Jerry Bryant's Security Blog

Security Program Manager - Microsoft PSS Security Team

June 2004 - Posts

Microsoft Product Support Reporting Tool

This is the tool we use to gather system information to assist in trouble shooting customer support issues. There are different tools for different scenarios. Check out the readme files for details on all the information that a given tool collects.

These tools are only supported for reporting information to Microsoft during a support incident but you may find the results handy for your own analysis of your systems.

Get the tools here:

http://www.microsoft.com/downloads/details.aspx?familyid=cebf3c7c-7ca5-408f-88b7-f9c79b7306c0&displaylang=en

IEEE 802.11 Wireless LAN Security with Microsoft Windows XP

A good read if you are looking to utilize Windows XP to make wireless communications as secure as they can possibly be given the current set of 802.11 technologies.

http://www.microsoft.com/downloads/details.aspx?familyid=67fdeb48-74ec-4ee8-a650-334bb8ec38a9&displaylang=en

Deploying PKI inside Microsoft

Read about how Microsoft used Windows Server 2003 to upgrade our public key infrastructure for secure communications.

http://www.microsoft.com/downloads/details.aspx?familyid=46ca7043-0433-4140-853a-05f01430a30d&displaylang=en

What You Should Know About Download.Ject

What You Should Know About Download.Ject

Published: June 24, 2004 | Updated June 25, 2004 12:35 A.M. Pacific Time

Microsoft teams are investigating a report of a security issue affecting customers using Microsoft Internet Information Services 5.0 (IIS) and Microsoft Internet Explorer, components of Windows.

Important  Customers who have deployed Windows XP Service Pack 2 RC2 are not at risk.

Reports indicate that Web servers running Windows 2000 Server and IIS that have not applied update 835732, which was addressed by Microsoft Security Bulletin MS04-011, are possibly being compromised and being used to attempt to infect users of Internet Explorer with malicious code.

More info:

http://www.microsoft.com/security/incident/download_ject.mspx

Update (6/25/04 3:40 PM PST):
Microsoft has confirmed that this is not a self-propagating attack (not a worm). We continue to work with ISPs to shut down malicous URLs. The primary attack web site was taken offline Thursday evening June 24, 2004. We continue to urge customers to make sure they have the latest security updates and virus signatures installed on their systems and to follow the security guidance in the more info link above.

Update (6/26/04 8:57 AM PST):
Microsoft has published a KB article describing how to check your Windwos 2000 server to see if it has been compromised:

http://support.microsoft.com/?kbid=871277

If you feel your fully patched machine has been compromised, please call 1-866-PCSafety right away!

Excellent information on the new IE pop up blocker from JeffDav of the IE Core team
http://blogs.msdn.com/jeffdav/archive/2004/06/21/161789.aspx
STRIDE model of threat categories

At Microsoft, we have developed what we call the STRIDE model for categorizing software threats. These are used in security bulletins to describe the nature of a security vulnerability.

Here is a summary of the model:

Term Definition

Spoofing identity

Illegally obtaining access and use of another person's authentication information, such as a user name or password.

Tampering with data

The malicious modification of data.

Repudiation

Associated with users who deny performing an action, yet there is no way to prove otherwise. (Non-repudiation refers to the ability of a system to counter repudiation threats, and includes techniques such as signing for a received parcel so that the signed receipt can be used as evidence.)

Information disclosure

The exposure of information to individuals who are not supposed to have access to it, such as accessing files without having the appropriate rights.

Denial of service

An explicit attempt to prevent legitimate users from using a service or system.

Elevation of privilege

Where an unprivileged user gains privileged access. An example of privilege elevation would be an unprivileged user who contrives a way to be added to the Administrators group.

This model is discussed in detail in the book “Writing Secure Code, Second Edition” by Michael Howard and David LaBlanc.

