<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:copyright="http://blogs.law.harvard.edu/tech/rss" xmlns:image="http://purl.org/rss/1.0/modules/image/">
    <channel>
        <title>Development</title>
        <link>http://geekswithblogs.net/ssimakov/category/772.aspx</link>
        <description>Development information</description>
        <language>en-US</language>
        <copyright>Sergey Simakov</copyright>
        <managingEditor>sim@yandex.ru</managingEditor>
        <generator>Subtext Version 0.0.0.0</generator>
        <item>
            <title>Great blog on smartcards deployment</title>
            <link>http://geekswithblogs.net/ssimakov/archive/2006/11/20/97647.aspx</link>
            <description>I just found that I've missed a great blog by Steve Patrick (from Critical Problem Resolution&amp;nbsp;team)&amp;nbsp;with invaluable information on SmartCard deployment, so begin with this post - &lt;A href="http://blogs.msdn.com/spatdsg/archive/2006/09/05/739565.aspx"&gt;So, you want to use smart cards?&lt;/A&gt;. Thanks for sharing this information, Steve! [&lt;A href="http://blogs.msdn.com/spatdsg/rss.xml"&gt;subscribed&lt;/A&gt;]&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=97647"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=97647" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/97647.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid>http://geekswithblogs.net/ssimakov/archive/2006/11/20/97647.aspx</guid>
            <pubDate>Mon, 20 Nov 2006 19:13:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/11/20/97647.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/97647.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Microsoft acquires Sysinternals and Wininternals</title>
            <link>http://geekswithblogs.net/ssimakov/archive/2006/07/18/85552.aspx</link>
            <description>&lt;P&gt;According to Mark's &lt;A href="http://www.sysinternals.com/blog/2006/07/on-my-way-to-microsoft.html"&gt;blog post&lt;/A&gt;&amp;nbsp;-&amp;nbsp;Microsoft &lt;A href="http://www.winternals.com/Company/PressRelease92.aspx"&gt;has acquired Wininternals&lt;/A&gt; and Sysinternals: developers of&amp;nbsp;great&amp;nbsp;troubleshooting and management tools such as Recovery Manager, Protection Manager and ERD Commander (part of Administrator Pack), free &lt;A href="http://www.sysinternals.com/Utilities/Autologon.html"&gt;Autoruns&lt;/A&gt;/Process Explorer/&lt;A href="http://www.sysinternals.com/Utilities/RootkitRevealer.html"&gt;Rootkit Revealer&lt;/A&gt;, and many others that are included in my must-have utilities&amp;nbsp;list.&lt;/P&gt;
&lt;P&gt;Congratulations to Mark and Bruce!&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=85552"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=85552" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/85552.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid>http://geekswithblogs.net/ssimakov/archive/2006/07/18/85552.aspx</guid>
            <pubDate>Tue, 18 Jul 2006 13:44:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/07/18/85552.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/85552.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Crypto classes</title>
            <link>http://geekswithblogs.net/ssimakov/archive/2006/05/23/79344.aspx</link>
            <description>&lt;P&gt;Michael Howard &lt;A href="http://blogs.msdn.com/michael_howard/archive/2006/05/22/604076.aspx"&gt;posted&lt;/A&gt; a link to the &lt;A href="http://www.cs.washington.edu/education/courses/csep590/06wi/lectures/"&gt;lecture materials&lt;/A&gt; from University of Washington's cryptography class.&lt;/P&gt;
&lt;P&gt;And you should pay attention to the lecturers list:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Brian LaMacchia (ex-security architect for the .NET Framework and Common Language Runtime)&lt;/LI&gt;
