<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Channel 9</title>
    <atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Niners/Jossie/Posts/RSS"></atom:link>
    <itunes:summary></itunes:summary>
    <itunes:author>Microsoft</itunes:author>
    <itunes:subtitle></itunes:subtitle>
    <image>
      <url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url>
      <title>Channel 9</title>
      <link>http://channel9.msdn.com/Niners/Jossie/Posts</link>
    </image>
    <itunes:image href=""></itunes:image>
    <itunes:category text="Technology"></itunes:category>
    <description>Channel 9 keeps you up to date with the latest news and behind the scenes info from Microsoft that developers love to keep up with. From LINQ to SilverLight – Watch videos and hear about all the cool technologies coming and the people behind them.</description>
    <link>http://channel9.msdn.com/Niners/Jossie/Posts</link>
    <language>en</language>
    <pubDate>Sat, 18 May 2013 13:43:26 GMT</pubDate>
    <lastBuildDate>Sat, 18 May 2013 13:43:26 GMT</lastBuildDate>
    <generator>Rev9</generator>
    <c9:totalResults>20</c9:totalResults>
    <c9:pageCount>1</c9:pageCount>
    <c9:pageSize>25</c9:pageSize>
  <item>
      <title>Using the Code Analysis Tool (CAT.NET 2.0) to Identify Security Vulnerabilities</title>
      <description><![CDATA[
<p>Anil Revuru (RV) from <a shape="rect" href="http://www.msinfosec.com/" target="_blank" shape="rect">
Microsoft Information Security,</a> gives a demonstration of the new version of CAT.NET (Code Analysis Tool for .NET) version 2.0.&nbsp; It is a static analysis tool that uses the Phoenix Compiler and its data flow graph.</p>
<p>Anil walks us through the dataflow rules and how it uses the source sink analysis to determine if there is a vulnerability or not. He also explains how the configuration analysis works and walks through the rules where insecure conditions exist. The demo
 of the tool shows how the vulnerabilities are detected and how to interpret the results.<br /><br />To learn more about this application, stay up to date on the latest news by following&nbsp;the&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools/archive/tags/CAT.NET/default.aspx" target="_blank" shape="rect">Security Tools Team</a> blog.<br /><br /><a shape="rect" href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032438061&amp;EventCategory=4&amp;culture=en-US&amp;CountryCode=US" target="_blank" shape="rect">Watch related webcast</a><br /><a shape="rect" href="https://connect.microsoft.com/site734/Downloads/DownloadDetails.aspx?DownloadID=26086&amp;wa=wsignin1.0" target="_blank" shape="rect">Download: CAT.NET 2.0</a></p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:32c190ee12a64ef9898e9deb001b8827">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Using-the-Code-Analysis-Tool-CATNET-20-to-Identify-Security-Vulnerabilities</comments>
      <itunes:summary>
Anil Revuru (RV) from 
Microsoft Information Security, gives a demonstration of the new version of CAT.NET (Code Analysis Tool for .NET) version 2.0.&amp;nbsp; It is a static analysis tool that uses the Phoenix Compiler and its data flow graph. 
Anil walks us through the dataflow rules and how it uses the source sink analysis to determine if there is a vulnerability or not. He also explains how the configuration analysis works and walks through the rules where insecure conditions exist. The demo
 of the tool shows how the vulnerabilities are detected and how to interpret the results.To learn more about this application, stay up to date on the latest news by following&amp;nbsp;the&amp;nbsp;Security Tools Team blog.Watch related webcastDownload: CAT.NET 2.0 
</itunes:summary>
      <itunes:duration>522</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Using-the-Code-Analysis-Tool-CATNET-20-to-Identify-Security-Vulnerabilities</link>
      <pubDate>Thu, 25 Feb 2010 08:18:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Using-the-Code-Analysis-Tool-CATNET-20-to-Identify-Security-Vulnerabilities</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/532259_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/532259_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/5/2/2/3/5/CATNETCAST_320_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/5/2/2/3/5/CATNETCAST_512_ch9.png" height="384" width="512"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/5/2/2/3/5/CATNETCAST_85_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/5/2/2/3/5/CATNETCAST_2MB_ch9.wmv" expression="full" duration="522" fileSize="53416629" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/5/2/2/3/5/CATNETCAST_ch9.mp3" expression="full" duration="522" fileSize="4180644" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/5/2/2/3/5/CATNETCAST_ch9.mp4" expression="full" duration="522" fileSize="25563006" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/5/2/2/3/5/CATNETCAST_ch9.wma" expression="full" duration="522" fileSize="4237613" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/5/2/2/3/5/CATNETCAST_ch9.wmv" expression="full" duration="522" fileSize="29724841" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/5/2/2/3/5/CATNETCAST_Zune_ch9.wmv" expression="full" duration="522" fileSize="20748893" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ecn.channel9.msdn.com/o9/ch9/9/5/2/2/3/5/CATNETCAST_2MB_ch9.wmv" length="53416629" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>4</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Using-the-Code-Analysis-Tool-CATNET-20-to-Identify-Security-Vulnerabilities/RSS</wfw:commentRss>
      <category>cat.net</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>Security</category>
      <category>Tools</category>
    </item>
  <item>
      <title>Technical Preview for CAT.NET 2.0</title>
      <description><![CDATA[Maqbool Malik and Anil Revuru (RV), from <a shape="rect" href="http://www.msinfosec.com/" target="_blank" shape="rect">
Microsoft Information Security</a>, talk about the newly designed version of CAT.NET which will be part of the&nbsp;<a shape="rect" href="http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/" target="_blank" shape="rect">Assessment &amp; Protection
 (A&amp;P)</a> suite.<br /><br />CAT.NET&nbsp;is a static analysis tool on Visual Studio&nbsp;that helps find vulnerabilities like SQL Injection, CSRF, XSS among others, within managed code.&nbsp;This version is currently&nbsp;a technical preview which works on the command line only though for its release it
 will be integrated with Visual Studio's UI&nbsp;under the&nbsp;Code Analysis tab. In this interview you can learn all the new features as well as details on how to provide feedback on the tool.<br /><br />The CTP (Community Technology Preview) for this tool is available in <a shape="rect" href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank" shape="rect">
Microsoft Connect – Information Security Tools</a>. <br /><br /><a shape="rect" href="http://blogs.msdn.com/securitytools/archive/tags/CAT.NET/default.aspx" target="_blank" shape="rect">Learn more</a>&nbsp;about this tool by reading examples on how to run it&nbsp;by following the&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools" target="_blank" shape="rect">Security
 Tools Team</a> blog.  <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:37c907c065d64c119a6d9deb001b8f28">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Technical-Preview-for-CATNET-20</comments>
      <itunes:summary>Maqbool Malik and Anil Revuru (RV), from 
Microsoft Information Security, talk about the newly designed version of CAT.NET which will be part of the&amp;nbsp;Assessment &amp;amp; Protection
 (A&amp;amp;P) suite.CAT.NET&amp;nbsp;is a static analysis tool on Visual Studio&amp;nbsp;that helps find vulnerabilities like SQL Injection, CSRF, XSS among others, within managed code.&amp;nbsp;This version is currently&amp;nbsp;a technical preview which works on the command line only though for its release it
 will be integrated with Visual Studio&#39;s UI&amp;nbsp;under the&amp;nbsp;Code Analysis tab. In this interview you can learn all the new features as well as details on how to provide feedback on the tool.The CTP (Community Technology Preview) for this tool is available in 
Microsoft Connect – Information Security Tools. Learn more&amp;nbsp;about this tool by reading examples on how to run it&amp;nbsp;by following the&amp;nbsp;Security
 Tools Team blog. </itunes:summary>
      <itunes:duration>1221</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Technical-Preview-for-CATNET-20</link>
      <pubDate>Fri, 11 Dec 2009 19:32:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Technical-Preview-for-CATNET-20</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/512199_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/512199_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_320_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_512_ch9.png" height="384" width="512"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_85_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_2MB_ch9.wmv" expression="full" duration="1221" fileSize="149464552" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_ch9.mp3" expression="full" duration="1221" fileSize="9776817" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_ch9.mp4" expression="full" duration="1221" fileSize="90630071" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_ch9.wma" expression="full" duration="1221" fileSize="9891135" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_ch9.wmv" expression="full" duration="1221" fileSize="133190621" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_Zune_ch9.wmv" expression="full" duration="1221" fileSize="88742673" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_2MB_ch9.wmv" length="149464552" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Technical-Preview-for-CATNET-20/RSS</wfw:commentRss>
      <category>cat.net</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
      <category>Tools</category>
    </item>
  <item>
      <title>Using the Web Protection Library (WPL) - CTP Version</title>
      <description><![CDATA[
<p>Anil Revuru (RV), from <a shape="rect" href="http://www.msinfosec.com/" target="_blank" shape="rect">
Microsoft Information Security</a>,&nbsp;walks&nbsp;us through&nbsp;the expansion of what used to be the Anti-XSS Library.&nbsp;This enhanced version of the library will introduce mitigation to other attacks like:</p>
<ul>
<li>SQL Injection </li><li>Cross-Site Request Forgery (CSRF) </li><li>Setting Enforcement like SSL &amp; HTTP_ONLY cookies </li><li>Security Runtime Engine for SQL Injection &amp; XSS </li><li>Among others </li></ul>
<p>The CTP (Community Technology Preview) is available in <a shape="rect" href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank" shape="rect">
Microsoft Connect – Information Security Tools</a>. <br /><br />Read&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx" target="_blank" shape="rect">CTP announcement</a> and follow the&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools" target="_blank" shape="rect">Security
 Tools Team</a> blog. </p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:f8a6b2207e4b45b581b99deb001b9404">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Using-the-Web-Protection-Library-WPL-CTP-Version</comments>
      <itunes:summary>
Anil Revuru (RV), from 
Microsoft Information Security,&amp;nbsp;walks&amp;nbsp;us through&amp;nbsp;the expansion of what used to be the Anti-XSS Library.&amp;nbsp;This enhanced version of the library will introduce mitigation to other attacks like: 

