<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Risque Management - All Comments</title><link>http://msmvps.com/blogs/sp/default.aspx</link><description>Information Security for Information Society</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>99 angel perfume</title><link>http://msmvps.com/blogs/sp/archive/2007/04/23/picture-authentication-threat-modeling.aspx#1730251</link><pubDate>Tue, 06 Oct 2009 15:36:16 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1730251</guid><dc:creator>Mora</dc:creator><description>&lt;p&gt;Hi everyone. Enjoyed your site. Well Done. Help me! There is an urgent need for sites: SĂ¶renstam has criticized a attention of park theme debit transactions.. I found only this - [URL=&lt;a rel="nofollow" target="_new" href="http://www.sosiaalikollega.fi/Members/Angel"&gt;www.sosiaalikollega.fi/.../Angel&lt;/a&gt;]Angels desire perfume[/URL]. Hina, has and yuyu were other to be received, unfortunately hina ended through. During the nit&amp;#39;s several 15 merchants or only, the hills were saved as national champions by some, and credit marred which singer way was un-reimbursed. THX :cool:, Mora from Marino.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1730251" width="1" height="1"&gt;</description></item><item><title>re: How to prevent 1% of cybercrime?</title><link>http://msmvps.com/blogs/sp/archive/2007/05/04/how-to-prevent-1-percent-of-cybercrime.aspx#1710535</link><pubDate>Tue, 28 Jul 2009 14:03:46 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1710535</guid><dc:creator>Tom Rand</dc:creator><description>&lt;p&gt;I acualy used the service of an online scan for my site provide by GamaSec www.gamasec.com&lt;/p&gt;
&lt;p&gt;i can say that I am please of the service, the clear report with practical recommendation to solve the vulnerabilities and the easy and freindly control panel that provid on demand scan scheduler.&lt;/p&gt;
&lt;p&gt;I my opinion the use of 3th partty security scan and security seal is important for website and for customer but the it must be done by proffessional companies and not onlt seals marketing comapnies.&lt;/p&gt;
&lt;p&gt;I can from our experience recommend the used of www.gamasec.com for vulnerabilities scan&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1710535" width="1" height="1"&gt;</description></item><item><title>re: Smart card logon error 0xC00000BB</title><link>http://msmvps.com/blogs/sp/archive/2007/06/02/smart-card-logon-error-0xc00000bb.aspx#1710485</link><pubDate>Tue, 28 Jul 2009 07:29:32 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1710485</guid><dc:creator>Noble</dc:creator><description>&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.actividentity.com/support/kbase/cms/display_article.php?kbid=562"&gt;www.actividentity.com/.../display_article.php&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1710485" width="1" height="1"&gt;</description></item><item><title>Different Skype Issue</title><link>http://msmvps.com/blogs/sp/archive/2007/08/25/how-to-stop-skype-using-isa-server-and-why.aspx#1696418</link><pubDate>Tue, 23 Jun 2009 18:32:54 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1696418</guid><dc:creator>Tim </dc:creator><description>&lt;p&gt;I&amp;#39;m writing since you seem to understand the Skype issues. We do not want to stop Skype, but it has opened so many DNS requests and open connections that it blocks up our firewall, and we are forced to reset it.&lt;/p&gt;
&lt;p&gt;Are there any Skype settings that would reduce this need?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1696418" width="1" height="1"&gt;</description></item><item><title>re: How not to make decisions</title><link>http://msmvps.com/blogs/sp/archive/2009/04/12/how-not-to-make-decisions.aspx#1687324</link><pubDate>Mon, 13 Apr 2009 23:55:03 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1687324</guid><dc:creator>Nhon Yeung</dc:creator><description>&lt;p&gt;I lot of it comes down to whether you have the time and money to invest in trying something new. Most organizations opt for the known and supported solutions hence you get the &amp;quot;we don&amp;#39;t support it as we do not know how it&amp;#39;ll behave&amp;quot; type scenarios. This hinders innovation and you end up with cookie cutter architectures which may not take full advantage of the technology. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1687324" width="1" height="1"&gt;</description></item><item><title>US Senate: security through (more) bureaucracy</title><link>http://msmvps.com/blogs/sp/archive/2009/02/15/compliance-is-not-security.aspx#1684775</link><pubDate>Sun, 05 Apr 2009 01:07:45 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1684775</guid><dc:creator>Risque Management</dc:creator><description>&lt;p&gt;When I first read the news on the Washington Post web site, I thought this is a 1 April joke: Senate&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1684775" width="1" height="1"&gt;</description></item><item><title>Windows 2008 Security  - Compliance is not security</title><link>http://msmvps.com/blogs/sp/archive/2009/02/15/compliance-is-not-security.aspx#1672563</link><pubDate>Mon, 16 Feb 2009 05:16:49 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1672563</guid><dc:creator>Windows 2008 Security  - Compliance is not security</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Windows 2008 Security &amp;nbsp;- Compliance is not security&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1672563" width="1" height="1"&gt;</description></item><item><title>Security Product Watch  &amp;raquo; Blog Archive   &amp;raquo; What is more secure?