<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" media="screen" href="/App_Themes/default/rss.xslt"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:evnet="http://www.mscommunities.com/rssmodule/"><channel><title>Entries tagged with security - Channel 9</title><atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/tags/security/rss/default.aspx" /><image><url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url><title>Entries tagged with security - Channel 9</title><link>http://channel9.msdn.com/tags/Security/</link></image><description>security</description><link>http://channel9.msdn.com/tags/Security/</link><language>en-us</language><pubDate>Tue, 24 Nov 2009 19:51:15 GMT</pubDate><lastBuildDate>Tue, 24 Nov 2009 19:51:15 GMT</lastBuildDate><generator>EvNet (EvNet, Version=1.0.3608.3122, Culture=neutral, PublicKeyToken=null)</generator><item><title>Using the Web Protection Library (WPL) - CTP Version</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_85_ch9.png" border="0" /&gt;&lt;p&gt;Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, walks us through the expansion of what used to be the Anti-XSS Library. This enhanced version of the library will introduce mitigation to other attacks like:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;SQL Injection &lt;/li&gt;
    &lt;li&gt;Cross-Site Request Forgery (CSRF) &lt;/li&gt;
    &lt;li&gt;Setting Enforcement like SSL &amp;amp; HTTP_ONLY cookies &lt;/li&gt;
    &lt;li&gt;Security Runtime Engine for SQL Injection &amp;amp; XSS &lt;/li&gt;
    &lt;li&gt;Among others &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The CTP (Community Technology Preview) is available in &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank"&gt;Microsoft Connect – Information Security Tools&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
Read &lt;a href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx" target="_blank"&gt;CTP announcement&lt;/a&gt; and follow the &lt;a href="http://blogs.msdn.com/securitytools" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog. &lt;/p&gt;&lt;img src="http://channel9.msdn.com/508747/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Using-the-Web-Protection-Library-WPL-CTP-Version/</comments><link>http://channel9.msdn.com/posts/Jossie/Using-the-Web-Protection-Library-WPL-CTP-Version/</link><pubDate>Wed, 25 Nov 2009 00:00:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_ch9.wmv</guid><evnet:views>1294</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/508747/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, walks us through the expansion of what used to be the Anti-XSS Library. This enhanced version of the library will introduce mitigation to other attacks like:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;SQL Injection &lt;/li&gt;
    &lt;li&gt;Cross-Site Request Forgery (CSRF) &lt;/li&gt;
    &lt;li&gt;Setting Enforcement like SSL &amp;amp; HTTP_ONLY cookies &lt;/li&gt;
    &lt;li&gt;Security Runtime Engine for SQL Injection &amp;amp; XSS &lt;/li&gt;
    &lt;li&gt;Among others &lt;/li&gt;
&lt;/ul&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_ch9.mp4" expression="full" duration="656" fileSize="69586321" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_ch9.mp3" expression="full" duration="656" fileSize="5253700" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_ch9.mp4" expression="full" duration="656" fileSize="69586321" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_ch9.wma" expression="full" duration="656" fileSize="5316043" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_ch9.wmv" expression="full" duration="656" fileSize="95150711" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_2MB_ch9.wmv" expression="full" duration="656" fileSize="50563911" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_Zune_ch9.wmv" expression="full" duration="656" fileSize="53870763" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_512_ch9.png" expression="full" duration="656" type="image/jpeg" medium="image" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_ch9.wmv" expression="full" duration="656" fileSize="95150711" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/7/4/7/8/0/5/WPLdemo_ch9.wmv" length="95150711" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Using-the-Web-Protection-Library-WPL-CTP-Version/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/508747/Trackback.aspx</trackback:ping><category>antixss</category><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category><category>wpl</category></item><item><title>Using Web Application Configuration Analyzer (WACA) - CTP Version</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_85_ch9.png" border="0" /&gt;Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, walks us through a configuration verification tool that will be part of a suite of tools that will help you assess your code as well as protect it. For more info watch the &lt;a href="http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/" target="_blank"&gt;Assessment &amp;amp; Protection (A&amp;amp;P) Suite&lt;/a&gt; video.&lt;br /&gt;
&lt;br /&gt;
WACA is designed to scan your development environment against best practices for .NET security configuration, IIS settings, SQL Server Security best practices and some Windows permission settings. It is helpful for verifying your configuration while unit testing and ensuring there are no issues when the application is in production.&lt;br /&gt;
&lt;br /&gt;
The CTP (Community Technology Preview) for this tool is available in &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank"&gt;Microsoft Connect – Information Security Tools&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
Read &lt;a href="http://blogs.msdn.com/infosec/archive/2009/11/16/infosec-assessment-protection-a-p-suite-released.aspx" target="_blank"&gt;CTP announcement&lt;/a&gt; and follow the &lt;a href="http://blogs.msdn.com/securitytools" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog.&lt;img src="http://channel9.msdn.com/508745/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Web-Application-Configuration-Analizer-WACA/</comments><link>http://channel9.msdn.com/posts/Jossie/Web-Application-Configuration-Analizer-WACA/</link><pubDate>Tue, 24 Nov 2009 23:58:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_2MB_ch9.wmv</guid><evnet:views>1199</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/508745/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, walks us through a configuration verification tool that will be part of a suite of tools that will help you assess your code as well as protect it. For more info watch the &lt;a href="http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/" target="_blank"&gt;Assessment &amp;amp; Protection (A&amp;amp;P) Suite&lt;/a&gt; video.&lt;br /&gt;
&lt;br /&gt;
WACA is designed to scan your development environment against best practices for .NET security configuration, IIS settings, SQL Server Security best practices and some Windows permission settings. It is helpful for verifying your configuration while unit testing and ensuring there are no issues when the application is in production.</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_ch9.mp4" expression="full" duration="435" fileSize="28588657" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_ch9.mp3" expression="full" duration="435" fileSize="3488267" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_ch9.mp4" expression="full" duration="435" fileSize="28588657" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_ch9.wma" expression="full" duration="435" fileSize="3534677" type="audio/x-ms-wma" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_2MB_ch9.wmv" expression="full" duration="435" fileSize="42688653" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_Zune_ch9.wmv" expression="full" duration="435" fileSize="21947675" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_512_ch9.png" expression="full" duration="435" type="image/jpeg" medium="image" /><media:content url="http://mschannel9.vo.msecnd.net/ss1/ch9/5/4/7/8/0/5/WACAdemo.ism/Manifest" expression="full" duration="435" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_2MB_ch9.wmv" expression="full" duration="435" fileSize="42688653" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/5/4/7/8/0/5/WACAdemo_2MB_ch9.wmv" length="42688653" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Web-Application-Configuration-Analizer-WACA/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/508745/Trackback.aspx</trackback:ping><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category><category>waca</category></item><item><title>Web Application Configuration Analyzer (WACA)</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_85_ch9.png" border="0" /&gt;Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, introduces a configuration verification tool that will be part of a suite of tools that will help you assess your code as well as protect it. For more info watch the &lt;a href="http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/" target="_blank"&gt;Assessment &amp;amp; Protection (A&amp;amp;P) Suite&lt;/a&gt; video.&lt;br /&gt;
&lt;br /&gt;
WACA is designed to scan your development environment against best practices for .NET security configuration, IIS settings, SQL Server Security best practices and some Windows permission settings. It is helpful for verifying your configuration while unit testing and ensuring there are no issues when the application is in production.&lt;br /&gt;
&lt;br /&gt;
The CTP (Community Technology Preview) for this tool is available in &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank"&gt;Microsoft Connect – Information Security Tools&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
Read &lt;a href="http://blogs.msdn.com/infosec/archive/2009/11/16/infosec-assessment-protection-a-p-suite-released.aspx" target="_blank"&gt;CTP announcement&lt;/a&gt; and follow the &lt;a href="http://blogs.msdn.com/securitytools" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog.&lt;img src="http://channel9.msdn.com/507560/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Web-Application-Configuration-Analyzer-WACA/</comments><link>http://channel9.msdn.com/posts/Jossie/Web-Application-Configuration-Analyzer-WACA/</link><pubDate>Fri, 20 Nov 2009 22:21:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.wmv</guid><evnet:views>2036</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/507560/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, introduces a configuration verification tool that will be part of a suite of tools that will help you assess your code as well as protect it. For more info watch the &lt;a href="http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/" target="_blank"&gt;Assessment &amp;amp; Protection (A&amp;amp;P) Suite&lt;/a&gt; video.&lt;br /&gt;
&lt;br /&gt;
WACA is designed to scan your development environment against best practices for .NET security configuration, IIS settings, SQL Server Security best practices and some Windows permission settings. It is helpful for verifying your configuration while unit testing and ensuring there are no issues when the application is in production.</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.mp4" expression="full" duration="943" fileSize="103910191" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.mp3" expression="full" duration="943" fileSize="7549118" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.mp4" expression="full" duration="943" fileSize="103910191" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.wma" expression="full" duration="943" fileSize="7635131" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.wmv" expression="full" duration="943" fileSize="150098729" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_2MB_ch9.wmv" expression="full" duration="943" fileSize="115402475" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_Zune_ch9.wmv" expression="full" duration="943" fileSize="93794781" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_512_ch9.png" expression="full" duration="943" type="image/jpeg" medium="image" /><media:content url="http://ss.channel9.msdn.com/ch9/0/6/5/7/0/5/WACA.ism/Manifest" expression="full" duration="943" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.wmv" expression="full" duration="943" fileSize="150098729" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.wmv" length="150098729" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Web-Application-Configuration-Analyzer-WACA/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/507560/Trackback.aspx</trackback:ping><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category><category>waca</category></item><item><title>Assessment and Protection Suite</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_85_ch9.png" border="0" /&gt;&lt;p&gt;Anil Revuru (RV) and Mark Curphey, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, introduce what would be in the future a suite of tools that will help you assess your code as well as protect it. This is called the Assessment &amp;amp; Protection (A&amp;amp;P) Suite and it includes the following tools: &lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Web Protection Library (WPL) – which includes Anti-XSS, SRE, mitigation of SQL Injection, CSRF among others &lt;/li&gt;