SQL Injection Cross-Site Request Forgery (CSRF) Setting Enforcement like SSL &amp;amp; HTTP_ONLY cookies Security Runtime Engine for SQL Injection &amp;amp; XSS Among others 
The CTP (Community Technology Preview) is available in 
Microsoft Connect – Information Security Tools. Read&amp;nbsp;CTP announcement and follow the&amp;nbsp;Security
 Tools Team blog.  
</itunes:summary>
      <itunes:duration>656</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Using-the-Web-Protection-Library-WPL-CTP-Version</link>
      <pubDate>Wed, 25 Nov 2009 00:00:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Using-the-Web-Protection-Library-WPL-CTP-Version</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/508747_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/508747_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_320_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_512_ch9.png" height="384" width="512"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_85_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_2MB_ch9.wmv" expression="full" duration="656" fileSize="50563911" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_ch9.mp3" expression="full" duration="656" fileSize="5253700" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_ch9.mp4" expression="full" duration="656" fileSize="69586321" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_ch9.wma" expression="full" duration="656" fileSize="5316043" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_ch9.wmv" expression="full" duration="656" fileSize="95150711" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_Zune_ch9.wmv" expression="full" duration="656" fileSize="53870763" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_2MB_ch9.wmv" length="50563911" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Using-the-Web-Protection-Library-WPL-CTP-Version/RSS</wfw:commentRss>
      <category>Antixss</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>ist</category>
      <category>Security</category>
      <category>Tools</category>
      <category>wpl</category>
    </item>
  <item>
      <title>Using Web Application Configuration Analyzer (WACA) - CTP Version</title>
      <description><![CDATA[Anil Revuru (RV), from <a shape="rect" href="http://www.msinfosec.com/" target="_blank" shape="rect">
Microsoft Information Security</a>, walks us through a configuration verification tool that will be part of a suite of tools that will help you assess your code as well as protect it. For more info watch the&nbsp;<a shape="rect" href="http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/" target="_blank" shape="rect">Assessment
 &amp; Protection (A&amp;P) Suite</a> video.<br /><br />WACA is designed to scan your development environment against best practices for .NET security configuration, IIS settings, SQL Server Security best practices and some Windows permission settings. It is helpful for verifying your configuration while unit testing
 and ensuring there are no issues when the application is in production.<br /><br />The CTP (Community Technology Preview) for this tool is available in <a shape="rect" href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank" shape="rect">
Microsoft Connect – Information Security Tools</a>. <br /><br />Read&nbsp;<a shape="rect" href="http://blogs.msdn.com/infosec/archive/2009/11/16/infosec-assessment-protection-a-p-suite-released.aspx" target="_blank" shape="rect">CTP announcement</a> and follow the&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools" target="_blank" shape="rect">Security
 Tools Team</a> blog.  <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:666e76cbab124cb8b60c9deb001b98a8">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Web-Application-Configuration-Analizer-WACA</comments>
      <itunes:summary>Anil Revuru (RV), from 
Microsoft Information Security, walks us through a configuration verification tool that will be part of a suite of tools that will help you assess your code as well as protect it. For more info watch the&amp;nbsp;Assessment
 &amp;amp; Protection (A&amp;amp;P) Suite video.WACA is designed to scan your development environment against best practices for .NET security configuration, IIS settings, SQL Server Security best practices and some Windows permission settings. It is helpful for verifying your configuration while unit testing
 and ensuring there are no issues when the application is in production.The CTP (Community Technology Preview) for this tool is available in 
Microsoft Connect – Information Security Tools. Read&amp;nbsp;CTP announcement and follow the&amp;nbsp;Security
 Tools Team blog. </itunes:summary>
      <itunes:duration>435</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Web-Application-Configuration-Analizer-WACA</link>
      <pubDate>Tue, 24 Nov 2009 23:58:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Web-Application-Configuration-Analizer-WACA</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/508745_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/508745_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_320_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_512_ch9.png" height="384" width="512"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_85_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_2MB_ch9.wmv" expression="full" duration="435" fileSize="42688653" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_ch9.mp3" expression="full" duration="435" fileSize="3488267" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_ch9.mp4" expression="full" duration="435" fileSize="28588657" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_ch9.wma" expression="full" duration="435" fileSize="3534677" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_Zune_ch9.wmv" expression="full" duration="435" fileSize="21947675" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_Zune_ch9.wmv" length="21947675" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>3</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Web-Application-Configuration-Analizer-WACA/RSS</wfw:commentRss>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>ist</category>
      <category>Security</category>
      <category>Tools</category>
      <category>waca</category>
    </item>
  <item>
      <title>Web Application Configuration Analyzer (WACA)</title>
      <description><![CDATA[Anil Revuru (RV), from <a shape="rect" href="http://www.msinfosec.com/" target="_blank" shape="rect">
Microsoft Information Security</a>, introduces a configuration verification tool that will be part of a suite of tools that will help you assess your code as well as protect it. For more info watch the&nbsp;<a shape="rect" href="http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/" target="_blank" shape="rect">Assessment
 &amp; Protection (A&amp;P) Suite</a> video.<br /><br />WACA is designed to scan your development environment against best practices for .NET security configuration, IIS settings, SQL Server Security best practices and some Windows permission settings. It is helpful for verifying your configuration while unit testing
 and ensuring there are no issues when the application is in production.<br /><br />The CTP (Community Technology Preview) for this tool is available in <a shape="rect" href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank" shape="rect">
Microsoft Connect – Information Security Tools</a>. <br /><br />Read&nbsp;<a shape="rect" href="http://blogs.msdn.com/infosec/archive/2009/11/16/infosec-assessment-protection-a-p-suite-released.aspx" target="_blank" shape="rect">CTP announcement</a> and follow the&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools" target="_blank" shape="rect">Security
 Tools Team</a> blog.  <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:cac7252c874548d2b1f49deb001b9d28">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Web-Application-Configuration-Analyzer-WACA</comments>
      <itunes:summary>Anil Revuru (RV), from 
Microsoft Information Security, introduces a configuration verification tool that will be part of a suite of tools that will help you assess your code as well as protect it. For more info watch the&amp;nbsp;Assessment
 &amp;amp; Protection (A&amp;amp;P) Suite video.WACA is designed to scan your development environment against best practices for .NET security configuration, IIS settings, SQL Server Security best practices and some Windows permission settings. It is helpful for verifying your configuration while unit testing
 and ensuring there are no issues when the application is in production.The CTP (Community Technology Preview) for this tool is available in 
Microsoft Connect – Information Security Tools. Read&amp;nbsp;CTP announcement and follow the&amp;nbsp;Security
 Tools Team blog. </itunes:summary>
      <itunes:duration>943</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Web-Application-Configuration-Analyzer-WACA</link>
      <pubDate>Fri, 20 Nov 2009 22:21:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Web-Application-Configuration-Analyzer-WACA</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/507560_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/507560_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_320_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_512_ch9.png" height="384" width="512"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_85_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_2MB_ch9.wmv" expression="full" duration="943" fileSize="115402475" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.mp3" expression="full" duration="943" fileSize="7549118" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.mp4" expression="full" duration="943" fileSize="103910191" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.wma" expression="full" duration="943" fileSize="7635131" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.wmv" expression="full" duration="943" fileSize="150098729" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_Zune_ch9.wmv" expression="full" duration="943" fileSize="93794781" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_2MB_ch9.wmv" length="115402475" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Web-Application-Configuration-Analyzer-WACA/RSS</wfw:commentRss>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>ist</category>
      <category>Security</category>
      <category>Tools</category>
      <category>waca</category>
    </item>
  <item>
      <title>Assessment and Protection Suite</title>
      <description><![CDATA[
<p>Anil Revuru (RV) and Mark Curphey, from <a shape="rect" href="http://www.msinfosec.com" target="_blank" shape="rect">
Microsoft Information Security</a>, introduce what would be in the future a suite of tools that will help you assess your code as well as protect it. This is called the Assessment &amp; Protection (A&amp;P) Suite and it includes the following tools:
</p>
<ul>
<li>Web Protection Library (WPL) – which includes Anti-XSS, SRE, mitigation of SQL Injection, CSRF among others
</li><li>CAT.NET </li><li>Web Application Configuration Analyzer (WACA) </li><li>and room for more future add-ons </li></ul>
<p>The CTP (Community Technology Preview) for these tools are available in <a shape="rect" href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank" shape="rect">
Microsoft Connect – Information Security Tools</a>. These are currently individual as they shift to one-install.<br /><br />Read&nbsp;<a shape="rect" href="http://blogs.msdn.com/infosec/archive/2009/11/16/infosec-assessment-protection-a-p-suite-released.aspx" target="_blank" shape="rect">CTP announcement</a> and follow the&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools" target="_blank" shape="rect">Security
 Tools Team</a> blog. </p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:e21ffb3158bf4b2b81889deb001ba1e9">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Assessment-and-Protection-Suite</comments>
      <itunes:summary>
Anil Revuru (RV) and Mark Curphey, from 
Microsoft Information Security, introduce what would be in the future a suite of tools that will help you assess your code as well as protect it. This is called the Assessment &amp;amp; Protection (A&amp;amp;P) Suite and it includes the following tools:
 

