<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Jerry Bryant's Security Blog : General Security</title><link>http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx</link><description>Tags: General Security</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Shared Computer Toolkit for Windows XP</title><link>http://msmvps.com/blogs/secure/archive/2005/09/26/68007.aspx</link><pubDate>Mon, 26 Sep 2005 15:08:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:68007</guid><dc:creator>jbmsft</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/secure/rsscomments.aspx?PostID=68007</wfw:commentRss><comments>http://msmvps.com/blogs/secure/archive/2005/09/26/68007.aspx#comments</comments><description>&lt;P&gt;Here is a technology a lot of people are interested in...&lt;/P&gt;
&lt;H4&gt;Overview&lt;/H4&gt;
&lt;DIV class=DetailsContent&gt;Shared computers are commonly found in schools, libraries, Internet and gaming caf&amp;#233;s, community centers, and other locations. Often, non-technical personnel are asked to manage shared computers in addition to their primary responsibilities. &lt;BR&gt;&lt;BR&gt;Managing shared computers can be difficult, time-consuming, and expensive. Without restrictions, users can change the desktop appearance, reconfigure system settings, and introduce spyware, viruses, and other harmful programs. Repairing damaged shared computers costs significant time and effort. &lt;BR&gt;&lt;BR&gt;User privacy is also an issue. Shared computers often use shared accounts that make Internet history, saved documents, and cached Web pages available to subsequent users. &lt;BR&gt;&lt;BR&gt;The Microsoft Shared Computer Toolkit for Windows XP provides a simple and effective way to defend shared computers from untrusted users and malicious software, safeguard system resources, and enhance and simplify the user experience. The Toolkit runs on genuine copies of Windows XP Professional, Windows XP Home Edition, and Windows XP Tablet PC Edition. &lt;BR&gt;&lt;BR&gt;&lt;B style="FONT-SIZE: 125%"&gt;Tools Summary&lt;/B&gt;&lt;BR&gt;The Toolkit includes several command-line tools and the following graphical tools: &lt;/DIV&gt;
&lt;DIV class=DetailsContent&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;B&gt;Getting Started&lt;/B&gt;. Provides access to computer settings and utilities and helps first-time operators learn the Toolkit basics quickly. 
&lt;LI&gt;&lt;B&gt;Windows Disk Protection&lt;/B&gt;. Protects the Windows partition (typically drive C) that contains the Windows operating system and other programs from being modified without administrator approval. Disk changes made are cleared with each restart unless the administrator chooses to save them. 
&lt;LI&gt;&lt;B&gt;User Restrictions&lt;/B&gt;. Restricts user access to programs, settings, and Start menu items. The tool also allows you to lock shared local user profiles to prevent permanent changes. (This tool is specifically for use in workgroup environments that do not use Active Directory and Group Policy. A Group Policy template is also included for use in Active Directory environments.) 
&lt;LI&gt;&lt;B&gt;Profile Manager&lt;/B&gt;. Creates and deletes user profiles. You can use this tool to create user profiles on alternative drives that will retain data and settings even though Windows Disk Protection is on. You can also use the tool to completely delete profiles that have been locked by the User Restrictions tool. 
&lt;LI&gt;&lt;B&gt;Accessibility&lt;/B&gt;. Makes Windows accessibility options and utilities such as StickyKeys, FilterKeys, and Magnifier available to users who have been restricted from accessing Control Panel and other system settings. &lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=7256d456-e3da-42ea-857d-92b716077a84&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=7256d456-e3da-42ea-857d-92b716077a84&amp;amp;displaylang=en&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category></item><item><title>Anti-Phishing White Paper</title><link>http://msmvps.com/blogs/secure/archive/2005/09/26/68005.aspx</link><pubDate>Mon, 26 Sep 2005 15:03:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:68005</guid><dc:creator>jbmsft</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/secure/rsscomments.aspx?PostID=68005</wfw:commentRss><comments>http://msmvps.com/blogs/secure/archive/2005/09/26/68005.aspx#comments</comments><description>&lt;P&gt;IE 7.0 will have Anti-Phishing built in and this capability will be added to the MSN toolbar as well. This white paper describes the basic workings of this technology. From what I've seen, this will be a great addition for customers. Download the white paper here:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=b4022c66-99bc-4a30-9ecc-8bdefcf0501d&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=b4022c66-99bc-4a30-9ecc-8bdefcf0501d&amp;amp;displaylang=en&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category></item><item><title>Having problems with a security update? Call us!</title><link>http://msmvps.com/blogs/secure/archive/2005/04/19/43566.aspx</link><pubDate>Tue, 19 Apr 2005 14:46:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:43566</guid><dc:creator>jbmsft</dc:creator><slash:comments>3</slash:comments><description>&lt;P&gt;Sometimes after releasing a security update we hear of customers having issues. The only way we can validate those issues is to work directly with the folks that are having the problem. Once we find a problem we can then develop a solution. In other words, we need to be able to reproduce the problem before we can figure out how to address it. &lt;/P&gt;
&lt;P&gt;For problems with a security update, you can call 1-866-PCSafety (1-866-727-2338) in the US. All others should contact your local subsidiary. I hear feedback that people don't believe that this is a free call. As standard procedure, you may be asked for a credit card in case your issue is not actually related to the security update and you still want help. However, if your issue is with the security update you will not be charged. &lt;/P&gt;
&lt;P&gt;So please, if you are having a problem with a security update, give us a call. All numbers can be found at &lt;A href="http://support.microsoft.com"&gt;http://support.microsoft.com&lt;/A&gt;. &lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category></item><item><title>Announcement of Upcoming Release of Malicious Software Removal Tools</title><link>http://msmvps.com/blogs/secure/archive/2005/01/06/29992.aspx</link><pubDate>Thu, 06 Jan 2005 17:28:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:29992</guid><dc:creator>jbmsft</dc:creator><slash:comments>3</slash:comments><description>&lt;P&gt;Starting from January 11th, 2005, Microsoft will provide Windows customers with Malicious Software Removal Tools. New versions of these tools will be available monthly (second Tuesday of every month on the same schedule that Microsoft already delivers other security updates) or more frequently if necessary. &lt;/P&gt;
&lt;P&gt;These removal tools are an extension of virus or worm specific removal tools that Microsoft released in 2004. While tools released in 2004 have been specific to a single virus (and some of its variants), the new removal tools provide more convenience for customers by rolling up all viruses and variants targeted into a common removal tool. &lt;/P&gt;