    &lt;li&gt;CAT.NET &lt;/li&gt;
    &lt;li&gt;Web Application Configuration Analyzer (WACA) &lt;/li&gt;
    &lt;li&gt;and room for more future add-ons &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The CTP (Community Technology Preview) for these tools are available in &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank"&gt;Microsoft Connect – Information Security Tools&lt;/a&gt;. These are currently individual as they shift to one-install.&lt;br /&gt;
&lt;br /&gt;
Read &lt;a href="http://blogs.msdn.com/infosec/archive/2009/11/16/infosec-assessment-protection-a-p-suite-released.aspx" target="_blank"&gt;CTP announcement&lt;/a&gt; and follow the &lt;a href="http://blogs.msdn.com/securitytools" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog. &lt;/p&gt;&lt;img src="http://channel9.msdn.com/505599/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/</comments><link>http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/</link><pubDate>Thu, 12 Nov 2009 17:21:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.wmv</guid><evnet:views>2853</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/505599/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;Anil Revuru (RV) and Mark Curphey, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, introduce what would be in the future a suite of tools that will help you assess your code as well as protect it. This is called the Assessment &amp;amp; Protection (A&amp;amp;P) Suite and it includes the following tools: &lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Web Protection Library (WPL) – which includes Anti-XSS, SRE, mitigation of SQL Injection, CSRF among others &lt;/li&gt;
    &lt;li&gt;CAT.NET &lt;/li&gt;
    &lt;li&gt;Web Application Configuration Analyzer (WACA) &lt;/li&gt;
    &lt;li&gt;and room for more future add-ons &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The CTP (Community Technology Preview) for these tools are available in &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank"&gt;Microsoft Connect – Information Security Tools&lt;/a&gt;. These are currently individual as they shift to one-install.&lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.mp4" expression="full" duration="1044" fileSize="115680604" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.mp3" expression="full" duration="1044" fileSize="8359931" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.mp4" expression="full" duration="1044" fileSize="115680604" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.wma" expression="full" duration="1044" fileSize="8458227" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.wmv" expression="full" duration="1044" fileSize="169620143" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_2MB_ch9.wmv" expression="full" duration="1044" fileSize="127779102" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_Zune_ch9.wmv" expression="full" duration="1044" fileSize="112564195" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_512_ch9.png" expression="full" duration="1044" type="image/jpeg" medium="image" /><media:content url="http://mschannel9.vo.msecnd.net/ss1/ch9/9/9/5/5/0/5/AnPoverview.ism/Manifest" expression="full" duration="1044" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.wmv" expression="full" duration="1044" fileSize="169620143" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.wmv" length="169620143" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/505599/Trackback.aspx</trackback:ping><category>antixss</category><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category><category>wpl</category></item><item><title>Enhanced Web Protection Library</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_85_ch9.png" border="0" /&gt;&lt;p&gt;Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, introduces the expansion of what used to be the Anti-XSS Library. But web vulnerabilities are not only around Cross-Site Scripting (XSS) attacks. This enhanced version of the library will introduce mitigation to other attacks like:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;SQL Injection &lt;/li&gt;
    &lt;li&gt;Cross-Site Request Forgery (CSRF) &lt;/li&gt;
    &lt;li&gt;Setting Enforcement like SSL &amp;amp; HTTP_ONLY cookies &lt;/li&gt;
    &lt;li&gt;Security Runtime Engine for SQL Injection &amp;amp; XSS &lt;/li&gt;
    &lt;li&gt;Among others &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The CTP (Community Technology Preview) is available in &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank"&gt;Microsoft Connect – Information Security Tools&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
Read &lt;a href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx" target="_blank"&gt;CTP announcement&lt;/a&gt; and follow the &lt;a href="http://blogs.msdn.com/securitytools" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog. &lt;/p&gt;&lt;img src="http://channel9.msdn.com/505597/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Enhanced-Web-Protection-Library/</comments><link>http://channel9.msdn.com/posts/Jossie/Enhanced-Web-Protection-Library/</link><pubDate>Thu, 12 Nov 2009 17:21:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.wmv</guid><evnet:views>3122</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/505597/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, introduces the expansion of what used to be the Anti-XSS Library. But web vulnerabilities are not only around Cross-Site Scripting (XSS) attacks. This enhanced version of the library will introduce mitigation to other attacks like:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;SQL Injection &lt;/li&gt;
    &lt;li&gt;Cross-Site Request Forgery (CSRF) &lt;/li&gt;
    &lt;li&gt;Setting Enforcement like SSL &amp;amp; HTTP_ONLY cookies &lt;/li&gt;
    &lt;li&gt;Security Runtime Engine for SQL Injection &amp;amp; XSS &lt;/li&gt;
    &lt;li&gt;Among others &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The CTP (Community Technology Preview) is available in &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank"&gt;Microsoft Connect – Information Security Tools&lt;/a&gt;. &lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.mp4" expression="full" duration="928" fileSize="125005100" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.mp3" expression="full" duration="928" fileSize="7428509" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.mp4" expression="full" duration="928" fileSize="125005100" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.wma" expression="full" duration="928" fileSize="7517981" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.wmv" expression="full" duration="928" fileSize="169042525" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_2MB_ch9.wmv" expression="full" duration="928" fileSize="113545072" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_Zune_ch9.wmv" expression="full" duration="928" fileSize="105714577" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_512_ch9.png" expression="full" duration="928" type="image/jpeg" medium="image" /><media:content url="http://mschannel9.vo.msecnd.net/ss1/ch9/7/9/5/5/0/5/WPL.ism/Manifest" expression="full" duration="928" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.wmv" expression="full" duration="928" fileSize="169042525" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.wmv" length="169042525" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Enhanced-Web-Protection-Library/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/505597/Trackback.aspx</trackback:ping><category>antixss</category><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category><category>wpl</category></item><item><title>Microsoft Security Development Lifecycle (SDL) and Software Security Today</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_85_ch9.png" border="0" /&gt;&lt;p&gt;The &lt;a href="http://www.microsoft.com/sdl"&gt;Microsoft Security Development Lifecycle&lt;/a&gt; (SDL) team recently released two new security tools, BinScope Binary Analyzer and MiniFuzz File Fuzzer, to help you write more secure code. Jeremy Dallman, Michael Howard, and Ivan Medvedev created these tools so we decided to pay them a visit to chat about what these tools do and why they matter. Of course, it's been &lt;em&gt;way&lt;/em&gt; too long since &lt;a href="http://blogs.msdn.com/michael_howard/" target="_blank"&gt;Michael Howard&lt;/a&gt; has preached to us from his security soapbox so we just &lt;em&gt;had&lt;/em&gt; to get him talking about the general state of software security today and where it's going! &lt;br /&gt;
&lt;br /&gt;
For the Microsoft SDL team, SDL is as much a &lt;em&gt;lifestyle&lt;/em&gt; as it is a software development life&lt;em&gt;cycle&lt;/em&gt;. Developers, thrive securely so that others may securely thrive. Oh yeah, brothers and sisters. I'm sensing the need for a security soapbox show on 9. We need more preaching. There's still far too many developers writing insecure code. "Reverend" Howard, are you game, sir?&lt;br /&gt;
&lt;br /&gt;
Get BinScope and MiniFuzz on &lt;a href="http://msdn.microsoft.com/en-us/security/cc421514.aspx"&gt;SDL Tool Repository&lt;/a&gt;. Please use them!!!&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;Stay updated on the SDL at:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/sdl"&gt;http://www.microsoft.com/sdl&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.msdn.com/sdl"&gt;http://blogs.msdn.com/sdl&lt;/a&gt;&lt;/p&gt;&lt;img src="http://channel9.msdn.com/501491/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today/</comments><link>http://channel9.msdn.com/posts/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today/</link><pubDate>Fri, 06 Nov 2009 21:49:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_ch9.wmv</guid><evnet:views>35764</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/501491/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;The &lt;a href="http://www.microsoft.com/sdl"&gt;Microsoft Security Development Lifecycle&lt;/a&gt; (SDL) team recently released two new security tools, BinScope Binary Analyzer and MiniFuzz File Fuzzer, to help you write more secure code. Jeremy Dallman, Michael Howard, and Ivan Medvedev created these tools so we decided to pay them a visit to chat about what these tools do and why they matter. Of course, it's been &lt;em&gt;way&lt;/em&gt; too long since &lt;a href="http://blogs.msdn.com/michael_howard/" target="_blank"&gt;Michael Howard&lt;/a&gt; has preached to us from his security soapbox so we just &lt;em&gt;had&lt;/em&gt; to get him talking about the general state of software security today and where it's going!&lt;br /&gt;
&lt;br /&gt;
Get BinScope and MiniFuzz on &lt;a href="http://msdn.microsoft.com/en-us/security/cc421514.aspx"&gt;SDL Tool Repository&lt;/a&gt;. Please use them!!!&lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_ch9.mp4" expression="full" duration="1980" fileSize="356441344" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_ch9.mp3" expression="full" duration="1980" fileSize="15848596" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_ch9.mp4" expression="full" duration="1980" fileSize="356441344" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_ch9.wma" expression="full" duration="1980" fileSize="16025303" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_ch9.wmv" expression="full" duration="1980" fileSize="435889247" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_2MB_ch9.wmv" expression="full" duration="1980" fileSize="620705317" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_Zune_ch9.wmv" expression="full" duration="1980" fileSize="318638675" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_512_ch9.png" expression="full" duration="1980" type="image/jpeg" medium="image" /><media:content url="http://ss.channel9.msdn.com/ch9/1/9/4/1/0/5/SDLDevTools.ism/Manifest" expression="full" duration="1980" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_ch9.wmv" length="435889247" type="video/x-ms-wmv" /><dc:creator>Charles</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/501491/Trackback.aspx</trackback:ping><category>SDL</category><category>Security</category><category>Tools</category><category>Trustworthy Computing</category><category>Visual Studio</category><category>Visual Studio Team System</category></item><item><title>Aufzeichnung zum Oktober-TechTalk: Windows 7 – ein Überblick für Entwickler (Teil2)</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_85_ch9.png" border="0" /&gt;&lt;p&gt;Der Hauptfokus bei Windows 7 wurde auf die weitere Verbesserung der Sicherheit, Zuverlässigkeit und Performance des Betriebssystems gelegt - und auf die größtmögliche Kompatibilität zu Windows Vista , damit bereits bestehende Anwendungen auch in Zukunft laufen. Für Entwickler bietet Windows 7 viele neue Schnittstellen, um Anwendungen mit umfassenderen Funktionen zu versehen, die dem Endbenutzer eine neue Erfahrung im Umgang mit Software ermöglichen. &lt;/p&gt;