Web Protection Library (WPL) – which includes Anti-XSS, SRE, mitigation of SQL Injection, CSRF among others
CAT.NET Web Application Configuration Analyzer (WACA) and room for more future add-ons 
The CTP (Community Technology Preview) for these tools are available in 
Microsoft Connect – Information Security Tools. These are currently individual as they shift to one-install.Read&amp;nbsp;CTP announcement and follow the&amp;nbsp;Security
 Tools Team blog.  
</itunes:summary>
      <itunes:duration>1044</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Assessment-and-Protection-Suite</link>
      <pubDate>Thu, 12 Nov 2009 17:21:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Assessment-and-Protection-Suite</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/505599_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/505599_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_320_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_512_ch9.png" height="384" width="512"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_85_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_2MB_ch9.wmv" expression="full" duration="1044" fileSize="127779102" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.mp3" expression="full" duration="1044" fileSize="8359931" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.mp4" expression="full" duration="1044" fileSize="115680604" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.wma" expression="full" duration="1044" fileSize="8458227" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.wmv" expression="full" duration="1044" fileSize="169620143" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_Zune_ch9.wmv" expression="full" duration="1044" fileSize="112564195" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_2MB_ch9.wmv" length="127779102" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Assessment-and-Protection-Suite/RSS</wfw:commentRss>
      <category>Antixss</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>ist</category>
      <category>Security</category>
      <category>Tools</category>
      <category>waca</category>
      <category>wpl</category>
    </item>
  <item>
      <title>Enhanced Web Protection Library</title>
      <description><![CDATA[
<p>Anil Revuru (RV), from <a shape="rect" href="http://www.msinfosec.com/" target="_blank" shape="rect">
Microsoft Information Security</a>, introduces the expansion of what used to be the Anti-XSS Library. But web vulnerabilities are not only around Cross-Site Scripting (XSS) attacks. This enhanced version of the library will introduce mitigation to other attacks
 like:</p>
<ul>
<li>SQL Injection </li><li>Cross-Site Request Forgery (CSRF) </li><li>Setting Enforcement like SSL &amp; HTTP_ONLY cookies </li><li>Security Runtime Engine for SQL Injection &amp; XSS </li><li>Among others </li></ul>
<p>The CTP (Community Technology Preview) is available in <a shape="rect" href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank" shape="rect">
Microsoft Connect – Information Security Tools</a>. <br /><br />Read&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx" target="_blank" shape="rect">CTP announcement</a> and follow the&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools" target="_blank" shape="rect">Security
 Tools Team</a> blog. </p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:5c457ab422774b1aaccb9deb001ba6ca">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Enhanced-Web-Protection-Library</comments>
      <itunes:summary>
Anil Revuru (RV), from 
Microsoft Information Security, introduces the expansion of what used to be the Anti-XSS Library. But web vulnerabilities are not only around Cross-Site Scripting (XSS) attacks. This enhanced version of the library will introduce mitigation to other attacks
 like: 