&lt;P&gt;Microsoft will provide new versions of this tool updated to remove malicious software that is found to be prevalent for that month. The first version of the tool available in January will be able to remove Blaster, Sasser, MyDoom, DoomJuice, Zindos, Berweb (also known as Download.Ject), Gailbot and Nachi viruses / worms. &lt;/P&gt;
&lt;P&gt;These removal tools will be made available to customers through the following delivery vehicles:&lt;BR&gt;&amp;nbsp;- As a download through the Microsoft Download Center&lt;BR&gt;&amp;nbsp;- As a critical update through Windows Update and through Auto Update for those customers who have Auto Update turned on&lt;BR&gt;&amp;nbsp;- As an ActiveX control also available at &lt;A href="http://www.microsoft.com/malwareremove"&gt;www.microsoft.com/malwareremove&lt;/A&gt;&amp;nbsp; &lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Announcements/default.aspx">Security Announcements</category><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/secure/archive/tags/Jerry_2700_s+security+for+consumers/default.aspx">Jerry's security for consumers</category></item><item><title>Microsoft Anti-Spyware Public Beta</title><link>http://msmvps.com/blogs/secure/archive/2005/01/06/29989.aspx</link><pubDate>Thu, 06 Jan 2005 17:22:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:29989</guid><dc:creator>jbmsft</dc:creator><slash:comments>0</slash:comments><description>&lt;P&gt;This alert is to make you aware of the public availability of a beta version of Microsoft Windows AntiSpyware. This beta version is available at the following location: &lt;A href="http://www.microsoft.com/athome/security/spyware/software/default.mspx"&gt;http://www.microsoft.com/athome/security/spyware/software/default.mspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Support for Beta of Microsoft Windows AntiSpyware&lt;/P&gt;
&lt;P&gt;At this time, support for the beta version of Microsoft Windows AntiSpyware is being provided through the following Microsoft&lt;BR&gt;newsgroups:&lt;BR&gt;&amp;nbsp;- microsoft.private.security.spyware.announcements&lt;BR&gt;&amp;nbsp;- microsoft.private.security.spyware.appcompat&lt;BR&gt;&amp;nbsp;- microsoft.private.security.spyware.general&lt;BR&gt;&amp;nbsp;- microsoft.private.security.spyware.install&lt;BR&gt;&amp;nbsp;- microsoft.private.security.spyware.networking&lt;BR&gt;&amp;nbsp;- microsoft.private.security.spyware.signatures&lt;BR&gt;&amp;nbsp;- microsoft.private.security.spyware.onlinecommunity &lt;/P&gt;
&lt;P&gt;These newsgroups can be accessed via NNTP or HTTP.&lt;/P&gt;
&lt;P&gt;To access these newsgroups using HTTP, please go to the following&lt;BR&gt;location:&lt;BR&gt;&lt;A href="http://communities.microsoft.com/newsgroups/default.asp?ICP=spyware&amp;amp;sLCI"&gt;http://communities.microsoft.com/newsgroups/default.asp?ICP=spyware&amp;amp;sLCI&lt;/A&gt;&lt;BR&gt;D=us &lt;/P&gt;
&lt;P&gt;To access these newsgroups using NNTP, please use the following information for your NNTP client (such as Microsoft Outlook Express):&lt;BR&gt;&amp;nbsp;- NNTP Server: privatenews.microsoft.com&lt;BR&gt;&amp;nbsp;- Account name: privatenews\spyware&lt;BR&gt;&amp;nbsp;- Password: spyware &lt;/P&gt;
&lt;P&gt;NOTE: No password will be required via the HTTP link&lt;/P&gt;
&lt;P&gt;Objective Spyware Criteria and Vendor Dispute Information&lt;/P&gt;
&lt;P&gt;Information about the criteria that is part of a scoring system that determines whether a program is added for detection is available at this&lt;BR&gt;location:&lt;BR&gt;&lt;A href="http://www.spynet.com/info_spywarecriteria.aspx"&gt;http://www.spynet.com/info_spywarecriteria.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Vendors of products that are detected who feel the listing in the library is incorrect should fill out the request form located at this&lt;BR&gt;location:&lt;BR&gt;&lt;A href="http://www.spynet.com/vendors.aspx"&gt;http://www.spynet.com/vendors.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Additional Information&lt;/P&gt;
&lt;P&gt;For additional information about today's announcements regarding Microsoft Windows AntiSpyware and Microsoft Malicious Software Removal Tools, please see the public press release located here:&lt;BR&gt;&lt;A href="http://www.microsoft.com/presspass/press/2005/jan05/01-06NewSolutionsPR"&gt;http://www.microsoft.com/presspass/press/2005/jan05/01-06NewSolutionsPR&lt;/A&gt;.&lt;BR&gt;asp&lt;/P&gt;
&lt;P&gt;For additional, general information about Microsoft Windows AntiSpyware and Microsoft's acquisition of Giant Company, please see the public press release located here:&lt;BR&gt;&lt;A href="http://www.microsoft.com/presspass/press/2004/dec04/12-16GIANTPR.asp"&gt;http://www.microsoft.com/presspass/press/2004/dec04/12-16GIANTPR.asp&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Announcements/default.aspx">Security Announcements</category><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/secure/archive/tags/Jerry_2700_s+security+for+consumers/default.aspx">Jerry's security for consumers</category></item><item><title>How to help protect against a WINS security issue</title><link>http://msmvps.com/blogs/secure/archive/2004/11/29/21404.aspx</link><pubDate>Mon, 29 Nov 2004 19:55:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:21404</guid><dc:creator>jbmsft</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;An investigation is underway regarding reports of a security issue with the WINS service (Windows Internet Name Service). We have released the following KB article describing ways to mitigate:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;890710"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;890710&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;WINS is a server service so can be installed on Windows NT 4.0 Server, Windows 2000 Server and Windows Server 2003 but is not installed by default and should NOT be an internet facing service. &lt;/P&gt;
&lt;P&gt;Basically the advice for mitigating potential risk is to block TCP port 42 and UDP port 42 at your firewall or to uninstall the WINS service if you do not need it. &lt;/P&gt;
&lt;P&gt;See the KB article for more details. &lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Announcements/default.aspx">Security Announcements</category><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category></item><item><title>Windows 2000 Update Rollup</title><link>http://msmvps.com/blogs/secure/archive/2004/11/29/21402.aspx</link><pubDate>Mon, 29 Nov 2004 19:46:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:21402</guid><dc:creator>jbmsft</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/secure/rsscomments.aspx?PostID=21402</wfw:commentRss><comments>http://msmvps.com/blogs/secure/archive/2004/11/29/21402.aspx#comments</comments><description>&lt;P&gt;To make it as easy as possible for customers to maintain the security and stability of their Windows 2000 systems, Microsoft will produce an Update Rollup for Windows 2000 Service Pack 4 (SP4), with a planned release in mid-2005.&lt;/P&gt;