The New Wireless Network Setup Wizard in Windows XP Service Pack 2

Windows XP SP2 has a cool new wireless network setup wizard to help end users set up secure wireless in their homes. The wizard saves configuration information to a USB flash drive that can be carried to each wireless machine for setup.

You can read The Cable Guy's review here:
http://www.microsoft.com/technet/community/columns/cableguy/default.mspx

Or get more details in part 2 of the Changes to Functionality in Microsoft Windows XP Service Pack 2 online documentation here:
http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2netwk.mspx


 

Windows XP SP2 Release Candidate 2 now available

SP2 RC2 is now available for download:

http://www.microsoft.com/technet/prodtechnol/winxppro/sp2preview.mspx

You don't have to uninstall RC1 if you are running that but that might make for a cleaner install of RC2.

Security Chat with Microsoft VP Mike Nash

Join me tomorrow (Thursday, June 17, 2004 9:00am Pacific/12:00pm Eastern) in our monthly security chat with Mike Nash.

Chat room: http://communities2.microsoft.com/home/chatroom.aspx?siteid=34000081
Add to calendar: http://www.microsoft.com/technet/downloads/vcs/sec_0617.vcs

Microsoft Security Bulletin Release for June 15, 2004

June 15, 2004
Today Microsoft re-released the following Security Bulletin.

Note: www.microsoft.com/technet/security and www.microsoft.com/security are authoritative in all matters concerning Microsoft Security Bulletins! ANY e-mail, web board or newsgroup posting (including this one) should be verified by visiting these sites for official information. Microsoft never sends security or other updates as attachments. These updates must be downloaded from the microsoft.com download center or Windows Update. See the individual bulletins for details.

Because some malicious messages attempt to masquerade as official Microsoft security notices, it is recommended that you physically type the URLs into your web browser and not click on the hyperlinks provided.

Critical Bulletins:
 
MS04-011 - Vulnerability Security Update for Microsoft Windows (835732)
http://www.microsoft.com/technet/security/Bulletin/MS04-011.mspx

This DOES NOT represents our regularly scheduled monthly bulletin release (second Tuesday of each month). Please note that Microsoft may release bulletins out side of this schedule if we determine the need to do so.

If you have any questions regarding the patch or its implementation after reading the above listed bulletin you should contact Product Support Services in the United States at 1-866-PCSafety (1-866-727-2338). International customers should contact their local subsidiary.

Improving Security with Domain Isolation: Microsoft IT implements IP Security (IPsec)

Situation
As part of its “defense in depth” security strategy, Microsoft IT wanted to isolate their managed computers from unmanaged (and untrusted) computers. If trusted computers could be made to ignore requests from these untrusted computers, they could be kept more secure.

Solution
Microsoft IT chose IP Security (IPsec), a standards-based approach to authenticating network traffic. With IPsec, the corporate domains can be isolated, segmenting all computers into trusted and untrusted groups.

Benefits
• Allows creation of logical secure network segments behind the corporate network perimeter.
• Works independently of network hardware, computers, and other infrastructure, providing end-to-end security to the edges of the network.
• Can be deployed and managed centrally through the use of Group Policy.

Products & Technologies
• IP Security protocols (ESP, IKE)
• Windows Server 2003
• Windows XP Professional (SP 1)
• Windows 2000 (SP3)
• Group Policy
• Active Directory
• Public Key Infrastructure and Certificate Authority (CA)

Download the white paper here:

http://www.microsoft.com/downloads/details.aspx?familyid=a97ddc48-a364-4756-bb3c-91da274118fe&displaylang=en

Free online AV scanner

There are a few free online AV scanners out there. They are all really helpful when you are trying to help a friend or family member with a virus issue and they don't have any AV on their machine. Feel free to post your favorite as feedback to this post. Here's one of mine:

http://www.ravantivirus.com/scan/

Exchange Server 2003 Message Security Guide

This is really cool:

Overview
This book discusses how, when using S/MIME, encryption protects the contents of e-mail messages and digital signatures verify the identity of a purported sender of an e-mail message. In addition, this book provides guidance on how to implement S/MIME with Microsoft Exchange Server 2003. In addition, this book provides guidance and pointers to other resources where those are necessary.

