<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://weblogs.asp.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>A Blog for Graymad</title><link>http://weblogs.asp.net/gad/default.aspx</link><description>Musings about ASP.NET and more...by G. Andrew Duthie</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Have a fling!</title><link>http://weblogs.asp.net/gad/archive/2004/08/11/213143.aspx</link><pubDate>Thu, 12 Aug 2004 01:37:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:213143</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=213143</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/08/11/213143.aspx#comments</comments><description>&lt;div class="Section1"&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&lt;a href="http://www.trebuchet.com/" target="_blank"&gt;This&lt;/a&gt; is way cool&amp;hellip;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;[via &lt;a href="http://weblogs.asp.net/ericgu/archive/2004/08/10/212009.aspx" target="_blank"&gt;Eric Gunnerson's C# Compendium&lt;/a&gt;]&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/div&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=213143" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/Musings/default.aspx">Musings</category></item><item><title>Community Server :: Forums</title><link>http://weblogs.asp.net/gad/archive/2004/07/31/202999.aspx</link><pubDate>Sat, 31 Jul 2004 13:31:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:202999</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=202999</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/07/31/202999.aspx#comments</comments><description>&lt;div class="Section1"&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;Just announced by Rob Howard of &lt;a href="http://www.telligentsystems.com/" target="_blank"&gt;Telligent Systems&lt;/a&gt; (and former caching guru from the ASP.NET team at Microsoft):&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'&gt; &lt;div&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;One of the largest Microsoft Open Source projects&amp;nbsp; (previously known as ASP.NET Forums) &lt;a href="http://www.telligentsystems.com/Solutions/Forums/" title="http://www.telligentsystems.com/Solutions/Forums/"&gt;Community Server :: Forums&lt;/a&gt; has just been released!&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;More details here:&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;&lt;a href="http://forums.asp.net/Forums/ShowPost.aspx?PostID=457530#457530" title="http://forums.asp.net/Forums/ShowPost.aspx?PostID=457530#457530"&gt;http://forums.asp.net/Forums/ShowPost.aspx?PostID=457530#457530&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;A few tidbits...&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;ul type="disc"&gt; &lt;li class="MsoNormal" style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; mso-list:l1 level1 lfo3'&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;over 150 compiled server controls&lt;/span&gt;&lt;/font&gt;&lt;/li&gt; &lt;li class="MsoNormal" style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; mso-list:l1 level1 lfo3'&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;hundreds of thousands of lines of source code (C#) included&lt;/span&gt;&lt;/font&gt;&lt;/li&gt; &lt;li class="MsoNormal" style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; mso-list:l1 level1 lfo3'&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;localized in over 10 languages&lt;/span&gt;&lt;/font&gt;&lt;/li&gt; &lt;li class="MsoNormal" style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; mso-list:l1 level1 lfo3'&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;designed to run everything from small single server sites to large multi-server web farms, and the discussion&amp;nbsp;platform used by sites such as &lt;a href="http://channel9.msdn.com" title="http://channel9.msdn.com"&gt;http://channel9.msdn.com&lt;/a&gt;, &lt;a href="http://forums.xbox.com" title="http://forums.xbox.com"&gt;http://forums.xbox.com&lt;/a&gt;, and &lt;a href="http://www.asp.net/forums" title="http://www.asp.net/forums"&gt;http://www.asp.net/forums&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;Enjoy :)&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/div&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&lt;img border="0" width="1" height="1" id="_x0000_i1025" src="http://weblogs.asp.net/rhoward/aggbug/200953.aspx" /&gt;[&lt;a href="http://weblogs.asp.net/rhoward/archive/2004/07/29/200953.aspx"&gt;Rob Howard's Blog&lt;/a&gt;]&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=202999" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/ASP.NET+_2F00_+Coding/default.aspx">ASP.NET / Coding</category><category domain="http://weblogs.asp.net/gad/archive/tags/Announcements/default.aspx">Announcements</category></item><item><title>New weblog</title><link>http://weblogs.asp.net/gad/archive/2004/07/31/202749.aspx</link><pubDate>Sat, 