&lt;p&gt;In dieser TechTalk-Aufzeichnung erklären Oliver Scheer und Peter Kirchner, wie etwa die neue Taskbar genutzt werden kann, indem die Preview-Ansicht gesteuert, Status-Informationen ausgegeben oder die Sprunglisten nach Ihren  Wünschen angepasst werden können. Wir zeigen neue Möglichkeiten für die Anpassung von  Windows-Diensten, um die Performance des Betriebssystems optimal zu nutzen und demonstrieren die Verwendung der in Windows 7 eingeführten Bibliotheken, um den Zugriff auf Dokumente Ihrer Anwendung zu vereinfachen. Zusätzlich erfährt man, welche Punkte zu beachten sind, um die Kompatibilität Ihrer Anwendung mit Windows 7 sicher zu stellen, wenn diese bereits auf Windows XP oder Windows Vista laufen. Abschließend wird ein Überblick gegeben, welche Änderungen sich im Windows Logo Programm ergeben haben und wie Sie Ihre Anwendung für Windows 7 zertifizieren lassen können.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;b&gt;Allgemeine Information zu den TechTalks:&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Die kostenlosen TechTalk-Veranstaltungen sind ein lebendiges Forum zum Wissensaustausch unter Entwicklern und bieten Gelegenheit, "Microsoft zum Anfassen" zu erleben. Microsoft-Experten vermitteln dabei in Vorträgen ihr Wissen und stehen für Diskussionen zur Verfügung. Dabei ist der TechTalk keine überdimensionierte Massenveranstaltung, sondern bietet das angenehme und lockere Umfeld, das den ganz besonderen Reiz eines Entwicklertreffens ausmacht. Alle weiteren Informationen finden Sie unter &lt;a href="http://techtalk.ms/"&gt;http://techtalk.ms/&lt;/a&gt;  &lt;/p&gt;&lt;img src="http://channel9.msdn.com/503768/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/kitano/TechTalk-Windows-7-Ein-berblick-fr-Entwickler-Teil-2/</comments><link>http://channel9.msdn.com/posts/kitano/TechTalk-Windows-7-Ein-berblick-fr-Entwickler-Teil-2/</link><pubDate>Tue, 03 Nov 2009 18:32:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_ch9.wmv</guid><evnet:views>1999</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/503768/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Der Hauptfokus bei Windows 7 wurde auf die weitere Verbesserung der Sicherheit, Zuverlässigkeit und Performance des Betriebssystems gelegt - und auf die größtmögliche Kompatibilität zu Windows Vista , damit bereits bestehende Anwendungen auch in Zukunft laufen. Für Entwickler bietet Windows 7 viele neue Schnittstellen, um Anwendungen mit umfassenderen Funktionen zu versehen, die dem Endbenutzer eine neue Erfahrung im Umgang mit Software ermöglichen. In dieser TechTalk-Aufzeichnung erklären Oliver Scheer und Peter Kirchner, wie etwa die neue Taskbar genutzt werden kann, indem die…</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_ch9.mp4" expression="full" duration="4680" fileSize="246858138" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_ch9.mp3" expression="full" duration="4680" fileSize="37448083" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_ch9.mp4" expression="full" duration="4680" fileSize="246858138" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_ch9.wma" expression="full" duration="4680" fileSize="37861379" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_ch9.wmv" expression="full" duration="4680" fileSize="331591047" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_2MB_ch9.wmv" expression="full" duration="4680" fileSize="309343212" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_Zune_ch9.wmv" expression="full" duration="4680" fileSize="265463771" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_512_ch9.png" expression="full" duration="4680" type="image/jpeg" medium="image" /><media:content url="http://ss.channel9.msdn.com/ch9/8/6/7/3/0/5/TechTalkWindows72.ism/Manifest" expression="full" duration="4680" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/8/6/7/3/0/5/TechTalkWindows72_ch9.wmv" length="331591047" type="video/x-ms-wmv" /><dc:creator>Jan Schenk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/kitano/TechTalk-Windows-7-Ein-berblick-fr-Entwickler-Teil-2/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/503768/Trackback.aspx</trackback:ping><category>app  compat</category><category>betriebssystem</category><category>certified</category><category>dienste</category><category>jumplist</category><category>Kompatibilität</category><category>logo</category><category>OS</category><category>performance</category><category>Security</category><category>sprungliste</category><category>Taskbar</category><category>Windows 7</category></item><item><title>Aufzeichnung zum Oktober-TechTalk: Windows 7 – ein Überblick für Entwickler (Teil 1) </title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_85_ch9.png" border="0" /&gt;&lt;p&gt;Der Hauptfokus bei Windows 7 wurde auf die weitere Verbesserung der Sicherheit, Zuverlässigkeit und Performance des Betriebssystems gelegt - und auf die größtmögliche Kompatibilität zu Windows Vista , damit bereits bestehende Anwendungen auch in Zukunft laufen. Für Entwickler bietet Windows 7 viele neue Schnittstellen, um Anwendungen mit umfassenderen Funktionen zu versehen, die dem Endbenutzer eine neue Erfahrung im Umgang mit Software ermöglichen. &lt;/p&gt;
&lt;p&gt;In dieser TechTalk-Aufzeichnung erklären Oliver Scheer und Peter Kirchner, wie etwa die neue Taskbar genutzt werden kann, indem die Preview-Ansicht gesteuert, Status-Informationen ausgegeben oder die Sprunglisten nach Ihren  Wünschen angepasst werden können. Wir zeigen neue Möglichkeiten für die Anpassung von  Windows-Diensten, um die Performance des Betriebssystems optimal zu nutzen und demonstrieren die Verwendung der in Windows 7 eingeführten Bibliotheken, um den Zugriff auf Dokumente Ihrer Anwendung zu vereinfachen. Zusätzlich erfährt man, welche Punkte zu beachten sind, um die Kompatibilität Ihrer Anwendung mit Windows 7 sicher zu stellen, wenn diese bereits auf Windows XP oder Windows Vista laufen. Abschließend wird ein Überblick gegeben, welche Änderungen sich im Windows Logo Programm ergeben haben und wie Sie Ihre Anwendung für Windows 7 zertifizieren lassen können.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;b&gt;Allgemeine Information zu den TechTalks:&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Die kostenlosen TechTalk-Veranstaltungen sind ein lebendiges Forum zum Wissensaustausch unter Entwicklern und bieten Gelegenheit, "Microsoft zum Anfassen" zu erleben. Microsoft-Experten vermitteln dabei in Vorträgen ihr Wissen und stehen für Diskussionen zur Verfügung. Dabei ist der TechTalk keine überdimensionierte Massenveranstaltung, sondern bietet das angenehme und lockere Umfeld, das den ganz besonderen Reiz eines Entwicklertreffens ausmacht. Alle weiteren Informationen finden Sie unter &lt;a href="http://techtalk.ms/"&gt;http://techtalk.ms/&lt;/a&gt;  &lt;/p&gt;&lt;img src="http://channel9.msdn.com/503755/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/kitano/Aufzeichnung-zum-Oktober-TechTalk-Windows-7--ein-berblick-fr-Entwickler-Teil-1/</comments><link>http://channel9.msdn.com/posts/kitano/Aufzeichnung-zum-Oktober-TechTalk-Windows-7--ein-berblick-fr-Entwickler-Teil-1/</link><pubDate>Tue, 03 Nov 2009 18:31:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_ch9.wmv</guid><evnet:views>2077</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/503755/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Der Hauptfokus bei Windows 7 wurde auf die weitere Verbesserung der Sicherheit, Zuverlässigkeit und Performance des Betriebssystems gelegt - und auf die größtmögliche Kompatibilität zu Windows Vista , damit bereits bestehende Anwendungen auch in Zukunft laufen. Für Entwickler bietet Windows 7 viele neue Schnittstellen, um Anwendungen mit umfassenderen Funktionen zu versehen, die dem Endbenutzer eine neue Erfahrung im Umgang mit Software ermöglichen. In dieser TechTalk-Aufzeichnung erklären Oliver Scheer und Peter Kirchner, wie etwa die neue Taskbar genutzt werden kann, indem die…</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_ch9.mp4" expression="full" duration="5364" fileSize="281236620" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_ch9.mp3" expression="full" duration="5364" fileSize="42917496" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_ch9.mp4" expression="full" duration="5364" fileSize="281236620" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_ch9.wma" expression="full" duration="5364" fileSize="43391749" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_ch9.wmv" expression="full" duration="5364" fileSize="368272629" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_2MB_ch9.wmv" expression="full" duration="5364" fileSize="354602341" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_Zune_ch9.wmv" expression="full" duration="5364" fileSize="302599257" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_512_ch9.png" expression="full" duration="5364" type="image/jpeg" medium="image" /><media:content url="http://ss.channel9.msdn.com/ch9/5/5/7/3/0/5/TechTalkWindows71.ism/Manifest" expression="full" duration="5364" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/5/5/7/3/0/5/TechTalkWindows71_ch9.wmv" length="368272629" type="video/x-ms-wmv" /><dc:creator>Jan Schenk</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/kitano/Aufzeichnung-zum-Oktober-TechTalk-Windows-7--ein-berblick-fr-Entwickler-Teil-1/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/503755/Trackback.aspx</trackback:ping><category>app  compat</category><category>betriebssystem</category><category>certified</category><category>dienste</category><category>jumplist</category><category>Kompatibilität</category><category>logo</category><category>OS</category><category>performance</category><category>Security</category><category>sprungliste</category><category>Taskbar</category><category>Windows 7</category></item><item><title>Claims-Based Security, Windows Identity Foundation and Dominick Baier</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_85_ch9.png" border="0" /&gt;I had the chance to do an interview with security expert Dominick Baier. I visited Dominick and talked with him about Claims, Windows Identity Foundation and his StarterSTS Project hosted on Codeplex.&lt;br /&gt;
&lt;br /&gt;
You can contact Dominick via his &lt;a href="http://www.leastprivilege.com/"&gt;blog &lt;/a&gt;and you can get more information about the &lt;a href="http://startersts.codeplex.com"&gt;StarterSTS&lt;/a&gt; on Codeplex.&lt;br /&gt;
&lt;br /&gt;
Enjoy,&lt;br /&gt;
&lt;a href="http://blogs.msdn.com/dparys"&gt;Dariusz&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
I'm sorry about the video quality after 20 minutes, my camera just broke during recording. Yes this sorts of things just happen when they shouldn't.&lt;img src="http://channel9.msdn.com/496889/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Dariusz/Claims-Based-Security-Windows-Identity-Foundation-and-Dominick-Baier/</comments><link>http://channel9.msdn.com/posts/Dariusz/Claims-Based-Security-Windows-Identity-Foundation-and-Dominick-Baier/</link><pubDate>Fri, 09 Oct 2009 05:41:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_ch9.wmv</guid><evnet:views>6171</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/496889/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>I had the chance to do an interview with security expert Dominick Baier. I visited Dominick and talked with him about Claims, Windows Identity Foundation and his StarterSTS Project hosted on Codeplex.&lt;br /&gt;
&lt;br /&gt;