&lt;P&gt;Here's the announcement: &lt;BR&gt;&lt;A href="http://www.microsoft.com/windows2000/server/evaluation/news/bulletins/rollup.asp"&gt;http://www.microsoft.com/windows2000/server/evaluation/news/bulletins/rollup.asp&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;And an FAQ:&lt;BR&gt;&lt;A href="http://www.microsoft.com/windows2000/server/evaluation/news/bulletins/rollupfaq.asp"&gt;http://www.microsoft.com/windows2000/server/evaluation/news/bulletins/rollupfaq.asp&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Announcements/default.aspx">Security Announcements</category><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category></item><item><title>Security Resource Guide - November 2004</title><link>http://msmvps.com/blogs/secure/archive/2004/11/24/20647.aspx</link><pubDate>Thu, 25 Nov 2004 02:05:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:20647</guid><dc:creator>jbmsft</dc:creator><slash:comments>10</slash:comments><description>&lt;DIV xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;FONT face=Arial size=2&gt;Microsoft continues to be committed to building software and services that will help better protect our customers and the industry.  Because there is no one solution, our approach to security includes technology innovations to improve the ability to isolate malicious code, improvements in tools and processes for security updates, ongoing work on engineering excellence, and enhancements and improvements for managing user authentication and authorization.  This includes improving our tools and training and providing better prescriptive guidance.   BillG executive email of March 31: &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/mscorp/execmail/2004/03-31security.asp"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/mscorp/execmail/2004/03-31security.asp&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV xmlns="http://www.w3.org/1999/xhtml"&gt;
&lt;TABLE class="MsoTableGrid msoUcTable" style="TABLE-LAYOUT: fixed; WIDTH: 274.5pt; BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" tabIndex=-1 cellPadding=0 width=748 border=1&gt;
&lt;COLGROUP&gt;&lt;FONT size=2&gt;
&lt;COL style="WIDTH: 366px"&gt;&lt;/FONT&gt;&lt;/COLGROUP&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none" vAlign=top&gt;
&lt;DIV align=center&gt;&lt;U&gt;&lt;STRONG&gt;&lt;FONT face=Arial size=2&gt;Tools&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 377.25pt"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none" vAlign=top&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Microsoft Baseline Security Analyzer (MBSA)&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/mbsa"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/mbsa&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Use this tool to identify common security misconfigurations and missing security updates. MBSA runs on the Windows Server&amp;#8482; 2003, Windows&amp;#174; 2000, and Windows XP operating systems and will scan for vulnerabilities in multiple products and technologies, including Microsoft Internet Information Services (IIS) and SQL Server&amp;#8482;.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Software Update Services (SUS) / Windows Update Services (WUS) &lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/wus"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/wus&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Quickly and reliably deploy the latest security updates, and service packs with Software Update Services. This new site now has the latest info on WUS.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Windows Update&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://windowsupdate.microsoft.com/"&gt;&lt;FONT face=Arial size=2&gt;http://windowsupdate.microsoft.com/&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Scans your computer and provides a selection of updates tailored for your operating system, software, and hardware.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Microsoft Office Product Updates&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://office.microsoft.com/productupdates/"&gt;&lt;FONT face=Arial size=2&gt;http://office.microsoft.com/productupdates/&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Scans and updates Microsoft Office products.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;IIS Web Server Lockdown Wizard&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/tools/locktool.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/tools/locktool.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Reduces the attack surface of Internet Information Services (IIS) and includes URLScan to provide multiple layers of protection against attackers.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;UrlScan Security Tool&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/tools/urlscan.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/tools/urlscan.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Helps prevent potentially harmful HTTP requests from reaching IIS Web servers.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Removal Tools:&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Mydoom, Zindos and Doomjuice worms: &lt;/FONT&gt;&lt;A href="http://support.microsoft.com/?kbid=836528"&gt;&lt;FONT face=Arial size=2&gt;http://support.microsoft.com/?kbid=836528&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Blaster Removal Tool for Windows XP and 2000:&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A title=http://www.microsoft.com/downloads/details.aspx?familyid=e70a0d8b-fe98-493f-ad76-bf673a38b4cf&amp;displaylang=en href="http://www.microsoft.com/downloads/details.aspx?familyid=e70a0d8b-fe98-493f-ad76-bf673a38b4cf&amp;displaylang=en"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/downloads/details.aspx?familyid=e70a0d8b-fe98-493f-ad76-bf673a38b4cf&amp;displaylang=en&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Sasser (A-F) Worm Removal Tool: &lt;/FONT&gt;&lt;A href="http://support.microsoft.com/?kbid=841720"&gt;&lt;FONT face=Arial size=2&gt;http://support.microsoft.com/?kbid=841720&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;MS04-028 Enterprise Scanning Tool: &lt;/FONT&gt;&lt;A href="http://support.microsoft.com/?kbid=886988"&gt;&lt;FONT face=Arial size=2&gt;http://support.microsoft.com/?kbid=886988&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Other Tools:&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/tools/default.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/tools/default.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Security Risk Self-Assessment for Midsize Organizations &lt;/FONT&gt;&lt;A href="http://www.securityguidance.com/"&gt;&lt;FONT face=Arial size=2&gt;http://www.securityguidance.com&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;
&lt;DIV xmlns="http://www.w3.org/1999/xhtml"&gt;
&lt;TABLE class="MsoTableGrid msoUcTable" style="TABLE-LAYOUT: fixed; WIDTH: 274.5pt; BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" tabIndex=-1 cellPadding=0 width=748 border=1&gt;
&lt;COLGROUP&gt;&lt;FONT size=2&gt;
&lt;COL style="WIDTH: 366px"&gt;&lt;/FONT&gt;&lt;/COLGROUP&gt;
&lt;TBODY&gt;
&lt;TR style="MIN-HEIGHT: 8.25pt"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none" vAlign=top&gt;
