<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type='text/xsl' href='http://securitymario.spaces.live.com/mmm2008-05-17_13.22/rsspretty.aspx?rssquery=en-US;http%3a%2f%2fsecuritymario.spaces.live.com%2fblog%2ffeed.rss' version='1.0'?><rss version="2.0" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:msn="http://schemas.microsoft.com/msn/spaces/2005/rss" xmlns:live="http://schemas.microsoft.com/live/spaces/2006/rss" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:cf="http://www.microsoft.com/schemas/rss/core/2005" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Montreal blog on Internet Security Software: Blog</title><description /><link>http://securitymario.spaces.live.com/blog</link><language>en-US</language><pubDate>Thu, 26 Jun 2008 20:11:41 GMT</pubDate><lastBuildDate>Thu, 26 Jun 2008 20:11:41 GMT</lastBuildDate><generator>Microsoft Spaces v1.1</generator><docs>http://www.rssboard.org/rss-specification</docs><ttl>60</ttl><cf:parentRSS>http://securitymario.spaces.live.com/feed.rss</cf:parentRSS><live:type>blog</live:type><live:identity><live:id>-809307349871158204</live:id><live:alias>securitymario</live:alias></live:identity><image><title>Montreal blog on Internet Security Software: Blog</title><url>http://blufiles.storage.live.com/y1pmZFvuoX1rQm76FxXj6RCKYBJAd8Cr7ahl0YUWPKNcn3o9bIWuzR138ITixyyhAA2</url><link>http://securitymario.spaces.live.com/blog</link></image><cf:listinfo><cf:group ns="http://schemas.microsoft.com/live/spaces/2006/rss" element="typelabel" label="Type" /><cf:group ns="http://schemas.microsoft.com/live/spaces/2006/rss" element="tag" label="Tag" /><cf:group element="category" label="Category" /><cf:sort element="pubDate" label="Date" data-type="date" default="true" /><cf:sort element="title" label="Title" data-type="string" /><cf:sort ns="http://purl.org/rss/1.0/modules/slash/" element="comments" label="Comments" data-type="number" /></cf:listinfo><item><title>Binary vulnerabilities and Exploit Writing</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!268.entry</link><description>&lt;div&gt;I've been writing assembly all day at the recon 2008 security conference with Gerardo 'gera' Richarte.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;This is really really really fun. Hands on buffer overflows and exploits using OllyDbg....&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://recon.cx/2008/training2.html"&gt;http://recon.cx/2008/training2.html&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Binary+vulnerabilities+and+Exploit+Writing&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!268.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!268.entry</guid><pubDate>Tue, 10 Jun 2008 19:02:45 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!268/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!268.entry#comment</wfw:comment><dcterms:modified>2008-06-10T19:02:45Z</dcterms:modified></item><item><title>http://www.superconfigure.com/home.html</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!267.entry</link><description>&lt;br&gt;I wrote a small Windows (XP &amp;amp; Vista) reset &amp;amp; harden like tool, check it out: &lt;a href="http://www.superconfigure.com/home.html"&gt;http://www.superconfigure.com/home.html&lt;/a&gt; &lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+http%3a%2f%2fwww.superconfigure.com%2fhome.html&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!267.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!267.entry</guid><pubDate>Fri, 06 Jun 2008 18:37:42 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!267/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!267.entry#comment</wfw:comment><dcterms:modified>2008-06-23T19:30:25Z</dcterms:modified></item><item><title>Windows Vista</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!265.entry</link><description>&lt;div&gt;&lt;span&gt;&lt;font face="Segoe UI" color="#323e58" size=3&gt;Top Security Features in Windows Vista&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;a href="http://technet.microsoft.com/en-us/magazine/cc546565.aspx"&gt;http://technet.microsoft.com/en-us/magazine/cc546565.aspx&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;User Account Control&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;Internet Explorer Protected Mode&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;Standard User Support&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;BitLocker Drive Encryption&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;Windows Resource Protection&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;Services Hardening&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;Advanced Firewall&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;/span&gt; &lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;/span&gt; &lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;a title=Permalink href="http://securitymario.spaces.live.com/Media/Windows-Vista-SP1-UAC-improvements/"&gt;&lt;font color="#0066cc"&gt;Windows Vista SP1 UAC improvements&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;a href="http://edge.technet.com/Media/Windows-Vista-SP1-UAC-improvements/"&gt;http://edge.technet.com/Media/Windows-Vista-SP1-UAC-improvements/&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Windows+Vista&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!265.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!265.entry</guid><pubDate>Fri, 06 Jun 2008 14:46:04 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!265/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!265.entry#comment</wfw:comment><dcterms:modified>2008-06-06T14:46:04Z</dcterms:modified></item><item><title>MSFT Live Mesh Beta..wtf?!</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!262.entry</link><description>&lt;div&gt;Oh come on..I can't upload a folder, I gotta do it &lt;font color="#c00000"&gt;file by file &lt;/font&gt;?!&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://blufiles.storage.live.com/y1p4HHC2kax1FgrnSfMBBj3pWOENlyiRyTpOChDQ-528iPL1I4g3ma1_VqFxdnlql-Hi25i7Ui-U2w" target="_blank"&gt;&lt;img height=140 alt=misc src="http://blufiles.storage.live.com/y1p4HHC2kax1FgrnSfMBBj3pWOENlyiRyTpOChDQ-528iPL1I4g3ma1_VqFxdnlql-Hi25i7Ui-U2w" width=260&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Thanks live mesh, but I'll stick with jungle disk for now....&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+MSFT+Live+Mesh+Beta..wtf%3f!&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!262.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!262.entry</guid><pubDate>Wed, 28 May 2008 13:47:04 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!262/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!262.entry#comment</wfw:comment><dcterms:modified>2008-05-28T13:47:04Z</dcterms:modified></item><item><title>phishing email collection...</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!261.entry</link><description>&lt;div&gt;&lt;font face="Courier New" color="#00b0f0"&gt;&amp;quot;If you have found this site by searching for an email address or information contained in an email sent to you and you have sent money to the person who sent you that email please...&amp;quot;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Courier New" color="#00b0f0"&gt;&lt;/font&gt; &lt;/div&gt;
&lt;div&gt;&lt;font face="Courier New" color="#00b0f0"&gt;&lt;font face=Arial color="#000000"&gt;interesting site, seems to be a collection of phishing emails..&lt;/font&gt;: &lt;a href="http://www.scamwarning.org/"&gt;http://www.scamwarning.org/&lt;/a&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Courier New" color="#00b0f0"&gt;&lt;/font&gt; &lt;/div&gt;
&lt;div&gt;&lt;font face=Arial color="#000000"&gt;Maybe I'll 'email' them and get something funny up there;-)&lt;/font&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+phishing+email+collection...&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!261.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!261.entry</guid><pubDate>Wed, 28 May 2008 13:16:24 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!261/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!261.entry#comment</wfw:comment><dcterms:modified>2008-05-28T13:44:41Z</dcterms:modified></item><item><title>Are these actual, free MP3's on the net?</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!260.entry</link><description>&lt;div&gt;&lt;a href="http://muxfind.com/"&gt;http://muxfind.com/&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Are+these+actual%2c+free+MP3's+on+the+net%3f&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!260.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!260.entry</guid><pubDate>Tue, 27 May 2008 13:18:15 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!260/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!260.entry#comment</wfw:comment><dcterms:modified>2008-05-27T13:18:15Z</dcterms:modified></item><item><title>10 years and 499,999 servers later...</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!255.entry</link><description>&lt;div&gt;This old picture from google labs circa 1999..&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.codinghorror.com/blog/archives/000305.html"&gt;http://www.codinghorror.com/blog/archives/000305.html&lt;/a&gt;&lt;a href="http://blufiles.storage.live.com/y1p4HHC2kax1FjzCWp9ttwkDx06-N3vi9fg7U_5xjLzfjXpCj-8pCUOUZdcAj0penixNjUfSR9s1cQ" target="_blank"&gt;&lt;img height=180 alt=googlehardwarecirca1999tr4 src="http://blufiles.storage.live.com/y1p4HHC2kax1FjzCWp9ttwkDx06-N3vi9fg7U_5xjLzfjXpCj-8pCUOUZdcAj0penixNjUfSR9s1cQ" width=240&gt;&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+10+years+and+499%2c999+servers+later...&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!255.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!255.entry</guid><pubDate>Tue, 20 May 2008 13:51:00 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!255/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!255.entry#comment</wfw:comment><dcterms:modified>2008-05-20T13:51:00Z</dcterms:modified></item><item><title>Setting privileges on a specific thread</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!251.entry</link><description>&lt;div&gt;If you've ever needed to set &lt;font color="#c0504d"&gt;privileges to a specific thread Id &lt;/font&gt;only, and not an entire process, you may of visited quite a few MSDN web pages trying to figure out exactly how to achieve this.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Here is a function that does this, call it using a format such as:&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;AddThreadPriv(GetCurrentThreadId(), SE_BACKUP_NAME);&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;font face="Courier New" color="#00b050"&gt;AddThreadPriv(const DWORD in_tid, const std::string&amp;amp; in_rstrPrivilegeName)&lt;br&gt;{&lt;br&gt; ImpersonateSelf(SECURITY_MAX_IMPERSONATION_LEVEL);&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Courier New" color="#00b050"&gt; HANDLE h = OpenThread( TOKEN_ALL_ACCESS, FALSE, in_tid);&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Courier New" color="#00b050"&gt; HANDLE hToken = NULL;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Courier New" color="#00b050"&gt; if(h)&lt;br&gt;  OpenThreadToken(h, TOKEN_ALL_ACCESS, TRUE, &amp;amp;hToken);&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Courier New" color="#00b050"&gt; if( hToken )&lt;br&gt; {&lt;br&gt;  TOKEN_PRIVILEGES tpNew = { 1 };&lt;br&gt;  tpNew.Privileges[0].Attributes = SE_PRIVILEGE_ENABLED;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Courier New" color="#00b050"&gt;  if( ::LookupPrivilegeValue( NULL, in_rstrPrivilegeName.c_str(), &amp;amp;tpNew.Privileges[0].Luid ) )&lt;br&gt;  {&lt;br&gt;   VERIFY( ::AdjustTokenPrivileges( hToken, FALSE, &amp;amp;tpNew, 0, NULL, NULL ) );&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Courier New" color="#00b050"&gt;   CLOSEHANDLE(h);&lt;br&gt;   CLOSEHANDLE(hToken);&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Courier New" color="#00b050"&gt;   return (ERROR_SUCCESS == GetLastError());&lt;br&gt;  }  &lt;br&gt; }&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Courier New" color="#00b050"&gt; CLOSEHANDLE(h);&lt;br&gt; return false;&lt;br&gt;}&lt;/font&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Trying to locate the proper documentation shouldn't be this difficult, certainly not for a company that size.