<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>SDDL - easier to read, except when it's not.</title><link>http://msmvps.com/blogs/alunj/archive/2006/02/13/83472.aspx</link><description>SDDL was introduced by Microsoft in Windows 2000, as a counter to the difficulty developers had in writing (and administrators had in reading) Security Descriptors, and specifically the Access Control Lists that come with them. The recent advisory about</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Microsoft releases DACL guidance for developers of Window services</title><link>http://msmvps.com/blogs/alunj/archive/2006/02/13/83472.aspx#84539</link><pubDate>Wed, 22 Feb 2006 16:33:19 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:84539</guid><dc:creator>Dana Epp's ramblings at the Sanctuary</dc:creator><description>Microsoft has recently released a KB article on Best practices and guidance for writers of service discretionary access control lists that I think developers of services on Windows should really read. In the article Microsoft shows how to successfully apply DACLs to make services more secure for our workstations and servers, and offers guidance on how to assess the security of your application. A majority of the information surrounds around understanding and interpreting SDDL (Security Descriptor Definition Language), something I fear too many developers don't properly understand. I would also recommend that you check out the MSDN hub on Service Security and Access Rights. There you can get a better feeling for how the Windows security model enables controlled access to service objects and the service control manager (SCM). Happy reading! UPDATE: Alun reminded me in the comments that he wrote a pretty good post on how to read SDDL a few weeks back. You can check it out here....&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=84539" width="1" height="1"&gt;</description></item><item><title>Making more sense of service SDDL</title><link>http://msmvps.com/blogs/alunj/archive/2006/02/13/83472.aspx#84538</link><pubDate>Wed, 22 Feb 2006 16:09:03 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:84538</guid><dc:creator>Tales from the Crypto</dc:creator><description>Thanks to Dana Epp's blog for drawing my attention to Microsoft's rather easier-to-read explanation of...&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=84538" width="1" height="1"&gt;</description></item></channel></rss>