Note: A script (ListSMIMECerts.vbs) is included in this download and will be unpackaged with the guide.

Download it here:

http://www.microsoft.com/downloads/details.aspx?familyid=2305405c-faf1-488a-a856-ad467bb59b26&displaylang=en

Deploying Windows Firewall Settings for Microsoft Windows XP with Service Pack 2

Overview
Windows XP Service Pack 2 (SP2), currently a Release Candidate in Beta testing, includes significant enhancements to the Windows Firewall component, previously known as the Internet Connection Firewall (ICF). Windows Firewall is a stateful host-based firewall that discards unsolicited incoming traffic, providing a level of protection for computers against malicious users or programs. To provide better protection for computers connected to any kind of network (such as the Internet, a home network, or an organization network), Windows XP SP2 enables Windows Firewall on all network connections by default. This new behavior can impair some types of communications. This article describes how to deploy the appropriate configuration settings for Windows Firewall on an organization network so that it is enabled and providing protection, and so that communications are not impaired.

Get the white paper here:

http://www.microsoft.com/downloads/details.aspx?familyid=4454e0e1-61fa-447a-bdcd-499f73a637d1&displaylang=en

Microsoft Security Bulletins for June 2004

June 8, 2004
Today Microsoft released the following Security Bulletins.

Note: www.microsoft.com/technet/security and www.microsoft.com/security are authoritative in all matters concerning Microsoft Security Bulletins! ANY e-mail, web board or newsgroup posting (including this one) should be verified by visiting these sites for official information. Microsoft never sends security or other updates as attachments. These updates must be downloaded from the microsoft.com download center or Windows Update. See the individual bulletins for details.

Because some malicious messages attempt to masquerade as official Microsoft security notices, it is recommended that you physically type the URLs into your web browser and not click on the hyperlinks provided.

Bulletin Summaries:

Microsoft: http://www.microsoft.com/technet/security/Bulletin/ms04-jun.mspx

Moderate Bulletins:
 
MS04-016 - Vulnerability in DirectPlay Could Allow Denial of Service (839643)
http://www.microsoft.com/technet/security/Bulletin/MS04-016.mspx

MS04-017 - Vulnerability in Crystal Reports Web Viewer Could Allow Information Disclosure and Denial of Service (842689)
http://www.microsoft.com/technet/security/Bulletin/MS04-017.mspx

This represents our regularly scheduled monthly bulletin release (second Tuesday of each month). Please note that Microsoft may release bulletins out side of this schedule if we determine the need to do so.

If you have any questions regarding the patch or its implementation after reading the above listed bulletin you should contact Product Support Services in the United States at 1-866-PCSafety (1-866-727-2338). International customers should contact their local subsidiary.

Security Web Casts for June 2004

Upcoming Security Webcasts: June 2004
Security Webcasts are a convenient way for IT Professionals and Developers to stay technically updated on the latest Microsoft Security Guidance. These webcasts concentrate on security information and are presented by senior executives and other subject matter experts. They feature interactive technical presentations, product demonstrations, and question-and-answer sessions.

For IT Executives

Microsoft Executive Circle Webcast:  Monthly Update from Microsoft's VP for Security - Level

June 22, 2004

8:30 AM - 9:30AM Pacific Time

Mike Nash, VP Security Business Unit, Microsoft Corporation

Join Mike Nash, Microsoft’s senior executive in charge of security, for his monthly security update. Mike will provide the latest details on Microsoft’s security enhancements, offer tips and insights into key security strategies for customers and provide new information on Microsoft's security technologies being delivered in upcoming service packs.

http://go.microsoft.com/fwlink/?LinkId=28964

 

For IT Professionals
 
 Attend a TechNet webcast. Qualify to win a TechNet Plus subscription

Attend any live TechNet webcasts and be eligible to win a one year TechNet

Plus subscription. One winner will be selected from each webcast (U.S. only).