&lt;LI&gt;Josh Benaloh (senior cryptographer in Microsoft Research)&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;John Manferdelli (Distinguished Engineer, worked on the TPM stuff at Microsoft.)&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;BTW, does anyone mentions that v1.1 of KMDF was &lt;A href="http://www.microsoft.com/whdc/driver/wdf/KMDF_pkg.mspx"&gt;released&lt;/A&gt;? It supports Windows 2000 now, so driver developers&amp;nbsp;position&amp;nbsp;helped =)&amp;nbsp;&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=79344"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=79344" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/79344.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid>http://geekswithblogs.net/ssimakov/archive/2006/05/23/79344.aspx</guid>
            <pubDate>Tue, 23 May 2006 14:41:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2006/05/23/79344.aspx#feedback</comments>
            <slash:comments>1</slash:comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/79344.aspx</wfw:commentRss>
        </item>
        <item>
            <title>news for last three months </title>
            <link>http://geekswithblogs.net/ssimakov/archive/2005/12/14/63144.aspx</link>
            <description>&lt;P&gt;Well,&amp;nbsp;period of silence on this blog ended. Unfortunately I couldn't post for last three months for many reasons&amp;nbsp;and I'm sorry for it :(( &lt;/P&gt;
&lt;P&gt;In this post I'll try to summarize what interesting&amp;nbsp;things&amp;nbsp;happened in security from my point of view (actually Valery already mentioned most of them in his &lt;A href="http://www.harper.no/valery/"&gt;blog&lt;/A&gt;):&lt;/P&gt;
&lt;P&gt;Peter Gutmann updated his &amp;#8220;&lt;A href="http://www.cs.auckland.ac.nz/~pgut001/tutorial/index.html"&gt;Godzilla crypto and security&lt;/A&gt;&amp;#8220; tutorial&amp;nbsp;with excellent quote on current state of laws in Russia: &amp;#8220;The severity of Russian law is compensated for by it&amp;#8217;s non-mandatoryness.&amp;#8221;&lt;/P&gt;
&lt;P&gt;NSA announced &lt;A href="http://www.nsa.gov/ia/industry/crypto_suite_b.cfm"&gt;Suite B Cryptography&lt;/A&gt; at RSA 2005 consisting of AES, Elliptic Curve Digital Signature and Key Exchange and SHA-256/384.&lt;/P&gt;
&lt;P&gt;
&lt;HR id=null&gt;
&lt;/P&gt;
&lt;P&gt;For this reason I try to&amp;nbsp;describe &lt;STRONG&gt;unofficial&lt;/STRONG&gt; Russian &amp;#8220;Suite B&amp;#8220;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;GOST 28147-89 for encryption&lt;/LI&gt;
&lt;LI&gt;GOST R 34.10-2001 (Elliptic Curve Digital Signature) for DS and Key Exchange (it supersedes GOST R 34.10-94 that should be withdrawn&amp;nbsp;before&amp;nbsp;1.01.2008)&lt;/LI&gt;
&lt;LI&gt;GOST R 34.11-94 for hash function&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;More information about using these algorithms with X.509 certificate and CRL profile is&amp;nbsp;currently&amp;nbsp;available as &lt;A href="http://www.ietf.org/internet-drafts/draft-ietf-pkix-gost-cppk-03.txt"&gt;draft &lt;/A&gt;(and will be accepted as informational RFC in the&amp;nbsp;&lt;A href="http://article.gmane.org/gmane.ietf.x509/22808/match=draft+ietf+pkix+gost+cppk+03"&gt;nearest time&lt;/A&gt;). Basic implementation for OpenSSL 0.9.8 could be downloaded at &lt;A href="http://www.cryptocom.ru/OpenSource/OpenSSL_eng.html"&gt;CryptoCom open-source&amp;nbsp;site&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;
&lt;HR id=null&gt;
&lt;/P&gt;
&lt;P&gt;Bruce Schneier posted his impressions from&amp;nbsp;&lt;A href="http://www.csrc.nist.gov/pki/HashWorkshop/index.html"&gt;&lt;FONT color=#0000eb&gt;Cryptographic Hash Workshop&lt;/FONT&gt;&lt;/A&gt; hosted by NIST: &lt;A href="http://www.schneier.com/blog/archives/2005/10/nist_hash_works_1.html"&gt;1&lt;/A&gt;, &lt;A href="http://www.schneier.com/blog/archives/2005/10/nist_hash_works_2.html"&gt;2&lt;/A&gt;, &lt;A href="http://www.schneier.com/blog/archives/2005/10/nist_hash_works_3.html"&gt;3&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;This autumn was a bad time for many IPSec ISAKMP/IKE implementations: &lt;A href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/"&gt;Protos test suite&lt;/A&gt; from Oulu University Secure Programming Group found multiple vendor &lt;A href="http://www.kb.cert.org/vuls/id/226364"&gt;implementation vulnerabilities&lt;/A&gt;. And this is an exact sample of using &lt;A href="http://doi.ieeecomputersociety.org/10.1109/MSP.2005.55"&gt;fuzzing technique&lt;/A&gt; to find security flaws.&lt;/P&gt;
