Monthly Archives: December 2004

EvidenceBrowser

Shows you the evidence of an assembly. Nice for demos, e.g. EvidenceBrowser d:etctoolstool.exeopposed toEvidenceBrowser http://localhost/tool.exeandEvidenceBrowser http://127.0.0.1/tool.exe This tool is basically a hybrid of two code fragments by fellow DM trainers jason whittington and henkk de koning. Henkk has done the heavy … Continue reading

Posted in Uncategorized | Leave a comment

CompuWare Keynote

The slides from the CompuWare product launch – about Application Security. CW_ApplicationSecurity.pdf (155,5 KB)  

Posted in Uncategorized | Leave a comment

XSS through dynamic Colors

A nice observation by Nikhil Kothari. Another hole in HTML – but of course boils down to : don’t let your users cross the thin line between the data and control channel – or put otherwise : validate that input! … Continue reading

Posted in Uncategorized | Leave a comment

Security Instrumentation with Performance Monitor

It is impossible to build unbreakable applications. Just as in physical security we need to incorporate Protection Detection Reaction in our software systems. Once an attempt to break into your application is detected, it is easier for an admin to … Continue reading

Posted in Uncategorized | Leave a comment

ASP.NET Security Checker

Compuware was so kind to invite me to do the keynote on their product launch of two security/quality related products for .net in Amsterdam yesterday. thanks for the invitation and hospitality! ASP.NET Security Checker is an add-in for visual studio which … Continue reading

Posted in Uncategorized | Leave a comment

WSCF 0.4 released

christian released a 0.4 version of his web service contract first tool. good stuff.  

Posted in Uncategorized | Leave a comment