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Setting+privileges+on+a+specific+thread&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!251.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!251.entry</guid><pubDate>Tue, 13 May 2008 16:33:49 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!251/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!251.entry#comment</wfw:comment><dcterms:modified>2008-05-13T16:33:49Z</dcterms:modified></item><item><title>IPv6 is good for business, and will flush out unmaintained crapware</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!250.entry</link><description>&lt;div&gt;Ipv4 will be out of addresses sooner than most people realize.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;This will probably occur within 24 months, and will likely cement Vista as the desktop os replacement for Xp, since its stack has IPv6 out-of-the-box.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;The good news is that this will weed out the smaller software products who do not have the man-power to upgrade their existing applications to this newer reality.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;We may even see well established products lag behind because they may be dealing with too much legacy Ipv4 code.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Time will tell...&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+IPv6+is+good+for+business%2c+and+will+flush+out+unmaintained+crapware&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!250.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!250.entry</guid><pubDate>Sat, 10 May 2008 15:17:11 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!250/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!250.entry#comment</wfw:comment><dcterms:modified>2008-05-10T15:17:11Z</dcterms:modified></item><item><title>What Will Microsoft Do With Credentica?</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!248.entry</link><description>&lt;p&gt;  &lt;p&gt;Written by Bernard Lunn / May 3, 2008  &lt;p&gt;  &lt;p&gt;&lt;a href="http://www.readwriteweb.com/archives/what_will_microsoft_do_with_credentica.php"&gt;http://www.readwriteweb.com/archives/what_will_microsoft_do_with_credentica.php&lt;/a&gt; &lt;p&gt;  &lt;div style="padding-right:0px;display:inline;padding-left:0px;float:none;padding-bottom:0px;margin:0px;padding-top:0px"&gt;   &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+What+Will+Microsoft+Do+With+Credentica%3f&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!248.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!248.entry</guid><pubDate>Tue, 06 May 2008 18:29:51 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!248/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!248.entry#comment</wfw:comment><dcterms:modified>2008-05-06T18:31:35Z</dcterms:modified></item><item><title>The Race to Zero</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!247.entry</link><description>&lt;p&gt;The Race to Zero contest is being held during Defcon 16 at the Riviera Hotel in Las Vegas, 8-10 August 2008. &lt;p&gt;The event involves contestants being given a sample set of viruses and malcode to modify and upload through the contest portal. The portal passes the modified samples through a number of antivirus engines and determines if the sample is a known threat. The first team or individual to pass their sample past all antivirus engines undetected wins that round. Each round increases in complexity as the contest progresses. &lt;p&gt;  &lt;p&gt;&lt;a href="http://www.racetozero.net/index.html"&gt;http://www.racetozero.net/index.html&lt;/a&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+The+Race+to+Zero&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!247.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!247.entry</guid><pubDate>Mon, 05 May 2008 13:36:10 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!247/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!247.entry#comment</wfw:comment><dcterms:modified>2008-05-05T13:36:10Z</dcterms:modified></item><item><title>Bjarne Stroustrup on the Evolution of Languages</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!245.entry</link><description>&lt;p&gt;&lt;a title="http://msdn.microsoft.com/en-us/magazine/cc500572.aspx" href="http://msdn.microsoft.com/en-us/magazine/cc500572.aspx"&gt;http://msdn.microsoft.com/en-us/magazine/cc500572.aspx&lt;/a&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Bjarne+Stroustrup+on+the+Evolution+of+Languages&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!245.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!245.entry</guid><pubDate>Wed, 30 Apr 2008 17:49:35 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!245/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!245.entry#comment</wfw:comment><dcterms:modified>2008-04-30T17:49:35Z</dcterms:modified></item><item><title>twitter</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!244.entry</link><description>&lt;div style="width:176px;text-align:center"&gt;&lt;br&gt;&lt;a style="font-size:10px;color:#fd3699;text-decoration:none" href="http://twitter.com/0utlaw"&gt;follow 0utlaw at http://twitter.com&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+twitter&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!244.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!244.entry</guid><pubDate>Mon, 28 Apr 2008 14:44:23 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!244/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!244.entry#comment</wfw:comment><dcterms:modified>2008-04-28T14:44:23Z</dcterms:modified></item><item><title>Encrypt Anything: 50 Ways to Secure ALL Your Data, Regardless of Medium</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!239.entry</link><description>&lt;div&gt;&lt;a href="http://www.businesscreditcards.com/bootstrapper/encrypt-anything-50-ways-to-secure-all-your-data-regardless-of-medium/" target="_blank"&gt;http://www.businesscreditcards.com/bootstrapper/encrypt-anything-50-ways-to-secure-all-your-data-regardless-of-medium/&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Encrypt+Anything%3a+50+Ways+to+Secure+ALL+Your+Data%2c+Regardless+of+Medium&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!239.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!239.entry</guid><pubDate>Wed, 23 Apr 2008 14:09:44 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!239/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!239.entry#comment</wfw:comment><dcterms:modified>2008-04-23T14:09:44Z</dcterms:modified></item><item><title>Speed up that old system</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!237.entry</link><description>&lt;div&gt;Is your dev machine running &lt;strong&gt;&lt;font color="#ff0000"&gt;slower&lt;/font&gt;&lt;/strong&gt; due to the increased &lt;font color="#00b050"&gt;number &lt;/font&gt;of software pieces tacked on over the years?&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Clean up your &lt;u&gt;registry&lt;/u&gt;, remove &lt;u&gt;duplicate files&lt;/u&gt;, and then &lt;u&gt;defrag&lt;/u&gt; the drive for that new-car smell.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Here are three free utilities to do just that:&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Eusing Free Registry Cleaner&lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.pcworld.com/downloads/file/fid,64953-page,1-c,systemresourcestuneup/description.html"&gt;http://www.pcworld.com/downloads/file/fid,64953-page,1-c,systemresourcestuneup/description.html&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;DoubleKiller&lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.bigbangenterprises.de/en/doublekiller/"&gt;http://www.bigbangenterprises.de/en/doublekiller/&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Defraggler&lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.defraggler.com/"&gt;http://www.defraggler.com/&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Speed+up+that+old+system&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!237.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!237.entry</guid><pubDate>Mon, 21 Apr 2008 13:12:22 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!237/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!237.entry#comment</wfw:comment><dcterms:modified>2008-04-21T13:12:22Z</dcterms:modified></item><item><title>I actually hit an XP Home Limitation</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!233.entry</link><description>&lt;div&gt;I think this is a first for me. I do not think I've ever had to choose one flavor of an OS over an other because of a feature set.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;I'm configuring some of my home LAN and set up remote desktop on the machines so I can log onto each one from my laptop.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Except for one.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;You can't remote desktop to an XP Home edition.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;So I installed something I haven't used in forever, vncviewer. It works OK, but IFF you lock the computer running the vnc server, you can't connect to it; something which is not a limitation using remote desktop.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+I+actually+hit+an+XP+Home+Limitation&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!233.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!233.entry</guid><pubDate>Fri, 18 Apr 2008 14:41:00 GMT</pubDate><slash:comments>1</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!233/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!233.entry#comment</wfw:comment><dcterms:modified>2008-04-18T14:41:00Z</dcterms:modified></item><item><title>Microsoft has released Microsoft Security Development Lifecycle, version 3.2</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!232.entry</link><description>&lt;div&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Microsoft has released &lt;a href="http://go.microsoft.com/?linkid=8685076" target="_blank"&gt;Microsoft Security Development Lifecycle, version 3.2&lt;/a&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;&lt;/font&gt; 
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Tons of great recommendations for your development team, to better your software product, such as&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;&lt;/font&gt; 