&lt;P&gt;Sun Microsystem released Solaris 10 source code as &lt;A href="http://www.opensolaris.org/os/community/security/"&gt;OpenSolaris&lt;/A&gt; including &lt;A href="http://cvs.opensolaris.org/source/xref/usr/src/uts/common/crypto"&gt;Kernel Crypto Framework/Drivers&lt;/A&gt;, &lt;A href="http://cvs.opensolaris.org/source/xref/usr/src/lib/pkcs11"&gt;&lt;FONT color=#002c99&gt;User Crypto Framework (PKCS#11)&lt;/FONT&gt;&lt;/A&gt; and &lt;A href="http://cvs.opensolaris.org/source/xref/usr/src/common/crypto"&gt;&lt;FONT color=#002c99&gt;Crypto Algorithms&lt;/FONT&gt;&lt;/A&gt; (more information is available at &lt;A href="http://blogs.sun.com/roller/page/darren"&gt;Darren J. Moffat blog&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;
&lt;HR id=null&gt;
&lt;/P&gt;
&lt;P&gt;BTW, it is interesting to compare design of future Microsoft&amp;nbsp;CryptoAPI NG from &lt;A href="http://geekswithblogs.net/ssimakov/archive/2005/09/15/53963.aspx"&gt;previous post&lt;/A&gt; and &lt;A href="http://www.opensolaris.org/os/community/security/projects/ef/"&gt;The (Open)Solaris Cryptographic Framework&lt;/A&gt;. They are build of the same cryptoproviders separation as distinct&amp;nbsp;digest, signature, etc providers and both moving to support kernel (right now it's impossible to use CryptoAPI in ipsec driver for example).&lt;/P&gt;
&lt;P&gt;
&lt;HR id=null&gt;
&lt;/P&gt;
&lt;P&gt;And&amp;nbsp;developer part&amp;nbsp;of news: two most successful Microsoft Shared Source projects released as &lt;A href="http://wix.sourceforge.net/latestrelease.html"&gt;WiX 2.0&lt;/A&gt; and &lt;A href="http://wtl.sourceforge.net/"&gt;WTL 7.5&lt;/A&gt;&amp;nbsp;- and MSFT could be really proud of them (we use them extensively in our projects). &lt;/P&gt;
&lt;P&gt;Windows kernel developers also received new development framework - &lt;A href="http://www.microsoft.com/whdc/driver/wdf/KMDF_pkg.mspx"&gt;Kernel Mode Driver Framework 1.0&lt;/A&gt; (unfortunately it didn't support Windows 2000 in version 1.0, but I hope it will due to &lt;A href="http://www.osronline.com/article.cfm?article=429"&gt;feedback from developers community&lt;/A&gt;) and &amp;nbsp;updated &lt;A href="http://www.microsoft.com/whdc/driver/wdf/KMDF_pkg.mspx"&gt;Driver Install Framework Tools 2.01&lt;/A&gt;. And best of all - WDF contains Windows Server 2003 SP1 DDK with Static Driver Verifier for free ;-) If you're interested in Windows Kernel development - watch for OSR &lt;A href="http://www.osronline.com/rss/ntdev.xml"&gt;NTDEV&lt;/A&gt; and &lt;A href="http://kernelmustard.com/"&gt;Steve Dispensa&amp;nbsp;blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Well, it's enough for today - thank you&amp;nbsp;for reading&amp;nbsp;=)&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=63144"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=63144" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/63144.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid>http://geekswithblogs.net/ssimakov/archive/2005/12/14/63144.aspx</guid>
            <pubDate>Wed, 14 Dec 2005 19:03:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2005/12/14/63144.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/63144.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Security slide decks at PDC2005</title>
            <link>http://geekswithblogs.net/ssimakov/archive/2005/09/15/53963.aspx</link>
            <description>&lt;P&gt;For poor souls like me (who could not attent PDC this year&amp;nbsp;;-) - at least we can check&amp;nbsp;PDC2005&amp;nbsp;&lt;A href="http://commnet.microsoftpdc.com/content/downloads.aspx"&gt;slide decks&lt;/A&gt; [via &lt;A href="http://samgentile.com/blog/archive/2005/09/15/31946.aspx"&gt;Sam Gentile&lt;/A&gt;].&lt;/P&gt;
