<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:copyright="http://blogs.law.harvard.edu/tech/rss" xmlns:image="http://purl.org/rss/1.0/modules/image/">
    <channel>
        <title>Testing</title>
        <link>http://geekswithblogs.net/AJWarnock/category/10379.aspx</link>
        <description>Testing</description>
        <language>en-US</language>
        <copyright>AJ Warnock</copyright>
        <managingEditor>aj.warnock@jtax.com</managingEditor>
        <generator>Subtext Version 0.0.0.0</generator>
        <item>
            <title>Microsoft getting busy with Security this week...</title>
            <link>http://geekswithblogs.net/AJWarnock/archive/2009/09/29/135163.aspx</link>
            <description>&lt;div style="MARGIN: 0in 0in 0pt"&gt;Well, it looks like Microsoft has been busy on the security front this month. Not only did they release their security essentials this week but also some interesting testing tools, too.&lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt; &lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt;&lt;strong&gt;&lt;a href="http://www.microsoft.com/security_Essentials/"&gt;&lt;font color="#800080"&gt;Microsoft Essentials&lt;/font&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt;Essentials is the Microsoft answer to real-time Home PC protection. It guards against viruses, spyware and other malicious software. It is now available for download from Microsoft.&lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt; &lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt;&lt;strong&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=b2307ca4-638f-4641-9946-dc0a5abe8513"&gt;&lt;font color="#800080"&gt;MiniFuzz File Fuzzer&lt;/font&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt;MiniFuzz is a basic testing tool designed to help detect code flaws that may expose security vulnerabilities in file-handling code. This tool creates multiple random variations of file content and feeds it to the application to exercise the code in an attempt to expose unexpected and potentially insecure application behaviors. &lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt; &lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt;&lt;strong&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=90e6181c-5905-4799-826a-772eafd4440a"&gt;&lt;font color="#800080"&gt;BinScope Binary Analyzer&lt;/font&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt;BinScope is a Microsoft verification tool that analyzes binaries on a project-wide level to ensure that they have been built in compliance with Microsoft's Security Development Lifecycle (SDL) requirements and recommendations. BinScope checks that SDL-required compiler/linker flags are being set, strong-named assemblies are in use, up-to-date build tools are in place, and the latest good ATL headers are being used.&lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt; &lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt;I would recommend you check these out…&lt;/div&gt; &lt;img src="http://geekswithblogs.net/AJWarnock/aggbug/135163.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>AJ Warnock</dc:creator>
            <guid>http://geekswithblogs.net/AJWarnock/archive/2009/09/29/135163.aspx</guid>
            <pubDate>Tue, 29 Sep 2009 18:58:50 GMT</pubDate>
            <comments>http://geekswithblogs.net/AJWarnock/archive/2009/09/29/135163.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/AJWarnock/comments/commentRss/135163.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Imortant VS Patch</title>
            <link>http://geekswithblogs.net/AJWarnock/archive/2009/07/30/133815.aspx</link>
            <description>&lt;div&gt;&lt;font size="2"&gt;&lt;span style="FONT-SIZE: 11pt"&gt;Emergency patches issued for IE and Visual Studio&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="FONT-SIZE: 11pt"&gt;Microsoft on Tuesday issued two out-of-band security patches -- one for the development tools suite Visual Studio and another for Internet Explorer.&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size="2"&gt; &lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="FONT-SIZE: 11pt"&gt;Read the full article here:&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="FONT-SIZE: 11pt"&gt;&lt;a title="http://www.scmagazineus.com/Emergency-patches-issued-for-IE-and-Visual-Studio/article/140737/" href="http://www.scmagazineus.com/Emergency-patches-issued-for-IE-and-Visual-Studio/article/140737/"&gt;Emergency patches issued for IE and Visual Studio&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt; &lt;img src="http://geekswithblogs.net/AJWarnock/aggbug/133815.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>AJ Warnock</dc:creator>
            <guid>http://geekswithblogs.net/AJWarnock/archive/2009/07/30/133815.aspx</guid>
            <pubDate>Thu, 30 Jul 2009 14:06:21 GMT</pubDate>
            <comments>http://geekswithblogs.net/AJWarnock/archive/2009/07/30/133815.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/AJWarnock/comments/commentRss/133815.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Got SDL?</title>
