-
The Microsoft Patterns & Practices team just published a beta copy of Improving Web Service Security for WCF or code name Indigo last week. This is another great playbook from the team that gives us many great guides and practices in using Microsoft technologies. If you are into Indigo, this is a...
-
Damn! I love this blog post from Thomas , and you can easily noticed that IIS team has put lot of effort in shared hosting environment, from shared to delegated configuration, and all the way to process model improvements. The dynamicIdleThreshold for example is a fantastic feature for shared hosting...
-
Years ago, I wrote the KB on passive port range at MSKB site - How To Configure PassivePortRange In IIS http://support.microsoft.com/?id=555022 Lazy to update the article for IIS 7.0 FTP detail, and I'm not going to add that here :) Coz you can get it from Microsoft Support Team - http://blogs.msdn...
-
Microsoft revised two security bulletins yesterday. One of which is related to .Net Framework published last year , not major update or new fixes but rather doc updates on changes related to releases of WinXP SP3. On the other hand, in the recent Hack in the Box conference in Dubai, a new exploit in...
-
Oh well, been busy and no time to post this back then. In the routine patch Tuesday this month, Microsoft released 8 security bulletins with 5 of which in critical severity and one specific bulletin is related to IIS in a way. The 08-022 actually replaced the old fixes in 2006. Summary: This security...
-
Today, Microsoft released a major revision for a vulneribility reported last year on .Net Framework. If you running framework version 1.0, 1.1 and 2.0. Please apply the fix asap. Take note that even you are running 3.0, it is essentially using .Net Framework 2.0 runtime with extra bonus feature like...
-
In this month security bulletin , although all critical fixes are related to MS Office, one of the bulletin is related to Office Web Component and hence if you utilizing OWC in your web application, you need to apply the patch asap. Details: Vulnerabilities in Microsoft Office Web Components Could Allow...
-
It is official now :) lazy to type.... head over to Bill Staples blog post for more info :) Together with many great stuff from IIS team, including the new FTP component , FPSE , and Web Playlist :) (errr.. related to media server if you are in to media streaming) Last but not least..... the IIS 7 Resource...
-
In this month security bulletin , there are two important bulletins related to IIS, depend on your environment setup, though it is rated as important, you might want to patch it asap. Here's the bulletin details. Vulnerability in Internet Information Services Could Allow Elevation of Privilege (942831...
-
After a lonnnnng wait !! Today, the IIS team releases the new web deployment tool technical preview 1 :) The deployment tool called msdeploy.exe is essentially a migration toolkit similar with the one the shipped for IIS 6.0. However, the team spent extra effort and includes few extra features in the...