&lt;P&gt;I'm&amp;nbsp;interested in&amp;nbsp;&amp;#8220;&lt;A href="http://216.55.183.63/pdc2005/slides/TLNL06_Guerrera.ppt"&gt;Scrubbing Source Code for Common Coding Mistakes (FxCop and PreFast)&lt;/A&gt;&amp;#8220;,&amp;nbsp;&amp;nbsp;&amp;#8220;&lt;A href="http://216.55.183.63/pdc2005/slides/COM304_Talwar.ppt"&gt;Building IPv6, Firewall, and IPsec Aware Applications&lt;/A&gt;&amp;#8220; and especially &amp;#8220;&lt;A href="http://216.55.183.63/pdc2005/slides/FUN210_Ben-Menahem_Tucker.ppt"&gt;Understanding, Enhancing, and Extending Security End-to-End&lt;/A&gt;&amp;#8220; (because it mentions CryptoAPI NG)&lt;/P&gt;
&lt;P&gt;[Updated 2005/12/07 to include direct links to presentations and btw CNG is _must read_ for any CSP developer!]&lt;BR&gt;&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=53963"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=53963" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/53963.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid>http://geekswithblogs.net/ssimakov/archive/2005/09/15/53963.aspx</guid>
            <pubDate>Thu, 15 Sep 2005 16:23:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2005/09/15/53963.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/53963.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Security Tools for Development</title>
            <link>http://geekswithblogs.net/ssimakov/archive/2005/04/25/37709.aspx</link>
            <description>&lt;P&gt;Last friday at Microsoft Moscow&amp;nbsp;office&amp;nbsp;&lt;A href="http://blogs.dotnetthis.com/Ivan"&gt;Ivan Medvedev&lt;/A&gt; (from SWI team)&amp;nbsp;made a presentation about &lt;A href="http://download.microsoft.com/download/b/b/f/bbf3137e-de8e-495d-9fae-999052ff9bc2/SecurityTools-External-final.ppt"&gt;Security Tools for Software Development&lt;/A&gt;. He mentioned new Threat Modeling tool, AppVerifier, PreFast, &lt;A title="" href="http://www.gotdotnet.com/team/fxcop" target=_blank&gt;FxCop&lt;/A&gt;,&amp;nbsp;and new Whidbey compiler switches.&lt;/P&gt;
&lt;P&gt;[Update] May be &lt;A href="http://blogs.dotnetthis.com/Ivan/archives/2005/05/index.html"&gt;Ivan will&amp;nbsp;post&lt;/A&gt; some new information at his blog about those and new tools ;-)&lt;/P&gt;
&lt;P&gt;An intoduction in testing methods used at Microsoft&amp;nbsp;awake my interesting in &lt;A href="http://csdl.computer.org/comp/mags/sp/2005/02/j2058abs.htm"&gt;fuzzing&lt;/A&gt; - a method of finding software security holes by feeding purposely invalid and ill-formed data as input to program interfaces. Microsoft currently uses automated &lt;A href="http://www.princeton.edu/~echi/ele572/Howard%20-%20Windows%20security%20push.pdf"&gt;fuzzing tools&lt;/A&gt; internally (as desribed in &lt;A href="http://geekswithblogs.net/ssimakov/archive/2005/03/21/26875.aspx"&gt;SDL&lt;/A&gt; whitepaper). There are tools by other companies in this fields already&amp;nbsp;- &lt;A href="http://www.sisecure.com/company/ourtechnology/index.shtml"&gt;Hydra&lt;/A&gt; from Security Innovations (authors of &lt;A href="http://www.sisecure.com/holodeck/index.shtml"&gt;Holodeck&lt;/A&gt;) or&amp;nbsp;&lt;A href="http://www.immunitysec.com/resources-freesoftware.shtml"&gt;sharefuzz&lt;/A&gt; concept&amp;nbsp;from Immunity, but I think they're not &lt;EM&gt;automated&lt;/EM&gt; the same way (but mb it's based on some of&amp;nbsp;this products, as&amp;nbsp;with PreFix from Intrinsa previously).&lt;/P&gt;
&lt;P&gt;[Update 28/04/2005] There is also interesting paper &lt;A href="http://www.cs.berkeley.edu/~pbwell/papers/saswifi.pdf"&gt;A Comparison of Static Analysis and Fault Injection Techniques for Developing Robust System Services&lt;/A&gt; by Pete Broadwell and Emil Ong, mentioned at &lt;A href="http://www.dwheeler.com/flawfinder/"&gt;Flawfinder&lt;/A&gt; static analysis tool.&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=37709"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=37709" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/37709.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid>http://geekswithblogs.net/ssimakov/archive/2005/04/25/37709.aspx</guid>