&lt;DIV align=center&gt;&lt;U&gt;&lt;STRONG&gt;&lt;FONT face=Arial size=2&gt;Updating&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 66.75pt"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none" vAlign=top&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Understanding Update Management: Microsoft&amp;#8217;s Software Update Strategy &lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/topics/patch/patchmanagement.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/topics/patch/patchmanagement.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Updated white paper talks about the need for strong update management process.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Other Update Management info in the TechNet Topics Page&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/topics/patch/default.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/topics/patch/default.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 6.75pt"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none" vAlign=top&gt;
&lt;DIV align=center&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;U&gt;&lt;STRONG&gt;Isolation and Resiliency&lt;/STRONG&gt;&lt;/U&gt; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 77.25pt"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none" vAlign=top&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Listing of resources for the IT Pro to evaluate and deploy XP SP2&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/winxpsp2"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/winxpsp2&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Network Access Protection&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/nap"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/nap&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Internet Security and Acceleration (ISA) Server 2004 whitepapers updated&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/isaserver/evaluation/whitepapers/default.asp"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/isaserver/evaluation/whitepapers/default.asp&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Read about secure remote Outlook access in the &lt;EM&gt;Unique Protection for Microsoft Exchange Server&lt;/EM&gt; whitepaper, a very viable business scenario with ISA Server&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 8.25pt"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none" vAlign=top&gt;
&lt;DIV align=center&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;U&gt;&lt;STRONG&gt;Engineering Excellence&lt;/STRONG&gt;&lt;/U&gt; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 1.896in"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none" vAlign=top&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Trustworthy Computing: Security&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/mscorp/twc/security/default.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/mscorp/twc/security/default.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Whitepapers on Security Enhancements:&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Describes the Trustworthy Computing initiative as applied to the Windows Server, Office 2003 and Exchange Server 2003 development processes respectively.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Windows Server 2003:&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/windowsserver2003/techinfo/overview/secinnovation.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/windowsserver2003/techinfo/overview/secinnovation.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Office 2003:&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/prodtechnol/office/office2003/deploy/secdesn.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/prodtechnol/office/office2003/deploy/secdesn.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Exchange Server 2003:&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/exchange/evaluation/Security_e2k3.asp"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/exchange/evaluation/Security_e2k3.asp&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Get the Facts: &lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Windows and Linux: &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/getthefacts"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/getthefacts&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;FONT color=#00ff00&gt;NEW &lt;/FONT&gt;&lt;/EM&gt;&lt;/STRONG&gt;SQL: &lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/sql/evaluation/compare/databasesecurity.asp"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/sql/evaluation/compare/databasesecurity.asp&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;
&lt;DIV xmlns="http://www.w3.org/1999/xhtml"&gt;
&lt;TABLE class="MsoTableGrid msoUcTable" style="TABLE-LAYOUT: fixed; WIDTH: 277.5pt; BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-COLLAPSE: collapse; WORD-WRAP: break-word; BORDER-BOTTOM-STYLE: none" tabIndex=-1 cellPadding=0 width=748 border=1&gt;
&lt;COLGROUP&gt;&lt;FONT size=2&gt;
&lt;COL style="WIDTH: 366px"&gt;
&lt;COL style="WIDTH: 4px"&gt;&lt;/FONT&gt;&lt;/COLGROUP&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-RIGHT: medium none; BORDER-TOP-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none" vAlign=top&gt;
&lt;DIV align=center&gt;&lt;U&gt;&lt;STRONG&gt;&lt;FONT face=Arial size=2&gt;Guidance and Training&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/DIV&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" width=0&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 377.25pt"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none" vAlign=top rowSpan=7&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Security Guidance Centers on Microsoft.com &lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Worldwide: &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/guidance/worldwide/default.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/security/guidance/worldwide/default.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;US: &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/guidance"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/security/guidance&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Prescriptive guidance to help provide defence-in-depth security.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;E-Learning Security Training&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="https://www.microsoftelearning.com/security/"&gt;&lt;FONT face=Arial size=2&gt;https://www.microsoftelearning.com/security/&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;E-Learning self-paced clinics - 4 Developer and 8 ITPro modules &lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Now available in French, German, Spanish and Japanese&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;XP SP2: &lt;/FONT&gt;&lt;A href="https://www.microsoftelearning.com/xpsp2"&gt;&lt;FONT face=Arial size=2&gt;https://www.microsoftelearning.com/xpsp2&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Security Guidance Kit CD (now shipping in US and Canada)&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/security/guidance/order/default.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/security/guidance/order/default.