Monthly Archives: October 2004

Speaking at DevWeek 2005

i will do three talks and the post-conference at DevWeek 2005 in Lodon. Other speakers include tim ewald, ingo rammer, jeff richter, jeff prosise, simon horell and dino esposito… the talks: Designing Application Managed Authorization Authorization is a task, which every … Continue reading

Posted in Uncategorized | Leave a comment

Back Home

i had a great week at windev. this is such a nice conference. i’ve seen some very interesting talks, met a lot of people for the first time, met a lot of people again – you know who you are … Continue reading

Posted in Uncategorized | Leave a comment

WinDev: Improving Application Security through Penetration Testing

the slide for my penetration testing talk – all urls of the tools i showed are included in the slides. Pentest.pdf (1,11 MB)  

Posted in Uncategorized | Leave a comment

WinDev : Designing Application Managed Authorization

as promised – the slides and source code for my talk about authorization slides Authz.pdf (220,7 KB) .NET IIdentity/IPrincipal Roles.zip (16,76 KB) AzMan AzMan.zip (83,66 KB) For a more detailed explanation of the AzMan source code – check out the … Continue reading

Posted in Uncategorized | Leave a comment

WinDev and Slides

whew. i had big fun in my two talks at WinDev. What a nice conference! i have some problems uploading the slides from the hotel to this server. i will do it in the next days. just subscribe and stay … Continue reading

Posted in Uncategorized | Leave a comment

Off to WinDev

i am currently making my final preparations for WinDev (take care that all my tools and demos are working, preparing a VMWare image, going through the slides, trying to fight my excitement etc). I am leaving tomorrow.  

Posted in Uncategorized | Leave a comment

ACL Support in .NET 2.0

The new issue of MSDN Magazine is focused on Security – one article covers the new ACL support in .NET 2.0.  

Posted in Uncategorized | Leave a comment

OWASP-DOTNET Blog

I am proud to announce that we (my company ERNW) are hosting the blog of dinis cruz. This is the official OWASP-DOTNET blog – dedicated to .NET Security in general, and ASP.NET Security and Full Trust in particular. subscribed!  

Posted in Uncategorized | Leave a comment

Go to Definition in VS.NET 2005

I wanted to start a debug session and hit by accident F12 in VS.NET 2005 – a new tab opened up and showed me a C# class called String with the stubs of every public member of the System.String class + … Continue reading

Posted in Uncategorized | Leave a comment

The official Word on the ASP.NET Vulnerability

MS says: http://www.microsoft.com/security/incident/aspnet.mspx UPDATEThough we could not reproduce it – Microsoft states that Windows 2003 and IIS6 are also affected…

Posted in Uncategorized | Leave a comment