Category Archives: Uncategorized

System.DirectoryServices.AccountManagement

Looking through some of the new 3.5 stuff I stumbled over a new assembly named “System.DirectoryServices.AccountManagement” – that caught my attention. The whole namespace reminds a little bit of ADSI – an API tailored to create user, group and machine … Continue reading

Posted in Uncategorized | Leave a comment

Configuration Section Designer

Writing configuration sections is tedious – a perfect candidate for code-gen. Try this. Very nice.

Posted in Uncategorized | Leave a comment

The Future of the ASP.NET InfoCardSelector Control

From now on I will make all updates to the control code available via this link. The zip contains the control itself plus the code for the demo site you can find here. I will also include a changelog in … Continue reading

Posted in Uncategorized | Leave a comment

Demo Site for InfoCardSelector ASP.NET Control

I have uploaded a mini site to test the InfoCardSelector ASP.NET control. The site features three options: self-issued cards with and without SSL and a managed card (using the Microsoft FederatedIdentity test STS). Have fun! http://www.leastprivilege.com/InfoCardSelector

Posted in Uncategorized | Leave a comment

Updated InfoCardSelector ASP.NET Control for No-SSL Scenarios

Starting with .NET 3.5, CardSpace does not demand SSL connections anymore (see here). Kim shows how to get this scenario to work with “less than 30 lines of code” (link). This involves setting up the object tag, retrieving the clear … Continue reading

Posted in Uncategorized | Leave a comment

Poor Man's File Replication using Robocopy

Robocopy has an option to monitor a directory tree for changes – and if a change occurs robocopy will re-rerun the last copy operation. This way you can have something like a “realtime” backup of data. Example: robocopy c:etcsource e:source … Continue reading

Posted in Uncategorized | Leave a comment

Does Microsoft regret the Security Push?

Well – at least parts of it – but this did get your attention, right? Not sure what to think about that. Remember the ILoveYou virus? It replicated itself to file shares to spread across intranets. I think the argument … Continue reading

Posted in Uncategorized | Leave a comment

Try XSSDetect

Exciting things are happening over at the ACE team at Microsoft. One is XSSDetect – a Visual Studio plugin that analyzes your code to find potential XSS vulnerabilities. Mark also gives a sneak preview of other upcoming tools. Interesting!  

Posted in Uncategorized | Leave a comment

.net@movies Episode 1 – Web Security

Am 17.Dezember findet die erste Veranstaltung der brandneuen .net@movies Serie des ProDev Colleges statt. Bei diesem ersten Event geht es um ein Thema, das mir schon lange sehr am Herzen liegt: Web Security. Mein geschätzer Kollege Christian Wenz und ich … Continue reading

Posted in Uncategorized | Leave a comment

Sichere Software mit Microsoft .NET entwickeln

…ist der Titel eines neuen Buches vom Entwickler.Press Verlag. Darin könnt Ihr eine Artikelsammlung von Autoren wie Michael Howard, Steve Lippner, Christian Wenz, Darius Parys und mir finden. Behandelt werden Themen wie Windows, ASP.NET, .NET und WCF Security. Das ganze … Continue reading

Posted in Uncategorized | Leave a comment