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;CD-ROM with tools, templates, and how-to guides&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Microsoft IT Security Showcase&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/itsolutions/msit/default.mspx#EDBAAA"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/itsolutions/msit/default.mspx#EDBAAA&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;An insider view into Microsoft's process of deploying, and managing its own enterprise solutions.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Security Newsletter&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/secnews/default.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/secnews/default.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Register for our free monthly e-mail newsletter that's packed with security news, guidance, updates, and community resources to help you protect your network.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Security Program Guide: Events and Training Information&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/seminar/events/security.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/seminar/events/security.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Events, webcasts and training ivailable for both IT Professionals and Developers.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;US Security Summit Keynote and Training Content&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/seminar/securitysummit/presentations/default.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/seminar/securitysummit/presentations/default.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Security Notifications via e-mail&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/notify.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/bulletin/notify.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Sign up today to get e-mail alerts when an important security bulletin or virus alert has been released.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Security Update RSS Feed&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/secrss.aspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/bulletin/secrss.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Security Bulletin Search Page&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/current.aspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/current.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Search on product, technology or KB article&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Security Bulletin Webcast&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/summary.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/bulletin/summary.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Join Microsoft experts on the day after bulletin announcements to get the latest information and have the opportunity to ask questions.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;How to Tell If a Microsoft Security-Related Message Is Genuine&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/security/antivirus/authenticate_mail.asp"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/security/antivirus/authenticate_mail.asp&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Writing Secure Code, 2nd edition&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/mspress/books/5957.asp"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/mspress/books/5957.asp&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Best practices for writing secure code and stopping malicious hackers.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Building and Configuring More Secure Web Sites&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://msdn.microsoft.com/library/en-us/dnnetsec/html/openhack.asp"&gt;&lt;FONT face=Arial size=2&gt;http://msdn.microsoft.com/library/en-us/dnnetsec/html/openhack.asp&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Best Practices used at OpenHack.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Recent Security Guidance Center additions:&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Windows XP Guide, includes SP2&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/prodtech/winclnt/secwinxp/default.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/prodtech/winclnt/secwinxp/default.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;New Security Risk Management Guide&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://go.microsoft.com/fwlink/?LinkId=30794"&gt;&lt;FONT face=Arial size=2&gt;http://go.microsoft.com/fwlink/?LinkId=30794&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Windows NT 4.0 and Windows 98 Threat Mitigation Guide&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://go.microsoft.com/fwlink/?linkid=32048"&gt;&lt;FONT face=Arial size=2&gt;http://go.microsoft.com/fwlink/?linkid=32048&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Microsoft Identity and Access Management Series&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://go.microsoft.com/fwlink/?LinkId=14841"&gt;&lt;FONT face=Arial size=2&gt;http://go.microsoft.com/fwlink/?LinkId=14841&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Antivirus Defense-in-Depth&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/guidance/avdind_0.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/guidance/avdind_0.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Securing Wireless LANs with PEAP and Passwords&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/security/guidance/peap_0.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/security/guidance/peap_0.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;U&gt;&lt;FONT face=Arial size=2&gt;Small Business Guidance:&lt;/FONT&gt;&lt;/U&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/smallbusiness/gtm/securityguidance/hub.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/smallbusiness/gtm/securityguidance/hub.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Guidance specifically for the smaller business&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Configuring Windows XP 802.11 Wireless Networks for the Home / Small Business &lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/wifisoho.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/wifisoho.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;U&gt;&lt;FONT face=Arial size=2&gt;Consumer Information:&lt;/FONT&gt;&lt;/U&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/security/protect"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/security/protect&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/athome/security/default.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/athome/security/default.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Newsletter for home users&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://www.microsoft.com/security/home/secnews/current.asp"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/security/home/secnews/current.asp&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;Security bulletin notifications for home users&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="http://register.microsoft.com/subscription/subscribeme.asp?id=166"&gt;&lt;FONT face=Arial size=2&gt;http://register.microsoft.com/subscription/subscribeme.asp?id=166&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM-STYLE: none" width=0&gt;&lt;FONT face=Arial size=2&gt; &lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 9pt"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none"&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 66.75pt"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none"&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 9pt"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none"&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 77.25pt"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none"&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 9pt"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none"&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="MIN-HEIGHT: 1.896in"&gt;