31 Jul 2004 04:22:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:202749</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>6</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=202749</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/07/31/202749.aspx#comments</comments><description>&lt;DIV class=Section1&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;I&amp;#8217;ve got a &lt;A title=http://blogs.msdn.com/gduthie/ href="http://blogs.msdn.com/gduthie/" target=_blank&gt;new blog&lt;/A&gt;, on the MSDN blog server that I&amp;#8217;ll be using for my blogging while I&amp;#8217;m a Microsoft employee. Not sure whether I will continue updating my weblogs.asp.net blog or not, but most of my blogging energy will be directed at the new blog. The new address is:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;A title=http://blogs.msdn.com/gduthie/ href="http://blogs.msdn.com/gduthie/" target=_blank&gt;http://blogs.msdn.com/gduthie/&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;Visit early&amp;#8230;visit often.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=202749" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/Announcements/default.aspx">Announcements</category></item><item><title>Why you shouldn't be using passwords of any kind on your Windows networks . . . </title><link>http://weblogs.asp.net/gad/archive/2004/07/28/200096.aspx</link><pubDate>Wed, 28 Jul 2004 19:17:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:200096</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=200096</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/07/28/200096.aspx#comments</comments><description>&lt;div class="Section1"&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;&amp;nbsp;&amp;hellip;use passphrases instead:&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'&gt; &lt;div&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;So this is my first ever blog entry and seeing as how I'm a senior member of the PSS Security Incident Response team, you may think I've stopped taking my medication by opening with a title like the one above!&amp;nbsp; Medication issues notwithstanding, it's true - you should NOT be using passwords of any kind.&amp;nbsp; Why?&amp;nbsp; For starters, passwords are ridiculously easy to guess or crack.&amp;nbsp; Worms like Agobot / Phatbot / Polybot / SDBot / RBot (no I didn't write this one) all ship with dictionaries of passwords numbering in the hundreds and they can easily replicate to a system that has a password in this word list, and the miscreants are really good at keeping these wordlists up to date with passwords that they've cracked from other systems.&amp;nbsp;&lt;br /&gt; As an example of what I'm talking about check out Symantec's write-up of this little nasty that we encounter on my team just about every day:&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;&lt;a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ae.html" title="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ae.html"&gt;http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ae.html&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/div&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&amp;nbsp;[&lt;a href="http://weblogs.asp.net/robert_hensing/archive/2004/07/28/199610.aspx"&gt;Robert Hensing&lt;/a&gt;]&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;Read the whole thing at: &lt;a href="http://weblogs.asp.net/robert_hensing/archive/2004/07/28/199610.aspx"&gt;http://weblogs.asp.net/robert_hensing/archive/2004/07/28/199610.aspx&lt;/a&gt;.&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=200096" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/Security/default.aspx">Security</category></item><item><title>Now running under WPA...</title><link>http://weblogs.asp.net/gad/archive/2004/07/26/197803.aspx</link><pubDate>Tue, 27 Jul 2004 02:54:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:197803</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=197803</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/07/26/197803.aspx#comments</comments><description>&lt;div class="Section1"&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;It took me a while, but I&amp;rsquo;ve finally upgraded my home network to use WiFi-Protected Access (WPA) instead of WEP for securing my wireless connectivity. The upgrade was complicated by a laptop with a built-in WLAN adapter that didn&amp;rsquo;t support WPA (I switched to using the wired connection on that one) and a wireless bridge that was the wrong hardware revision to support an upgraded firmware patch to enable WPA (a Linksys WET54G). The good news is that after a few frustrating phone calls to Linksys, they allowed me to swap my wireless bridge for the later revision, which supports WPA via a firmware update. I got the new unit today, updated the firmware, configured my router (WRT54G), bridge, and