SQL Injection Cross-Site Request Forgery (CSRF) Setting Enforcement like SSL &amp;amp; HTTP_ONLY cookies Security Runtime Engine for SQL Injection &amp;amp; XSS Among others 
The CTP (Community Technology Preview) is available in 
Microsoft Connect – Information Security Tools. Read&amp;nbsp;CTP announcement and follow the&amp;nbsp;Security
 Tools Team blog.  
</itunes:summary>
      <itunes:duration>928</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Enhanced-Web-Protection-Library</link>
      <pubDate>Thu, 12 Nov 2009 17:21:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Enhanced-Web-Protection-Library</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/505597_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/505597_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_320_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_512_ch9.png" height="384" width="512"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_85_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_2MB_ch9.wmv" expression="full" duration="928" fileSize="113545072" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.mp3" expression="full" duration="928" fileSize="7428509" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.mp4" expression="full" duration="928" fileSize="125005100" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.wma" expression="full" duration="928" fileSize="7517981" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.wmv" expression="full" duration="928" fileSize="169042525" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_Zune_ch9.wmv" expression="full" duration="928" fileSize="105714577" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_2MB_ch9.wmv" length="113545072" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Enhanced-Web-Protection-Library/RSS</wfw:commentRss>
      <category>Antixss</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>ist</category>
      <category>Security</category>
      <category>Tools</category>
      <category>wpl</category>
    </item>
  <item>
      <title>Anti-XSS Library v3.1: Find, Fix, and Verify Errors</title>
      <description><![CDATA[
<p>Anil Revuru (RV) from <a shape="rect" href="http://www.msinfosec.com/" target="_blank" shape="rect">
Microsoft Information Security,</a> gives a demonstration of the new features on the Anti-XSS Library v3.1 &nbsp;including HTML Sanitization which provides new methods to the Anti-XSS class to strip malicious characters or scripts off of&nbsp;HTML and returns safe HTML.<br /><br />He talks about:</p>
<ul>
<li>
<div>What is Cross-Site Scripting Attack (XSS)</div>
</li><li>
<div>How to detect Cross Site Scripting Vulnerabilities</div>
</li><li>
<div>Introduction of Anti-XSS Library</div>
</li><li>
<div>What’s new in Anti-XSS Library 3.1</div>
</li><li>
<div>Anti-XSS 3.1 demo</div>
</li><li>
<div>Security Runtime Engine (SRE)</div>
</li><li>
<div>SRE Demo</div>
</li></ul>
<p>To learn more about this application and stay up to date on the latest news, read the following blogs from&nbsp;<a shape="rect" href="http://blogs.msdn.com/infosec/archive/2009/09/17/anti-xss-3-1-released.aspx" target="_blank" shape="rect">Information Security</a>
 and previous posts from the&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools/archive/tags/Anti-XSS/default.aspx" target="_blank" shape="rect">Security Tools Team</a> blog.<br /><br /><a shape="rect" href="http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/" target="_blank" shape="rect">Overview of the Anti-XSS Library</a><br /><a shape="rect" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=051ee83c-5ccf-48ed-8463-02f56a6bfc09&amp;displaylang=en" target="_blank" shape="rect">Download: Microsoft Anti-Cross Site Scripting Library v3.1</a></p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:942aff168e87405aa50f9deb001bb062">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Anti-XSS-Library-v31-Find-Fix-and-Verify-Errors</comments>
      <itunes:summary>
Anil Revuru (RV) from 
Microsoft Information Security, gives a demonstration of the new features on the Anti-XSS Library v3.1 &amp;nbsp;including HTML Sanitization which provides new methods to the Anti-XSS class to strip malicious characters or scripts off of&amp;nbsp;HTML and returns safe HTML.He talks about: 


What is Cross-Site Scripting Attack (XSS)

How to detect Cross Site Scripting Vulnerabilities

Introduction of Anti-XSS Library

What’s new in Anti-XSS Library 3.1

Anti-XSS 3.1 demo

Security Runtime Engine (SRE)

SRE Demo

To learn more about this application and stay up to date on the latest news, read the following blogs from&amp;nbsp;Information Security
 and previous posts from the&amp;nbsp;Security Tools Team blog.Overview of the Anti-XSS LibraryDownload: Microsoft Anti-Cross Site Scripting Library v3.1 
</itunes:summary>
      <itunes:duration>1311</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Anti-XSS-Library-v31-Find-Fix-and-Verify-Errors</link>
      <pubDate>Wed, 23 Sep 2009 17:20:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Anti-XSS-Library-v31-Find-Fix-and-Verify-Errors</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/493696_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/493696_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_320_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_512_ch9.png" height="384" width="512"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_85_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_2MB_ch9.wmv" expression="full" duration="1311" fileSize="190365309" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.mp3" expression="full" duration="1311" fileSize="10494270" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.mp4" expression="full" duration="1311" fileSize="30406648" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.wma" expression="full" duration="1311" fileSize="10612095" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.wmv" expression="full" duration="1311" fileSize="44119933" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_Zune_ch9.wmv" expression="full" duration="1311" fileSize="31639861" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_2MB_ch9.wmv" length="190365309" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>9</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Anti-XSS-Library-v31-Find-Fix-and-Verify-Errors/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Antixss</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>ist</category>
      <category>Security</category>
      <category>Tools</category>
    </item>
  <item>
      <title>Connected Information Security Framework: Core Components</title>
      <description><![CDATA[
<p>Marius Grigoriu and Vineet Batta, from&nbsp;<a shape="rect" href="http://www.msinfosec.com/" target="_blank" shape="rect">Microsoft Information Security,</a> talk about the technical components for the first version of
<b>C</b>onnected <b>I</b>nformation <b>S</b>ecurity <b>F</b>ramework (<a shape="rect" href="http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/" target="_blank" shape="rect">CISF</a>).&nbsp; A software development framework comprising of
 API’s and reusable components that is designed to create bespoke or custom information security and risk management solutions&nbsp;like
<a shape="rect" href="http://edge.technet.com/Media/Risk-Tracker/" target="_blank" shape="rect">
Risk Tracker</a>.<br /><br />Microsoft’s IT Information Security Tools Team designs and develops CISF to “engineer the security delta” meaning as a way to rapidly meet business requirements and create functionality that doesn’t exist or is not yet available in their product range.<br /><br />They explain the core pieces CISF consists of like: Business Intelligent, Portal, Notification, and others that help build information security applications cheaper, faster, and better
</p>
<p>To learn more about this framework and stay up to date on the latest news, read the following blogs from&nbsp;<a shape="rect" href="http://blogs.msdn.com/infosec/archive/tags/CISF/default.aspx" target="_blank" shape="rect">Information Security</a> and previous
 posts from the&nbsp;&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools/archive/tags/CISF/default.aspx" target="_blank" shape="rect">Security Tools Team</a> blog</p>
<p>To see an overview of what CISF is watch the video:&nbsp;<a shape="rect" href="http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/" target="_blank" shape="rect">CISF: Build Custom Security Solutions</a>
</p>
<p><a shape="rect" href="http://cisf.codeplex.com/" target="_blank" shape="rect">CISF CTP download</a></p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:478d3cc4c2e14ba797ef9deb001bab79">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Connected-Information-Security-Framework-Core-Components</comments>
      <itunes:summary>
Marius Grigoriu and Vineet Batta, from&amp;nbsp;Microsoft Information Security, talk about the technical components for the first version of
Connected Information Security Framework (CISF).&amp;nbsp; A software development framework comprising of
 API’s and reusable components that is designed to create bespoke or custom information security and risk management solutions&amp;nbsp;like

Risk Tracker.Microsoft’s IT Information Security Tools Team designs and develops CISF to “engineer the security delta” meaning as a way to rapidly meet business requirements and create functionality that doesn’t exist or is not yet available in their product range.They explain the core pieces CISF consists of like: Business Intelligent, Portal, Notification, and others that help build information security applications cheaper, faster, and better
 
