<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The What, Why and How of Software Security : Security Conference/ Workshop</title><link>http://blogs.msdn.com/varun_sharma/archive/tags/Security+Conference_2F00_+Workshop/default.aspx</link><description>Tags: Security Conference/ Workshop</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>TechNet Webcast: Configuring with Least Privilege in SQL Server 2008</title><link>http://blogs.msdn.com/varun_sharma/archive/2009/06/20/technet-webcast-configuring-with-least-privilege-in-sql-server-2008.aspx</link><pubDate>Sat, 20 Jun 2009 23:00:09 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9793958</guid><dc:creator>Varun Sharma</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/varun_sharma/comments/9793958.aspx</comments><wfw:commentRss>http://blogs.msdn.com/varun_sharma/commentrss.aspx?PostID=9793958</wfw:commentRss><description>&lt;p&gt;I recently presented a TechNet Webcast on the topic “Configuring with Least Privilege in SQL Server 2008”. &lt;/p&gt;  &lt;p&gt;The topics covered in the Webcast are:-&lt;/p&gt;  &lt;p&gt;1. Configuring SQL Server service accounts with least privilege. Service isolation is also explained. &lt;/p&gt;  &lt;p&gt;2. Configuring accounts connecting to SQL Server from a Web application (Principals) with least privilege. &lt;/p&gt;  &lt;p&gt;3. Running xp_cmdshell with a proxy so that the account invoking xp_cmdshell need not be a sysadmin.&lt;/p&gt;  &lt;p&gt;4. Running SQL Server jobs with least privilege. &lt;/p&gt;  &lt;p&gt;The Webcast can be viewed here:-&lt;/p&gt;  &lt;p&gt;&lt;a title="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;amp;EventID=1032415807&amp;amp;CountryCode=US" href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;amp;EventID=1032415807&amp;amp;CountryCode=US"&gt;http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;amp;EventID=1032415807&amp;amp;CountryCode=US&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9793958" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/varun_sharma/archive/tags/Least+Priv/default.aspx">Least Priv</category><category domain="http://blogs.msdn.com/varun_sharma/archive/tags/Security+Conference_2F00_+Workshop/default.aspx">Security Conference/ Workshop</category></item><item><title>Virtual techdays: Top 5 Web Application security bugs in custom code</title><link>http://blogs.msdn.com/varun_sharma/archive/2009/02/16/virtual-techdays-top-5-web-application-security-bugs-in-custom-code.aspx</link><pubDate>Mon, 16 Feb 2009 07:23:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9425301</guid><dc:creator>Varun Sharma</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/varun_sharma/comments/9425301.aspx</comments><wfw:commentRss>http://blogs.msdn.com/varun_sharma/commentrss.aspx?PostID=9425301</wfw:commentRss><description>&lt;P&gt;Microsoft &lt;A href="http://www.virtualtechdays.com/home.aspx" mce_href="http://www.virtualtechdays.com/home.aspx"&gt;Virtual TechDays&lt;/A&gt; is starting from the 18th February 09. In the &lt;A href="http://www.virtualtechdays.com/Agenda.aspx?Event=10" mce_href="http://www.virtualtechdays.com/Agenda.aspx?Event=10"&gt;security track&lt;/A&gt;, I will be presenting on the topic “Top 5 Web Application Security bugs in custom code”. As a security engineer in the &lt;A class="" href="http://blogs.msdn.com/ace_team" mce_href="http://blogs.msdn.com/ace_team"&gt;ACE Team&lt;/A&gt;, I have been reviewing line-of-business applications for the past two years. In this presentation, I will talk about the most common security mistakes that developers make while writing code. Since developers from various geographical locations tend to make the same mistakes, the audience can take back a lot of practical knowledge and apply it to secure their applications. &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9425301" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/varun_sharma/archive/tags/Security+Conference_2F00_+Workshop/default.aspx">Security Conference/ Workshop</category></item><item><title>NASSCOM – DSCI Information Security Summit 2008 Security Tutorial</title><link>http://blogs.msdn.com/varun_sharma/archive/2008/11/24/nasscom-dsci-information-security-summit-2008-security-tutorial.aspx</link><pubDate>Mon, 24 Nov 2008 14:38:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9136839</guid><dc:creator>Varun Sharma</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/varun_sharma/comments/9136839.aspx</comments><wfw:commentRss>http://blogs.msdn.com/varun_sharma/commentrss.aspx?PostID=9136839</wfw:commentRss><description>&lt;p&gt;&lt;/p&gt;  &lt;p&gt;My colleague Sagar and I will be conducting an application security workshop at the NASSCOM – DSCI Information Security Summit 2008 on the 1st December in IIIT, Hyderabad, India. &lt;/p&gt;  &lt;p&gt;More information can be found here:- &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;a title="http://www.nasscom.in/Nasscom/Templates/CustomEvents.aspx?id=55164" href="http://www.nasscom.in/Nasscom/Templates/CustomEvents.aspx?id=55164"&gt;http://www.nasscom.in/Nasscom/Templates/CustomEvents.aspx?id=55164&lt;/a&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The agenda is here:-&lt;/p&gt;  &lt;p&gt;&lt;a title="http://www.nasscom.in/upload/59314/Agenda_Tutorial.pdf" href="http://www.nasscom.in/upload/59314/Agenda_Tutorial.pdf"&gt;http://www.nasscom.in/upload/59314/Agenda_Tutorial.pdf&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9136839" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/varun_sharma/archive/tags/Security+Conference_2F00_+Workshop/default.aspx">Security Conference/ Workshop</category></item><item><title>ClubHACK 2007: I will be presenting some “Subtle Security Flaws” </title><link>http://blogs.msdn.com/varun_sharma/archive/2007/11/26/clubhack-2007-i-will-be-presenting-some-subtle-security-flaws.aspx</link><pubDate>Mon, 26 Nov 2007 14:52:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6529794</guid><dc:creator>Varun Sharma</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/varun_sharma/comments/6529794.aspx</comments><wfw:commentRss>http://blogs.msdn.com/varun_sharma/commentrss.aspx?PostID=6529794</wfw:commentRss><description>&lt;P mce_keep="true"&gt;In its own words, "&lt;A class="" href="http://www.clubhack.com/index.html" mce_href="http://www.clubhack.com/index.html"&gt;ClubHACK&lt;/A&gt; is one of its kind hacker's convention in India which serves as a meeting place for hackers, security professionals, law enforcement agencies and all other security enthusiasts."&lt;/P&gt;
&lt;P mce_keep="true"&gt;At ClubHACK, I will &lt;A class="" href="http://www.clubhack.com/speakers.html#Varun_Sharma" mce_href="http://www.clubhack.com/speakers.html#Varun_Sharma"&gt;talk&lt;/A&gt; about some interesting and subtle security flaws found while assessing business applications, which principles were not followed that resulted in the flaws and why, no matter how good a developer you are, you should always follow the basic principles of software security.&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=6529794" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/varun_sharma/archive/tags/Security+Conference_2F00_+Workshop/default.aspx">Security Conference/ Workshop</category></item></channel></rss>