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Code priority definitions are provided in the following list:&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.25in"&gt;&lt;font color="#000000"&gt;&lt;span style="font-family:Symbol"&gt;&lt;span style=""&gt;&lt;font size=2&gt;·&lt;/font&gt;&lt;span style="font:7pt 'Times New Roman'"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face=Arial size=2&gt;Pri1 code is considered the most sensitive from a security standpoint. The following examples of Pri1 code are not necessarily a definitive list:&lt;/font&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.5in"&gt;&lt;font color="#000000"&gt;&lt;span style="font-family:Symbol"&gt;&lt;span style=""&gt;&lt;font size=2&gt;·&lt;/font&gt;&lt;span style="font:7pt 'Times New Roman'"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face=Arial size=2&gt;All Internet- or network-facing code&lt;/font&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.5in"&gt;&lt;font color="#000000"&gt;&lt;span style="font-family:Symbol"&gt;&lt;span style=""&gt;&lt;font size=2&gt;·&lt;/font&gt;&lt;span style="font:7pt 'Times New Roman'"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face=Arial size=2&gt;Code in the Trusted Computing Base (TCB) (for example, kernel or SYSTEM code)&lt;/font&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.5in"&gt;&lt;font color="#000000"&gt;&lt;span style="font-family:Symbol"&gt;&lt;span style=""&gt;&lt;font size=2&gt;·&lt;/font&gt;&lt;span style="font:7pt 'Times New Roman'"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face=Arial size=2&gt;Code running as administrator or Local System&lt;/font&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.5in"&gt;&lt;font color="#000000"&gt;&lt;span style="font-family:Symbol"&gt;&lt;span style=""&gt;&lt;font size=2&gt;·&lt;/font&gt;&lt;span style="font:7pt 'Times New Roman'"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face=Arial size=2&gt;Code running as an elevated user (including LocalService and NetworkService)&lt;/font&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.5in"&gt;&lt;font color="#000000"&gt;&lt;span style="font-family:Symbol"&gt;&lt;span style=""&gt;&lt;font size=2&gt;·&lt;/font&gt;&lt;span style="font:7pt 'Times New Roman'"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face=Arial size=2&gt;Features with a history of vulnerability, regardless of version&lt;/font&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.5in"&gt;&lt;font color="#000000"&gt;&lt;span style="font-family:Symbol"&gt;&lt;span style=""&gt;&lt;font size=2&gt;·&lt;/font&gt;&lt;span style="font:7pt 'Times New Roman'"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face=Arial size=2&gt;Any code that handles secret data, such as encryption keys and passwords&lt;/font&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.5in"&gt;&lt;font color="#000000"&gt;&lt;span style="font-family:Symbol"&gt;&lt;span style=""&gt;&lt;font size=2&gt;·&lt;/font&gt;&lt;span style="font:7pt 'Times New Roman'"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face=Arial size=2&gt;Any unverifiable managed code (any code that the standard PEVerify.exe tool reports as not verified)&lt;/font&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.5in"&gt;&lt;font color="#000000"&gt;&lt;span style="font-family:Symbol"&gt;&lt;span style=""&gt;&lt;font size=2&gt;·&lt;/font&gt;&lt;span style="font:7pt 'Times New Roman'"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face=Arial size=2&gt;All code supporting functionality exposed on the maximum attack surface&lt;/font&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.25in"&gt;&lt;font color="#000000"&gt;&lt;span style="font-family:Symbol"&gt;&lt;span style=""&gt;&lt;font size=2&gt;·&lt;/font&gt;&lt;span style="font:7pt 'Times New Roman'"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face=Arial size=2&gt;Pri2 is optionally installed code that runs with user privilege, or code that is installed by default that does not meet the Pri1 criteria.&lt;/font&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.25in"&gt;&lt;font color="#000000"&gt;&lt;span style="font-family:Symbol"&gt;&lt;span style=""&gt;&lt;font size=2&gt;·&lt;/font&gt;&lt;span style="font:7pt 'Times New Roman'"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face=Arial size=2&gt;Pri3 is rarely used code and setup code. (Setup code that handles secret data, such as encryption keys and passwords, is always considered Pri1 code.)&lt;/font&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.25in"&gt;&lt;font color="#000000"&gt;&lt;span style="font-family:Symbol"&gt;&lt;span style=""&gt;&lt;font size=2&gt;·&lt;/font&gt;&lt;span style="font:7pt 'Times New Roman'"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face=Arial size=2&gt;Any code or component that has experienced large numbers of security bugs is considered Pri1 code, even if it would otherwise be considered Pri2 or Pri3. Although the definition of large numbers is subjective, it is important to scrutinize carefully the portions of code that contain the most security bugs.&lt;/font&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.25in"&gt;&lt;font face=Arial color="#000000" size=2&gt;&lt;/font&gt; 
&lt;p style="margin:3pt 0in 3pt 0.25in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Here's a table of recommended settings compiler/linker settings for unmanaged code.&lt;/font&gt;
&lt;h1 style="margin:0.25in 0in 5pt"&gt;&lt;font face="Arial Black" color="#000000" size=5&gt;Win32 Requirements: Unmanaged Code&lt;/font&gt;&lt;/h1&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;strong&gt;&lt;font size=2&gt;&lt;font color="#000000"&gt;&lt;font face=Arial&gt;Table G.1. Win32 Requirements: Unmanaged Code&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;
&lt;p style="margin:0in 0in 0pt"&gt;&lt;font face=Arial color="#ff00ff" size=1&gt; &lt;/font&gt;
&lt;p style="margin:3pt 0in 3pt 0.25in"&gt;
&lt;table style="border-right:medium none;border-top:medium none;border-left:medium none;border-bottom:medium none;border-collapse:collapse" cellspacing=0 cellpadding=0 border=1&gt;
&lt;tbody&gt;
&lt;tr style=""&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:silver 1pt solid;padding-left:4pt;background:#e2e2e2;padding-bottom:0in;border-left:silver 1pt solid;width:19.72%;padding-top:0in;border-bottom:silver 1pt solid" valign=top width="19%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;&lt;strong&gt;Compiler/&lt;br&gt;tool&lt;/strong&gt;&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:silver 1pt solid;padding-left:4pt;background:#e2e2e2;padding-bottom:0in;border-left:#f0f0f0;width:29.32%;padding-top:0in;border-bottom:silver 1pt solid" valign=top width="29%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;&lt;strong&gt;Minimum required version and switches/options&lt;/strong&gt;&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:silver 1pt solid;padding-left:4pt;background:#e2e2e2;padding-bottom:0in;border-left:#f0f0f0;width:24.6%;padding-top:0in;border-bottom:silver 1pt solid" valign=top width="24%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;strong&gt;&lt;font face=Arial color="#000000" size=2&gt;Optimal/&lt;br&gt;recommended version and switches/options&lt;/font&gt;&lt;/strong&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:silver 1pt solid;padding-left:4pt;background:#e2e2e2;padding-bottom:0in;border-left:#f0f0f0;width:26.36%;padding-top:0in;border-bottom:silver 1pt solid" valign=top width="26%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;strong&gt;&lt;font size=2&gt;&lt;font color="#000000"&gt;&lt;font face=Arial&gt;Comments&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;
&lt;tr style=""&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:silver 1pt solid;width:19.72%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="19%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;C/C++ Compiler&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:29.32%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="29%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Microsoft® Visual Studio® .NET 2005&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:24.6%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="24%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:26.36%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="26%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;
&lt;tr style=""&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:silver 1pt solid;width:19.72%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="19%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;cl.exe&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:29.32%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="29%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Version 14.0.50727.42&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Use /GS&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:24.6%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="24%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Use /GS&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:26.36%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="26%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;
&lt;tr style=""&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:silver 1pt solid;width:19.72%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="19%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Link.exe&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:29.32%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="29%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Version 8.0.50727.42&lt;br style=""&gt;&lt;br style=""&gt;&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Use /SAFESEH&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Use /NXCOMPAT and don’t use /NXCOMPAT:NO.&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;See &amp;quot;&lt;/font&gt;&lt;a href="http://securitymario.spaces.live.com/mmm2008-03-18_13.51/#appendix_F"&gt;&lt;u&gt;&lt;font face="Times New Roman" color="#0000ff" size=2&gt;Appendix F: SDL Requirement: No Executable Pages&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;font face=Arial color="#000000" size=2&gt;&amp;quot; for more information.&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:24.6%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="24%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Use /SAFESEH&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Use /functionpadmin:5&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Use /DYNAMICBASE&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:26.36%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="26%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Visual Studio 2005 SP1 is needed for /DYNAMICBASE&lt;/font&gt;
&lt;tr style=""&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:silver 1pt solid;width:19.72%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="19%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;MIDL.exe&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:29.32%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="29%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Version 6.0.366.1&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Use /robust&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:24.6%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="24%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Use /robust&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:26.36%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="26%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;