You can contact Dominick via his &lt;a href="http://www.leastprivilege.com/"&gt;blog &lt;/a&gt;and you can get more information about the &lt;a href="http://startersts.codeplex.com"&gt;StarterSTS&lt;/a&gt; on Codeplex.&lt;br /&gt;
&lt;br /&gt;
Enjoy,&lt;br /&gt;
&lt;a href="http://blogs.msdn.com/dparys"&gt;Dariusz&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_ch9.mp4" expression="full" duration="2359" fileSize="335963316" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_ch9.mp3" expression="full" duration="2359" fileSize="18876059" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_ch9.mp4" expression="full" duration="2359" fileSize="335963316" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_ch9.wma" expression="full" duration="2359" fileSize="19089383" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_ch9.wmv" expression="full" duration="2359" fileSize="427142553" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_2MB_ch9.wmv" expression="full" duration="2359" fileSize="284435645" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_Zune_ch9.wmv" expression="full" duration="2359" fileSize="258118533" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_512_ch9.png" expression="full" duration="2359" type="image/jpeg" medium="image" /><media:content url="http://ss.channel9.msdn.com/ch9/9/8/8/6/9/4/dpwif.ism/Manifest" expression="full" duration="2359" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_2MB_ch9.wmv" expression="full" duration="2359" fileSize="284435645" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/9/8/8/6/9/4/dpwif_ch9.wmv" length="427142553" type="video/x-ms-wmv" /><dc:creator>Dariusz Parys</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Dariusz/Claims-Based-Security-Windows-Identity-Foundation-and-Dominick-Baier/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/496889/Trackback.aspx</trackback:ping><category>claims</category><category>CodePlex</category><category>de-de</category><category>Security</category><category>Windows Identity Foundation</category></item><item><title>Anti-XSS Library v3.1: Find, Fix, and Verify Errors</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_85_ch9.png" border="0" /&gt;&lt;p&gt;Anil Revuru (RV) from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security,&lt;/a&gt; gives a demonstration of the new features on the Anti-XSS Library v3.1  including HTML Sanitization which provides new methods to the Anti-XSS class to strip malicious characters or scripts off of HTML and returns safe HTML.&lt;br /&gt;
&lt;br /&gt;
He talks about:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;
    &lt;div&gt;What is Cross-Site Scripting Attack (XSS)&lt;/div&gt;
    &lt;/li&gt;
    &lt;li&gt;
    &lt;div&gt;How to detect Cross Site Scripting Vulnerabilities&lt;/div&gt;
    &lt;/li&gt;
    &lt;li&gt;
    &lt;div&gt;Introduction of Anti-XSS Library&lt;/div&gt;
    &lt;/li&gt;
    &lt;li&gt;
    &lt;div&gt;What’s new in Anti-XSS Library 3.1&lt;/div&gt;
    &lt;/li&gt;
    &lt;li&gt;
    &lt;div&gt;Anti-XSS 3.1 demo&lt;/div&gt;
    &lt;/li&gt;
    &lt;li&gt;
    &lt;div&gt;Security Runtime Engine (SRE)&lt;/div&gt;
    &lt;/li&gt;
    &lt;li&gt;
    &lt;div&gt;SRE Demo&lt;/div&gt;
    &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To learn more about this application and stay up to date on the latest news, read the following blogs from &lt;a href="http://blogs.msdn.com/infosec/archive/2009/09/17/anti-xss-3-1-released.aspx" target="_blank"&gt;Information Security&lt;/a&gt; and previous posts from the &lt;a href="http://blogs.msdn.com/securitytools/archive/tags/Anti-XSS/default.aspx" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/" target="_blank"&gt;Overview of the Anti-XSS Library&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=051ee83c-5ccf-48ed-8463-02f56a6bfc09&amp;amp;displaylang=en" target="_blank"&gt;Download: Microsoft Anti-Cross Site Scripting Library v3.1&lt;/a&gt;&lt;/p&gt;&lt;img src="http://channel9.msdn.com/493696/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Anti-XSS-Library-v31-Find-Fix-and-Verify-Errors/</comments><link>http://channel9.msdn.com/posts/Jossie/Anti-XSS-Library-v31-Find-Fix-and-Verify-Errors/</link><pubDate>Wed, 23 Sep 2009 17:20:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.wmv</guid><evnet:views>4145</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/493696/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;Anil Revuru (RV) from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security,&lt;/a&gt; gives a demonstration of the new features on the Anti-XSS Library v3.1 including HTML Sanitization which provides new methods to the Anti-XSS class to strip malicious characters or scripts off of HTML and returns safe HTML.&lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.mp4" expression="full" duration="1311" fileSize="30406648" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.mp3" expression="full" duration="1311" fileSize="10494270" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.mp4" expression="full" duration="1311" fileSize="30406648" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.wma" expression="full" duration="1311" fileSize="10612095" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.wmv" expression="full" duration="1311" fileSize="44119933" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_2MB_ch9.wmv" expression="full" duration="1311" fileSize="190365309" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_Zune_ch9.wmv" expression="full" duration="1311" fileSize="31639861" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_512_ch9.png" expression="full" duration="1311" type="image/jpeg" medium="image" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.wmv" expression="full" duration="1311" fileSize="44119933" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.wmv" length="44119933" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>5</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Anti-XSS-Library-v31-Find-Fix-and-Verify-Errors/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/493696/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>antixss</category><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category></item><item><title>Connected Information Security Framework: Core Components</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_85_ch9.png" border="0" /&gt;&lt;p&gt;Marius Grigoriu and Vineet Batta, from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security,&lt;/a&gt; talk about the technical components for the first version of &lt;b&gt;C&lt;/b&gt;onnected &lt;b&gt;I&lt;/b&gt;nformation &lt;b&gt;S&lt;/b&gt;ecurity &lt;b&gt;F&lt;/b&gt;ramework (&lt;a href="http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/" target="_blank"&gt;CISF&lt;/a&gt;).  A software development framework comprising of API’s and reusable components that is designed to create bespoke or custom information security and risk management solutions like &lt;a href="http://edge.technet.com/Media/Risk-Tracker/" target="_blank"&gt;Risk Tracker&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Microsoft’s IT Information Security Tools Team designs and develops CISF to “engineer the security delta” meaning as a way to rapidly meet business requirements and create functionality that doesn’t exist or is not yet available in their product range.&lt;br /&gt;
&lt;br /&gt;
They explain the core pieces CISF consists of like: Business Intelligent, Portal, Notification, and others that help build information security applications cheaper, faster, and better &lt;/p&gt;
&lt;p&gt;To learn more about this framework and stay up to date on the latest news, read the following blogs from &lt;a href="http://blogs.msdn.com/infosec/archive/tags/CISF/default.aspx" target="_blank"&gt;Information Security&lt;/a&gt; and previous posts from the  &lt;a href="http://blogs.msdn.com/securitytools/archive/tags/CISF/default.aspx" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog&lt;/p&gt;
&lt;p&gt;To see an overview of what CISF is watch the video: &lt;a href="http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/" target="_blank"&gt;CISF: Build Custom Security Solutions&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;a href="http://cisf.codeplex.com/" target="_blank"&gt;CISF CTP download&lt;/a&gt;&lt;/p&gt;&lt;img src="http://channel9.msdn.com/493725/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Connected-Information-Security-Framework-Core-Components/</comments><link>http://channel9.msdn.com/posts/Jossie/Connected-Information-Security-Framework-Core-Components/</link><pubDate>Wed, 23 Sep 2009 17:19:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.wmv</guid><evnet:views>5856</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/493725/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Marius Grigoriu and Vineet Batta, from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security,&lt;/a&gt; talk about the technical components for the first version of &lt;b&gt;C&lt;/b&gt;onnected &lt;b&gt;I&lt;/b&gt;nformation &lt;b&gt;S&lt;/b&gt;ecurity &lt;b&gt;F&lt;/b&gt;ramework (&lt;a href="http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/"&gt;CISF&lt;/a&gt;). A software development framework comprising of API’s and reusable components that is designed to create bespoke or custom information security and risk management solutions like &lt;a href="http://edge.technet.com/Media/Risk-Tracker/" target="_blank"&gt;Risk Tracker&lt;/a&gt;.</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.mp4" expression="full" duration="1326" fileSize="142845363" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.mp3" expression="full" duration="1326" fileSize="10612355" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.mp4" expression="full" duration="1326" fileSize="142845363" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.wma" expression="full" duration="1326" fileSize="10735265" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.wmv" expression="full" duration="1326" fileSize="192376149" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_2MB_ch9.wmv" expression="full" duration="1326" fileSize="162366459" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_Zune_ch9.wmv" expression="full" duration="1326" fileSize="104040077" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_512_ch9.png" expression="full" duration="1326" type="image/jpeg" medium="image" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.wmv" length="192376149" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Connected-Information-Security-Framework-Core-Components/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/493725/Trackback.aspx</trackback:ping><category>cisf</category><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category></item><item><title>CISF: Build Custom Security Solutions</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_85_ch9.png" border="0" /&gt;Mark Curphey and Marius Grigoriu, from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security,&lt;/a&gt; talk about the release of the first version of &lt;b&gt;C&lt;/b&gt;onnected &lt;b&gt;I&lt;/b&gt;nformation &lt;b&gt;S&lt;/b&gt;ecurity &lt;b&gt;F&lt;/b&gt;ramework (CISF).  A software development framework comprising of API’s and reusable components that is designed to create bespoke or custom information security and risk management solutions like &lt;a href="http://edge.technet.com/Media/Risk-Tracker/" target="_blank"&gt;Risk Tracker&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Microsoft’s IT Information Security Tools Team designs and develops CISF to “engineer the security delta” meaning as a way to rapidly meet business requirements and create functionality that doesn’t exist or is not yet available in their product range.&lt;br /&gt;
&lt;br /&gt;
They explain benefits found on this framework including:
&lt;ul&gt;
    &lt;li&gt;Building information security applications cheaper, faster, and better &lt;/li&gt;