            <link>http://geekswithblogs.net/AJWarnock/archive/2009/07/15/133510.aspx</link>
            <description>&lt;div style="MARGIN: 0in 0in 0pt"&gt;If you have not heard there is an updated MS SDL Starter Kit available for download. This kit provides a compilation of baseline developer security training materials on core Microsoft Security Development Lifecycle (SDL) topics.&lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt; &lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt;The core Microsoft Security Development Lifecycle (SDL) topics include:&lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt; &lt;/div&gt;
&lt;ul style="MARGIN-TOP: 0in" type="disc"&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;Secure design principles&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;Secure implementation principles&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;Secure verification principles&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;SQL injection&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;Cross-site scripting&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;Code analysis&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;Banned application programming interfaces (APIs)&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;Buffer overflows&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;iSource code annotation language&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;Security code reviews&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;Compiler defenses&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;Fuzz testing&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;Microsoft SDL threat modeling principles&lt;/li&gt;
    &lt;li style="MARGIN: 0in 0in 0pt"&gt;The Microsoft SDL threat modeling tool&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt; &lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt;Each set of guidance contains Microsoft Office PowerPoint slides, speaker notes, train-the-trainer audio files, and sample comprehension questions. All materials have limited formatting so that you can leverage the content to achieve broader, enhanced adoption of Microsoft SDL principles in your development organization.&lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt; &lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt;Check it out here: &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=0fcba3c7-bc30-47b0-a2f8-2e702720998a&amp;amp;DisplayLang=en"&gt;&lt;font color="#800080"&gt;MS Download Center - MS SDL - Starter Kit&lt;/font&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="MARGIN: 0in 0in 0pt"&gt; &lt;/div&gt; &lt;img src="http://geekswithblogs.net/AJWarnock/aggbug/133510.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>AJ Warnock</dc:creator>
            <guid>http://geekswithblogs.net/AJWarnock/archive/2009/07/15/133510.aspx</guid>
            <pubDate>Wed, 15 Jul 2009 15:39:44 GMT</pubDate>
            <comments>http://geekswithblogs.net/AJWarnock/archive/2009/07/15/133510.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/AJWarnock/comments/commentRss/133510.aspx</wfw:commentRss>
        </item>
        <item>
            <title>New VSTS SDL Template</title>
            <link>http://geekswithblogs.net/AJWarnock/archive/2009/07/01/133184.aspx</link>
            <description>&lt;div&gt;&lt;font face="Verdana"&gt;Using the SDL? if not, you should be considering it…&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Verdana"&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Verdana"&gt;Having blurred the line between development and Test Engineering at our organization, I am finding out how little our development team(s) knows about secure development practices.   Not a good thing.   Recently, Microsoft released the SDL process template for VSTS and I think it’s going to help.&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Verdana"&gt; &lt;/font&gt;&lt;/div&gt;
&lt;p&gt;&lt;font face="Verdana"&gt;So, if you have not seen this it is a nice start at helping ensure secure development practices are used by your team. Hmmm, amazing what a little process, a little knowledge and a nice video can achieve?&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana"&gt;So, check it out &lt;/font&gt;&lt;a href="http://msdn.microsoft.com/en-us/security/cc448177.aspx"&gt;&lt;font color="#800080" face="Verdana"&gt;Here at the Microsoft Security Development Center.&lt;/font&gt;&lt;/a&gt;&lt;/p&gt; &lt;img src="http://geekswithblogs.net/AJWarnock/aggbug/133184.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>AJ Warnock</dc:creator>
            <guid>http://geekswithblogs.net/AJWarnock/archive/2009/07/01/133184.aspx</guid>
            <pubDate>Wed, 01 Jul 2009 13:57:14 GMT</pubDate>
            <comments>http://geekswithblogs.net/AJWarnock/archive/2009/07/01/133184.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/AJWarnock/comments/commentRss/133184.aspx</wfw:commentRss>
        </item>
    </channel>
</rss>