</title><link>http://msmvps.com/blogs/sp/archive/2007/11/09/what-is-more-secure.aspx#1292224</link><pubDate>Sat, 10 Nov 2007 07:26:49 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1292224</guid><dc:creator>Security Product Watch  » Blog Archive   » What is more secure?</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Security Product Watch &amp;nbsp;&amp;amp;raquo; Blog Archive &amp;nbsp; &amp;amp;raquo; What is more secure?&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1292224" width="1" height="1"&gt;</description></item><item><title>re: Integrating Java, JDBC and Kerberos</title><link>http://msmvps.com/blogs/sp/archive/2007/06/05/integrating-java-jdbc-and-kerberos.aspx#1276659</link><pubDate>Thu, 01 Nov 2007 10:54:38 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1276659</guid><dc:creator>grrd</dc:creator><description>&lt;p&gt;host/XXXXX@FORMUE.LOCAL is a user account in Active Directory, but it represents the machine on which the application runs (as described in &lt;a rel="nofollow" target="_new" href="http://edocs.bea.com/wls/docs81/secmanage/sso.html"&gt;edocs.bea.com/.../sso.html&lt;/a&gt;). The user in &amp;#39;Invalid Subject: xxxxx&amp;#39; is a normal user with a valid account. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1276659" width="1" height="1"&gt;</description></item><item><title>re: Integrating Java, JDBC and Kerberos</title><link>http://msmvps.com/blogs/sp/archive/2007/06/05/integrating-java-jdbc-and-kerberos.aspx#1276507</link><pubDate>Thu, 01 Nov 2007 07:17:49 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1276507</guid><dc:creator>Slav</dc:creator><description>&lt;p&gt;Principal is host/XXXXX@FORMUE.LOCAL, eh? I reckon using a user account is a better option.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1276507" width="1" height="1"&gt;</description></item><item><title>re: Integrating Java, JDBC and Kerberos</title><link>http://msmvps.com/blogs/sp/archive/2007/06/05/integrating-java-jdbc-and-kerberos.aspx#1275337</link><pubDate>Wed, 31 Oct 2007 11:09:37 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1275337</guid><dc:creator>grrd</dc:creator><description>&lt;p&gt;Hello and thanks for your helpful blog post. This is the only useful piece of information I have been able to find on this subject. &lt;/p&gt;
&lt;p&gt;I am running WebLogic 8.1.6 on Win2003 server, and using the Datadirect Driver for my connection pool. I have set up Kerberos authentication as described and am trying to get a connection (and execute a stored procedure) as a logged in user, but when I do Datasource#getConnection (in Security.runAs(subject, new PrivilegedExceptionAction() {....) I get the following error:&lt;/p&gt;
&lt;p&gt;Debug is &amp;nbsp;true storeKey false useTicketCache true useKeyTab false doNotPrompt true ticketCache is null KeyTab is null refreshKrb5Config is false princ&lt;/p&gt;
&lt;p&gt;ipal is null tryFirstPass is false useFirstPass is false storePass is false clearPass is false&lt;/p&gt;
&lt;p&gt;Principal is host/XXXXX@FORMUE.LOCAL&lt;/p&gt;
&lt;p&gt;Commit Succeeded&lt;/p&gt;
&lt;p&gt;applicationlogger 2007-10-31 12:01:54,202 ERROR java.sql.SQLException: Pool connect failed : java.lang.SecurityException: [Security:090398]Invalid Sub&lt;/p&gt;
&lt;p&gt;ject: xxxxx&lt;/p&gt;
&lt;p&gt;&amp;lt;Oct 31, 2007 12:01:54 PM CET&amp;gt; &amp;lt;Error&amp;gt; &amp;lt;HTTP&amp;gt; &amp;lt;BEA-101020&amp;gt; &amp;lt;[ServletContext(id=28475974,name=web,context-path=)] Servlet failed with Exception&lt;/p&gt;
&lt;p&gt;java.lang.RuntimeException: java.sql.SQLException: Pool connect failed : java.lang.SecurityException: [Security:090398]Invalid Subject: xxxxx&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;at no.formue.util.database.DBMgr$1.run(DBMgr.java:308)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;at weblogic.security.acl.internal.AuthenticatedSubject.doAs(AuthenticatedSubject.java:363)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;at weblogic.security.service.SecurityManager.runAs(SecurityManager.java:147)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;at weblogic.security.Security.runAs(Security.java:61)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;at no.formue.util.database.DBMgr.getConnection(DBMgr.java:294)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;at no.formue.util.database.DBMgr.getDefaultConnection(DBMgr.java:262)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;at no.formue.login.servlet.ADLoginServlet.doGet(ADLoginServlet.java:45)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;at javax.servlet.http.HttpServlet.service(HttpServlet.java:740)&lt;/p&gt;