&lt;tr style=""&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:silver 1pt solid;width:19.72%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="19%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Source code analysis&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:29.32%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="29%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Visual Studio 2005 Code Analysis Options (“/analyze”) &lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;For Visual Studio 2005 code analysis, all warning IDs from the following list must be fixed: 4532 6029 6053 6057 6059 6063 6067 6200 6201 6202 6203 6204 6248 6259 6260 6268 6276 6277 6281 6282 6287 6288 6289 6290 6291 6296 6298 6299 6305 6306 6308 6334 6383 &lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:24.6%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="24%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Visual Studio 2005 Code Analysis Options (“/analyze”). &lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;For Visual Studio 2005 code analysis, all warning IDs from the following list must be fixed: 4532 6029 6053 6057 6059 6063 6067 6200 6201 6202 6203 6204 6248 6259 6260 6268 6276 6277 6281 6282 6287 6288 6289 6290 6291 6296 6298 6299 6305 6306 6308 6334 6383 &lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Standard Annotation Language (SAL): Code annotated with SAL should correct additional warnings in addition to those listed above. See “&lt;/font&gt;&lt;a href="http://securitymario.spaces.live.com/mmm2008-03-18_13.51/#appendix_H"&gt;&lt;u&gt;&lt;font face="Times New Roman" color="#0000ff" size=2&gt;Appendix H: SDL Standard Annotation Language (SAL) Recommendations for Native Win32 Code&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;font face=Arial color="#000000" size=2&gt;” for more information. The warnings are summarized as follows:&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;b style=""&gt;&lt;font face=Arial color="#000000" size=2&gt;SAL Compliance&lt;/font&gt;&lt;/b&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Visual Studio 2005:&lt;span style=""&gt;  &lt;/span&gt;26020 - 26023&lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;b style=""&gt;&lt;font size=2&gt;&lt;font color="#000000"&gt;&lt;font face=Arial&gt;/analyze&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/b&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Visual Studio 2005:&lt;span style=""&gt;  &lt;/span&gt;6029; 6053; 6057; 6059; 6063; 6067; 6201-6202; 6248; 6260; 6276; 6277; 6305&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:26.36%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="26%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Visual Studio 2005 Team Edition contains a publicly available version that is branded as “C/C++ Code Analysis”. &lt;/font&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;
&lt;tr style=""&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:silver 1pt solid;width:19.72%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="19%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;Protecting against Heap Corruption&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:29.32%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="29%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;n/a&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:24.6%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="24%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt;All executable programs written using unmanaged code (.EXE) must call the HeapSetInformation interface. See “&lt;/font&gt;&lt;a href="http://securitymario.spaces.live.com/mmm2008-03-18_13.51/#appendix_I"&gt;&lt;u&gt;&lt;font face="Times New Roman" color="#0000ff" size=2&gt;Appendix I: SDL Requirement: Heap Manager Fail Fast Setting&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;font face=Arial color="#000000" size=2&gt;” for more information.&lt;/font&gt;
&lt;td style="border-right:silver 1pt solid;padding-right:4pt;border-top:#f0f0f0;padding-left:4pt;padding-bottom:0in;border-left:#f0f0f0;width:26.36%;padding-top:0in;border-bottom:silver 1pt solid;background-color:transparent" valign=top width="26%"&gt;
&lt;p style="margin:3pt 0in"&gt;&lt;font face=Arial color="#000000" size=2&gt; &lt;/font&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Microsoft+has+released+Microsoft+Security+Development+Lifecycle%2c+version+3.2&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!232.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!232.entry</guid><pubDate>Tue, 15 Apr 2008 02:58:53 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!232/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!232.entry#comment</wfw:comment><dcterms:modified>2008-04-15T02:58:53Z</dcterms:modified></item><item><title>Been a target of an attack?</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!231.entry</link><description>&lt;div&gt;What do you do if you receive a phishing email?&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;And what will you do if you find a site which is distributing malware?&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;I gathered a list of emails and forms which can be used for reporting phishing sites, phishing emails, and malware sites:&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Report a &lt;font color="#ff0000"&gt;site&lt;/font&gt; that you suspect contains &lt;font color="#ff0000"&gt;malicious software&lt;/font&gt;.&lt;br&gt;&lt;a href="http://www.google.com/safebrowsing/report_badware/"&gt;http://www.google.com/safebrowsing/report_badware/&lt;/a&gt;&lt;br&gt;&lt;a href="http://www.stopbadware.org/home/new"&gt;http://www.stopbadware.org/home/new&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;&lt;br&gt;Report a &lt;font color="#ff0000"&gt;Phishing Page&lt;br&gt;&lt;/font&gt;&lt;a href="http://www.google.com/safebrowsing/report_phish/"&gt;http://www.google.com/safebrowsing/report_phish/&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;&lt;br&gt;Forward &lt;font color="#ff0000"&gt;phishing emails&lt;/font&gt; to my company: &lt;a href="mailto:fraudsubmission@radialpoint.com"&gt;fraudsubmission@radialpoint.com&lt;/a&gt;&lt;br&gt;To fraud watch international: &lt;a href="mailto:scams@fraudwatchinternational.com"&gt;scams@fraudwatchinternational.com&lt;/a&gt;&lt;br&gt;To APWG: &lt;a href="mailto:reportphishing@antiphishing.org"&gt;reportphishing@antiphishing.org&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;If you have found a security vulnerability in any of Microsoft’s online services,&lt;br&gt;&lt;a href="mailto:secure@microsoft.com"&gt;secure@microsoft.com&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;&lt;br&gt;&lt;font color="#ff0000"&gt;virus, worm, or trojan horse&lt;/font&gt; submission to &lt;br&gt;&lt;a href="mailto:avsubmit@submit.microsoft.com"&gt;avsubmit@submit.microsoft.com&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;font color="#ff0000"&gt;spyware&lt;/font&gt; or other malware submission to &lt;br&gt;&lt;a href="mailto:windefend@submit.microsoft.com"&gt;windefend@submit.microsoft.com&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Been+a+target+of+an+attack%3f&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!231.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!231.entry</guid><pubDate>Wed, 09 Apr 2008 19:13:09 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!231/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!231.entry#comment</wfw:comment><dcterms:modified>2008-04-09T19:13:09Z</dcterms:modified></item><item><title>Stroustrup Says C++ Education Needs To Improve</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!225.entry</link><description>&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Although I rarely head over to slashdot anymore, (I prefer Digg), but once in a a while there's a great thread over there. &lt;/div&gt;
&lt;div&gt;This thread &lt;a href="http://developers.slashdot.org/article.pl?no_d2=1&amp;amp;sid=08/03/30/1155216"&gt;http://developers.slashdot.org/article.pl?no_d2=1&amp;amp;sid=08/03/30/1155216&lt;/a&gt; on C++ really shows how much developers either really love it, or hate it.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;One thing is sure, C++ 'experts' are few and far between. With the upcoming TR1 adding yet more to the language, it's difficult just to keep up with everything. &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;I can't imagine a newbie trying to step through 8 boost pointer indirections and not getting discouraged, or trying to decipher template compiler errors.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;For a TR1 overview, check out &lt;a href="http://www.amazon.com/dp/0321412990?tag=montblogonint-20&amp;amp;camp=14573&amp;amp;creative=327641&amp;amp;linkCode=as1&amp;amp;creativeASIN=0321412990&amp;amp;adid=1SK1DHV51WJ7NDEYTMF0&amp;amp;" target="_blank"&gt;Pete Becker's book&lt;/a&gt;. &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://tkfiles.storage.live.com/y1p4HHC2kax1Fib1Npvufl0kI0GG3fLOqOym6HXgdt1mD8knuYpylegXceqotDyuaRRSD4nIGzjxhQ" target="_blank"&gt;&lt;img height=110 alt=pete src="http://tkfiles.storage.live.com/y1p4HHC2kax1Fib1Npvufl0kI0GG3fLOqOym6HXgdt1mD8knuYpylegXceqotDyuaRRSD4nIGzjxhQ" width=88&gt;&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Stroustrup+Says+C%2b%2b+Education+Needs+To+Improve&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!225.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!225.entry</guid><pubDate>Tue, 08 Apr 2008 14:55:41 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!225/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!225.entry#comment</wfw:comment><dcterms:modified>2008-04-08T15:03:37Z</dcterms:modified></item><item><title>Et tu, Amazon?</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!221.entry</link><description>&lt;p&gt;  &lt;p&gt;Amazon has DRM free music. If you want to download songs, that's what you need to be using, &lt;font color="#ff0000"&gt;not iTunes&lt;/font&gt;. &lt;p&gt;But, I tried purchasing the latest Moby CD MP3's, and because I'm a Canadian customer &lt;u&gt;it won't let me&lt;/u&gt;. &lt;p&gt;This reminds me of that great pandora.com service which every coder here used, before it too shut down streaming to Canadian IPs. &lt;p&gt;&lt;a href="http://kbrxeq.tuk.livefilestore.com/y1pco3nbQnfcTy91tOE2VOOgW30qHZeHMJqt6Jj9J6P7Vc-rKz3z4ltm0ZrbEt4RYSzD3A5QJCSlbRh_o53LBVfz-X7ky-XQMa_?PARTNER=WRITER"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" height=129 alt=misc src="http://tk3.storage.msn.com/y1pMuHNZN0Rj5K2MEDG92IGduUU_8nZpuaFL_W3H-uNBn3Afj4XU1jQFuzW8HnzWZ8LvXDoatEowzRFHNs2UzjbnQ?PARTNER=WRITER" width=244 border=0&gt;&lt;/a&gt;  &lt;div style="padding-right:0px;display:inline;padding-left:0px;padding-bottom:0px;margin:0px;padding-top:0px"&gt;   &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Et+tu%2c+Amazon%3f&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!221.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!221.entry</guid><pubDate>Tue, 01 Apr 2008 14:07:09 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!221/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!221.entry#comment</wfw:comment><dcterms:modified>2008-04-30T17:59:34Z</dcterms:modified></item><item><title>OpenDNS rocks!</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!213.entry</link><description>&lt;div&gt;So far this year I am using two amazing products.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.jungledisk.com/" target="_blank"&gt;Jungledisk&lt;/a&gt; has rendered all my USB keys useless. I have it installed on &lt;u&gt;all&lt;/u&gt; my machines, my sample code and all my tools are saved in the amazon cloud.&lt;/div&gt;