See the official rules for details.
 

 

TechNet Webcast: Implementing Server Security on Windows 2000 and Windows 2003 (Part 1) - Securing Servers: Core Server Security and Active Directory Security - Level 200

June 8, 2004

9:00 AM - 9:45 AM Pacific Time

Mark Mortimore, Senior Technical Specialist, Microsoft Corporation

 

This webcast discusses and explains the importance of server security to your organization. We will explore core server security and the key components in the process of securing Active Directory®. We will then discuss some of the challenges small-to-medium sized businesses face when trying to secure a server environment, the importance of multiple layers of security, managing software updates, and how to use Active Directory to secure your server environment. This webcast includes a demonstration on how to create an Organizational Unit structure and apply a security template.

http://go.microsoft.com/fwlink/?LinkId=29281

 

 

TechNet Webcast: Implementing Client Security on Windows 2000 and Windows XP (Part 1) - Core Client Security, Securing Applications and Group Policy for Standalone Clients - Level 200

June 8, 2004

11:00 AM - 11:45 AM Pacific Time

Mark Mortimore, Senior Technical Specialist, Microsoft Corporation

 

This webcast discusses the importance of implementing a core client security, concentrating on securing applications and securing standalone Windows® clients. We will discuss a fundamental, core set of client security topics along with securing a variety of applications such as Internet Explorer and Microsoft® Outlook® within an organization. From there we’ll discuss how to use Active Directory® and Group Policy to secure Windows clients. The presentation includes a demonstration on Securing Standalone Clients.

http://go.microsoft.com/fwlink/?LinkId=29849

 

 

TechNet Webcast: IIS 6.0: Built for Stability - Level 200

June 8, 2004

11:30 AM - 1:00 PM Pacific Time

Don Jones, Book Author and Founding partner of BrainCore.Net, BrainCore.Net

 

Sure, IIS 6.0 has a new architecture, and you may have heard about http.sys, application pools, Web gardens, and more, but what does it all mean, and why should you care? Join this Webcast and see what the new IIS architecture offers Web server administrators, and learn how to build Web servers than can survive the most challenging designs your Web developers can throw at it!

http://go.microsoft.com/fwlink/?LinkId=25234

 

 

TechNet Webcast: Information about Microsoft's June Security Bulletins - Level 200

June 9, 2004

10:00 AM - 11:00 AM Pacific Time

Christopher Budd, CISM, CISSP/Security Program Manager and Debby Fry Wilson, Director/Security Response Marketing

 

On June 8, Microsoft will release its monthly security bulletins. Join us for a brief overview of the technical details of the June security bulletins followed by an extensive Q&A session.

This webcast will focus on addressing your questions and concerns about the security bulletins. Therefore, the majority of the webcast session will give you the opportunity to ask questions and get answers from our security experts.

http://go.microsoft.com/fwlink/?LinkId=28770

 

 

TechNet Webcast: Security Patch Management Tools (Part 1) - Windows and Office Update - Level 200

June 9, 2004

11:00 AM - 11:45 AM Pacific Time

Kai Axford, TechNet Presenter, Microsoft Corporation

 

How are you evaluating, distributing, and installing software patches? This webcast discusses the importance of patch management and establishing a patch management process using Windows and Office Update as a patch management tool in your environment. We will present a brief overview of the patch management landscape, focusing on the role of Windows and Office Update as one of your patch management tools. From there this webcast will walk you through a demonstration on Configuring Automatic Windows Update.

http://go.microsoft.com/fwlink/?LinkId=29871

 

 

TechNet Webcast: Essentials of Security (Part 1) - Security and Defense - Level 200

June 14, 2004

9:00 AM - 9:45 AM Pacific Time

Shawn Travers, SST TechNet Presenter, Microsoft Corporation

 