            <pubDate>Mon, 25 Apr 2005 10:03:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2005/04/25/37709.aspx#feedback</comments>
            <slash:comments>1</slash:comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/37709.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Microsoft Knowledgebase is now RSS-enabled</title>
            <link>http://geekswithblogs.net/ssimakov/archive/2005/04/19/36837.aspx</link>
            <description>Well, it finally happens. After using &lt;A href="http://www.kbalertz.com/"&gt;kbAlertz&lt;/A&gt; for so long time we can use official RSS feeds for Microsoft Knowledgebase at &lt;A href="http://support.microsoft.com/selectindex/?target=rss"&gt;http://support.microsoft.com/selectindex/?target=rss&lt;/A&gt;&amp;nbsp;now&amp;nbsp;[via &lt;A href="http://blogs.technet.com/jhoward/archive/2005/04/16/KB_RSS.aspx"&gt;John Howard&lt;/A&gt;]&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=36837"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=36837" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/36837.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid>http://geekswithblogs.net/ssimakov/archive/2005/04/19/36837.aspx</guid>
            <pubDate>Tue, 19 Apr 2005 04:27:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2005/04/19/36837.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/36837.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Windows NT kernel internals</title>
            <link>http://geekswithblogs.net/ssimakov/archive/2005/04/15/34121.aspx</link>
            <description>&lt;P&gt;Four part video presentation of the Windows NT kernel by Dave Probert (an architect for Windows) is posted at Channel 9. He does a very good job of comparing the Windows kernel to UNIX-style kernels and how they tackle the same problems differently.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://channel9.msdn.com/ShowPost.aspx?PostID=53470#53470"&gt;Part I&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://channel9.msdn.com/ShowPost.aspx?PostID=53472"&gt;Part II&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://channel9.msdn.com/ShowPost.aspx?PostID=54611"&gt;Part III&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://channel9.msdn.com/ShowPost.aspx?PostID=55222"&gt;Part IV&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Also very interesting &lt;A href="http://www.i.u-tokyo.ac.jp/ss/msprojects/"&gt;Course about Windows Internals&lt;/A&gt;&amp;nbsp;by Dave Probert exists at Strategic Software program&amp;nbsp;site of the University of Tokyo&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=34121"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=34121" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/34121.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid>http://geekswithblogs.net/ssimakov/archive/2005/04/15/34121.aspx</guid>
            <pubDate>Fri, 15 Apr 2005 09:31:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2005/04/15/34121.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/34121.aspx</wfw:commentRss>
        </item>
        <item>
            <title>New security books from Microsoft security team</title>
            <link>http://geekswithblogs.net/ssimakov/archive/2005/04/13/33330.aspx</link>
            <description>&lt;P&gt;As I &lt;A href="http://geekswithblogs.net/ssimakov/archive/2005/01/14/20008.aspx"&gt;posted&lt;/A&gt; recently &lt;A href="http://www.awprofessional.com/title/0321336437"&gt;&lt;FONT color=#ff9900&gt;Protect Your Windows Network&lt;/FONT&gt;&lt;/A&gt; book by &lt;A href="http://blogs.msdn.com/steriley/archive/2005/03/21/399990.aspx"&gt;&lt;FONT color=#ff9900&gt;Steve Riley&lt;/FONT&gt;&lt;/A&gt; and Jesper M. Johansson&amp;nbsp;is available for pre-ordering. Both &lt;A href="http://blogs.msdn.com/michael_howard/archive/2005/04/12/407641.aspx"&gt;Michael Howard&lt;/A&gt; and &lt;A href="http://blogs.technet.com/steriley/archive/2005/04/12/403642.aspx"&gt;Steve Riley&lt;/A&gt; posted&amp;nbsp;updated information about&amp;nbsp;preorder (with promo code ;-)&lt;/P&gt;
