Category Archives: Uncategorized

HttpListener Artikel

Teil 1 meines HttpListener Artikels ist online. Dort werden Themen with Authentifizierung, Autorisierung, Impersonierung, Sandboxing und SSL mit Client Zertifikaten besprochen. Teil 2 wird in Kürze auch verfügbar sein – dort dreht sich alles um ASP.NET Integration.  

Posted in Uncategorized | Leave a comment

Hosting PowerShell in ASP.NET

Having read this post. I just couldn’t resist :) Of course, this is not a full featured PS host – but simple commands like get-process work and by caching the runspace you keep state between the commands you invoke. Needless to … Continue reading

Posted in Uncategorized | Leave a comment

AuthenticateRequest vs PostAuthenticateRequest

I get questions every now and then why there are these two events and which one to use for what. The way I like to think about it: If you change the IIdentity – use AuthenticateRequest. If you change the … Continue reading

Posted in Uncategorized | Leave a comment

Very happy to announce…

…that Mark Curphey and Rudolph Araujo from Foundstone will contribute to my Tools & Resources book chapter!!! Foundstone have always been my pen testing/auditing tools heros. And from books like the “Hacking Exposed” series, I learned a lot about tools & … Continue reading

Posted in Uncategorized | Leave a comment

Re-MVPed

My MVP award for the “Visual Developer – Security” category has been renewned for another year. thanks!  

Posted in Uncategorized | Leave a comment

ASP.NET/.NET Guidance Explorer

Die Patterns & Practices Gruppe hat eine Winforms Anwendung veröffentlicht, in der man die Security & Performance Best Practices für seine Projekt-Zwecke browsen, durchsuchen, sortieren und neu anordnen kann. Noch Beta – aber sieht vielversprechend aus. Download.

Posted in Uncategorized | Leave a comment

Source Code for AzMan Bulk Importer

Joe finally got permission from his employer to realease the source code for the excellent AzMan Export/Import tool. Essential if you are doing AzMan development. AzManBulkImport1.zip (5.17 KB)  

Posted in Uncategorized | Leave a comment

ASP.NET Security Hub

Auf dieser Seite hat Scott Guthrie eine Reihe von Links und Ressourcen zu ASP.NET Security zusammengestellt. Dort kann man exzellente Informationen finden, und es wird auch weiterhin Content hinzugefügt. Also ab und zu mal vorbeischauen lohnt sich.  

Posted in Uncategorized | Leave a comment

HttpCfgAcl Update: SSL Support

I already wrapped the ACL part of HttpCfg.exe. Another piece of functionality of this tool is to associate SSL certificates with endpoints. For an article I am currently writing, I needed easy access to that syntax (picking a cert, extracting the … Continue reading

Posted in Uncategorized | Leave a comment

Chapter 7: Logging and Instrumentation

Another finished and reviewed Chapter: Logging and Instrumentation Prevention, Detection, Reaction Handling ErrorsCustom Errors, Catching 401s, Exception Bubbling, Runtime Exceptions Event LogCreating Event Sources, Custom Event Logs, Remote Access and ACLs Performance MonitorRegistering Counters, Writing to Counters, Remote Access E-Mail … Continue reading

Posted in Uncategorized | Leave a comment