March 2004 - Posts

Speaker photos from Pittsburgh DevDays 2004.
Thursday, March 11, 2004 3:38 PM

http://thycotic.com/devdays_2004.html

I didn't take enough pictures but with all the buzz it was difficult to remember. :-)

Dinner with the pros - aka DevDays and punch cards
Monday, March 08, 2004 11:45 PM

After the Microsoft DevDays rehearsal this evening we all had dinner at Pittsburgh's FishMarket.  It was great to share war stories of tough projects and encountered .NET challenges.  The crowd was really interesting and you could feel the brain power at the table right up until the conversation turned to programming with punch cards and all was lost! :-)  The crowd included - John McClelland, Mike Snell, Craig Oaks, Chris Mazzanti, Pat Santry, Stan Spotts, and Terry Weiss stopped by for a minute.

The stage is set (literally), the rabble have been fed - roll on DevDays tomorrow!  There are over 200 registered attendees and it promises to be a great event.

by thycotic | with no comments
Filed under: ,
Background reading for DevDays 2004
Monday, March 08, 2004 11:31 PM

In preparation for my presentation at Microsoft DevDays 2004 in Pittsburgh,  I have been reading “Writing Secure Code” by Michael Howard and David LeBlanc (which a past colleague, David Williams, pointed me towards).  For those of us living in the business application and web application realm, a buffer overrun is something we read about on security bulletins.  It was fascinating to read how it all works and how to overcome it.  Some great code examples - thoroughly interesting.  But don't leave thinking that this book is only for those dealing with unmanaged code ... !

It discusses web application threats including a detailed discussion of SQL injections, cross site scripting attacks, hidden field tampering and also canonical issues.  There is also a chapter on securing .NET code which includes requesting permissions programmatically which most people probably don't even know about.  It also details modeling threats and determining your vulnerabilities before and during application development.

Microsoft also offers the following freely available resources:

by thycotic | with no comments
Filed under: ,
More Posts

This Blog

Syndication