Category Archives: Uncategorized

How to change validity period of issued certificates in Windows Certificate Services

http://support.microsoft.com/kb/254632  

Posted in Uncategorized | Leave a comment

Two important Security changes in .NET 3.5 SP1

Shawn details the two big security changes in .NET 3.5 SP1 on his blog: Strong Name Bypass Full Trust on the Local Intranet We have discussed both changes internally – and I have mixed feelings about them. I guess the … Continue reading

Posted in Uncategorized | Leave a comment

Improved IisRegMgmt

Thanks to CarlosAg from the IIS team, I was able to improve my tool for registering IIS 7 management modules. IisRegMgmt01.zip

Posted in Uncategorized | Leave a comment

Ein Session Abstract ganz genau nach meinem Geschmack

Gesehen auf der JAX2008 Webseite: Security Last – Sicherheitsentscheidungen spät treffenSicherheitsanforderungen wie Logins und Berechtigung sind wichtig – aber müssen diese wirklich gleich am Anfang umgesetzt werden? Das nachträgliche Hinzufügen dieser Anforderungen mit reinem Java und OOP ist sehr schwierig, … Continue reading

Posted in Uncategorized | Leave a comment

Token Kidnapping

Interesting…and shocking. Read more here: http://www.argeniss.com/research/TokenKidnapping.pdf

Posted in Uncategorized | Leave a comment

Installing an IIS 7 Extension

Related to cleaning up my authentication module for Codeplex, I needed a way to (semi) automatically install a complete IIS extension (including schema, config sections and management extensions). I came up with a batch file that does the necessary steps … Continue reading

Posted in Uncategorized | Leave a comment

LINQ to SQL and Security

I don’t know how many SQL injection demos I did in my life – and it is still surprising (or shocking rather) how many people don’t know about this. It is even more surprising how many people fight for their … Continue reading

Posted in Uncategorized | Leave a comment

General Failure when pinging the local Machine Name

I have this strange problem that when I ping my local machine name, I get a General Failure. Forcing the ping to IPv4 with the /4 option works. I could live with that, but another side effect is that opening … Continue reading

Posted in Uncategorized | Leave a comment

Troopers08

My good friends at ERNW are organizing a fantastic security conference to take place in Munich in April. There are two tracks appropriately named “attack” and “defense” and interesting speakers like Dan Bernstein, Andrew Cushman, Enno Rey, Michael Thumann and … Continue reading

Posted in Uncategorized | Leave a comment

New IIS7 Resources

Hardening IIS 7 IIS 7 FTP Server IIS 7 Manager HTH

Posted in Uncategorized | Leave a comment