To learn more about this framework and stay up to date on the latest news, read the following blogs from&amp;nbsp;Information Security and previous
 posts from the&amp;nbsp;&amp;nbsp;Security Tools Team blog 
To see an overview of what CISF is watch the video:&amp;nbsp;CISF: Build Custom Security Solutions
 
CISF CTP download 
</itunes:summary>
      <itunes:duration>1326</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Connected-Information-Security-Framework-Core-Components</link>
      <pubDate>Wed, 23 Sep 2009 17:19:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Connected-Information-Security-Framework-Core-Components</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/493725_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/493725_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_320_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_512_ch9.png" height="384" width="512"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_85_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_2MB_ch9.wmv" expression="full" duration="1326" fileSize="162366459" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.mp3" expression="full" duration="1326" fileSize="10612355" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.mp4" expression="full" duration="1326" fileSize="142845363" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.wma" expression="full" duration="1326" fileSize="10735265" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.wmv" expression="full" duration="1326" fileSize="192376149" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_Zune_ch9.wmv" expression="full" duration="1326" fileSize="104040077" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/5/2/7/3/9/4/cisfTech_s_ch9.wmv" expression="full" duration="1326" fileSize="197" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.wmv" length="192376149" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Connected-Information-Security-Framework-Core-Components/RSS</wfw:commentRss>
      <category>cisf</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>ist</category>
      <category>Security</category>
      <category>Tools</category>
    </item>
  <item>
      <title>CISF: Build Custom Security Solutions</title>
      <description><![CDATA[Mark Curphey and Marius Grigoriu, from&nbsp;<a shape="rect" href="http://www.msinfosec.com/" target="_blank" shape="rect">Microsoft Information Security,</a> talk about the release of the first version of
<b>C</b>onnected <b>I</b>nformation <b>S</b>ecurity <b>F</b>ramework (CISF).&nbsp; A software development framework comprising of API’s and reusable components that is designed to create bespoke or custom information security and risk management solutions&nbsp;like&nbsp;<a shape="rect" href="http://edge.technet.com/Media/Risk-Tracker/" target="_blank" shape="rect">Risk
 Tracker</a>.<br /><br />Microsoft’s IT Information Security Tools Team designs and develops CISF to “engineer the security delta” meaning as a way to rapidly meet business requirements and create functionality that doesn’t exist or is not yet available in their product range.<br /><br />They explain benefits found on this framework including:
<ul>
<li>Building information security applications cheaper, faster, and better </li><li>Migrate applications efficiently and effectively to their products when they become available
</li></ul>
<p>To learn more about this framework and stay up to date on the latest news, read the following blogs from&nbsp;<a shape="rect" href="http://blogs.msdn.com/infosec/archive/tags/CISF/default.aspx" target="_blank" shape="rect">Information Security</a> and previous
 posts from the&nbsp;&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools/archive/tags/CISF/default.aspx" target="_blank" shape="rect">Security Tools Team</a> blog.&nbsp;<br /><br /><a shape="rect" href="http://cisf.codeplex.com/" target="_blank" shape="rect">CISF CTP download</a>
</p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:3ef949bfdc72417087489deb001bb9d8">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/CISF-Build-Custom-Security-Solutions</comments>
      <itunes:summary>Mark Curphey and Marius Grigoriu, from&amp;nbsp;Microsoft Information Security, talk about the release of the first version of
Connected Information Security Framework (CISF).&amp;nbsp; A software development framework comprising of API’s and reusable components that is designed to create bespoke or custom information security and risk management solutions&amp;nbsp;like&amp;nbsp;Risk
 Tracker.Microsoft’s IT Information Security Tools Team designs and develops CISF to “engineer the security delta” meaning as a way to rapidly meet business requirements and create functionality that doesn’t exist or is not yet available in their product range.They explain benefits found on this framework including:

Building information security applications cheaper, faster, and better Migrate applications efficiently and effectively to their products when they become available

To learn more about this framework and stay up to date on the latest news, read the following blogs from&amp;nbsp;Information Security and previous
 posts from the&amp;nbsp;&amp;nbsp;Security Tools Team blog.&amp;nbsp;CISF CTP download
 
</itunes:summary>
      <itunes:duration>1182</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/CISF-Build-Custom-Security-Solutions</link>
      <pubDate>Fri, 18 Sep 2009 03:31:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/CISF-Build-Custom-Security-Solutions</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/492501_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/492501_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_320_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_512_ch9.png" height="384" width="512"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_85_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_2MB_ch9.wmv" expression="full" duration="1182" fileSize="369989037" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.mp3" expression="full" duration="1182" fileSize="9464808" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.mp4" expression="full" duration="1182" fileSize="102375658" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.wma" expression="full" duration="1182" fileSize="9575715" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.wmv" expression="full" duration="1182" fileSize="231270127" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_Zune_ch9.wmv" expression="full" duration="1182" fileSize="128822055" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/1/0/5/2/9/4/CISFoverview_s_ch9.wmv" expression="full" duration="1182" fileSize="205" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.wmv" length="231270127" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/CISF-Build-Custom-Security-Solutions/RSS</wfw:commentRss>
      <category>cisf</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>ist</category>
      <category>Security</category>
      <category>Tools</category>
    </item>
  <item>
      <title>SDL-LOB Phase 3: Implementation</title>
      <description><![CDATA[<span id="ctl00_MainPlaceHolder_Starter_BodyLabel">The third phase of the <a shape="rect" href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank" shape="rect">
<span>SDL-LOB </span></a>(Security Development Lifecycle for Line-of-Business applications) includes
<span><a shape="rect" href="http://msdn.microsoft.com/en-us/library/dd831972.aspx" target="_blank" shape="rect"><span>Implementation</span></a>.</span><br>
<br>
Eugene Siu, from <a shape="rect" href="http://www.msinfosec.com" target="_blank" shape="rect">
Microsoft Information Security</a>, describes some of the security pillars&nbsp;that are key in this phase, including code review, authentication, authorization and configuration settings. Also, he&nbsp;explains how penetration testing can complement your code review
 when bulletproofing your code against vulnerabilities.<br>
<br>
Read more on the Implementation Phase&nbsp;<a shape="rect" href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx" target="_blank" shape="rect">here</a>.<br>
</span> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:b18ee43f9f404acd9acc9deb017310f2">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/SDL-LOB-Phase-3-Implementation</comments>
      <itunes:summary>The third phase of the 
SDL-LOB (Security Development Lifecycle for Line-of-Business applications) includes
Implementation.

Eugene Siu, from 
Microsoft Information Security, describes some of the security pillars&amp;nbsp;that are key in this phase, including code review, authentication, authorization and configuration settings. Also, he&amp;nbsp;explains how penetration testing can complement your code review
 when bulletproofing your code against vulnerabilities.

