow Registration Is Now Open
I see the registration pages are up on our events site . We'll be visiting Cardiff, London, Manchester, Glasgow and Newcastle this year. The event description is as follows: "This is your opportunity to meet the MSDN team and find out all about the Read More...
New Lenovo T61p
I've just got a shiny new Lenovo T61p to replace my Dell D820 but it hasn't been an entirely smooth ride so far. I thoroughly recommend reading Keith Combes blog post on installing Vista x64 on the T61p (I've installed Windows Vista Enterprise x64 Edition). Read More...
Jeff Prosise on Hacking ASP.NET Web Applications
Last night I was fortunate to be able to attend a local VBUG meeting where Jeff Prosise of Wintellect talked about ASP.NET Security and specifically the threats posed to your ASP.NET applications. Jeff is in the UK for DevWeek ("the UK's leading technical Read More...
Page view tracker