    &lt;li&gt;Migrate applications efficiently and effectively to their products when they become available &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To learn more about this framework and stay up to date on the latest news, read the following blogs from &lt;a href="http://blogs.msdn.com/infosec/archive/tags/CISF/default.aspx" target="_blank"&gt;Information Security&lt;/a&gt; and previous posts from the  &lt;a href="http://blogs.msdn.com/securitytools/archive/tags/CISF/default.aspx" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog. &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://cisf.codeplex.com/" target="_blank"&gt;CISF CTP download&lt;/a&gt; &lt;/p&gt;&lt;img src="http://channel9.msdn.com/492501/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/</comments><link>http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/</link><pubDate>Fri, 18 Sep 2009 03:31:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.wmv</guid><evnet:views>3918</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/492501/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Mark Curphey and Marius Grigoriu, from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security,&lt;/a&gt; talk about the release of the first version of &lt;b&gt;C&lt;/b&gt;onnected &lt;b&gt;I&lt;/b&gt;nformation &lt;b&gt;S&lt;/b&gt;ecurity &lt;b&gt;F&lt;/b&gt;ramework (CISF).  A software development framework comprising of API’s and reusable components that is designed to create bespoke or custom information security and risk management solutions like &lt;a href="http://edge.technet.com/Media/Risk-Tracker/" target="_blank"&gt;Risk Tracker&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.mp4" expression="full" duration="1182" fileSize="102375658" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.mp3" expression="full" duration="1182" fileSize="9464808" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.mp4" expression="full" duration="1182" fileSize="102375658" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.wma" expression="full" duration="1182" fileSize="9575715" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.wmv" expression="full" duration="1182" fileSize="231270127" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_2MB_ch9.wmv" expression="full" duration="1182" fileSize="369989037" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_Zune_ch9.wmv" expression="full" duration="1182" fileSize="128822055" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_512_ch9.png" expression="full" duration="1182" type="image/jpeg" medium="image" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.wmv" length="231270127" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/492501/Trackback.aspx</trackback:ping><category>cisf</category><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category></item><item><title>Expert to Expert: Erik Meijer and Butler Lampson - Abstraction, Security and Embodiment</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/1/9/7/4/8/4/E2EButlerLampson_small_ch9.png" border="0" /&gt;This is a very special episode of &lt;a href="http://channel9.msdn.com/tags/expert-to-expert" target="_blank"&gt;Expert to Expert&lt;/a&gt;. We were very fortunate to get some time with renowned computer scientist and Microsoft Technical Fellow &lt;a href="http://en.wikipedia.org/wiki/Butler_Lampson" target="_blank"&gt;Butler Lampson&lt;/a&gt;. Butler's impact on general purpose computing is profound. Personal computing as it exists today is in part the result of the great work done by Butler over the past 30 years. &lt;br /&gt;
&lt;br /&gt;
Programming language designer and high priest of the lamda calculus &lt;a href="http://research.microsoft.com/en-us/um/people/emeijer/" target="_blank"&gt;Erik Meijer&lt;/a&gt; hosts this episode of E2E and Erik and Butler cover a very wide swath of computing topics. It's simply beautiful and very deep geekiness. In fact, this is one of my favorite Channel 9 conversations of late. I know you will enjoy both the usual &lt;em&gt;real&lt;/em&gt; conversational aspect of this and the depth of historical insight into some of the core aspects and unresolved problems of general purpose personal computing. &lt;br /&gt;
&lt;br /&gt;
Go get some popcorn, stream this into your XBox or Media Center and learn from one of our industry's pioneers who still has a great deal to offer to the world of personal computing. What's Butler working on these days, you wonder? What's top of mind for him as it relates to today's biggest challenges in computing? What does software security really mean? How many levels of software abstraction do we need? Why is data synchronization such a hard problem? What is software embodiment, exactly (Butler will be &lt;a href="http://microsoftpdc.com/Sessions/CL05" target="_blank"&gt;presenting his thinking on software embodiment at PDC09&lt;/a&gt;, as part of the &lt;a href="http://microsoftpdc.com/Sessions/Tags/TechnicalLeaders" target="_blank"&gt;new Technical Leaders track&lt;/a&gt; (something yours truly is responsible for - I hope you plan on attending these very special sessions and if not you will be able to watch them right here on Channel 9))?&lt;br /&gt;
&lt;br /&gt;
Tune in and meet a true legend in our industry. Microsoft is very forunate to have Butler Lampson thinking about some of the hardest problems we face as an industry and ensuring that Microsoft is capable of tackling these challenges in a way that extends the solutions for long term relevance in a changing and unpredictable environment.&lt;img src="http://channel9.msdn.com/484791/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/shows/Going+Deep/E2E-Erik-Meijer-and-Butler-Lampson-Abstraction-Security-Embodiment/</comments><link>http://channel9.msdn.com/shows/Going+Deep/E2E-Erik-Meijer-and-Butler-Lampson-Abstraction-Security-Embodiment/</link><pubDate>Thu, 17 Sep 2009 16:09:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/1/9/7/4/8/4/E2EButlerLampson_ch9.wmv</guid><evnet:views>43021</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/484791/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>This is a very special episode of &lt;a href="http://channel9.msdn.com/tags/expert-to-expert" target="_blank"&gt;Expert to Expert&lt;/a&gt;. We were very fortunate to get some time with renowned computer scientist and Microsoft Technical Fellow &lt;a href="http://en.wikipedia.org/wiki/Butler_Lampson" target="_blank"&gt;Butler Lampson&lt;/a&gt;. Butler's impact on general purpose computing is vast and profound. Personal computing as it exists today is in part the result of the great work done by Butler over the past 30 years. &lt;br /&gt;
&lt;br /&gt;
Programming language designer and high priest of the lamda calculus Erik Meijer hosts this episode and Erik and Butler cover a very wide swath of computing topics. It's simply beautiful and very deep geekiness. In fact, this is one of my favorite Channel 9 conversations of late. I know you will enjoy both the usual &lt;em&gt;real&lt;/em&gt; conversational aspect of this and the depth of historical insight into some of the core aspects and unresolved problems of general purpose personal computing. &lt;br /&gt;
&lt;br /&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/9/7/4/8/4/E2EButlerLampson_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/9/7/4/8/4/E2EButlerLampson_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/7/4/8/4/E2EButlerLampson_ch9.mp4" expression="full" duration="3584" fileSize="457092149" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/7/4/8/4/E2EButlerLampson_ch9.mp3" expression="full" duration="3584" fileSize="28673494" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/7/4/8/4/E2EButlerLampson_ch9.mp4" expression="full" duration="3584" fileSize="457092149" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/1/9/7/4/8/4/E2EButlerLampson_ch9.wma" expression="full" duration="3584" fileSize="28993571" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/1/9/7/4/8/4/E2EButlerLampson_ch9.wmv" expression="full" duration="3584" fileSize="787927755" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/7/4/8/4/E2EButlerLampson_2MB_ch9.wmv" expression="full" duration="3584" fileSize="1408395549" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/7/4/8/4/E2EButlerLampson_Zune_ch9.wmv" expression="full" duration="3584" fileSize="508135683" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/1/9/7/4/8/4/E2EButlerLampson_ch9.wmv" length="787927755" type="video/x-ms-wmv" /><dc:creator>Charles</dc:creator><slash:comments>23</slash:comments><wfw:commentRss>http://channel9.msdn.com/shows/Going+Deep/E2E-Erik-Meijer-and-Butler-Lampson-Abstraction-Security-Embodiment/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/484791/Trackback.aspx</trackback:ping><category>Butler Lampson</category><category>Erik Meijer</category><category>Expert to Expert</category><category>PDC09</category><category>Programming</category><category>Security</category><category>Technical Leaders</category></item><item><title>Glenn Pittaway on SDL</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_small_ch9.png" border="0" /&gt;&lt;p&gt;I'm posting this on behalf of &lt;a href="http://blogs.technet.com/andrew/"&gt;Andrew Fryer &lt;/a&gt;who usually posts to TechNet but today has something developer focused for us:&lt;br /&gt;
&lt;br /&gt;
"Glenn Pittaway the Group Program Manager for the Secure development Lifecycle (SDL) talks about the past present and future of SDL.  The SDL methodology is at the core of all development work that has an internet facing element (i.e. virtually everything!) at Microsoft.   You might argue that this gives this gives Microsoft developers an edge over the competition as they can write more secure code more quickly, however these same &lt;a href="http://msdn.microsoft.com/en-us/security/cc448177.aspx"&gt;SDL resources&lt;/a&gt; are also publicly available so you can adopt the same approach in your organisation."&lt;/p&gt;&lt;img src="http://channel9.msdn.com/485096/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/mike+ormond/Glenn-Pittaway-on-SDL/</comments><link>http://channel9.msdn.com/posts/mike+ormond/Glenn-Pittaway-on-SDL/</link><pubDate>Fri, 14 Aug 2009 07:30:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_2MB_ch9.wmv</guid><evnet:views>3873</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/485096/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>I'm posting this on behalf of Andrew Fryer who usually posts to TechNet but today has something developer focused for us:

"Glenn Pittaway the Group Program Manager for the Secure development Lifecycle (SDL) talks about the past present and future of SDL.  The SDL methodology is at the core of all&amp;#8230;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_ch9.mp4" expression="full" duration="715" fileSize="37051924" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_ch9.mp3" expression="full" duration="715" fileSize="5727174" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_ch9.mp4" expression="full" duration="715" fileSize="37051924" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_ch9.wma" expression="full" duration="715" fileSize="5793685" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_2MB_ch9.wmv" expression="full" duration="715" fileSize="32052173" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_2MB_ch9.wmv" expression="full" duration="715" fileSize="32052173" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_Zune_ch9.wmv" expression="full" duration="715" fileSize="38223523" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_2MB_ch9.wmv" length="32052173" type="video/x-ms-wmv" /><dc:creator>Mike Ormond</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/mike+ormond/Glenn-Pittaway-on-SDL/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/485096/Trackback.aspx</trackback:ping><category>en-GB</category><category>SDL</category><category>Security</category><category>Team System</category><category>TFS2010</category><category>Trustworthy Computing</category><category>UKDevTeam</category></item><item><title>Internet Explorer 8 named most secure browser [Internet Explorer 8 named most secure browser]</title><description>&lt;img src="http://channel9.msdn.com/Link/8296ecd0-6bf2-486b-859d-375b1361543b/" border="0" /&gt;Yes, you read that right, Internet Explorer was named by NSS Labs the Most Secure Browser. Giorgio Sardo, our IE Evangelist, fittingly has &lt;a href="http://blogs.msdn.com/giorgio/archive/2009/08/12/most-secure-browser-internet-explorer-8.aspx"&gt;all the details&lt;/a&gt;.&lt;p&gt;in reply to &lt;a href='http://channel9.msdn.com/posts/ContinuumNews/Internet-Explorer-8-named-most-secure-browser/'&gt;Internet Explorer 8 named most secure browser&lt;/a&gt;&lt;/p&gt;&lt;img src="http://channel9.msdn.com/485040/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/ContinuumNews/Internet-Explorer-8-named-most-secure-browser/</comments><link>http://channel9.msdn.com/posts/ContinuumNews/Internet-Explorer-8-named-most-secure-browser/</link><pubDate>Thu, 13 Aug 2009 21:34:00 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/ContinuumNews/Internet-Explorer-8-named-most-secure-browser/</guid><evnet:views>2422</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/485040/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Yes, you read that right, Internet Explorer was named by NSS Labs the Most Secure Browser. Giorgio Sardo, our IE Evangelist, fittingly has all the details.in reply to Internet Explorer 8 named most secure browser</evnet:previewtext><media:thumbnail url="http://channel9.msdn.com/Link/e311e88d-bba4-4c44-8a8b-8771d73779ba/" height="240" width="320" /><media:thumbnail url="http://channel9.msdn.com/Link/8296ecd0-6bf2-486b-859d-375b1361543b/" height="64" width="85" /><dc:creator>Adam Kinney</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/ContinuumNews/Internet-Explorer-8-named-most-secure-browser/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/485040/Trackback.aspx</trackback:ping><category>Internet Explorer</category><category>Security</category><category>Web</category></item><item><title>Inside the Active Template Library (ATL) Security Update</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/7/4/1/1/8/4/InsideATLSecurityUpdate_small_ch9.png" border="0" /&gt;&lt;p&gt;Today, Microsoft announced the details of an out-of-band &lt;a href="http://www.microsoft.com/security/atl.aspx" target="_blank"&gt;security update that impacts ATL&lt;/a&gt; components and controls (like ActiveX controls, for example) -&amp;gt; &lt;i&gt;Developers who have built controls using vulnerable versions of ATL should take immediate action to review and identify any vulnerabilities, modify and recompile their affected controls and components using the updated versions of ATL and finally distribute a non-vulnerable version of the controls and components to their customers&lt;/i&gt;.&lt;/p&gt;