Read more on the Implementation Phase&amp;nbsp;here.
</itunes:summary>
      <itunes:duration>1099</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/SDL-LOB-Phase-3-Implementation</link>
      <pubDate>Mon, 20 Jul 2009 17:54:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/SDL-LOB-Phase-3-Implementation</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/479451_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/479451_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_2MB_ch9.wmv" expression="full" duration="1099" fileSize="134509761" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp3" expression="full" duration="1099" fileSize="8798169" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp4" expression="full" duration="1099" fileSize="81603875" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wma" expression="full" duration="1099" fileSize="17803689" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wmv" expression="full" duration="1099" fileSize="154844037" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_Zune_ch9.wmv" expression="full" duration="1099" fileSize="97484017" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/1/5/4/9/7/4/lobSDLdev_s_ch9.wmv" expression="full" duration="1099" fileSize="199" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wmv" length="154844037" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>2</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/SDL-LOB-Phase-3-Implementation/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Development</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
    </item>
  <item>
      <title>Anti-XSS 3.0 Released</title>
      <description><![CDATA[
<p>Vineet Batta and Anil Revuru (RV), from <a shape="rect" href="http://www.msinfosec.com" target="_blank" shape="rect">
Microsoft&nbsp;Information Security</a>,&nbsp;talk about the release of the new version of the Anti-XSS library, which is&nbsp;designed to encode output to help developers protect their ASP.NET web-based applications from&nbsp;cross-site scripting&nbsp;attacks.<br>
<br>
They explain the new features and benefits found on version 3.0, including:</p>
<ul>
<li>Extended white list </li><li>Better performance </li><li>MSDN Style Help documentation </li><li>Marked Anti-XSS Output </li><li>Security Runtime Engine (SRE) </li></ul>
<p>To learn more about this library read the following blogs from the <a shape="rect" href="http://blogs.msdn.com/securitytools/archive/tags/Anti-XSS/default.aspx" target="_blank" shape="rect">
Security Tools Team blog</a>&nbsp;and previous <a shape="rect" href="http://blogs.msdn.com/cisg/archive/tags/Anti-XSS/default.aspx" target="_blank" shape="rect">
posts</a>.</p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:c9a3a5ada73c4a08827d9deb0173162e">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Anti-XSS-30-Released</comments>
      <itunes:summary>
Vineet Batta and Anil Revuru (RV), from 
Microsoft&amp;nbsp;Information Security,&amp;nbsp;talk about the release of the new version of the Anti-XSS library, which is&amp;nbsp;designed to encode output to help developers protect their ASP.NET web-based applications from&amp;nbsp;cross-site scripting&amp;nbsp;attacks.

They explain the new features and benefits found on version 3.0, including: 

Extended white list Better performance MSDN Style Help documentation Marked Anti-XSS Output Security Runtime Engine (SRE) 
To learn more about this library read the following blogs from the 
Security Tools Team blog&amp;nbsp;and previous 
posts. 
</itunes:summary>
      <itunes:duration>1055</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Anti-XSS-30-Released</link>
      <pubDate>Wed, 15 Jul 2009 16:12:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Anti-XSS-30-Released</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/478820_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/478820_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv" expression="full" duration="1055" fileSize="47180833" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp3" expression="full" duration="1055" fileSize="8447064" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp4" expression="full" duration="1055" fileSize="79917703" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.wma" expression="full" duration="1055" fileSize="17085733" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_Zune_ch9.wmv" expression="full" duration="1055" fileSize="103371753" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_Zune_ch9.wmv" length="103371753" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Anti-XSS-30-Released/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Antixss</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>ist</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
      <category>Tools</category>
    </item>
  <item>
      <title>Silverlight 2 Security</title>
      <description><![CDATA[The usage of Silverlight to provide users a rich internet experience continues to increase. As it becomes a key element on our web applications, it is good to keep in mind that it still runs code on the user's machine.<br>
<br>
That is why Maqbool Malik, from <a href="http://www.msinfosec.com" target="_blank">
Microsoft Information Security</a>, describes some key features added on the second version of Silverlight to enhance security.<br>
<br>
Among the features discussed, Maqbool talks about XAP files, cross-domain policy files, HTML access,&nbsp;etc.
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:dbd74045c06b43f19ec49deb01731a4d">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Silverlight-20-Security</comments>
      <itunes:summary>The usage of Silverlight to provide users a rich internet experience continues to increase. As it becomes a key element on our web applications, it is good to keep in mind that it still runs code on the user&#39;s machine.

That is why Maqbool Malik, from 
Microsoft Information Security, describes some key features added on the second version of Silverlight to enhance security.

Among the features discussed, Maqbool talks about XAP files, cross-domain policy files, HTML access,&amp;nbsp;etc.
</itunes:summary>
      <itunes:duration>1120</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Silverlight-20-Security</link>
      <pubDate>Tue, 14 Jul 2009 00:43:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Silverlight-20-Security</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/477261_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/477261_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_2MB_ch9.wmv" expression="full" duration="1120" fileSize="136994891" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.mp3" expression="full" duration="1120" fileSize="8961987" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.mp4" expression="full" duration="1120" fileSize="110340362" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.wma" expression="full" duration="1120" fileSize="18134129" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.wmv" expression="full" duration="1120" fileSize="158924157" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_Zune_ch9.wmv" expression="full" duration="1120" fileSize="145052137" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/1/6/2/7/7/4/silverlightSec_s_ch9.wmv" expression="full" duration="1120" fileSize="209" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.wmv" length="158924157" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Silverlight-20-Security/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>Security</category>
      <category>Silverlight 2</category>
    </item>
  <item>
      <title>Threat Modeling LOB Applications with TAM 3.0</title>
      <description><![CDATA[
<p>Andrew Law, from <a href="http://www.msinfosec.com" target="_blank">Microsoft Information Security</a>, walks us through the creation of a threat model for a line-of-business application using the Threat Analysis &amp; Modeling tool version 3.0. This screencast
 includes the definition and purpose of a threat model as well as its alignment with the
<a href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank">SDL-LOB</a>.
</p>
<p>Threat Model ownership is discussed as well as the use of the central repository, common task list and how to leverage them to automatically generate threats.</p>
<p>Learn more&nbsp;on the&nbsp;<a href="http://msdn.microsoft.com/en-us/security/aa570413.aspx" target="_blank">Threat Modeling</a> site &amp;&nbsp;<a href="http://blogs.msdn.com/securitytools" target="_blank">Information Security Tools</a>&nbsp;blog.</p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:93644617a0db420994e09deb00db584a">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30</comments>
      <itunes:summary>
Andrew Law, from Microsoft Information Security, walks us through the creation of a threat model for a line-of-business application using the Threat Analysis &amp;amp; Modeling tool version 3.0. This screencast
 includes the definition and purpose of a threat model as well as its alignment with the
SDL-LOB.
 
Threat Model ownership is discussed as well as the use of the central repository, common task list and how to leverage them to automatically generate threats. 
Learn more&amp;nbsp;on the&amp;nbsp;Threat Modeling site &amp;amp;&amp;nbsp;Information Security Tools&amp;nbsp;blog. 
</itunes:summary>
      <itunes:duration>2925</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30</link>
      <pubDate>Mon, 06 Jul 2009 22:38:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/477063_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/477063_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_2MB_ch9.wmv" expression="full" duration="2925" fileSize="132391501" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp3" expression="full" duration="2925" fileSize="23406707" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp4" expression="full" duration="2925" fileSize="77895311" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wma" expression="full" duration="2925" fileSize="47320993" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wmv" expression="full" duration="2925" fileSize="127654993" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_Zune_ch9.wmv" expression="full" duration="2925" fileSize="97750973" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/3/6/0/7/7/4/tam3onLOB_s_ch9.wmv" expression="full" duration="2925" fileSize="199" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wmv" length="127654993" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
      <category>tam</category>
      <category>threat modeling</category>
      <category>Tools</category>
    </item>
  <item>
      <title>SQL Detect</title>
      <description><![CDATA[SQL Detect is&nbsp;a SQL injection filter in real-time mode. When a request happens in the application the tool applies different heuristics to the data and tries to identify the attack. After the request is validated it proceeds.<br>
<br>
Maqbool Malik, from <a shape="rect" href="http://www.msinfosec.com" target="_blank" shape="rect">
Microsoft Information Security</a>, describes how this is one of the tools to be included in the to-be-released Security Runtime Engine (SRE).<br>
<br>
To learn more about their tools, read the&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools/" target="_blank" shape="rect">Information Security Tools</a> blog.<br>
<br>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:773562286bb64bc38c379deb00db5c51">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/SQL-Detect</comments>
      <itunes:summary>SQL Detect is&amp;nbsp;a SQL injection filter in real-time mode. When a request happens in the application the tool applies different heuristics to the data and tries to identify the attack. After the request is validated it proceeds.