TabletPC to use WPA, and all is working quite nicely. If only it was as easy getting WPA-enabled hardware as it was to configure the settings&amp;hellip;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/div&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=197803" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/Musings/default.aspx">Musings</category><category domain="http://weblogs.asp.net/gad/archive/tags/Security/default.aspx">Security</category></item><item><title>Nifty solution to some of the problems of least privilege</title><link>http://weblogs.asp.net/gad/archive/2004/07/25/196126.aspx</link><pubDate>Sun, 25 Jul 2004 12:29:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:196126</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=196126</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/07/25/196126.aspx#comments</comments><description>&lt;div class="Section1"&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;One of my fellow Microsofties has come up with a neat solution to some of the hassles of running your workstation using a non-admin account. My advice for getting around things you can&amp;rsquo;t do as a non-admin has long been to simply run programs from a command prompt that you&amp;rsquo;ve started with RunAs, using the credentials for an account with admin privileges. The problem is that some programs don&amp;rsquo;t play well in this scenario, particularly install programs that run based on specific settings for the user installing the program. When you run programs like this, they (and/or their settings) end up associated with the admin account you&amp;rsquo;re using, rather than your less-privileged account.&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&lt;a href="http://weblogs.asp.net/Aaron_Margosis/" target="_blank"&gt;Aaron Margosis&lt;/a&gt; has come up with a way to fix this that&amp;rsquo;s quite easy to use. &lt;a href="http://weblogs.asp.net/Aaron_Margosis/archive/2004/07/24/193721.aspx" target="_blank"&gt;His solution&lt;/a&gt; is to create a batch file that adds your less-privileged account to the Administrators group, using the credentials of an existing admin account, then spawns a new command prompt using the account that you just added to the administrators group. The batch file then removes your less-privileged account from the Administrators group.&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;By doing it this way, Aaron&amp;rsquo;s solved two of the tricky parts of elevated privilege&amp;hellip;keeping the scope small (only the command window has the elevated privileges, until/unless you spawn other programs from it), and making sure that profiles of apps that you install are associated with YOUR account, rather than the admin account you&amp;rsquo;re using). I&amp;rsquo;ve only played with this briefly, but it looks to be quite a nice solution to a vexing problem.&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;The download available from Aaron&amp;rsquo;s blog also includes a batch file for setting yourself up as a Power User, in case you&amp;rsquo;d like to further limit the privileges you&amp;rsquo;re granting yourself. There are still some caveats with Aaron&amp;rsquo;s approach, so make sure you read his entire post and understand what the batch files are doing before you use them, but with that caveat, I think this is a great addition to our security toolbox!&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/div&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=196126" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/Security/default.aspx">Security</category></item><item><title>Lookout 1.2 Available for download</title><link>http://weblogs.asp.net/gad/archive/2004/07/23/193434.aspx</link><pubDate>Fri, 23 Jul 2004 20:49:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:193434</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>8</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=193434</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/07/23/193434.aspx#comments</comments><description>&lt;DIV class=Section1&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;Despite the concerns of some that Microsoft was taking it away from the community by acquiring the company, Microsoft has made Lookout, an add-in for searching through Outlook email stores quickly, &lt;STRIKE&gt;available for download&lt;/STRIKE&gt; from the Microsoft download center. Enjoy!&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;STRONG&gt;&lt;FONT color=#ff0000&gt;UPDATE&lt;/FONT&gt;&lt;/STRONG&gt;: Apparently, the old link is dead, but the download can now be found at &lt;A href="http://www.lookoutsoft.com/Lookout/download.html"&gt;http://www.lookoutsoft.com/Lookout/download.html&lt;/A&gt;&amp;nbsp;(via &lt;A href="http://sandbox.msn.com/" target=_new&gt;http://sandbox.msn.com/&lt;/A&gt;). Thanks to &lt;A id=Comments.ascx_CommentList__ctl5_NameLink href="http://sandbox.msn.com/" target=_blank&gt;Niclas Lindgren&lt;/A&gt;&amp;nbsp;for the update on the whereabouts of the download.