&lt;p&gt;Here, Damien Watkins from the VC++ team and Damian Hasse and Jonathan Ness from MSRC Engineering review the steps to identify and address vulnerable controls and components. Of course, being a Channel 9 interview, we dig into various aspects of the problem without veering away from the goal here: &lt;i&gt;helping you understand the exact issues with this vulnerability&lt;/i&gt;. If you own a component or control that uses ATL, then you will know what you need to do to prevent a possible attack. &lt;/p&gt;
&lt;p&gt; &lt;br /&gt;
Please visit the URLs below as soon as possible for detailed information on this vulnerability.&lt;/p&gt;
&lt;p&gt;Resources discussed in this video are available on MSDN: &lt;a href="http://go.microsoft.com/?linkid=9674481"&gt;Active Template Library Security Update and Developers&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
Detailed technical information on this security release for ATL developers: &lt;a href="http://blogs.technet.com/srd/archive/2009/07/28/overview-of-the-out-of-band-release.aspx"&gt;http://blogs.technet.com/srd/archive/2009/07/28/overview-of-the-out-of-band-release.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Additional information on this security release is available on the &lt;a href="http://go.microsoft.com/?linkid=9674666"&gt;Security Research &amp;amp; Defense blog&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Overview with background + table of links:  &lt;a href="http://blogs.technet.com/srd/archive/2009/07/28/overview-of-the-out-of-band-release.aspx"&gt;http://blogs.technet.com/srd/archive/2009/07/28/overview-of-the-out-of-band-release.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;IE mitigation explanation:  &lt;a href="http://blogs.technet.com/srd/archive/2009/07/28/internet-explorer-mitigations-for-atl-data-stream-vulnerabilities.aspx"&gt;http://blogs.technet.com/srd/archive/2009/07/28/internet-explorer-mitigations-for-atl-data-stream-vulnerabilities.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Deep dive for developers:  &lt;a href="http://blogs.technet.com/srd/archive/2009/07/28/atl-vulnerability-developer-deep-dive.aspx"&gt;http://blogs.technet.com/srd/archive/2009/07/28/atl-vulnerability-developer-deep-dive.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;How msvidctl.dll is related:  &lt;a href="http://blogs.technet.com/srd/archive/2009/07/28/msvidctl-ms09-032-and-the-atl-vulnerability.aspx"&gt;http://blogs.technet.com/srd/archive/2009/07/28/msvidctl-ms09-032-and-the-atl-vulnerability.aspx&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Michael Howard's perspective on this issue: &lt;a href="http://blogs.msdn.com/sdl/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx"&gt;http://blogs.msdn.com/sdl/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/07/28/overview-of-the-out-of-band-release.aspx"&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://channel9.msdn.com/481147/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Charles/Out-of-Band-Inside-the-ATL-Security-Update/</comments><link>http://channel9.msdn.com/posts/Charles/Out-of-Band-Inside-the-ATL-Security-Update/</link><pubDate>Tue, 28 Jul 2009 17:02:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/7/4/1/1/8/4/InsideATLSecurityUpdate_ch9.wmv</guid><evnet:views>322699</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/481147/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;Today, Microsoft announced the details of an out-of-band &lt;a href="http://www.microsoft.com/security/atl.aspx" target="_blank"&gt;security update that impacts ATL&lt;/a&gt; components and controls (like ActiveX controls, for example) -&amp;gt; &lt;i&gt;Developers who have built controls using vulnerable versions of ATL should take immediate action to review and identify any vulnerabilities, modify and recompile their affected controls and components using the updated versions of ATL and finally distribute a non-vulnerable version of the controls and components to their customers&lt;/i&gt;.&lt;br /&gt;
&lt;br /&gt;
Here, Damien Watkins from the VC++ team and Damian Hasse and Jonathan Ness from MSRC Engineering review the steps to identify and address vulnerable controls and components. Of course, being a Channel 9 interview, we dig into various aspects of the problem without veering away from the goal here: helping you understand the exact issues with this vulnerability. If you own a component or control that uses ATL, then you will know what you need to do to prevent a possible attack. &lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/4/1/1/8/4/InsideATLSecurityUpdate_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/4/1/1/8/4/InsideATLSecurityUpdate_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/4/1/1/8/4/InsideATLSecurityUpdate_ch9.mp4" expression="full" duration="2057" fileSize="260973247" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/4/1/1/8/4/InsideATLSecurityUpdate_ch9.mp3" expression="full" duration="2057" fileSize="16461580" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/4/1/1/8/4/InsideATLSecurityUpdate_ch9.mp4" expression="full" duration="2057" fileSize="260973247" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/4/1/1/8/4/InsideATLSecurityUpdate_ch9.wma" expression="full" duration="2057" fileSize="16647137" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/4/1/1/8/4/InsideATLSecurityUpdate_ch9.wmv" expression="full" duration="2057" fileSize="451666383" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/4/1/1/8/4/InsideATLSecurityUpdate_2MB_ch9.wmv" expression="full" duration="2057" fileSize="808522387" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/4/1/1/8/4/InsideATLSecurityUpdate_Zune_ch9.wmv" expression="full" duration="2057" fileSize="292210311" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/4/1/1/8/4/InsideATLSecurityUpdate_ch9.wmv" length="451666383" type="video/x-ms-wmv" /><dc:creator>Charles</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Charles/Out-of-Band-Inside-the-ATL-Security-Update/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/481147/Trackback.aspx</trackback:ping><category>ATL</category><category>C++</category><category>Programming</category><category>Security</category><category>Trustworthy Computing</category></item><item><title>SDL-LOB Phase 3: Implementation</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_small_ch9.png" border="0" /&gt;&lt;span id="ctl00_MainPlaceHolder_Starter_BodyLabel"&gt;The third phase of the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank"&gt;&lt;span&gt;SDL-LOB &lt;/span&gt;&lt;/a&gt;(Security Development Lifecycle for Line-of-Business applications) includes &lt;span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd831972.aspx" target="_blank"&gt;&lt;span&gt;Implementation&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Eugene Siu, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes some of the security pillars that are key in this phase, including code review, authentication, authorization and configuration settings. Also, he explains how penetration testing can complement your code review when bulletproofing your code against vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
Read more on the Implementation Phase &lt;a href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx" target="_blank"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;/span&gt;&lt;img src="http://channel9.msdn.com/479451/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/SDL-LOB-Phase-3-Implementation/</comments><link>http://channel9.msdn.com/posts/Jossie/SDL-LOB-Phase-3-Implementation/</link><pubDate>Mon, 20 Jul 2009 17:54:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wmv</guid><evnet:views>5107</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/479451/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;span id="ctl00_MainPlaceHolder_Starter_BodyLabel"&gt;The third phase of the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank"&gt;&lt;span&gt;SDL-LOB &lt;/span&gt;&lt;/a&gt;(Security Development Lifecycle for Line-of-Business applications) includes &lt;span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd831972.aspx" target="_blank"&gt;&lt;span&gt;Implementation&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Eugene Siu, from Microsoft Information Security, describes some of the security pillars that are key in this phase, including code review, authentication, authorization and configuration settings. Also, he explains how penetration testing can complement your code review when bulletproofing your code against vulnerabilities.&lt;/span&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp4" expression="full" duration="1099" fileSize="81603875" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp3" expression="full" duration="1099" fileSize="8798169" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp4" expression="full" duration="1099" fileSize="81603875" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wma" expression="full" duration="1099" fileSize="17803689" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wmv" expression="full" duration="1099" fileSize="154844037" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_2MB_ch9.wmv" expression="full" duration="1099" fileSize="134509761" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_Zune_ch9.wmv" expression="full" duration="1099" fileSize="97484017" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wmv" length="154844037" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/SDL-LOB-Phase-3-Implementation/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/479451/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>development</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category></item><item><title>Anti-XSS 3.0 Released</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_small_ch9.png" border="0" /&gt;&lt;p&gt;Vineet Batta and Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, talk about the release of the new version of the Anti-XSS library, which is designed to encode output to help developers protect their ASP.NET web-based applications from cross-site scripting attacks.&lt;br /&gt;
&lt;br /&gt;
They explain the new features and benefits found on version 3.0, including:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Extended white list &lt;/li&gt;
    &lt;li&gt;Better performance &lt;/li&gt;
    &lt;li&gt;MSDN Style Help documentation &lt;/li&gt;
    &lt;li&gt;Marked Anti-XSS Output &lt;/li&gt;