&lt;TD style="BORDER-TOP-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none"&gt;
&lt;DIV&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt; &lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Resources/default.aspx">Security Resources</category></item><item><title>Security At Home</title><link>http://msmvps.com/blogs/secure/archive/2004/11/22/20245.aspx</link><pubDate>Mon, 22 Nov 2004 23:12:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:20245</guid><dc:creator>jbmsft</dc:creator><slash:comments>0</slash:comments><description>&lt;P&gt;At Microsoft, we are making new efforts to educate end users on computer security. Moreover, our web site has been reorganized in a way to make it easier for this audience to find information that should make more sense to them. All the information has been organized under &amp;#8220;&lt;A href="http://www.microsoft.com/athome"&gt;Microsoft At Home&lt;/A&gt;&amp;#8221;. For Security related information, see:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/athome/security/default.mspx"&gt;http://www.microsoft.com/athome/security/default.mspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;A series of videos are also being produced to better demonstrate the information like this one on phishing:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/athome/security/spam/phishing/video1.mspx"&gt;http://www.microsoft.com/athome/security/spam/phishing/video1.mspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We would love to get as much feedback on this infromation as possible. There are several places on the site to give that feedback. &lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/secure/archive/tags/Jerry_2700_s+security+for+consumers/default.aspx">Jerry's security for consumers</category></item><item><title>Sender ID information</title><link>http://msmvps.com/blogs/secure/archive/2004/10/28/16999.aspx</link><pubDate>Thu, 28 Oct 2004 14:47:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:16999</guid><dc:creator>jbmsft</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;&lt;STRONG&gt;Sender ID Framework Overview:&lt;BR&gt;&lt;/STRONG&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=81682a25-a628-4771-8481-5cb9ffddffe8"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=81682a25-a628-4771-8481-5cb9ffddffe8&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Overview of the Sender ID Framework, including the use of text files using the revised Sender Policy Framework (SPF) format, Purported Responsible Address (PRA) and Mail From checks, and the submitter Optimizations. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Sender ID: Authenticating E-Mail Specification (Draft):&lt;BR&gt;&lt;/STRONG&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=cf24ffd3-b04e-4b89-9d15-069c44aef7f2"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=cf24ffd3-b04e-4b89-9d15-069c44aef7f2&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This core document describes how the Sender ID Framework works. The specification provides an overview of the usage of Sender Policy Framework (SPF) records, how to check the validity of either the Mail From or the PRA of an e-mail message, and how to interpret the results of the check.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Sender Policy Framework: Authorizing Use of Domains in Mail From:&lt;BR&gt;&lt;/STRONG&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=d8a174b1-697c-4aea-9c92-2e70a013c30b"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=d8a174b1-697c-4aea-9c92-2e70a013c30b&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This document describes the content and format of the SPF record, the information that senders need to publish in DNS regarding their outbound e-mail servers. It also describes how receivers use this information to validate the Mail From domain of an e-mail message. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Purported Responsible Address in E-Mail Messages Specification (Draft):&lt;/STRONG&gt;&lt;BR&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=f8e9cb40-cc7c-46d6-8cd1-3a86a46546d5"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=f8e9cb40-cc7c-46d6-8cd1-3a86a46546d5&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Describes how to extract from an e-mail message the Purported Responsible Address (PRA). &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Sender ID Framework Deployment Overview:&lt;BR&gt;&lt;/STRONG&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=8958ab23-f350-40fe-ba0a-2967b968fd8d"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=8958ab23-f350-40fe-ba0a-2967b968fd8d&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Deployment overview that describes the steps e-mail senders must take to comply with the Sender ID Framework specification. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Sender ID Framework Executive Overview:&lt;BR&gt;&lt;/STRONG&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=f23a8ddd-f4dd-4419-b7e0-2b1d189789db"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=f23a8ddd-f4dd-4419-b7e0-2b1d189789db&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Executive overview of the group Sender ID Framework, including the issues, process, and design goals. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Sender ID Framework and Intellectual Property Overview and FAQ:&lt;BR&gt;&lt;/STRONG&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=4b1c931a-57cf-40a4-91b0-80e18cfd2be1"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=4b1c931a-57cf-40a4-91b0-80e18cfd2be1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;FAQ regarding the need and use of Microsoft's royalty-free license for implementation of the Sender ID Framework. &lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Resources/default.aspx">Security Resources</category></item><item><title>What You Should Know About a Reported Vulnerability in Microsoft ASP.NET</title><link>http://msmvps.com/blogs/secure/archive/2004/10/06/15120.aspx</link><pubDate>Wed, 06 Oct 2004 19:14:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:15120</guid><dc:creator>jbmsft</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;Microsoft is currently investigating a reported vulnerability in Microsoft ASP.NET. An attacker can send specially crafted requests to the server and view secured content without providing the proper credentials. This reported vulnerability exists in ASP.NET and does not affect ASP.&lt;/P&gt;
