-
Recent Posts
- Customizing IdentityServer
- ASP.NET Web API Authentication: Using multiple (simultaneous) Authentication Methods with Thinktecture AuthenticationHandler
- LeastPrivilege on Flipboard
- Support for X.509 Client Certificates in Thinktecture.IdentityModel for Web API
- Web API Security: JSON Web Token/OAuth2 with Thinktecture.IdentityModel AuthenticationHandler
Categories
- .NET Security (32)
- ASP.NET (89)
- Azure (26)
- Conferences & Training (27)
- IdentityModel (284)
- IdentityServer (77)
- OAuth (23)
- Photography (14)
- Resources (1)
- Uncategorized (549)
- WCF (104)
- WebAPI (78)
Tweets
- RT @richardblewett: Shindler’s Lifts http://t.co/SOWVG6munp 4 days ago
- Skógafoss tmblr.co/ZtWeVslF2fZL #iceland 5 days ago
Feed
Archives
- May 2013
- April 2013
- March 2013
- February 2013
- January 2013
- December 2012
- November 2012
- October 2012
- September 2012
- August 2012
- July 2012
- June 2012
- May 2012
- April 2012
- March 2012
- February 2012
- January 2012
- December 2011
- November 2011
- October 2011
- September 2011
- July 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- August 2010
- July 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- August 2006
- July 2006
- June 2006
- May 2006
- April 2006
- March 2006
- February 2006
- January 2006
- December 2005
- November 2005
- October 2005
- September 2005
- August 2005
- July 2005
- June 2005
- May 2005
- April 2005
- March 2005
- February 2005
- January 2005
- December 2004
- November 2004
- October 2004
- September 2004
- August 2004
- July 2004
- June 2004
- May 2004
Monthly Archives: July 2006
Joe Kaplan is blogging
Joe Kaplan finally has a blog. He is the author of this great book and you can find a lot of useful LDAP/AD and ADFS related content on his brand new blog. http://www.joekaplan.net/
Posted in Uncategorized
Leave a comment
The Appendixes
OK – that’s the last book related post for now – if you think this information is useful and you want it at the earliest possible date – you can pre-order here or here :) Appendix A: Building a Custom Protected Configuration … Continue reading
Posted in Uncategorized
Leave a comment
Chapter 3: Input Validation
- What is Input?- The Need for Input Validation – The Data/Control Channel Problem – SQL Injection, Cross Site Scripting, Directory Traversal- Input Validation Techniques – Black Listing – White Listing – Data Type Conversion – Regular Expressions – XML … Continue reading
Posted in Uncategorized
Leave a comment
Chapter 5: Authentication and Authorization
the biggest chapter in the whole book… Fundamentals – Terminology- Application Design (Trusted Subsystem vs Impersonation/Delegation)- ASP.NET Security Pipeline and Infrastructure – IPrincipal and IIdentity – Role-based Authorization (programmatically vs declarative)- Server Authentication Using Windows Accounts – IIS Authentication Methods (Basic, … Continue reading
Posted in Uncategorized
1 Comment
Manuscript Shipped
Finally! I shipped the complete manuscript to MS Press on Monday….The final book is supposed to hit the shelves in October. With that much spare time, I am almost bored now….
Posted in Uncategorized
Leave a comment
Eval is not Evil
While working through the ASP.NET security reference implementation (which is good work btw), the following guideline caught my attention: “Additionally, all calls to DataBinder.Eval() have been removed. While Eval is sometimes safe to use on purely static data, it is … Continue reading
Posted in Uncategorized
Leave a comment
How to get Cookieless FormsAuthentication to work with self-issued FormsAuthenticationTickets and custom UserData
This question was asked by Scott recently. Short answer: you can :) The trick is to do a Response.Redirect with an appended query string in the following format: ~/Page.aspx?{0}={1} where {0} = forms ticket name{1} = encrypted forms ticket string … Continue reading
Posted in Uncategorized
Leave a comment
Update for AzMan Bulk Importer
via Joe Langley: UPDATED 7/24/2006:Bug fixed where top level application groups were not copiedOption added so that you can have a patch mode (patch only one application in a store…helpful if you have more than one application in a store) UPDATED … Continue reading
Posted in Uncategorized
Leave a comment
iTunes and Windows 2003 – Update
OK – this is broken. The version of QuickTime that comes with the latest iTunes download is conflicting with MS06-15 (kb908531). The only work around seems to be uninstalling the hotfix (which is a critical, remote exploitable one – so don’t … Continue reading
Posted in Uncategorized
Leave a comment
ASP.NET 2.0 Security Reference Implementation
The patterns&practices group has released a version of Pet Shop that uses and applies all the PAG security guidance. You can download the complete source code + design document here. Interesting read (both the .doc and the source).
Posted in Uncategorized
Leave a comment