    &lt;li&gt;Security Runtime Engine (SRE) &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To learn more about this library read the following blogs from the &lt;a href="http://blogs.msdn.com/securitytools/archive/tags/Anti-XSS/default.aspx" target="_blank"&gt;Security Tools Team blog&lt;/a&gt; and previous &lt;a href="http://blogs.msdn.com/cisg/archive/tags/Anti-XSS/default.aspx" target="_blank"&gt;posts&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://channel9.msdn.com/478820/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/</comments><link>http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/</link><pubDate>Wed, 15 Jul 2009 16:12:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv</guid><evnet:views>6313</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/478820/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Vineet Batta and Anil Revuru (RV), from Microsoft Information Security, talk about the release of the new version of the Anti-XSS library, which is designed to encode output to help developers protect their ASP.NET web-based applications from cross-site scripting attacks. &lt;br /&gt;
&lt;br /&gt;
They explain the new features and benefits found on version 3.0, including: &lt;br /&gt;
&lt;ul&gt;
    &lt;li&gt;Extended white list &lt;/li&gt;
    &lt;li&gt;Better performance &lt;/li&gt;
    &lt;li&gt;MSDN Style Help documentation &lt;/li&gt;
    &lt;li&gt;Marked Anti-XSS Output &lt;/li&gt;
    &lt;li&gt;Security Runtime Engine (SRE) &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt; &lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp4" expression="full" duration="1055" fileSize="79917703" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp3" expression="full" duration="1055" fileSize="8447064" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp4" expression="full" duration="1055" fileSize="79917703" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.wma" expression="full" duration="1055" fileSize="17085733" type="audio/x-ms-wma" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv" expression="full" duration="1055" fileSize="47180833" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_Zune_ch9.wmv" expression="full" duration="1055" fileSize="103371753" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv" expression="full" duration="1055" fileSize="47180833" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv" length="47180833" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/478820/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>antixss</category><category>information security</category><category>infosec</category><category>ist</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>Tools</category></item><item><title>Patrice Godefroid - Automated Whitebox Fuzz Testing with SAGE</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_small_ch9.png" border="0" /&gt;&lt;a href="http://research.microsoft.com/en-us/um/people/pg/"&gt;Patrice Godefroid&lt;/a&gt; gives an overview of &lt;a href="http://research.microsoft.com/en-us/um/people/pg/public_psfiles/ndss2008.pdf"&gt;Automated Whitebox Fuzz Testing&lt;/a&gt;, a powerful testing technique applied at Microsoft through a tool called SAGE. Listen how he is working with the SAGE team to 'eradicate all buffer overrun bugs' in Windows... &lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
    &lt;li&gt;Read more in &lt;a href="http://research.microsoft.com/en-us/um/people/pg/public_psfiles/ndss2008.pdf"&gt;this paper&lt;/a&gt; or &lt;a href="http://research.microsoft.com/en-us/um/people/pg/public_psfiles/talk-spin2009.pdf"&gt;this slide deck&lt;/a&gt;. &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;i&gt;The &lt;/i&gt;&lt;a href="http://research.microsoft.com/rise"&gt;&lt;i&gt;Research in Software Engineering team&lt;/i&gt;&lt;/a&gt;&lt;i&gt; (RiSE) coordinates Microsoft's research in Software Engineering in Redmond, USA.&lt;/i&gt;&lt;/p&gt;&lt;img src="http://channel9.msdn.com/478581/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Peli/Automated-Whitebox-Fuzz-Testing-with-SAGE/</comments><link>http://channel9.msdn.com/posts/Peli/Automated-Whitebox-Fuzz-Testing-with-SAGE/</link><pubDate>Tue, 14 Jul 2009 18:29:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_ch9.wmv</guid><evnet:views>50206</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/478581/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Patrice Godefroid gives an overview of Automated Whitebox Fuzz Testing, a powerful testing technique applied at Microsoft through a tool called SAGE. Listen how he is working with the SAGE team to 'eradicate all buffer overrun bugs' in Windows...</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_ch9.mp4" expression="full" duration="644" fileSize="63596831" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_ch9.mp3" expression="full" duration="644" fileSize="5159270" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_ch9.mp4" expression="full" duration="644" fileSize="63596831" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_ch9.wma" expression="full" duration="644" fileSize="10443889" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_ch9.wmv" expression="full" duration="644" fileSize="91145307" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_2MB_ch9.wmv" expression="full" duration="644" fileSize="200217293" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_Zune_ch9.wmv" expression="full" duration="644" fileSize="91049287" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_2MB_ch9.wmv" expression="full" duration="644" fileSize="200217293" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/8/5/8/7/4/sageautomatedwhiteboxfuzztesting_ch9.wmv" length="91145307" type="video/x-ms-wmv" /><dc:creator>Peli de Halleux</dc:creator><slash:comments>4</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Peli/Automated-Whitebox-Fuzz-Testing-with-SAGE/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/478581/Trackback.aspx</trackback:ping><category>fuzzing</category><category>Microsoft Research</category><category>rise</category><category>SAGE</category><category>Security</category><category>Testing</category></item><item><title>Silverlight 2 Security</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_small_ch9.png" border="0" /&gt;The usage of Silverlight to provide users a rich internet experience continues to increase. As it becomes a key element on our web applications, it is good to keep in mind that it still runs code on the user's machine.&lt;br /&gt;
&lt;br /&gt;
That is why Maqbool Malik, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes some key features added on the second version of Silverlight to enhance security.&lt;br /&gt;
&lt;br /&gt;
Among the features discussed, Maqbool talks about XAP files, cross-domain policy files, HTML access, etc.&lt;img src="http://channel9.msdn.com/477261/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Silverlight-20-Security/</comments><link>http://channel9.msdn.com/posts/Jossie/Silverlight-20-Security/</link><pubDate>Tue, 14 Jul 2009 00:43:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.wmv</guid><evnet:views>7419</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477261/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>The usage of Silverlight to provide users a rich internet experience continues to increase. As it becomes a key element on our web applications, it is good to keep in mind that it still runs code on the user's machine.&lt;br /&gt;
&lt;br /&gt;
That is why Maqbool Malik, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes some key features added on the second version of Silverlight to enhance security.&lt;br /&gt;
&lt;br /&gt;
Among the features discussed, Maqbool talks about XAP files, cross-domain policy files, HTML access, etc.</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.mp4" expression="full" duration="1120" fileSize="110340362" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.mp3" expression="full" duration="1120" fileSize="8961987" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.mp4" expression="full" duration="1120" fileSize="110340362" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.wma" expression="full" duration="1120" fileSize="18134129" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.wmv" expression="full" duration="1120" fileSize="158924157" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_2MB_ch9.wmv" expression="full" duration="1120" fileSize="136994891" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_Zune_ch9.wmv" expression="full" duration="1120" fileSize="145052137" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.wmv" length="158924157" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Silverlight-20-Security/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/477261/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>Security</category><category>Silverlight 2</category></item><item><title>Threat Modeling LOB Applications with TAM 3.0</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_small_ch9.png" border="0" /&gt;&lt;p&gt;Andrew Law, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, walks us through the creation of a threat model for a line-of-business application using the Threat Analysis &amp;amp; Modeling tool version 3.0. This screencast includes the definition and purpose of a threat model as well as its alignment with the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank"&gt;SDL-LOB&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;Threat Model ownership is discussed as well as the use of the central repository, common task list and how to leverage them to automatically generate threats.&lt;/p&gt;
&lt;p&gt;Learn more on the &lt;a href="http://msdn.microsoft.com/en-us/security/aa570413.aspx" target="_blank"&gt;Threat Modeling&lt;/a&gt; site &amp;amp; &lt;a href="http://blogs.msdn.com/securitytools" target="_blank"&gt;Information Security Tools&lt;/a&gt; blog.&lt;/p&gt;&lt;img src="http://channel9.msdn.com/477063/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30/</comments><link>http://channel9.msdn.com/posts/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30/</link><pubDate>Mon, 06 Jul 2009 22:38:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wmv</guid><evnet:views>3316</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477063/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;Andrew Law, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, walks us through the creation of a threat model for a line-of-business application using the Threat Analysis &amp;amp; Modeling tool version 3.0. This screencast includes the definition and purpose of a threat model as well as its alignment with the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank"&gt;SDL-LOB&lt;/a&gt;. &lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp4" expression="full" duration="2925" fileSize="77895311" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp3" expression="full" duration="2925" fileSize="23406707" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp4" expression="full" duration="2925" fileSize="77895311" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wma" expression="full" duration="2925" fileSize="47320993" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wmv" expression="full" duration="2925" fileSize="127654993" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_2MB_ch9.wmv" expression="full" duration="2925" fileSize="132391501" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_Zune_ch9.wmv" expression="full" duration="2925" fileSize="97750973" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wmv" length="127654993" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/477063/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>tam</category><category>threat modeling</category><category>Tools</category></item><item><title>SQL Detect</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_small_ch9.png" border="0" /&gt;SQL Detect is a SQL injection filter in real-time mode. When a request happens in the application the tool applies different heuristics to the data and tries to identify the attack. After the request is validated it proceeds.&lt;br /&gt;
&lt;br /&gt;
Maqbool Malik, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes how this is one of the tools to be included in the to-be-released Security Runtime Engine (SRE).&lt;br /&gt;
&lt;br /&gt;
To learn more about their tools, read the &lt;a href="http://blogs.msdn.com/securitytools/" target="_blank"&gt;Information Security Tools&lt;/a&gt; blog.&lt;br /&gt;
&lt;br /&gt;&lt;img src="http://channel9.msdn.com/477052/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/SQL-Detect/</comments><link>http://channel9.msdn.com/posts/Jossie/SQL-Detect/</link><pubDate>Mon, 06 Jul 2009 19:41:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wmv</guid><evnet:views>6093</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477052/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>SQL Detect is a SQL injection filter in real-time mode. When a request happens in the application the tool applies different heuristics to the data and tries to identify the attack. After the request is validated it proceeds.&lt;br /&gt;