&lt;P&gt;Read more:&lt;BR&gt;&lt;A href="http://www.microsoft.com/security/incident/aspnet.mspx"&gt;http://www.microsoft.com/security/incident/aspnet.mspx&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Announcements/default.aspx">Security Announcements</category><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category></item><item><title>Controlling block storage devices on USB buses</title><link>http://msmvps.com/blogs/secure/archive/2004/09/10/13309.aspx</link><pubDate>Fri, 10 Sep 2004 13:04:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:13309</guid><dc:creator>jbmsft</dc:creator><slash:comments>2</slash:comments><description>&lt;P&gt;I haven't seen a lot of talk about this recently but I recall several months or even a year or so ago that this was a hot topic with all of the new USB flash drives hitting the market. I had some conversations with MVPs and members of the product teams about this. At the time, we didn't have any plans to tighten things down and give the ability to block users from writing to these types of devices but with our SP2 security push, lots of plans got changed. &lt;/P&gt;
&lt;P&gt;So, the ability to turn USB storage devices in to ReadOnly devices has been implemented in SP2 through a registry setting. &lt;/P&gt;
&lt;P&gt;
&lt;TABLE class=dataTable id=XSLTdataTable121123127121120120 cellSpacing=0 cellPadding=0&gt;
&lt;THEAD&gt;
&lt;TR class=stdHeader vAlign=top&gt;
&lt;TD id=colXSLTfield120120121123127121120120 width="14%"&gt;Setting name&lt;/TD&gt;
&lt;TD id=colXSLTfield121120121123127121120120 width="46%"&gt;Location&lt;/TD&gt;
&lt;TD id=colXSLTfield122120121123127121120120 width="17%"&gt;Default value&lt;/TD&gt;
&lt;TD id=colXSLTfield123120121123127121120120 style="BORDER-RIGHT: #cccccc 1px solid" width="23%"&gt;Possible values&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR class=record vAlign=top&gt;
&lt;TD&gt;
&lt;P class=lastInCell&gt;&lt;B&gt;WriteProtect&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P class=lastInCell&gt;&lt;B&gt;HKEY_LOCAL_MACHINE\System\&lt;/B&gt;&lt;BR&gt;&lt;B&gt;CurrentControlSet\Control \StorageDevicePolicies&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P class=lastInCell&gt;DWORD=0&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: #cccccc 1px solid"&gt;
&lt;P&gt;&lt;B&gt;0 - &lt;/B&gt;Disabled&lt;/P&gt;
&lt;P&gt;&lt;B&gt;1 -&lt;/B&gt; Enabled&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P&gt;More information here:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2otech.mspx#XSLTsection127121120120"&gt;http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2otech.mspx#XSLTsection127121120120&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category></item><item><title>More time to test Windows XP SP2</title><link>http://msmvps.com/blogs/secure/archive/2004/09/09/13272.aspx</link><pubDate>Thu, 09 Sep 2004 16:34:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:13272</guid><dc:creator>jbmsft</dc:creator><slash:comments>2</slash:comments><description>&lt;P&gt;As you may or may not know, we have implemented a method that will allow corporations to block their systems from downloading SP2 from either Windows Update or Automatic Update. See the following link for details:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2aumng.mspx"&gt;http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2aumng.mspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Originally this mechanism was only going to be in place for 120 days. This has been extended to 240 days or April 12, 2005 in order to allow customers more time for deployment testing. &lt;/P&gt;
&lt;P&gt;The &amp;#8220;mechanism&amp;#8221; in question is a registry setting that WU/AU looks for. After the 240 period ends, WU/AU will no longer check for that setting.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category></item><item><title>Stephen Toulouse from the MSRC on Channel 9</title><link>http://msmvps.com/blogs/secure/archive/2004/08/27/12478.aspx</link><pubDate>Fri, 27 Aug 2004 20:57:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:12478</guid><dc:creator>jbmsft</dc:creator><slash:comments>10</slash:comments><description>&lt;P&gt;Stephen is a program manager on the Microsoft Security Response Center team. Watch his video interview on Channel 9 to get a first hand look at how the MSRC works:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://channel9.msdn.com/ShowPost.aspx?PostID=19449"&gt;http://channel9.msdn.com/ShowPost.aspx?PostID=19449&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category></item><item><title>Excellent information on the new IE pop up blocker from JeffDav of the IE Core team</title><link>http://msmvps.com/blogs/secure/archive/2004/06/22/8754.aspx</link><pubDate>Wed, 23 Jun 2004 00:14:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:8754</guid><dc:creator>jbmsft</dc:creator><slash:comments>10</slash:comments><description>&lt;A href="http://blogs.msdn.com/jeffdav/archive/2004/06/21/161789.aspx"&gt;http://blogs.msdn.com/jeffdav/archive/2004/06/21/161789.aspx&lt;/A&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Resources/default.aspx">Security Resources</category></item><item><title>STRIDE model of threat categories</title><link>http://msmvps.com/blogs/secure/archive/2004/06/22/8728.aspx</link><pubDate>Tue, 22 Jun 2004 12:26:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:8728</guid><dc:creator>jbmsft</dc:creator><slash:comments>11</slash:comments><description>&lt;P&gt;At Microsoft, we have developed what we call the STRIDE model for categorizing software threats. These are used in security bulletins to describe the nature of a security vulnerability. &lt;/P&gt;
&lt;P&gt;Here is a summary of the model:&lt;/P&gt;
&lt;P&gt;
&lt;TABLE class=dataTable id=table1 cellSpacing=0 cellPadding=0&gt;
&lt;THEAD&gt;
&lt;TR class=stdHeader vAlign=top&gt;
&lt;TD id=colXSLTfield120120123125128121120120 width="32%" bgColor=#000000&gt;&lt;FONT color=#ffffff&gt;Term&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD id=colXSLTfield121120123125128121120120 style="BORDER-RIGHT: #cccccc 1px solid" width="68%" bgColor=#000000&gt;&lt;FONT color=#ffffff&gt;Definition&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR class=record vAlign=top&gt;
&lt;TD&gt;
&lt;P class=lastInCell&gt;Spoofing identity&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: #cccccc 1px solid"&gt;
&lt;P class=lastInCell&gt;Illegally obtaining access and use of another person's authentication information, such as a user name or password.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR class=evenRecord vAlign=top&gt;
&lt;TD bgColor=#c0c0c0&gt;
&lt;P class=lastInCell&gt;Tampering with data&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: #cccccc 1px solid" bgColor=#c0c0c0&gt;
&lt;P class=lastInCell&gt;The malicious modification of data.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR class=record vAlign=top&gt;
&lt;TD&gt;
&lt;P class=lastInCell&gt;Repudiation&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: #cccccc 1px solid"&gt;
&lt;P class=lastInCell&gt;Associated with users who deny performing an action, yet there is no way to prove otherwise. (Non-repudiation refers to the ability of a system to counter repudiation threats, and includes techniques such as signing for a received parcel so that the signed receipt can be used as evidence.)&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR class=evenRecord vAlign=top&gt;