Maqbool Malik, from 
Microsoft Information Security, describes how this is one of the tools to be included in the to-be-released Security Runtime Engine (SRE).

To learn more about their tools, read the&amp;nbsp;Information Security Tools blog.

</itunes:summary>
      <itunes:duration>734</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/SQL-Detect</link>
      <pubDate>Mon, 06 Jul 2009 19:41:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/SQL-Detect</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/477052_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/477052_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_2MB_ch9.wmv" expression="full" duration="734" fileSize="89893228" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp3" expression="full" duration="734" fileSize="5880981" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp4" expression="full" duration="734" fileSize="45367124" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wma" expression="full" duration="734" fileSize="11897825" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wmv" expression="full" duration="734" fileSize="95065847" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_Zune_ch9.wmv" expression="full" duration="734" fileSize="54601827" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/2/5/0/7/7/4/SQLdetect_s_ch9.wmv" expression="full" duration="734" fileSize="199" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wmv" length="95065847" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>2</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/SQL-Detect/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
      <category>sre</category>
      <category>Tools</category>
    </item>
  <item>
      <title>Architecture Behind CAT.NET</title>
      <description><![CDATA[
<p>Ben Livshits, from Microsoft Research, talks about the architecture behind <a shape="rect" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&amp;displaylang=en" target="_blank" shape="rect">
CAT.NET</a>, which is a static analysis tool on Visual Studio&nbsp;that helps find vulnerabilities like SQL Injection, CSRF, &nbsp;XSS among others, within managed code.
<br>
<br>
Ben’s knowledge on static and dynamic dataflow analysis made him a key contributor on the creation of CAT.NET. He walks us through different examples of how the data analysis happens depending on complexity and explains how precision varies.
<br>
<br>
Learn more about <a shape="rect" href="http://blogs.msdn.com/securitytools/default.aspx" target="_blank" shape="rect">
Microsoft Information Security Tools</a>.&nbsp;<br>
<br>
<a shape="rect" href="http://www.msinfosec.com" shape="rect">www.msinfosec.com</a>&nbsp;</p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:b31a7863ee494b97a5109deb00db613d">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Architecture-behind-CATNET</comments>
      <itunes:summary>
Ben Livshits, from Microsoft Research, talks about the architecture behind 
CAT.NET, which is a static analysis tool on Visual Studio&amp;nbsp;that helps find vulnerabilities like SQL Injection, CSRF, &amp;nbsp;XSS among others, within managed code.


Ben’s knowledge on static and dynamic dataflow analysis made him a key contributor on the creation of CAT.NET. He walks us through different examples of how the data analysis happens depending on complexity and explains how precision varies.


Learn more about 
Microsoft Information Security Tools.&amp;nbsp;

www.msinfosec.com&amp;nbsp; 
</itunes:summary>
      <itunes:duration>1067</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Architecture-behind-CATNET</link>
      <pubDate>Mon, 29 Jun 2009 22:24:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Architecture-behind-CATNET</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/476042_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/476042_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_2MB_ch9.wmv" expression="full" duration="1067" fileSize="130500881" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp3" expression="full" duration="1067" fileSize="8540072" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp4" expression="full" duration="1067" fileSize="77800586" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wma" expression="full" duration="1067" fileSize="17268977" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wmv" expression="full" duration="1067" fileSize="150763845" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_Zune_ch9.wmv" expression="full" duration="1067" fileSize="90075825" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/2/4/0/6/7/4/catNET_s_ch9.wmv" expression="full" duration="1067" fileSize="193" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wmv" length="150763845" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>1</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Architecture-behind-CATNET/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>cat.net</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>RiSE</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
      <category>Tools</category>
    </item>
  <item>
      <title>Threat Analysis &amp; Modeling Tool - TAM 3.0</title>
      <description><![CDATA[Anil Revuru (RV), from <a shape="rect" href="http://blogs.msdn.com/securitytools/default.aspx" target="_blank" shape="rect">
Information Security Tools</a>, provides an overview of the new version of TAM (Threat Analysis &amp; Modeling), an asset-centric tool which&nbsp;uses an objective methodology to analyze applications for&nbsp;threats and define mitigation plans for them. TAM aligns to the&nbsp;<a shape="rect" href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank" shape="rect">SDL-LOB</a>
 as part of the Design phase.<br>
<br>
RV describes the new features in this version,&nbsp;including&nbsp;the online repository for the attack countermeasures,&nbsp;automated use cases creation, composite threats, among others.<br>
<br>
Learn more:<br>
<ol>
<li><a shape="rect" href="http://www.msinfosec.com/" target="_blank" shape="rect">Microsoft Information Security</a>
</li><li><a shape="rect" href="http://msdn.microsoft.com/en-us/security/aa570413.aspx" target="_blank" shape="rect">TAM Tool Site</a>&nbsp;
</li></ol>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:056ccc53c07c480f8a3c9deb00db65c7">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Thread-Analysis--Modeling-Tool-TAM-30</comments>
      <itunes:summary>Anil Revuru (RV), from 
Information Security Tools, provides an overview of the new version of TAM (Threat Analysis &amp;amp; Modeling), an asset-centric tool which&amp;nbsp;uses an objective methodology to analyze applications for&amp;nbsp;threats and define mitigation plans for them. TAM aligns to the&amp;nbsp;SDL-LOB
 as part of the Design phase.

RV describes the new features in this version,&amp;nbsp;including&amp;nbsp;the online repository for the attack countermeasures,&amp;nbsp;automated use cases creation, composite threats, among others.

Learn more:

Microsoft Information Security
TAM Tool Site&amp;nbsp;

</itunes:summary>
      <itunes:duration>961</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Thread-Analysis--Modeling-Tool-TAM-30</link>
      <pubDate>Mon, 29 Jun 2009 20:43:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Thread-Analysis--Modeling-Tool-TAM-30</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/476038_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/476038_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_2MB_ch9.wmv" expression="full" duration="961" fileSize="117606784" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.mp3" expression="full" duration="961" fileSize="7697076" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.mp4" expression="full" duration="961" fileSize="65596326" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.wma" expression="full" duration="961" fileSize="15574721" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.wmv" expression="full" duration="961" fileSize="131291209" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_Zune_ch9.wmv" expression="full" duration="961" fileSize="79195189" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/8/3/0/6/7/4/TAM3_s_ch9.wmv" expression="full" duration="961" fileSize="189" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.wmv" length="131291209" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>2</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Thread-Analysis--Modeling-Tool-TAM-30/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
      <category>tam</category>
      <category>threat modeling</category>
      <category>Tools</category>
    </item>
  <item>
      <title>Security Design Reviews</title>
      <description><![CDATA[Security is not something we just add at the end of the implementation phase...it should be
<em>baked</em> into the application all the way from design. <br>
<br>
Anmol Malhotra, from <a shape="rect" href="http://www.msinfosec.com" target="_blank" shape="rect">
Microsoft Information Security</a>, provides more than enough reasons why Security Design Reviews make sense and why they are so important...let him walk you through the SDLC phases and how security tasks are found in each step.<br>
<br>
To learn more about security on line-of-business applications using the SDL-LOB go&nbsp;<a shape="rect" href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank" shape="rect">here</a>.
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:e6e19c534ac147ea84ea9deb00db6b09">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Security-Design-Reviews</comments>
      <itunes:summary>Security is not something we just add at the end of the implementation phase...it should be
baked into the application all the way from design. 