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=193434" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/Announcements/default.aspx">Announcements</category></item><item><title>Red pill</title><link>http://weblogs.asp.net/gad/archive/2004/07/19/187750.aspx</link><pubDate>Mon, 19 Jul 2004 19:21:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:187750</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>31</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=187750</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/07/19/187750.aspx#comments</comments><description>&lt;P&gt;So...&lt;/P&gt;
&lt;P&gt;The big announcement that I hinted at last week is that, as of today, I have assumed the role of. NET developer evangelist with Microsoft, working in the East region. I want to say thanks to all the folks who've helped me develop the skills to get here, particularly my friends at&amp;nbsp;&lt;A href="http://www.ineta.org/" target=_blank&gt;INETA&lt;/A&gt; and &lt;A href="http://www.aspinsiders.com/" target=_blank&gt;ASPInsiders&lt;/A&gt;. I'm looking forward to helping folks in my new role. Though it may take me some time to get up to speed, feel free to ping me via the &lt;A href="http://weblogs.asp.net/gad/contact.aspx" target=_blank&gt;Contact&lt;/A&gt; link if I can be of assistance.&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#ff0000&gt;UPDATE&lt;/FONT&gt;: I'm ashamed to admit that I forgot to thank a very important group of people...the MVPs. Between my leads, my fellow ASP.NET MVPs, and others I've met through the program, I learned a good deal, and had a lot of fun. Thanks to Ben, John, and the rest for honoring me with the award, and for being great colleagues and friends.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=187750" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/.NET+_2F00_+ASP.NET+Community/default.aspx">.NET / ASP.NET Community</category><category domain="http://weblogs.asp.net/gad/archive/tags/Announcements/default.aspx">Announcements</category></item><item><title>BlueVision ASP.NET Intellisense Generator</title><link>http://weblogs.asp.net/gad/archive/2004/07/15/184536.aspx</link><pubDate>Thu, 15 Jul 2004 22:29:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:184536</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=184536</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/07/15/184536.aspx#comments</comments><description>&lt;div class="Section1"&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;Thanks to Wim for the plug, and for letting us know about a way to get intellisense for custom ASP.NET server controls without hacking XSD:&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'&gt; &lt;div&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;ASP.NET control developers know how much of a pain it can be to create&amp;nbsp;a specific&amp;nbsp;XSD file in order to achieve IntelliSense support in your ASPX mark-up. See &lt;a href="http://weblogs.asp.net/gad/" title="http://weblogs.asp.net/gad/"&gt;Andrew Duthie's&lt;/a&gt; article on MSDN &lt;a href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnaspp/html/ASPNet-AddDesignTimeSupport.asp" title="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnaspp/html/ASPNet-AddDesignTimeSupport.asp"&gt;here&lt;/a&gt;.&lt;br /&gt; &lt;br /&gt; I've been using the &lt;a href="http://www.bluevisionsoftware.com/WebSite/ProductsAndServicesInfo.aspx?ID=9" title="http://www.bluevisionsoftware.com/WebSite/ProductsAndServicesInfo.aspx?ID=9"&gt;ASP.NET IntelliSense Generator&lt;/a&gt; from &lt;a href="http://www.bluevisionsoftware.com" title="http://www.bluevisionsoftware.com"&gt;BlueVision Software&lt;/a&gt; for quite a while now and thought I'd share it with you.&lt;br /&gt; &lt;br /&gt; Enjoy!&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/div&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&lt;br /&gt; [&lt;a href="http://weblogs.asp.net/Wim/archive/2004/07/15/184406.aspx"&gt;Wim Hollebrandse&lt;/a&gt;]&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=184536" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/ASP.NET+_2F00_+Coding/default.aspx">ASP.NET / Coding</category></item><item><title>An open letter to wireless networking manufacturers</title><link>http://weblogs.asp.net/gad/archive/2004/07/14/183434.aspx</link><pubDate>Wed, 14 Jul 2004 20:49:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:183434</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=183434</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/07/14/183434.aspx#comments</comments><description>&lt;DIV class=Section1&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;Dear Wireless Networking Manufacturer,&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; It has come to my attention that some of you (one rhymes with ink-sys) are still shipping new wireless networking equipment that does not support WPA out of the box. This is inexcusable.