&lt;TD bgColor=#c0c0c0&gt;
&lt;P class=lastInCell&gt;Information disclosure&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: #cccccc 1px solid" bgColor=#c0c0c0&gt;
&lt;P class=lastInCell&gt;The exposure of information to individuals who are not supposed to have access to it, such as accessing files without having the appropriate rights.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR class=record vAlign=top&gt;
&lt;TD&gt;
&lt;P class=lastInCell&gt;Denial of service&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: #cccccc 1px solid"&gt;
&lt;P class=lastInCell&gt;An explicit attempt to prevent legitimate users from using a service or system.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR class=evenRecord vAlign=top&gt;
&lt;TD bgColor=#c0c0c0&gt;
&lt;P class=lastInCell&gt;Elevation of privilege&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: #cccccc 1px solid" bgColor=#c0c0c0&gt;
&lt;P class=lastInCell&gt;Where an unprivileged user gains privileged access. An example of privilege elevation would be an unprivileged user who contrives a way to be added to the Administrators group.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P&gt;This model is discussed in detail in the book &amp;#8220;&lt;A href="http://www.microsoft.com/mspress/books/5957.asp"&gt;Writing Secure Code, Second Edition&lt;/A&gt;&amp;#8221; by Michael Howard and David LaBlanc.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Resources/default.aspx">Security Resources</category></item><item><title>The New Wireless Network Setup Wizard in Windows XP Service Pack 2</title><link>http://msmvps.com/blogs/secure/archive/2004/06/20/8592.aspx</link><pubDate>Sun, 20 Jun 2004 13:36:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:8592</guid><dc:creator>jbmsft</dc:creator><slash:comments>10</slash:comments><description>&lt;P&gt;Windows XP SP2 has a cool new wireless network setup wizard to help end users set up secure wireless in their homes. The wizard saves configuration information to a USB flash drive that can be carried to each wireless machine for setup. &lt;/P&gt;
&lt;P&gt;You can read The Cable Guy's review here:&lt;BR&gt;&lt;A href="http://www.microsoft.com/technet/community/columns/cableguy/default.mspx"&gt;http://www.microsoft.com/technet/community/columns/cableguy/default.mspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Or get more details in part 2 of the Changes to Functionality in Microsoft Windows XP Service Pack 2 online documentation here:&lt;BR&gt;&lt;A href="http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2netwk.mspx"&gt;http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2netwk.mspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR&gt; &lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Resources/default.aspx">Security Resources</category></item><item><title>Improving Security with Domain Isolation: Microsoft IT implements IP Security (IPsec)</title><link>http://msmvps.com/blogs/secure/archive/2004/06/14/8175.aspx</link><pubDate>Mon, 14 Jun 2004 18:49:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:8175</guid><dc:creator>jbmsft</dc:creator><slash:comments>11</slash:comments><description>&lt;P&gt;&lt;STRONG&gt;Situation&lt;/STRONG&gt;&lt;BR&gt;As part of its &amp;#8220;defense in depth&amp;#8221; security strategy, Microsoft IT wanted to isolate their managed computers from unmanaged (and untrusted) computers. If trusted computers could be made to ignore requests from these untrusted computers, they could be kept more secure.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Solution&lt;BR&gt;&lt;/STRONG&gt;Microsoft IT chose IP Security (IPsec), a standards-based approach to authenticating network traffic. With IPsec, the corporate domains can be isolated, segmenting all computers into trusted and untrusted groups.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Benefits&lt;/STRONG&gt;&lt;BR&gt;&amp;#8226; Allows creation of logical secure network segments behind the corporate network perimeter.&lt;BR&gt;&amp;#8226; Works independently of network hardware, computers, and other infrastructure, providing end-to-end security to the edges of the network.&lt;BR&gt;&amp;#8226; Can be deployed and managed centrally through the use of Group Policy.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Products &amp; Technologies&lt;/STRONG&gt; &lt;BR&gt;&amp;#8226; IP Security protocols (ESP, IKE)&lt;BR&gt;&amp;#8226; Windows Server 2003&lt;BR&gt;&amp;#8226; Windows XP Professional (SP 1)&lt;BR&gt;&amp;#8226; Windows 2000 (SP3)&lt;BR&gt;&amp;#8226; Group Policy&lt;BR&gt;&amp;#8226; Active Directory&lt;BR&gt;&amp;#8226; Public Key Infrastructure and Certificate Authority (CA)&lt;/P&gt;
&lt;P&gt;Download the white paper here:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=a97ddc48-a364-4756-bb3c-91da274118fe&amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=a97ddc48-a364-4756-bb3c-91da274118fe&amp;displaylang=en&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Resources/default.aspx">Security Resources</category></item><item><title>Free online AV scanner</title><link>http://msmvps.com/blogs/secure/archive/2004/06/12/8052.aspx</link><pubDate>Sat, 12 Jun 2004 14:29:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:8052</guid><dc:creator>jbmsft</dc:creator><slash:comments>18</slash:comments><description>&lt;P&gt;There are a few free online AV scanners out there. They are all really helpful when you are trying to help a friend or family member with a virus issue and they don't have any AV on their machine. Feel free to post your favorite as feedback to this post. Here's one of mine:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.ravantivirus.com/scan/"&gt;http://www.ravantivirus.com/scan/&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Resources/default.aspx">Security Resources</category></item><item><title>Exchange Server 2003 Message Security Guide</title><link>http://msmvps.com/blogs/secure/archive/2004/06/12/8051.aspx</link><pubDate>Sat, 12 Jun 2004 14:22:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:8051</guid><dc:creator>jbmsft</dc:creator><slash:comments>8</slash:comments><description>&lt;P&gt;This is really cool:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overview&lt;BR&gt;&lt;/STRONG&gt;This book discusses how, when using S/MIME, encryption protects the contents of e-mail messages and digital signatures verify the identity of a purported sender of an e-mail message. In addition, this book provides guidance on how to implement S/MIME with Microsoft Exchange Server 2003. In addition, this book provides guidance and pointers to other resources where those are necessary.&lt;/P&gt;
&lt;P&gt;Note: A script (ListSMIMECerts.vbs) is included in this download and will be unpackaged with the guide.&lt;/P&gt;
&lt;P&gt;Download it here:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=2305405c-faf1-488a-a856-ad467bb59b26&amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=2305405c-faf1-488a-a856-ad467bb59b26&amp;displaylang=en&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description><category domain="http://msmvps.com/blogs/secure/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/secure/archive/tags/Security+Resources/default.aspx">Security Resources</category></item></channel></rss>