How does a security plan affect the commerce of the business it is supposed to protect? How can you be sure your security plan implements the right kind of security for each type of vulnerability? This webcast presents a defense-in-depth model that can help provide protection for each layer of an infrastructure. The discussion also includes strategies for security response, common attack scenarios, and best practices. During this webcast we will walk through two demonstrations: Internet Connection Firewall and Protecting IIS 5.0.

http://go.microsoft.com/fwlink/?LinkId=29329

 

 

TechNet Webcast: Implementing Network and Perimeter Security - Level 300

June 14, 2004

11:00 AM - 12:30 PM Pacific Time

Byron Hynes, Consultant, Market Star

 

In this session for experienced IT professionals, you will build on existing knowledge of server and client security and learn how to apply best practices to implement perimeter and network defenses. The session will discuss the use of hardware and software firewalls for network and application filtering and how to implement intrusion detection mechanisms. You will also learn how to increase security for wireless network access through the use of encryption and password authentication protocols.

http://go.microsoft.com/fwlink/?LinkId=29394

 

 

TechNet Webcast: Implementing Server Security on Windows 2000 and Windows 2003 (Part 2) - Hardening Member Servers and Hardening Domain Controllers - Level 200

June 15, 2004

9:00 AM - 9:45 AM Pacific Time

Mark Mortimore, Senior Technical Specialist, Microsoft Corporation

 

This webcast addresses implementing security on many different types of servers found in a Windows 2000 Server and Windows Server 2003 environment and practical information on how to harden domain controllers.  We will provide recommendations and practical information about how to harden servers in general and how to harden member servers, in particular. During this webcast we will see two demonstrations on using MBSA and Hardening Domain Controllers.

http://go.microsoft.com/fwlink/?LinkId=29399

 

 

TechNet Webcast: Implementing Client Security on Windows 2000 and Windows XP (Part 2) - Securing Your Environment with Active Directory - Level 200

June 15, 2004

11:00 AM - 11:45 AM Pacific Time

Mark Mortimore, Senior Technical Specialist, Microsoft Corporation

 

This webcast will cover the role of Active Directory® in securing network clients and how to leverage Group Policy as a tool to enhance network security. Learn how to use Group Policy to standardize user permissions, simplify administration, and ensure consistent access and security standards. This webcast will also will walk you through two demonstrations with prescriptive information on how to modify Active Directory for client security and how to use Group Policy.

http://go.microsoft.com/fwlink/?LinkId=29874

 

 

TechNet Webcast: Security Patch Management Tools (Part 2) - MBSA and SUS - Level 200

June 16, 2004

11:00 AM - 11:45 AM Pacific Time

Kai Axford, TechNet Presenter, Microsoft Corporation

 

How are you evaluating, distributing, and installing software patches? This webcast reviews the importance of patch management and establishing a patch management process using the Microsoft® Baseline Security Analyzer (MBSA) and Software Update Services (SUS) as a patch management tool in your environment. Using these tools as part of a patch management strategy can benefit your organization in many ways, ultimately improving efficiency and saving time and money. Used properly, they can prevent downtime, loss of data, and other costly problems resulting from an improperly patched infrastructure. Join this webcast to find out how.

http://go.microsoft.com/fwlink/?LinkId=29882

 

 

TechNet Webcast: Essentials of Security (Part 2) - Security Risk Management Discipline - Level 200

June 21, 2004

9:00 AM - 9:45 AM Pacific Time

Shawn Travers, SST TechNet Presenter, Microsoft Corporation

 

So maybe you've heard of Security Risk Management Discipline (SRMD), but what is it exactly, what does it entail, and how do you implement it? This webcast will introduce you to SRMD and discuss its three primary processes: assessment, development, and implementation and operation. Then we go into extensive detail on the SRMD processes, their use and implementation, and best practices. We’ll also walk you through two demonstrations:  Encrypting Network Traffic and Securing Data on a Disk. Join this webcast to learn not only the benefits of SRMD, but how to get the most out of it.