&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;Please stop manufacturing and selling products that do not support WPA out of the box, particularly newly-introduced products. Also, please ensure that any current products clearly state whether they do or do not support WPA. And, no, &amp;#8220;future&amp;#8221; support via firmware flash does NOT count. For the record, WEP doesn&amp;#8217;t count, either. WEP and MAC filtering are better than nothing at all, but they are grossly inadequate for security purposes, and have been known to be so for years at this point.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; From this point on, I will NOT be purchasing any wireless networking gear that does not support WPA, and I will do my darndest to convince my friends and family to follow suit. If you wish to sell your products to me, get on the stick and do what&amp;#8217;s necessary to WPA-enable your products.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for your attention to this matter&amp;#8230;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=183434" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/Musings/default.aspx">Musings</category><category domain="http://weblogs.asp.net/gad/archive/tags/Security/default.aspx">Security</category></item><item><title>Security at Home</title><link>http://weblogs.asp.net/gad/archive/2004/07/14/183280.aspx</link><pubDate>Wed, 14 Jul 2004 19:27:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:183280</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=183280</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/07/14/183280.aspx#comments</comments><description>&lt;div class="Section1"&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;If you&amp;rsquo;ve got friends or family who are the non-geek types, and need help with security, this might save you a few of those &amp;ldquo;how do I&amp;hellip;?&amp;rdquo; phone calls&amp;hellip;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'&gt; &lt;div&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;Last week, Microsoft put up an updated Security at Home web site for home users. This is a great place to send your family and friends who are interested in security issues and in protecting their PCs. Check it out here:&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal" style='margin-left:.5in'&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;&lt;a href="http://www.microsoft.com/athome/security/default.mspx" title="http://www.microsoft.com/athome/security/default.mspx"&gt;Security at Home&lt;/a&gt;&lt;br /&gt; Microsoft's new Security at Home site helps non-technical users by providing tips and tricks, how-tos, and the latest virus information without all the technical talk.&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&lt;img border="0" width="1" height="1" src="http://weblogs.asp.net/brianjo/aggbug/183237.aspx" /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="ngrelatedlinks" align="right" style='text-align:right'&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;&lt;a href="http://services.newsgator.com/subscriber/Related.aspx?relurl=http%3a%2f%2fweblogs.asp.net%2fbrianjo%2farchive%2f2004%2f07%2f14%2f183237.aspx"&gt;Related...&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/div&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&lt;br /&gt; [&lt;a href="http://weblogs.asp.net/brianjo/archive/2004/07/14/183237.aspx"&gt;Brian Johnson&lt;/a&gt;]&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=183280" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/Security/default.aspx">Security</category></item><item><title>News coming Monday...</title><link>http://weblogs.asp.net/gad/archive/2004/07/13/182679.aspx</link><pubDate>Wed, 14 Jul 2004 02:15:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:182679</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=182679</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/07/13/182679.aspx#comments</comments><description>&lt;div class="Section1"&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;In a little less than a week, I&amp;rsquo;ll have an announcement to make here&amp;hellip;watch this space!