Anmol Malhotra, from 
Microsoft Information Security, provides more than enough reasons why Security Design Reviews make sense and why they are so important...let him walk you through the SDLC phases and how security tasks are found in each step.

To learn more about security on line-of-business applications using the SDL-LOB go&amp;nbsp;here.
</itunes:summary>
      <itunes:duration>1083</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Security-Design-Reviews</link>
      <pubDate>Wed, 24 Jun 2009 16:07:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Security-Design-Reviews</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/475065_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/475065_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_2MB_ch9.wmv" expression="full" duration="1083" fileSize="263445138" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp3" expression="full" duration="1083" fileSize="8670049" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp4" expression="full" duration="1083" fileSize="106866291" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.wmv" expression="full" duration="1083" fileSize="153867941" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_Zune_ch9.wmv" expression="full" duration="1083" fileSize="153579921" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/5/6/0/5/7/4/designRev_s_ch9.wmv" expression="full" duration="1083" fileSize="199" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.wmv" length="153867941" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>2</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Security-Design-Reviews/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
    </item>
  <item>
      <title>ACE&#39;s Performance Development Lifecycle for IT (PDL-IT)</title>
      <description><![CDATA[
<p align="justify">Microsoft ACE team has been involved in performance testing and tuning of web applications within Microsoft and externally for several years now.&nbsp;<a href="http://www.msinfosec.com" title="Microsoft Information Security" target="_blank">Microsoft's
 Information Security</a> - ACE Performance has been using a methodology which they have now formalized as PDL-IT (Performance Development Lifecycle for IT) which consists of a proactive approach for application performance within the SDLC.<br>
<br>
Irfan Chaudhry, Director of InfoSec's ACE Team, explains this methodology after being part of ACE for 8 years&nbsp;and having started as a Performance Analyst himself.
<br>
<br>
If you want to learn more about PDL-IT, you can read more on the&nbsp;<a href="http://blogs.msdn.com/ace_team/default.aspx" title="ACE Team Blog" target="_blank">ACE Team</a> blog in a
<a href="http://blogs.msdn.com/ace_team/archive/2009/03/04/performance-development-life-cycle-for-it-part-1.aspx" title="PDL-IT Post #1" target="_blank">
series of posts</a>.</p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:c53a95b19cad450e94e49deb0173293d">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/ACEs-Performance-Development-Lifecycle-for-IT-PDL-IT</comments>
      <itunes:summary>
Microsoft ACE team has been involved in performance testing and tuning of web applications within Microsoft and externally for several years now.&amp;nbsp;Microsoft&#39;s
 Information Security - ACE Performance has been using a methodology which they have now formalized as PDL-IT (Performance Development Lifecycle for IT) which consists of a proactive approach for application performance within the SDLC.

Irfan Chaudhry, Director of InfoSec&#39;s ACE Team, explains this methodology after being part of ACE for 8 years&amp;nbsp;and having started as a Performance Analyst himself.


If you want to learn more about PDL-IT, you can read more on the&amp;nbsp;ACE Team blog in a

series of posts. 
</itunes:summary>
      <itunes:duration>873</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/ACEs-Performance-Development-Lifecycle-for-IT-PDL-IT</link>
      <pubDate>Fri, 03 Apr 2009 16:29:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/ACEs-Performance-Development-Lifecycle-for-IT-PDL-IT</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/463611_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/463611_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_2MB_ch9.wmv" expression="full" duration="873" fileSize="273339205" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_ch9.mp3" expression="full" duration="873" fileSize="667" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_ch9.mp4" expression="full" duration="873" fileSize="86143172" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_ch9.wma" expression="full" duration="873" fileSize="14138809" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_ch9.wmv" expression="full" duration="873" fileSize="52906681" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_Zune_ch9.wmv" expression="full" duration="873" fileSize="114746661" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/1/1/6/3/6/4/PDLIT_s_ch9.wmv" expression="full" duration="873" fileSize="190" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_ch9.wmv" length="52906681" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/ACEs-Performance-Development-Lifecycle-for-IT-PDL-IT/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>pdl-it</category>
      <category>Performance</category>
    </item>
  <item>
      <title>Application Performance Reviews: ACE Team</title>
      <description><![CDATA[
<p>The Assessment Consulting &amp; Engineering (ACE) team, part of the&nbsp;<a href="http://msdn.microsoft.com/en-us/security/dd547422.aspx" title="Microsoft Information Security" target="_blank">Microsoft Information Security</a> group, assesses the performance of&nbsp;Microsoft
 applications.&nbsp; Principal Performance Manager, K.M. Lee, discusses his team's methodology after many years of experience on this area which keeps evolving as technology changes. &nbsp;K.M. also describes how they have taken their knowledge into the field&nbsp;to Microsoft
 customers and partners as well as how they are taking the next step&nbsp;by creating performance review tools.</p>
<p>For more information on the tool K.M. mentions, neXpert see: <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;EventID=1032398774&amp;CountryCode=US">
webcast</a>, <a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=5975da52-8ce6-48bd-9b3c-756a625024bb">
download</a></p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Niners/Jossie/Posts/RSS&WT.dl=0&WT.entryid=Entry:RSSView:db0fce784904494481f79deb01732edf">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Application-Performance-Reviews-ACE-Team</comments>
      <itunes:summary>
The Assessment Consulting &amp;amp; Engineering (ACE) team, part of the&amp;nbsp;Microsoft Information Security group, assesses the performance of&amp;nbsp;Microsoft
 applications.&amp;nbsp; Principal Performance Manager, K.M. Lee, discusses his team&#39;s methodology after many years of experience on this area which keeps evolving as technology changes. &amp;nbsp;K.M. also describes how they have taken their knowledge into the field&amp;nbsp;to Microsoft
 customers and partners as well as how they are taking the next step&amp;nbsp;by creating performance review tools. 
For more information on the tool K.M. mentions, neXpert see: 
webcast, 
download 
</itunes:summary>
      <itunes:duration>714</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Application-Performance-Reviews-ACE-Team</link>
      <pubDate>Wed, 04 Mar 2009 01:20:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Application-Performance-Reviews-ACE-Team</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/459476_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/459476_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_2MB_ch9.wmv" expression="full" duration="714" fileSize="223882243" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.mp3" expression="full" duration="714" fileSize="5719899" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.mp4" expression="full" duration="714" fileSize="70573660" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.wma" expression="full" duration="714" fileSize="11579399" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.wmv" expression="full" duration="714" fileSize="43097725" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_Zune_ch9.wmv" expression="full" duration="714" fileSize="56473705" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/6/7/4/9/5/4/aceperf_s_ch9.wmv" expression="full" duration="714" fileSize="194" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_2MB_ch9.wmv" length="223882243" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Application-Performance-Reviews-ACE-Team/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Information</category>
      <category>infosec</category>
      <category>nexPert</category>
      <category>Performance</category>
      <category>Security</category>
    </item>    
</channel>
</rss>