http://go.microsoft.com/fwlink/?LinkId=29891

 

 

TechNet Webcast: Implementing Server Security on Windows 2000 and Windows 2003 (Part 3) - Hardening Servers for Specific Roles and for Standalone Use - Level 200

June 22, 2004

9:00 AM - 9:45 AM Pacific Time

Mark Mortimore, Senior Technical Specialist, Microsoft Corporation

 

You already know that hardening the servers in your infrastructure would improve efficiency and security, but how to do it? This webcast discusses hardening both role-specific and standalone servers. In discussing hardening of servers for specific roles, we will review the importance of applying the appropriate security templates and manually configuring server settings for the role. We will then discuss how to harden standalone servers using Security Configuration and Analysis or Secedit to apply security settings.  This webcast will present two demonstrations on hardening servers for specific roles, and on hardening a stand-alone server.

http://go.microsoft.com/fwlink/?LinkId=29905

 

 

TechNet Webcast: Implementing Client Security on Windows 2000 and Windows XP (Part 3) - Software Restriction, Antivirus and Client Firewalls - Level 200

June 22, 2004

11:00 AM - 11:45 AM Pacific Time

Mark Mortimore, Senior Technical Specialist, Microsoft Corporation

 

Is your client-side security program effective and up-to-date? This webcast discusses important client defense strategies based on software restriction policies, antivirus software and client firewalls. Learn how a software restriction policy can improve client-side reliability and IT staff productivity, the importance of antivirus software and the cost-saving role it can play with a centralized deployment, and the need for client firewalls and the variety of firewall options available. This webcast also features two demonstrations: applying a software restriction policy and enabling the client firewall.

http://go.microsoft.com/fwlink/?LinkId=29912

 

 

TechNet Webcast: Applied Security Strategies - Level 300

June 23, 2004

9:00 AM - 10:30 PM Pacific Time

Byron Hynes, Consultant, Market Star

 

In this session for experienced IT professionals, you will build on existing knowledge of server and client security and learn how to apply best practices to implement perimeter and network defenses. The session will discuss the use of hardware and software firewalls for network and application filtering and how to implement intrusion detection mechanisms. You will also learn how to increase security for wireless network access through the use of encryption and password authentication protocols.

http://go.microsoft.com/fwlink/?LinkId=29916

 

 

TechNet Webcast: Security Patch Management Tools (Part 3) - SMS with the SUS Feature Pack - Level 200

June 23, 2004

11:00 AM - 11:45 AM Pacific Time

Kai Axford, TechNet Presenter, Microsoft Corporation

 

Do you have an effective, comprehensive patch management strategy? Do you know when to use Systems Management Server (SMS) and when to use Software Update Services (SUS)? In this webcast we will discuss using SMS and the SUS Feature Pack as patch management tools in your environment and how they fit into a comprehensive patch management strategy. SMS and SUS offer different advantages and benefits to an organization. This webcast will review their different capabilities and how they contribute to a secure infrastructure.

http://go.microsoft.com/fwlink/?LinkId=29917

 

 

TechNet Webcast: Mitigation Best Practices - Level 200

June 24, 2004

1:00 PM - 2:30 PM Pacific Time

Jesper Johansson, Security Program Manager, Microsoft Corporation

 

In a perfect world, everything is patched and up-to-date. But what if you have security vulnerabilities, a worm is on the loose, and deploying the patches would be too risky or time-consuming? Welcome to the security practice of "mitigation." In this webcast you will learn how mitigating measures can be used to minimize the impact of security problems in situations where you cannot install patches immediately. The discussion also shows how to analyze various scenarios to determine when and whether mitigation is appropriate for a given situation.

http://go.microsoft.com/fwlink/?LinkId=29918

 

 

TechNet Webcast: Passwords Demystified - Level 200

June 25, 2004

1:00 PM - 2:30 PM Pacific Time

Jesper Johansson, Security Program Manager, Microsoft Corporation

 