&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/div&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=182679" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/Announcements/default.aspx">Announcements</category><category domain="http://weblogs.asp.net/gad/archive/tags/Musings/default.aspx">Musings</category></item><item><title>MS04-024: Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)</title><link>http://weblogs.asp.net/gad/archive/2004/07/13/181964.aspx</link><pubDate>Tue, 13 Jul 2004 19:02:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:181964</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=181964</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/07/13/181964.aspx#comments</comments><description>&lt;div class="Section1"&gt; &lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size:12.0pt'&gt;Another example of why it&amp;rsquo;s a bad idea to run as an administrator on a day-to-day basis:&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'&gt; &lt;div&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;This update resolves a newly-discovered, publicly reported vulnerability. A remote code execution vulnerability exists in the way that the Windows Shell launches applications. If a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. However, significant user interaction is required to exploit this vulnerability. Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/div&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&lt;br /&gt; [&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS04-024.mspx"&gt;Microsoft Security Bulletins&lt;/a&gt;]&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=181964" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/Security/default.aspx">Security</category></item><item><title>Security...not just a Microsoft problem</title><link>http://weblogs.asp.net/gad/archive/2004/06/15/156167.aspx</link><pubDate>Tue, 15 Jun 2004 16:06:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:156167</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>6</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=156167</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/06/15/156167.aspx#comments</comments><description>&lt;div class="Section1"&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;As evidenced by a Linux kernel flaw that resulted in a &lt;a href="http://isc.incidents.org/diary.php?date=2004-06-14&amp;amp;isc=5d042324768853b55b27cec4d9741d09" target="_blank"&gt;DoS attack against Akamai&lt;/a&gt;, effectively denying access to large sites like Google, Yahoo, and Microsoft. Not gloating here, just observing that this demonstrates that &lt;b&gt;&lt;span style='font-weight:bold'&gt;all&lt;/span&gt;&lt;/b&gt; operating systems can be vulnerable to security issues. This also suggests that the &amp;ldquo;more eyes = more secure&amp;rdquo; assertion made by open source advocates is perhaps a little overstated. After all, the Linux kernel is probably one of the most read parts of the Linux codebase. If it&amp;rsquo;s possible to find a flaw in the kernel, what does that say for other parts of the codebase that are not as thouroughly vetted? Again, this is not about trashing Linux, it&amp;rsquo;s about being clear that security is an issue for everyone, it&amp;rsquo;s not just a Microsoft problem.&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;span style='font-size: 12.0pt'&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/div&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=156167" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/Security/default.aspx">Security</category></item><item><title>Hawaii photos</title><link>http://weblogs.asp.net/gad/archive/2004/06/13/154820.aspx</link><pubDate>Mon, 14 Jun 2004 00:07:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:154820</guid><dc:creator>G Andrew Duthie</dc:creator><slash:comments>7</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/gad/rsscomments.aspx?PostID=154820</wfw:commentRss><comments>http://weblogs.asp.net/gad/archive/2004/06/13/154820.aspx#comments</comments><description>&lt;DIV class=Section1&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;For those of you who might be interested, you may have noticed that on the &lt;A href="http://weblogs.asp.net/gad/archive/2004/04/23/118702.aspx" target=_blank&gt;schedule&lt;/A&gt; for my recent MSDN Security Briefing tour, was a stop in Honolulu, Hawaii. I had a great time there, as you might expect, though I did manage to get pretty badly sunburned (that&amp;#8217;s what happens when you spend two hours in a futile attempt to teach yourself how to surf, without using any sunscreen). Here&amp;#8217;s a couple of photos from the trip:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;A Hawaiian rainbow, viewed from the balcony of my room:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;A href="http://www.graymad.com/Photos/936.aspx" target=_blank&gt;&lt;IMG height=321 src="http://www.graymad.com/Photos/297.jpg?Width=480" border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;Diamond Head, viewed from a surfboard off Waikiki Beach:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;A href="http://www.graymad.com/Photos/937.aspx" target=_blank&gt;&lt;IMG height=321 src="http://www.graymad.com/Photos/298.jpg?Width=480" border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=154820" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/gad/archive/tags/Musings/default.aspx">Musings</category></item></channel></rss>