&lt;p&gt;The subject is authenticated and valid at this point as far as I can tell. Any ideas what might cause this?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1275337" width="1" height="1"&gt;</description></item><item><title>re: Notes from RIM BlackBerry presentation</title><link>http://msmvps.com/blogs/sp/archive/2007/03/01/notes-from-rim-blackberry-presentation.aspx#1242730</link><pubDate>Wed, 10 Oct 2007 01:30:01 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1242730</guid><dc:creator>muugi</dc:creator><description>&lt;p&gt;want to see content&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1242730" width="1" height="1"&gt;</description></item><item><title>re: VoIP Scaremongers</title><link>http://msmvps.com/blogs/sp/archive/2007/08/05/voip-scaremongers.aspx#1091278</link><pubDate>Mon, 06 Aug 2007 19:34:16 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1091278</guid><dc:creator>Joshua Thomas</dc:creator><description>&lt;p&gt;who knows they might have lots more up their sleeves ... &lt;/p&gt;
&lt;p&gt;AFAIK I know OCS has been cracked open too.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1091278" width="1" height="1"&gt;</description></item><item><title>Virtually hopeless</title><link>http://msmvps.com/blogs/sp/archive/2007/03/30/q-detecting-virtualisation.aspx#1072201</link><pubDate>Mon, 30 Jul 2007 09:50:55 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1072201</guid><dc:creator>Risque Management</dc:creator><description>&lt;p&gt;I don&amp;amp;#39;t know if that&amp;amp;#39;s CIOs, or the press, or both. Recently Byte &amp;amp;amp; Switch, CMP Technology&amp;amp;#39;s&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1072201" width="1" height="1"&gt;</description></item><item><title>re: Virtual infrastructure v Terminal servers</title><link>http://msmvps.com/blogs/sp/archive/2007/07/14/virtual-infrastructure-v-terminal-servers.aspx#1046465</link><pubDate>Sun, 22 Jul 2007 01:35:16 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1046465</guid><dc:creator>Slav</dc:creator><description>&lt;p&gt;Appareltly VMWare/EMC don't recommend iSCSI for enterprises. The recommendation is Fibre Channel but there are few things that aren't trivial if you want dynamic DR capability in multidatacentre environment. Namely - eliminating SAN as single point of failure.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1046465" width="1" height="1"&gt;</description></item><item><title>Governments are hopeless at security</title><link>http://msmvps.com/blogs/sp/archive/2007/03/01/notes-from-rim-blackberry-presentation.aspx#1000281</link><pubDate>Wed, 04 Jul 2007 09:36:13 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1000281</guid><dc:creator>Risque Management</dc:creator><description>&lt;p&gt;One of the good things about BlackBerry - apart from the main client platform that will never get really&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1000281" width="1" height="1"&gt;</description></item><item><title>re: Use glue instead</title><link>http://msmvps.com/blogs/sp/archive/2007/06/25/use-glue-instead.aspx#991841</link><pubDate>Tue, 26 Jun 2007 23:59:03 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:991841</guid><dc:creator>Nhon Yeung</dc:creator><description>&lt;p&gt;Another way without extra software is to do it in the BIOS. Most corporate pc's (ie dell/HP) also have hardware interlocks which can be configured to alert if the pc is opened as well. So you can be notified if someone tries to reset the BIOS or remove the HDD. I guess the only thing you need to glue to the pc is the mouse considering ps/2 or serial ports are pretty much extinct these days.&lt;/p&gt;
&lt;p&gt;But i agree, siphoning info is a null point.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=991841" width="1" height="1"&gt;</description></item><item><title>The attack surface</title><link>http://msmvps.com/blogs/sp/archive/2007/02/25/good-principles-for-solution-architects.aspx#962166</link><pubDate>Thu, 14 Jun 2007 09:25:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:962166</guid><dc:creator>Risque Management</dc:creator><description>&lt;p&gt;Jabez Gan, a fellow MVP, did an interesting book review - that of Professional Windows Desktop and Server&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=962166" width="1" height="1"&gt;</description></item><item><title>re: Single authority principle</title><link>http://msmvps.com/blogs/sp/archive/2007/05/15/single-authority-principle.aspx#949745</link><pubDate>Fri, 08 Jun 2007 07:58:06 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:949745</guid><dc:creator>Slav</dc:creator><description>&lt;p&gt;Yes, I should have used &amp;quot;circular cause&amp;quot; or something like that. Not that illustrous...&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=949745" width="1" height="1"&gt;</description></item><item><title>re: Single authority principle</title><link>http://msmvps.com/blogs/sp/archive/2007/05/15/single-authority-principle.aspx#949707</link><pubDate>Fri, 08 Jun 2007 06:49:54 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:949707</guid><dc:creator>Adrian</dc:creator><description>you can&amp;#39;t have a chicken-egg problem.   An almost chicken can produce a chicken egg, but a chicken can&amp;#39;t evolve from the part-chicken egg to become a chicken, hence the egg must come first.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=949707" width="1" height="1"&gt;</description></item></channel></rss>