How does Windows® handle, store, and use passwords? How are passwords attacked? This webcast discusses these vital password topics as they apply to Windows systems. Join this webcast to hear from a true expert in the field – Dr. Johannson – as he covers everything you wanted to know about how passwords are managed in Windows.

http://go.microsoft.com/fwlink/?LinkId=29919

 

For Developers
 

MSDN Webcast: Dave’s Top 10 Ways to Secure Your Web Application - Level 300

June 1, 2004

9:00 AM - 10:30 AM Pacific Time

David Anthony

 

This webcast presents practical best practices for writing secure ASP.NET code. Dave’s Top 10 field-tested practices are: 10) Hash your passwords in the Presentation Tier, 9) Use Role Based Authentication, 8) Use Declarative Security with PrincipalPermissionAttribute and SecurityAction.Demand, 7) Use Imperative Security with IsInRole, 6) Roll your own custom Principal, 5) Wrap possibly unsecure code with Try Finally (includes cleanup tips), 4) Defeat brute-force attacks with maximum retry counts, 3)  Encrypt sensitive data in .config files and other places with System.Security.Cryptography, 2)  Use Code Access Security to ensure least-privilege in your assemblies, 1)  Use the Framework – DON'T REINVENT THE WHEEL!

http://go.microsoft.com/fwlink/?LinkId=29503

 

 

MSDN Webcast: Essentials of Application Security (Part 1) - Secure Communications - Level 300

June 2, 2004

9:00 AM - 9:45 AM Pacific Time

Mark D. Scott, Senior Software Engineer, RDA Corporation

 

This webcast is the first of a 3-part series about the importance of Application Security and its best practices and guidelines. This part specifically addresses Secure Communications in the context of secure application development. After an overview of the costs of inadequate security and the benefits of developing secure applications, this presentation concentrates on secure communications as part of a larger security solution, examining specific techniques such as using certificates in the Secure Sockets Layer (SSL). The webcast includes two demonstrations: Buffer Overruns and SSL Server Certificates.

http://go.microsoft.com/fwlink/?LinkId=29505

 

 

MSDN Webcast: .NET Framework Security (Part 1) - Features and Cryptography - Level 300

June 7, 2004

1:00 PM - 2:30 PM Pacific Time

Dan Fox, Technical Director, Quilogy

 

Are you aware of the application security and cryptography features available to you through Microsoft® .NET Framework? This webcast begins with an overview of these features, including Buffer overrun protection, Arithmetic error trapping and Isolated Storage. From there we provide a review of cryptography and discuss the encryption features and tools that .NET offers the developer, such as Symmetric and Asymmetric Encryption. The webcast includes two encryption-related demonstrations: Investigating .NET Data-Type Safety Using the Checked Keyword and Performing Symmetric Encryption Signing Data.

http://go.microsoft.com/fwlink/?LinkId=29512

 

 

MSDN Webcast: Essentials of Application Security (Part 2) - Authentication - Level 300

June 9, 2004

9:00 AM - 9:45 AM Pacific Time

Mark D. Scott, Senior Software Engineer, RDA Corporation

 

This webcast is the second of a 3-part series about the importance of Application Security and its best practices and guidelines. This part specifically addresses Authentication in the context of secure application development. After an overview of the costs of inadequate security and the benefits of developing secure applications, we concentrate on Authentication as part of a larger security solution, examining specific Authentication techniques and best practices in IIS. The webcast includes two demonstrations: Buffer Overruns and IIS Authentication Techniques.

http://go.microsoft.com/fwlink/?LinkId=29860

 

 

MSDN Webcast: Writing Secure Code - Best Practices - Level 300

June 11, 2004

1:00 PM - 2:30 PM Pacific Time

Joel Semeniuk, VP of Software Development, ImagiNET Resources Corp.

