Category Archives: Uncategorized

IIS 7

For me, the most exciting feature in Vista is IIS 7 (well – there are some more – but IIS 7 is #1). Yesterday http://www.iis.net launched and it contains tons of good info! Looks like there is more to come.  

Posted in Uncategorized | Leave a comment

Chapter 4: Storing Secrets

Just to prove that I am still working on that book – here is the TOC for the “Storing Secrets” chapter. Attacks and Attackers Cryptography to the Rescue? Hashing DataHashing Algorithms, Hashing in .NET Storing PasswordsUsing Salted and Iterated Hashes … Continue reading

Posted in Uncategorized | Leave a comment

Online Krypto Vorlesungen

Die Krypto Vorlesungen an der University of Washington von Brian LaMacchia (Ex Security Architect der CLR), Josh Benaloh (Microsoft Senior Crypographer) und John Manferdeli (Architect für TPM) sind online verfügbar. Samt Videos und PowerPoints. Sehr interessant!  

Posted in Uncategorized | Leave a comment

MSDN Security Feature

Ich habe für MSDN Deutschland einen kleinen Überblick über die neuen Security Features in .NET 2.0, und wie diese beim Entwickeln von Sicherheits-Systemen helfen können, geschrieben. Der Artikel ist jetzt online.  

Posted in Uncategorized | Leave a comment

Snippet for ViewState-Backed Properties

Inspired by Fritz’ post, I created this little snippet on the train… <?xml version=“1.0“ encoding=“utf-8“ ?> <CodeSnippets  xmlns=“http://schemas.microsoft.com/VisualStudio/2005/CodeSnippet“&gt;   <CodeSnippet Format=“1.0.0“>     <Header>       <Title>aspprop</Title>       <Shortcut>aspprop</Shortcut>       <Description>New ASP.NET Property with ViewState</Description>       <Author>Dominick Baier</Author>       <SnippetTypes>         <SnippetType>Expansion</SnippetType>       … Continue reading

Posted in Uncategorized | Leave a comment

Zugriffsrechte für HTTP.SYS

Windows XP SP2 und Server 2003 enthalten einen Kernel-Treiber für HTTP Verkehr mit Namen HTTP.SYS. Anwendungen, die an HTTP Daten interessiert sind, registrieren einen URI Namensraum (z.b. „/foo“) an diesem Treiber, und wenn HTTP Requests für diesen Namensraum am System … Continue reading

Posted in Uncategorized | Leave a comment

Developing More-Secure ASP.NET 2.0 Applications

the first sign of life… http://www.microsoft.com/mspress/books/9989.asp  

Posted in Uncategorized | Leave a comment

HttpListener, Authentication and ASP.NET

One cool thing about HttpListener is that it gives you Basic, Digest and Negotiate authentication for free (and SSL too – btw). You don’t have to write a single line of code to get these authentication schemes in your own HTTP … Continue reading

Posted in Uncategorized | Leave a comment

Tool for HTTP.SYS Namespace Reservations

I posted the first version of this tool here – alongside with some explanations why this is useful and important. In this new version I added automatic namespace reservation using the HTTP.SYS API – so you don’t need to copy&paste … Continue reading

Posted in Uncategorized | Leave a comment

Consolas for Download

Have you ever wondered what font I am using for my code snippets on this blog? Well – it is called Consolas and is part of Vista. I copied it to my W2K3 installation to use it with Visual Studio. … Continue reading

Posted in Uncategorized | Leave a comment