&lt;div&gt;I don't even use its backup ability, just the storage &lt;font color="#0070c0"&gt;space.&lt;/font&gt; Finally no more stumbling around my DVDs looking for some old piece of code which I now need!&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;And &lt;a href="http://www.opendns.com/" target="_blank"&gt;OpenDNS&lt;/a&gt; rocks. Is it faster? Maybe. Is it safer? Maybe? is it &lt;strong&gt;better&lt;/strong&gt;? &lt;font color="#ff0000"&gt;Absolutely&lt;/font&gt;. Here's what I like most, besides the fact its free:&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;I no longer need to run my parental control tool client-side? Why is this &lt;strong&gt;good?&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;- Less client-side code means your Cpu is free to do other things&lt;/div&gt;
&lt;div&gt;- Less client-side code means less risk of it crashing&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Now, my parental tool is good, I was one of the guys who wrote it. I even &lt;u&gt;optimized&lt;/u&gt; the networking code of late. &lt;font color="#0070c0"&gt;But it uses an OOB network call to validate Urls&lt;/font&gt;! It cannot possibly go faster than a DNS based solution.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Now, instead of validating pbdkids.org (while the browser sits there and waits), by sending the Url to another server which categorizes the Url, the categorization is done at the DNS request level. Here's a snapshot of the OpenDNS web site where you can configure your networks:&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://tkfiles.storage.live.com/y1p4HHC2kax1FjPyqfgY0RSJDPHz1-4eQ-LkVnxMpzGn6PO03QNbGyPxUgukx1xukHi8I5Y2Mu66Is" target="_blank"&gt;&lt;img height=200 alt=delme src="http://tkfiles.storage.live.com/y1p4HHC2kax1FjPyqfgY0RSJDPHz1-4eQ-LkVnxMpzGn6PO03QNbGyPxUgukx1xukHi8I5Y2Mu66Is" width=213&gt;&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+OpenDNS+rocks!&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!213.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!213.entry</guid><pubDate>Tue, 25 Mar 2008 17:44:13 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!213/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!213.entry#comment</wfw:comment><dcterms:modified>2008-03-25T17:44:13Z</dcterms:modified></item><item><title>Anti-Malware field keeps getting more crowded</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!206.entry</link><description>&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Another &lt;font color="#7030a0"&gt;new &lt;/font&gt;Anti-Malware company is launched: &lt;a href="http://blogs.zdnet.com/security/?p=366"&gt;http://blogs.zdnet.com/security/?p=366&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;I have installed their product on a couple of my machines, and I really like it so far. I've been a proponent of securing the HTTP pipe between clients and web sites; that can provide users &lt;font color="#ff0000"&gt;MORE &lt;/font&gt;security than an up-to-date Av definition file...try it out, it's free &lt;a href="http://hautesecure.com/index.aspx"&gt;http://hautesecure.com/index.aspx&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;They seem to use the google safe browsing API to use the google blacklists (phishing + malware), &lt;a href="http://code.google.com/apis/safebrowsing/developers_guide.html"&gt;http://code.google.com/apis/safebrowsing/developers_guide.html&lt;/a&gt; in addition to other feeds. They send the URL to a backend (here's an actual trace for &lt;font color="#00b050"&gt;offensive-security.com&lt;/font&gt;):&lt;/div&gt;
&lt;div&gt;- Http: Request, GET /v1.2/QueryUrl.aspx&lt;br&gt;  - Request: &lt;br&gt;     Command: GET&lt;br&gt;   - URI: /v1.2/QueryUrl.aspx?Url=http:%2F%2Fwww.offensive-security.com%2F&amp;amp;HostId=6d0c1292-5589-4648-83c8-c68ed1a95adb&amp;amp;ClientVersion=1.2.1.1906&amp;amp;QueryThirdParty=1&amp;amp;QueryFrom=Client&lt;br&gt;    - Uri: &lt;br&gt;       Location: /v1.2/QueryUrl.aspx&lt;br&gt;       Url: http:%2F%2Fwww.offensive-security.com%2F&lt;br&gt;       HostId: 6d0c1292-5589-4648-83c8-c68ed1a95adb&lt;br&gt;       ClientVersion: 1.2.1.1906&lt;br&gt;       QueryThirdParty: 1&lt;br&gt;       QueryFrom: Client &lt;br&gt;     ProtocolVersion: HTTP/1.1&lt;br&gt;     UserAgent:  HauteSecure 1.0&lt;br&gt;     Host:  communitystats-cws.hautesecure.net&lt;br&gt;     HeaderEnd: CRLF&lt;br&gt;&lt;/div&gt;
&lt;div&gt;This is similar to the solution we use in our security product, which also validates URLs against a phishing blacklist (not a malware blacklist though).&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&amp;quot;The four founders are Iain Mulholland, a former security strategist and manager of the MSRC (Microsoft Security Response Center); Frank Swiderski, a software architect who did stints at Microsoft and @Stake; Rob Vucic, who worked at Redmond on Microsoft’s Secure Windows Initiative Internet Crime Investigations team; and Steve Anderson, who worked on the Windows Server team at Microsoft....TechCrunch &lt;a href="http://www.techcrunch.com/2007/07/10/site-advisor-20-haute-secure-launches-to-detect-and-block-malware/"&gt;&lt;font color="#004d99"&gt;reports&lt;/font&gt;&lt;/a&gt; that the company launched with $500,000 in funding&amp;quot;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;500K$ !? That's it? Ask my friend Austin, who's recently blogged about a couple of Montreal based shops being bought by US companies, will tell you that that's &lt;font color="#ff0000"&gt;peanuts&lt;/font&gt;!&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.billionswithzeroknowledge.com/2008/03/07/congratulations-its-a-startup-canadian-fairchildren-unite/"&gt;http://www.billionswithzeroknowledge.com/2008/03/07/congratulations-its-a-startup-canadian-fairchildren-unite/&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Anti-Malware+field+keeps+getting+more+crowded&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!206.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!206.entry</guid><pubDate>Fri, 14 Mar 2008 15:11:11 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!206/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!206.entry#comment</wfw:comment><dcterms:modified>2008-03-14T15:11:11Z</dcterms:modified></item><item><title>Great vacation reading</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!205.entry</link><description>&lt;div&gt;I had the pleasure of reading The Web Application hacker's Handbook on my vacation.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;It's terrific, check it out on amazon: &lt;a href="http://www.amazon.com/gp/product/0470170778?ie=UTF8&amp;amp;tag=montblogonint-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0470170778" target="_blank"&gt;The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://tkfiles.storage.live.com/y1p4HHC2kax1FhGYIRO8VuvSLB2CelTGwgbiI1rL_FVCqnbNWL_nV2LLgGm-9vkUokyZiYi2FnHE5k" target="_blank"&gt;&lt;img height=240 alt=wahh src="http://tkfiles.storage.live.com/y1p4HHC2kax1FhGYIRO8VuvSLB2CelTGwgbiI1rL_FVCqnbNWL_nV2LLgGm-9vkUokyZiYi2FnHE5k" width=240&gt;&lt;/a&gt;&lt;img style="border-right:medium none;border-top:medium none;margin:0px;border-left:medium none;border-bottom:medium none" height=1 alt="" src="http://www.assoc-amazon.com/e/ir?t=montblogonint-20&amp;amp;l=as2&amp;amp;o=1&amp;amp;a=0470170778" width=1 border=0&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Great+vacation+reading&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!205.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!205.entry</guid><pubDate>Tue, 11 Mar 2008 17:48:47 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!205/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!205.entry#comment</wfw:comment><dcterms:modified>2008-04-08T15:05:53Z</dcterms:modified></item><item><title>Disk encryption may not be secure enough, new research finds</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!201.entry</link><description>&lt;div&gt;Yet more proof that in computer security, there is no silver bullets and no free lunches.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Read the article &lt;a href="http://www.news.com/8301-13578_3-9876060-38.html" target="_blank"&gt;here&lt;/a&gt;.&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Disk+encryption+may+not+be+secure+enough%2c+new+research+finds&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!201.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!201.entry</guid><pubDate>Mon, 25 Feb 2008 20:32:39 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!201/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!201.entry#comment</wfw:comment><dcterms:modified>2008-02-25T20:32:39Z</dcterms:modified></item><item><title>"The Incredi" attack</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!199.entry</link><description>&lt;div&gt;I was probing a possible attack vector in a &amp;quot;security suite&amp;quot; type application, and found an interesting twist based on, &lt;strong&gt;The Incredibles&lt;/strong&gt; of all things...&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Recall the scene where Mr Incredible has trouble fighting off a robot, and ends up winning by having the robot attack itself? By using clever tricks, we can convince &amp;quot;security suites&amp;quot; to attack specific files, and remove them, simply by having the file trigger a hit (a positive virus detection).&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;How is this possible? Well, today's security vendors are constantly battling to achieve levels of certification by detecting as many malwares as possible, they &lt;strong&gt;want&lt;/strong&gt; to add database entries!&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;I won't list real-world examples, but here's an example:&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Just run [echo &amp;quot;removed for security purposes&amp;quot; &amp;gt; filetoberemoved] and presto!&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Obviously here I can just remove the file my own self, but in fact I have the anti-malware level do so, which they often can do with elevated privileges!&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+%22The+Incredi%22+attack&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!199.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!199.entry</guid><pubDate>Fri, 22 Feb 2008 22:15:40 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!199/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!199.entry#comment</wfw:comment><dcterms:modified>2008-02-22T22:17:44Z</dcterms:modified></item><item><title>Welcome to the jungle</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!198.entry</link><description>&lt;div&gt;I finally started using &lt;a href="http://www.jungledisk.com/" target="_blank"&gt;jungle disk&lt;/a&gt;, and after a little problem with it on Vista (which I managed to &lt;a href="http://forum.jungledisk.com/viewtopic.php?t=9484"&gt;workaround&lt;/a&gt;) I really enjoy it! Not only is it dirt cheap, but you use your existing Amazon account to pay...I use picasa for pixs simply because it finds the pictures locally easily, but that seems to have an upper limit of 1 G only..&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Welcome+to+the+jungle&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!198.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!198.entry</guid><pubDate>Wed, 20 Feb 2008 17:49:24 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!198/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!198.entry#comment</wfw:comment><dcterms:modified>2008-02-20T17:49:24Z</dcterms:modified></item><item><title>Windows Vista Media Center + Xbox 360</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!197.entry</link><description>&lt;div&gt;I set up a small home network (3PCs), with Vista Media Center on a laptop.&lt;/div&gt;