&lt;br /&gt;
Maqbool Malik, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes how this is one of the tools to be included in the to-be-released Security Runtime Engine (SRE).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp4" expression="full" duration="734" fileSize="45367124" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp3" expression="full" duration="734" fileSize="5880981" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp4" expression="full" duration="734" fileSize="45367124" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wma" expression="full" duration="734" fileSize="11897825" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wmv" expression="full" duration="734" fileSize="95065847" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_2MB_ch9.wmv" expression="full" duration="734" fileSize="89893228" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_Zune_ch9.wmv" expression="full" duration="734" fileSize="54601827" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wmv" length="95065847" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/SQL-Detect/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/477052/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>sre</category><category>Tools</category></item><item><title>Microsoft Security Development Lifecycle Template</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_small_ch9.png" border="0" /&gt;The &lt;a href="http://msdn.microsoft.com/en-us/security/cc448177.aspx"&gt;Microsoft SDL Process Template&lt;/a&gt; is a new process template for &lt;a href="http://msdn.microsoft.com/en-us/teamsystem/default.aspx"&gt;Visual Studio Team System&lt;/a&gt; intended to ease adoption of the Microsoft Security Development Lifecycle. The template integrates the SDL directly into your software development environment, provides auditable security requirements and status, and demonstrates security return on investment. &lt;br /&gt;
&lt;br /&gt;
I stopped by the Microsoft Security group and spoke with Jeremy Dallman about the SDL, and what it means for developers. The Process Template is free and can be downloaded from &lt;a href="http://www.microsoft.com/SDL/"&gt;www.microsoft.com/SDL/&lt;/a&gt;.&lt;img src="http://channel9.msdn.com/476309/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/LarryLarsen/Microsoft-Security-Development-Lifecycle-Templates/</comments><link>http://channel9.msdn.com/posts/LarryLarsen/Microsoft-Security-Development-Lifecycle-Templates/</link><pubDate>Thu, 02 Jul 2009 10:45:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_ch9.wmv</guid><evnet:views>52444</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/476309/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>The Microsoft SDL Process Template is a new process template for Visual Studio Team System intended to ease adoption of the Microsoft Security Development Lifecycle. The template integrates the SDL directly into your software development environment, provides auditable security requirements and&amp;#8230;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_ch9.mp4" expression="full" duration="837" fileSize="82472100" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_ch9.mp3" expression="full" duration="837" fileSize="6699764" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_ch9.mp4" expression="full" duration="837" fileSize="82472100" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_ch9.wma" expression="full" duration="837" fileSize="13559037" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_ch9.wmv" expression="full" duration="837" fileSize="118778465" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_2MB_ch9.wmv" expression="full" duration="837" fileSize="480089086" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_Zune_ch9.wmv" expression="full" duration="837" fileSize="118794445" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_ch9.wmv" length="118778465" type="video/x-ms-wmv" /><dc:creator>Larry Larsen</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/LarryLarsen/Microsoft-Security-Development-Lifecycle-Templates/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/476309/Trackback.aspx</trackback:ping><category>SDL</category><category>Security</category><category>Visual Studio Team System</category></item><item><title>Securing REST ful services</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/5/2/1/6/7/4/SecuringRestWS_small_ch9.png" border="0" /&gt;&lt;p&gt;REST is an acronym for Represntational state transfer, REST defines an architectural style based on a set of constraints for building things the “Web” way. &lt;/p&gt;
&lt;p&gt;In this screen cast I will demo how to secure a restful web service using WeServicebHost2Factory and Request Interceptors in WCF Rest Starter Kit. i will implement both Basic Authentication Request Interceptor and also Authorization Header token based authentication.&lt;/p&gt;
&lt;p&gt;The demo code is posted here - Code – &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://cid-0666e397c5ca74dd.skydrive.live.com/self.aspx/Screencast/ProjectService.zip"&gt;http://cid-0666e397c5ca74dd.skydrive.live.com/self.aspx/Screencast/ProjectService.zip&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Previous Screencast - &lt;a href="http://channel9.msdn.com/posts/ashishjaiman/WCF-35-RESTful-web-service/"&gt;http://channel9.msdn.com/posts/ashishjaiman/WCF-35-RESTful-web-service/&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Other resources – &lt;br /&gt;
&lt;a href="http://aspnet.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=24644"&gt;http://aspnet.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=24644&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://msdn.microsoft.com/en-us/netframework/cc950529.aspx"&gt;http://msdn.microsoft.com/en-us/netframework/cc950529.aspx&lt;/a&gt;&lt;/p&gt;&lt;img src="http://channel9.msdn.com/476125/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/ashishjaiman/Securing-REST-ful-services/</comments><link>http://channel9.msdn.com/posts/ashishjaiman/Securing-REST-ful-services/</link><pubDate>Tue, 30 Jun 2009 03:02:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/5/2/1/6/7/4/SecuringRestWS_2MB_ch9.wmv</guid><evnet:views>3089</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/476125/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>REST is an acronym for Represntational state transfer, REST defines an architectural style based on a set of constraints for building things the “Web” way. In this screen cast I will demo how to secure a restful web service using WeServicebHost2Factory and Request Interceptors in WCF Rest Starter Kit. i will implement both Basic Authentication Request Interceptor and also Authorization Header token based authentication. The demo code is posted here - Code – &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://cid-0666e397c5ca74dd.skydrive.live.com/self.aspx/Screencast/ProjectService.zip"&gt;http://cid-0666e397c5ca74dd.skydrive.live.com/self.aspx/Screencast/ProjectService.zip&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
Previous Screencast - &lt;a href="http://channel9.msdn.com/posts/ashishjaiman/WCF-35-RESTful-web-service/"&gt;http://channel9.msdn.com/posts/ashishjaiman/WCF-35-RESTful-web-service/&lt;/a&gt;  &lt;br /&gt;
&lt;br /&gt;
Other resources – &lt;a href="http://aspnet.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=24644http://msdn.microsoft.com/en-us/netframework/cc950529.aspx"&gt;http://aspnet.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=24644http://msdn.microsoft.com/en-us/netframework/cc950529.aspx&lt;/a&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/2/1/6/7/4/SecuringRestWS_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/2/1/6/7/4/SecuringRestWS_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/2/1/6/7/4/SecuringRestWS_ch9.mp4" expression="full" duration="1266" fileSize="29573840" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/2/1/6/7/4/SecuringRestWS_ch9.mp3" expression="full" duration="1266" fileSize="10130821" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/2/1/6/7/4/SecuringRestWS_ch9.mp4" expression="full" duration="1266" fileSize="29573840" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/2/1/6/7/4/SecuringRestWS_ch9.wma" expression="full" duration="1266" fileSize="20483257" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/2/1/6/7/4/SecuringRestWS_2MB_ch9.wmv" expression="full" duration="1266" fileSize="37791041" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/2/1/6/7/4/SecuringRestWS_2MB_ch9.wmv" expression="full" duration="1266" fileSize="37791041" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/2/1/6/7/4/SecuringRestWS_Zune_ch9.wmv" expression="full" duration="1266" fileSize="29229019" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/2/1/6/7/4/SecuringRestWS_2MB_ch9.wmv" length="37791041" type="video/x-ms-wmv" /><dc:creator>ashishjaiman</dc:creator><slash:comments>3</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/ashishjaiman/Securing-REST-ful-services/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/476125/Trackback.aspx</trackback:ping><category>REST</category><category>REST Starter Kit</category><category>Security</category><category>WCF</category></item><item><title>Architecture Behind CAT.NET</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_small_ch9.png" border="0" /&gt;&lt;p&gt;Ben Livshits, from Microsoft Research, talks about the architecture behind &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&amp;amp;displaylang=en" target="_blank"&gt;CAT.NET&lt;/a&gt;, which is a static analysis tool on Visual Studio that helps find vulnerabilities like SQL Injection, CSRF,  XSS among others, within managed code. &lt;br /&gt;
&lt;br /&gt;
Ben’s knowledge on static and dynamic dataflow analysis made him a key contributor on the creation of CAT.NET. He walks us through different examples of how the data analysis happens depending on complexity and explains how precision varies. &lt;br /&gt;
&lt;br /&gt;
Learn more about &lt;a href="http://blogs.msdn.com/securitytools/default.aspx" target="_blank"&gt;Microsoft Information Security Tools&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.msinfosec.com"&gt;www.msinfosec.com&lt;/a&gt; &lt;/p&gt;&lt;img src="http://channel9.msdn.com/476042/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Architecture-behind-CATNET/</comments><link>http://channel9.msdn.com/posts/Jossie/Architecture-behind-CATNET/</link><pubDate>Mon, 29 Jun 2009 22:24:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wmv</guid><evnet:views>3026</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/476042/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Ben Livshits, from Microsoft Research, talks about the architecture behind CAT.NET, which is a static analysis tool on Visual Studio that helps find vulnerabilities like SQL Injection, CSRF,  XSS among others, within managed code.   &lt;br /&gt;
&lt;br /&gt;
Ben’s knowledge on static and dynamic dataflow analysis made him a key contributor on the creation of CAT.NET. He walks us through different examples of how the data analysis happens depending on complexity and explains how precision varies.   Learn more about Microsoft Information Security Tools.</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp4" expression="full" duration="1067" fileSize="77800586" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp3" expression="full" duration="1067" fileSize="8540072" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp4" expression="full" duration="1067" fileSize="77800586" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wma" expression="full" duration="1067" fileSize="17268977" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wmv" expression="full" duration="1067" fileSize="150763845" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_2MB_ch9.wmv" expression="full" duration="1067" fileSize="130500881" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_Zune_ch9.wmv" expression="full" duration="1067" fileSize="90075825" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wmv" length="150763845" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Architecture-behind-CATNET/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/476042/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>cat.net</category><category>information security</category><category>infosec</category><category>LOB</category><category>rise</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>Tools</category></item></channel></rss>