&lt;P&gt;Also yesterday I accidentially found new book by Michael, David LeBlank AND &lt;A href="http://www.viega.org"&gt;John Viega&lt;/A&gt; - &lt;A href="http://books.mcgraw-hill.com/getbook.php?isbn=0072260858"&gt;19 Deadly Sins of Software Security&lt;/A&gt; due to August 2005. It should be interesting book from authors of Writing of Secure Code and &lt;A href="http://www.secureprogramming.com/"&gt;Secure Programming Cookbook&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;[Update] This monday Michael Howard &lt;A href="http://blogs.msdn.com/michael_howard/archive/2005/07/11/437875.aspx"&gt;officially announced&lt;/A&gt; this book on his blog.&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=33330"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=33330" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/33330.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid>http://geekswithblogs.net/ssimakov/archive/2005/04/13/33330.aspx</guid>
            <pubDate>Wed, 13 Apr 2005 07:03:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2005/04/13/33330.aspx#feedback</comments>
            <slash:comments>1</slash:comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/33330.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Application Verifier Security Tools for Windows</title>
            <link>http://geekswithblogs.net/ssimakov/archive/2005/03/17/26535.aspx</link>
            <description>&lt;P&gt;&lt;A href="http://www.microsoft.com/technet/security/secnews/articles/sec_tools_for_appverifier.mspx"&gt;Interesting article&lt;/A&gt;&amp;nbsp;about security tools to check for common security issues, including places where your code won't run properly under non-administrative accounts that are included in &lt;A href="http://www.microsoft.com/windows/appcompatibility/appverifier.mspx"&gt;Application Verifier&lt;/A&gt; is &lt;A href="http://www.microsoft.com/technet/security/secnews/articles/sec_tools_for_appverifier.mspx"&gt;posted at TechNet&lt;/A&gt;. [via &lt;A href="http://www.larkware.com/dg2/TheDailyGrind580.html"&gt;Larkware&lt;/A&gt;] &lt;/P&gt;
&lt;P&gt;Michael Howard also &lt;A href="http://msdn.microsoft.com/library/en-us/dncode/html/secure12112003.asp"&gt;described SecurityChecks&lt;/A&gt; in his Code Secure.&lt;/P&gt;&lt;p&gt;&lt;a href="http://www.pheedo.com/click.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=26535"&gt;&lt;img src="http://www.pheedo.com/img.phdo?x=6cda6ad746d942b9a1110d0715a4fa12&amp;u=26535" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;iframe src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;PageID=31016&amp;amp;SiteID=1" width=1 height=1 Marginwidth=0 Marginheight=0 Hspace=0 Vspace=0 Frameborder=0 Scrolling=No&gt;
&lt;script language='javascript1.1' src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Browser=NETSCAPE4&amp;amp;NoCache=True&amp;PageID=31016&amp;amp;SiteID=1"&gt;&lt;/script&gt;
&lt;noscript&gt;&lt;a href="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Click&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" target="_blank"&gt;
&lt;img src="http://ads.geekswithblogs.net/a.aspx?ZoneID=5&amp;amp;Task=Get&amp;amp;Mode=HTML&amp;amp;SiteID=1&amp;amp;PageID=31016" width="1" height="1" border="0"  alt=""&gt;&lt;/a&gt;
&lt;/noscript&gt;
&lt;/iframe&gt;
&lt;img src="http://geekswithblogs.net/ssimakov/aggbug/26535.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Sergey Simakov</dc:creator>
            <guid>http://geekswithblogs.net/ssimakov/archive/2005/03/17/26535.aspx</guid>
            <pubDate>Thu, 17 Mar 2005 07:49:00 GMT</pubDate>
            <comments>http://geekswithblogs.net/ssimakov/archive/2005/03/17/26535.aspx#feedback</comments>
            <wfw:commentRss>http://geekswithblogs.net/ssimakov/comments/commentRss/26535.aspx</wfw:commentRss>
        </item>
    </channel>
</rss>