&lt;div&gt;It detects the digital camera, imports the pictures, easily and seamlessly.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Then, one day, I had the Xbox 360 console on, and it &lt;em&gt;detected&lt;/em&gt; this (they are &lt;strong&gt;&lt;font color="#c00000"&gt;not&lt;/font&gt;&lt;/strong&gt; connected, but only share the same router) after which the Vista Media center asked me if I wanted to add it as an Extender.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Without any other configuration, I was browsing pictures (from the laptop) on my TV using the Xbox 360!!!&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;The only downside to my Vista+Xbox+HD Tv setup is the fact that I have an Xbox HD-DVD...something which will apparantly be replaced with Blu-Ray eventually. Perhaps Microsoft will put out a dual-reader.&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Windows+Vista+Media+Center+%2b+Xbox+360&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!197.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!197.entry</guid><pubDate>Mon, 18 Feb 2008 15:10:46 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!197/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!197.entry#comment</wfw:comment><dcterms:modified>2008-02-18T15:13:28Z</dcterms:modified></item><item><title>Zune + Windows Mobile</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!196.entry</link><description>&lt;div&gt;I've been using the new &lt;a href="http://www.zunescene.com/new-zune-scorpio/" target="_blank"&gt;Zune 80GB &lt;/a&gt;instead of my iPod Nano. &lt;/div&gt;
&lt;div&gt;The video podcasts are crystal clear on the 3.2&amp;quot; LCD, and space is not an issue.&lt;/div&gt;
&lt;div&gt;It understands WMA files, and can sync Wi-Fi, something an iPod cannot do.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;What I would really appreciate, is an iZune type device which incorporates all the Windows Mobile features, with those of the Zune.&lt;/div&gt;
&lt;div&gt;There's no reason to carry a cell phone &lt;em&gt;AND&lt;/em&gt; and Zune; these should be &lt;font color="#d99694"&gt;merged&lt;/font&gt; into a single device.&lt;/div&gt;
&lt;div&gt;As it stands my Windows mobile HTC cell cannot hold 80GB obviousy...&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Zune+%2b+Windows+Mobile&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!196.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!196.entry</guid><pubDate>Mon, 18 Feb 2008 15:01:34 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!196/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!196.entry#comment</wfw:comment><dcterms:modified>2008-02-18T15:04:46Z</dcterms:modified></item><item><title>Tracking someone's IP</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!184.entry</link><description>&lt;div&gt;If you ever need to know where an IP is from, say because of an email you want to trace (never mind web mail of course), here's what I use:&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.geobytes.com/IpLocator.htm" target="_blank"&gt;geobytes&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;and&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.ip2location.com/free.asp" target="_blank"&gt;ip2location&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;(You can see your own ip here: &lt;a href="http://www.ip-adress.com/" target="_blank"&gt;http://www.ip-adress.com/&lt;/a&gt;)&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Tracking+someone's+IP&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!184.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!184.entry</guid><pubDate>Thu, 25 Oct 2007 14:41:05 GMT</pubDate><slash:comments>1</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!184/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!184.entry#comment</wfw:comment><dcterms:modified>2007-10-25T14:41:05Z</dcterms:modified></item><item><title>XSSDetect Public Beta now Available</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!183.entry</link><description>&lt;div&gt;XSSDetect runs as a Visual Studio plug-in and can detect potential XSS issues in managed code.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;While the functionality may seem straight forward, many years of research and hard work have gone into making XSSDetect a reality.  XSSDetect is a stripped down version of our enterprise ready Code Analysis Tool for .NET code bases (CAT.NET for short).  CAT.NET adds such features as VSTF integration, centralized reporting using web services, customized rulesets and filters, integration with FXCop and MSBUILD as well as the ability to run from the command line to integrate with your build processes (or if you're just old school and rock it like that ;)  &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://blogs.msdn.com/ace_team/archive/2007/10/22/xssdetect-public-beta-now-available.aspx" target="_blank"&gt;XSSDetect Public Beta now Available&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+XSSDetect+Public+Beta+now+Available&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><category>Computers and Internet</category><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!183.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!183.entry</guid><pubDate>Wed, 24 Oct 2007 16:21:59 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!183/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!183.entry#comment</wfw:comment><dcterms:modified>2007-10-24T16:21:59Z</dcterms:modified></item><item><title>Some easy places to obtain malware</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!182.entry</link><description>&lt;div&gt;&lt;a href="http://www.frame4.net/mdpro/index.php" target="_blank"&gt;Malware distribution project &lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://vx.netlux.org/vl.php" target="_blank"&gt;Virus Collection (VX heavens)&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.offensivecomputing.net/?q=node"&gt;Offensive Computing&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Some+easy+places+to+obtain+malware&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><category>Computers and Internet</category><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!182.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!182.entry</guid><pubDate>Wed, 24 Oct 2007 16:13:51 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!182/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!182.entry#comment</wfw:comment><dcterms:modified>2007-10-24T16:13:51Z</dcterms:modified></item><item><title>Indiana University Security Awareness kit</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!176.entry</link><description>&lt;div&gt;Has some very funny posters!&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt; see &lt;a href="http://itpo.iu.edu/education/ncamkit.html"&gt;http://itpo.iu.edu/education/ncamkit.html&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;table cellspacing="0" border="0"&gt;&lt;tr height="8"&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top"&gt;&lt;p&gt;&lt;a href="http://blufiles.storage.live.com&amp;#47;y1piwqOXiZAJkL6s0ILvrGJEGqACNvFCbOlYWEFzSjggQAS_jB3TRMB_Z57o16BXVoR"&gt;&lt;img src="http://storage.live.com&amp;#47;items&amp;#47;F4C4C340D0D11C44&amp;#33;177&amp;#58;thumbnail" border="0"&gt;&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;td width="15"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Indiana+University+Security+Awareness+kit&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!176.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!176.entry</guid><pubDate>Sun, 16 Sep 2007 01:04:11 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!176/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!176.entry#comment</wfw:comment><dcterms:modified>2007-09-16T01:04:11Z</dcterms:modified></item><item><title>iPhone, _not_</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!173.entry</link><description>&lt;div&gt;&lt;a href="http://www.america.htc.com/products/p4000/default.html" target="_blank"&gt;I'm now using a HTC P4000 Pocket PC Phone&lt;/a&gt;.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;It's got everything a cell/pda can need, &lt;a href="http://www.microsoft.com/windowsmobile/6/default.mspx" target="_blank"&gt;and I upgraded to Windows Mobile 6&lt;/a&gt;.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Best of all, &lt;a href="http://www.thebestpageintheuniverse.net/c.cgi?u=iphone" target="_blank"&gt;it's not an iPhone&lt;/a&gt;.&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+iPhone%2c+_not_&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!173.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!173.entry</guid><pubDate>Sun, 19 Aug 2007 03:49:06 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!173/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!173.entry#comment</wfw:comment><dcterms:modified>2007-08-19T03:49:06Z</dcterms:modified></item><item><title>Security Links, and more</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!172.entry</link><description>&lt;div&gt;On June 8th 2007, Robin Bloor at the register wrote an article entitled, &amp;quot;&lt;a href="http://www.theregister.co.uk/2007/06/08/death_of_av/"&gt;The slow death of AV technology&lt;/a&gt;&amp;quot;. Then on August 9th, same guy same web site, writes an article entitled, &amp;quot;&lt;a href="http://www.theregister.co.uk/2007/08/09/anti_virus_testing/"&gt;Is AV product testing corrupt?&lt;/a&gt;&amp;quot;. Draw your own conclusions.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Mr Bloor is well liked over at the &lt;a href="http://blogs.authentium.com/virusblog/?p=187"&gt;Authentium Blog&lt;/a&gt;.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Here's a good article entitled, &amp;quot;&lt;span&gt;&lt;a href="http://www.securityfocus.com/columnists/449"&gt;Security conferences versus practical knowledge&lt;/a&gt;&lt;/span&gt;&amp;quot; which states, &amp;quot;the computer conference - specifically the computer security conference - has declined in relevance to the everyday sys-admin and network security practitioners.&amp;quot;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;I really enjoy conferences of all types, and I too think they've diminished in quality, and quantity; But *I* believe it is also due to the popularity of blogging by *everyone*; Why attend a conference on a topic you've just read it online?&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;A ok article entitled &amp;quot;&lt;a href="http://www.modsecurity.org/blog/archives/Secure_Browsing_Mode_Proposal.pdf"&gt;Secure Browsing Mode&lt;/a&gt;&amp;quot; by Ivan Ristic.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;u&gt;&lt;font color="#800080"&gt;&lt;a href="http://www.istartedsomething.com/20070727/msft-roadmap-fy08-beyond/"&gt;Microsoft products roadmap for FY08 and beyond&lt;/a&gt;&lt;/font&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div&gt;&lt;u&gt;&lt;font color="#800080"&gt;&lt;/font&gt;&lt;/u&gt; &lt;/div&gt;