 

In this webcast for experienced developers, you will learn established best practices for applying security principles throughout the development process. We will discuss common security threats faced by application developers, such as buffer overruns, cross-site scripting and denial of service attacks, and you will learn effective strategies to defend against those threats.

http://go.microsoft.com/fwlink/?LinkId=29284

 

 

MSDN Webcast: .NET Framework Security (Part 2) - Code Access and Role-Based Security - Level 300

June 14, 2004

1:00 PM - 2:30 PM Pacific Time

Dan Fox, Technical Director, Quilogy

 

Are you aware of the code access and role-based security features available to you through Microsoft® .NET Framework? This webcast delves into Framework’s many code access security concepts, including evidence-based security, partial trust applications, and Sandboxing privileged code. From there we will cover role-based security within the .NET Framework, such as authentication and authorization, creating generic identities and principals, and imperative and declarative security checks. This webcast features two important and useful demonstrations: Using the .NET Framework Configuration Tool, Performing Security Checks and Requesting Permissions; and Using Windows Role-Based Security and Using Generic Role-Based Security.

http://go.microsoft.com/fwlink/?LinkId=29869

 

 

MSDN Webcast: Essentials of Application Security (Part 3) - Authorization - Level 300

June 16, 2004

9:00 AM - 9:45 AM Pacific Time

Mark D. Scott, Senior Software Engineer, RDA Corporation

 

This webcast is the third of a 3-part series about the importance of Application Security and its best practices and guidelines. This part specifically addresses Authorization in the context of secure application development. After an overview of the costs of inadequate security and the benefits of developing secure applications, we concentrate on Authorization as part of a larger security solution, examining Trusted Subsystem Model Authorization techniques and best practices. The webcast includes two demonstrations: Buffer Overruns and Trusted Subsystem Model Authorization Techniques.

http://go.microsoft.com/fwlink/?LinkId=29877

 

 

MSDN Webcast: Writing Secure Code - Threat Defense - Level 300

June 18, 2004

9:00 AM - 10:30 AM Pacific Time

Joel Semeniuk, VP of Software Development, ImagiNET Resources Corp.

 

In this session for experienced developers, you will build upon existing knowledge of secure coding best practices to learn about analyzing, mitigating and modeling threats. The session will discuss established threat modeling methodologies and tools and show how they can be applied with other best practices to minimize vulnerabilities and limit damage from attacks.

http://go.microsoft.com/fwlink/?LinkId=29889

 

 

MSDN Webcast: .NET Framework Security (Part 3) - ASP .NET Web Applications and Services - Level 300

June 21, 2004

1:00 PM - 1:45 PM Pacific Time

Dan Fox, Technical Director, Quilogy

 

Are you aware of the security issues for Microsoft® ASP.NET Web applications, and the application security features available to you through Microsoft .NET Framework? This webcast begins by laying out the security issues for Microsoft ASP.NET Web applications. From there we’ll enumerate the security issues for Web services, and then delve into the Web Service Enhancements for security. This webcast features two important and useful demonstrations: Configuring Forms Authentication and Using Validation Controls and Implementing Security for a Web Service.

http://go.microsoft.com/fwlink/?LinkId=29900

 

Additional Webcast Resources
 

§          ALL upcoming Webcasts: http://go.microsoft.com/?LinkID=393776

§          ALL on-demand Webcasts: http://go.microsoft.com/?LinkID=393768

§          TechNet Webcasts: http://go.microsoft.com/?LinkID=446906

§          MSDN Webcasts: http://go.microsoft.com/?LinkID=410865

§          MSDN Architecture Webcasts: http://go.microsoft.com/?LinkID=410866

§          Microsoft Executive Circle Webcasts: http://go.microsoft.com/?LinkID=393792

§          Microsoft Office System Webcasts: http://go.microsoft.com/?LinkID=410868

§          Microsoft Business Solutions Webcasts: http://go.microsoft.com/fwlink/?LinkId=29943

§          Security Webcasts: http://go.microsoft.com/?LinkID=410863