&lt;div&gt;Fred George blog on &lt;a href="http://processpeoplepods.blogspot.com/2007/08/pods-ideal-agile-team-structures.html"&gt;Agile Team structures&lt;/a&gt;.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://blogs.msdn.com/somasegar/archive/2007/08/08/visual-c-futures.aspx"&gt;Vice President for the Microsoft Developer Division, blogged about the future of Visual C++&lt;/a&gt;.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;An finally, &lt;a href="https://www.stolenidsearch.com/search/"&gt;this site&lt;/a&gt; &amp;quot;monitors&amp;quot; the internet for your credit card or SSN.&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Security+Links%2c+and+more&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!172.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!172.entry</guid><pubDate>Tue, 14 Aug 2007 03:01:25 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!172/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!172.entry#comment</wfw:comment><dcterms:modified>2007-08-14T03:01:25Z</dcterms:modified></item><item><title>Wasting Time is not Time Wasted</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!171.entry</link><description>&lt;div&gt;Or something like that...every summer I take some time off on the beach and read computer magazines, those found in bookstores. It's an interesting read to say the least, a good change from the usual technical books.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;This summer I've learned that using ink from another manufacturer can void your printer warranty.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Wasting+Time+is+not+Time+Wasted&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!171.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!171.entry</guid><pubDate>Wed, 01 Aug 2007 14:22:53 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!171/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!171.entry#comment</wfw:comment><dcterms:modified>2007-08-01T14:22:53Z</dcterms:modified></item><item><title>Cool software article - 10 developers for the price of one</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!167.entry</link><description>&lt;div&gt;This is so true...&lt;a href="http://haacked.com/archive/2007/06/25/understanding-productivity-differences-between-developers.aspx"&gt;great article&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Cool+software+article+-+10+developers+for+the+price+of+one&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!167.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!167.entry</guid><pubDate>Sun, 15 Jul 2007 01:50:42 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!167/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!167.entry#comment</wfw:comment><dcterms:modified>2007-07-15T01:52:09Z</dcterms:modified></item><item><title>Some of My old blog at web.archive.org</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!164.entry</link><description>&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://web.archive.org/web/20060207233647/http:/bubbler.net/pages/560399"&gt;http://web.archive.org/web/20060207233647/http:/bubbler.net/pages/560399&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Some+of+My+old+blog+at+web.archive.org&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!164.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!164.entry</guid><pubDate>Wed, 20 Jun 2007 19:01:18 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!164/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!164.entry#comment</wfw:comment><dcterms:modified>2007-06-20T19:01:18Z</dcterms:modified></item><item><title>My company is ranked 32nd in Profit 100 Canada's fastest growing companies</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!162.entry</link><description>&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.canadianbusiness.com/rankings/profit100/list.jsp?pageID=profile&amp;amp;profile=32&amp;amp;year=2007&amp;amp;type=profile&amp;amp;listType=P100"&gt;http://www.canadianbusiness.com/rankings/profit100/list.jsp?pageID=profile&amp;amp;profile=32&amp;amp;year=2007&amp;amp;type=profile&amp;amp;listType=P100&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Radialpoint at google finance&lt;/div&gt;
&lt;div&gt;&lt;a href="http://finance.google.com/finance?cid=14413378"&gt;http://finance.google.com/finance?cid=14413378&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+My+company+is+ranked+32nd+in+Profit+100+Canada's+fastest+growing+companies&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!162.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!162.entry</guid><pubDate>Tue, 19 Jun 2007 03:08:06 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!162/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!162.entry#comment</wfw:comment><dcterms:modified>2007-06-19T03:08:06Z</dcterms:modified></item><item><title>C++/CLI</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!143.entry</link><description>&lt;div&gt; &lt;/div&gt;
&lt;div&gt;On 3-20-2006 I wrote:&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&amp;quot;and over the horizon looms another programming shift; from 32 to 64 bits, but also, (and here's the crystal ball part) from C++/MFC to the &lt;a href="http://msdn.microsoft.com/visualc/homepageheadlines/ecma/default.aspx"&gt;&lt;u&gt;&lt;font color="#0000ff"&gt;C++/CLI&lt;/font&gt;&lt;/u&gt;&lt;/a&gt; / &lt;a href="http://msdn.microsoft.com/winfx/"&gt;&lt;u&gt;&lt;font color="#0000ff"&gt;WinFx&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;. The similar pattern in both scenarios: the ubiquity of the MS OS, and the MS framework to leverage that OS.&amp;quot;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;I am now reading a terrific book on &lt;a href="http://www.amazon.com/C%2B%2B-CLI-Visual-Language-NET/dp/1590597052/ref=sr_1_1/105-9180350-3333204?ie=UTF8&amp;amp;s=books&amp;amp;qid=1181228546&amp;amp;sr=1-1"&gt;C++/CLI by Gordon Hogenson&lt;/a&gt;.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;&lt;div&gt;&lt;table cellspacing="0" border="0"&gt;&lt;tr height="8"&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top"&gt;&lt;p&gt;&lt;a href="http://blufiles.storage.live.com&amp;#47;y1ppDkBdtuR6S3d5iIc65Hf5BAInCVxpXYrQNMJMgelNncMHr0wGaexBiOFJYNT2w5T"&gt;&lt;img src="http://storage.live.com&amp;#47;items&amp;#47;F4C4C340D0D11C44&amp;#33;144&amp;#58;thumbnail" border="0"&gt;&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;td width="15"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+C%2b%2b%2fCLI&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!143.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!143.entry</guid><pubDate>Thu, 07 Jun 2007 15:18:33 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!143/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!143.entry#comment</wfw:comment><dcterms:modified>2007-06-13T03:19:25Z</dcterms:modified></item><item><title>Rich Internet Apps</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!140.entry</link><description>&lt;div&gt;On 0-3-2005 I was mumbled:&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;&amp;gt;&lt;/div&gt;
&lt;div&gt;
&lt;p&gt;I'll be honest I've tried several web incarnations of desktop apps, and in general the less they try to do, the better they were at doing it.
&lt;p&gt;For example, &lt;a href="http://www.thinkfree.com/"&gt;&lt;u&gt;&lt;font color="#0000ff"&gt;thinkfree&lt;/font&gt;&lt;/u&gt;&lt;/a&gt; has an online 'suite' which allows you to edit excel documents, word documents, all without installing any software (except for the Java Runtime Engine).
&lt;p&gt;Of course it freezes up just about everytime I scroll in the excel document I uploaded...and that's the crux of the problem, are you willing to potentially lose all of your existing work!?
&lt;p&gt;&amp;lt;
&lt;p&gt;So I figured I'd give ThinkFree another spin, it's been two years so surely they go their stuff running better....not. When I tried creating a presentation document, or a spreadsheet, it choked with &amp;quot;Error encountered&amp;quot;.
&lt;p&gt;Maybe in another 2 years then...&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Rich+Internet+Apps&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!140.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!140.entry</guid><pubDate>Thu, 07 Jun 2007 14:51:59 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!140/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!140.entry#comment</wfw:comment><dcterms:modified>2007-06-07T14:51:59Z</dcterms:modified></item><item><title>Netsh Commands for Wireless Local Area Network (WLAN) Entry from 5-17-2007</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!138.entry</link><description>&lt;div&gt;
&lt;p&gt;Being at a hotel, the wireless connections are flaky and I often have to change routers.
&lt;p&gt;I could use the Vista UI to browse and connect to wireless LANs, but here's what I do to find the best signal, from the command prompt:
&lt;p&gt;netsh wlan show networks mode=bssid
&lt;p&gt;For details on the Netsh Commands for Wireless Local Area Network (WLAN)
&lt;p&gt;see: &lt;a href="http://technet2.microsoft.com/WindowsVista/en/library/f435edbe-1d50-4774-bae2-0dda33eaeb2f1033.mspx?mfr=true"&gt;&lt;u&gt;&lt;font color="#0000ff"&gt;http://technet2.microsoft.com/WindowsVista/en/library/f435edbe-1d50-4774-bae2-0dda33eaeb2f1033.mspx?mfr=true&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;
&lt;p&gt;You'll get an output similar to the following:
&lt;p&gt;Interface Name : Wireless Network Connection&lt;br&gt;There are 5 networks currently visible.
&lt;p&gt;SSID 1 : VIGER-A&lt;br&gt;    Network type            : Infrastructure&lt;br&gt;    Authentication          : Open&lt;br&gt;    Encryption              : None&lt;br&gt;    BSSID 1                 : 00:1b:11:4b:40:d5&lt;br&gt;         Signal             : 84%&lt;br&gt;         Radio Type         : 802.11g&lt;br&gt;         Channel            : 6&lt;br&gt;         Basic Rates (Mbps) : 1 2 5.5 11&lt;br&gt;         Other Rates (Mbps) : 6 9 12 18 24 36 48 54
&lt;p&gt;SSID 2 : dlink&lt;br&gt;    Network type            : Infrastructure&lt;br&gt;    Authentication          : Open&lt;br&gt;    Encryption              : None&lt;br&gt;    BSSID 1                 : 00:1b:11:4b:64:c1&lt;br&gt;         Signal             : 0%&lt;br&gt;         Radio Type         : 802.11g&lt;br&gt;         Channel            : 6&lt;br&gt;         Basic Rates (Mbps) : 1 2 5.5 11&lt;br&gt;         Other Rates (Mbps) : 6 9 12 18 24 36 48 54&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Netsh+Commands+for+Wireless+Local+Area+Network+(WLAN)+Entry+from+5-17-2007&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!138.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!138.entry</guid><pubDate>Tue, 05 Jun 2007 20:40:02 GMT</pubDate><slash:comments>12</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!138/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!138.entry#comment</wfw:comment><dcterms:modified>2007-06-05T20:40:02Z</dcterms:modified></item><item><title>Enabling no-execute Entry from 4-30-2007</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!137.entry</link><description>&lt;div&gt;
&lt;p&gt;On XP32, to enable no execute protection (which is a good thing security-wise), you edit your boot.ini file&lt;br&gt;and simply add &amp;quot;/NoExecute=AlwaysOn&amp;quot;. Then, after half your apps fail to load, you can go back and undo that change...
&lt;p&gt;But what about Vista32? There's no boot.ini so how does one enable no execute protection? (Other than running the 64-bit version)&lt;br&gt;By using the &amp;quot;bcdedit&amp;quot; command. Simply execute the following.
&lt;p&gt;bcdedit /set nx AlwaysOn
&lt;p&gt;I haven't had to remove it on my Vista32, so far..&lt;br&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Enabling+no-execute+Entry+from+4-30-2007&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!137.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!137.entry</guid><pubDate>Tue, 05 Jun 2007 20:37:23 GMT</pubDate><slash:comments>1</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!137/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!137.entry#comment</wfw:comment><dcterms:modified>2007-06-05T20:37:23Z</dcterms:modified></item><item><title>ghost in the machine Entry from 5-13-2007</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!136.entry</link><description>&lt;div&gt;
&lt;p&gt;This following paper by google confirms what I've been saying for some time,&lt;br&gt;securing the sites is as important as securing the desktop.
&lt;p&gt;Google has access to all of the Internet's web sites essentially, and they can verify what some of these sites&lt;br&gt;contain, namely malware.
&lt;p&gt;These results show why SiteAdvisor was sold for so much...
&lt;p&gt;&lt;br&gt;The Ghost In The Browser Analysis of Web-based Malware&lt;br&gt;&lt;a href="http://www.usenix.org/events/hotbots07/tech/full_papers/provos/provos.pdf"&gt;&lt;u&gt;&lt;font color="#0000ff"&gt;http://www.usenix.org/events/hotbots07/tech/full_papers/provos/provos.pdf&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+ghost+in+the+machine+Entry+from+5-13-2007&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!136.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!136.entry</guid><pubDate>Tue, 05 Jun 2007 20:35:45 GMT</pubDate><slash:comments>2</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!136/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!136.entry#comment</wfw:comment><dcterms:modified>2007-06-05T20:35:45Z</dcterms:modified></item><item><title>Vista developers, on your mark, set, amazon! Entry from 5-14-2007</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!135.entry</link><description>&lt;div&gt;
&lt;p&gt;If you're a windows developer you cannot afford _not_ to read &amp;quot;Writing Secure Code for Windows Vista&amp;quot;.
&lt;p&gt;From the creators of &amp;quot;Writing Secure Code&amp;quot;, another great book, this one covers essentially Vista changes and additions.
&lt;p&gt;&lt;a href="http://www.microsoft.com/MSPress/books/10723.aspx"&gt;&lt;u&gt;&lt;font color="#0000ff"&gt;http://www.microsoft.com/MSPress/books/10723.aspx&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;
&lt;p&gt; 
&lt;p&gt;Alot of what I've learned was obtained through trial &amp;amp; error, and various MSDN articles.&lt;br&gt;It's really good to have a hard-copy explanation direct from the horses mouth to validate and consolidate all this information in one place;&lt;br&gt;and there is alot of information.
&lt;p&gt;&lt;br&gt;Couple of things I'm not totally clear on, in the &amp;quot;consolidated URL&amp;quot; section, they recommend not using some APIs such as&lt;br&gt;InternetCrackUrl(), and InternetCreateUrl()
&lt;p&gt;ok, those are in &amp;lt;wininet.h&amp;gt;, but what about UrlGetPart, and UrlGetLocation? Those are actually from the Windows light-weight utility APIs;&lt;br&gt;&amp;lt;shlwapi.h&amp;gt;. I thought using those were a *good thing* because if some wininet Apis were later deprecated, the shell DLL would later change&lt;br&gt;so that your code would not have to....
&lt;p&gt;And CapiCOM. I've been using CapiCOM on Vista forever, it's been working, I even just now updated it with the one from my XP machine, because&lt;br&gt;it was recently updated on a patch tuesday (&lt;a href="http://support.microsoft.com/kb/931906"&gt;&lt;u&gt;&lt;font color="#0000ff"&gt;http://support.microsoft.com/kb/931906&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;).&lt;br&gt;They say that it is &amp;quot;no longer supported on Vista&amp;quot;; I guess you shouldn't confuse that with &amp;quot;no longer works&amp;quot;.&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Vista+developers%2c+on+your+mark%2c+set%2c+amazon!+Entry+from+5-14-2007&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!135.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!135.entry</guid><pubDate>Tue, 05 Jun 2007 20:33:51 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!135/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!135.entry#comment</wfw:comment><dcterms:modified>2007-06-05T20:33:51Z</dcterms:modified></item><item><title>phishing paper from Carnegie Mellon Entry from 11-13-2006</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!134.entry</link><description>&lt;div&gt;
&lt;p&gt;The paper entitled, &amp;quot;&lt;b&gt;Protecting People from Phishing: The Design and Evaluation of an Embedded Training Email System &lt;/b&gt;&amp;quot; is available here &lt;a href="http://www.cylab.cmu.edu/default.aspx?id=2253" target="_blank"&gt;&lt;u&gt;&lt;font color="#0000ff"&gt;http://www.cylab.cmu.edu/default.aspx?id=2253&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;. 
&lt;p&gt;I try to keep up-to-speed on all the anti-phishing trends and found this idea really cute, 
&lt;p&gt; 
&lt;p&gt;&amp;quot;Our approach consists of periodically sending users fake phishing emails that are actually from our system rather than from a scammer. If a person falls for our fake email and clicks on a link, we display an intervention that provides immediate feedback about what happened and what simple actionable steps users could take to protect themselves.&amp;quot;
&lt;p&gt;I can already see a simimlar approach used for viruses; send users EXE's, archives, CMD files, etc which if executed simply warns the user that this is a very &lt;font color="#cc0000"&gt;dangerous&lt;/font&gt; action.
&lt;p&gt; 
&lt;p&gt;&amp;quot;Our email approach is designed to provide training in the course of normal email usage. If users are interested in learning more, they can then play our game to gain a more thorough understanding of phishing attacks and ways of identifying phishing web sites.
&lt;p&gt;The four suggestions we decided to teach people were: 
&lt;p&gt;• Never click on links in emails 
&lt;p&gt;• Initiate contact (i.e. manually type in URLs into the web browser) 
&lt;p&gt;• Call customer service 
&lt;p&gt;• Never give out personal information&amp;quot;
&lt;p&gt; 
&lt;p&gt;In any case, I too dislike the toolbar-like approach to site validation; at my company we use a different approach, we replace the &lt;font color="#3333ff"&gt;entire&lt;/font&gt; HTML page with &lt;font color="#ff6600"&gt;our own&lt;/font&gt;.&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+phishing+paper+from+Carnegie+Mellon+Entry+from+11-13-2006&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!134.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!134.entry</guid><pubDate>Tue, 05 Jun 2007 20:29:43 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!134/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!134.entry#comment</wfw:comment><dcterms:modified>2007-06-05T20:29:43Z</dcterms:modified></item><item><title>What is an architect? Entry from 11-27-2006</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!133.entry</link><description>&lt;div&gt;
&lt;p&gt;
&lt;p&gt;I had the &lt;font color="#ff6600"&gt;displeasure&lt;/font&gt; of working with an architect who's &lt;font color="#663366"&gt;entire day&lt;/font&gt; was spent doing, and then redoing, &lt;font color="#ff0000"&gt;UML&lt;/font&gt; diagrams. Of course we never used those diagrams to do the actual work, instead I build a &amp;quot;test app&amp;quot; which consisted of a dialog-like UI with a button to cover each of the major features of the component I was building.
&lt;p&gt;Back then (this was pre-dot-com) extreme programming was inexistant, and getting ISO 9001 certified was *the* big thing. I wasn't comfortable with a process that consisted of &amp;quot;&lt;em&gt;document what you do, do what you document&lt;/em&gt;.&amp;quot; but hey I was just a kid.
&lt;p&gt;I never knew of the existence of an actual extreme-architecture-like job title, but it exists. The &lt;a href="http://agilearchitect.org/agile/principles.htm" target="_blank"&gt;&lt;u&gt;&lt;font color="#0000ff"&gt;agilearchitect.org website&lt;/font&gt;&lt;/u&gt;&lt;/a&gt; is as plain as is it &lt;strong&gt;interesting&lt;/strong&gt;. Turns out I am an architect after-all, only a productive one:
&lt;p&gt; 
&lt;p&gt;The key objectives for an Agile Architect are:
&lt;ol&gt;
&lt;li&gt;Deliver working solutions 
&lt;li&gt;Maximise stakeholder value 
&lt;li&gt;Find solutions which meet the goals of all stakeholders 
&lt;li&gt;Enable the next effort 
&lt;li&gt;Manage change and complexity&lt;/ol&gt;&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+What+is+an+architect%3f+Entry+from+11-27-2006&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT1=securitymario"&gt;</description><comments>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!133.entry#comment</comments><guid isPermaLink="true">http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!133.entry</guid><pubDate>Tue, 05 Jun 2007 20:26:55 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://securitymario.spaces.live.com/blog/cns!F4C4C340D0D11C44!133/comments/feed.rss</wfw:commentRss><wfw:comment>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!133.entry#comment</wfw:comment><dcterms:modified>2007-06-05T20:26:55Z</dcterms:modified></item><item><title>Digging for my old blog</title><link>http://securitymario.spaces.live.com/Blog/cns!F4C4C340D0D11C44!132.entry</link><description>&lt;div&gt;I found the best way to look up entries from my old blog was with google queries using&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;mario site:bubbler.net&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;I'll try to revive those that seem still relevant.&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-809307349871158204&amp;page=RSS%3a+Digging+for+my+old+blog&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=securitymario.spaces.live.com&amp;amp;GT