The problem with Web security is that, as important as it is, it is also very complex.... Fact is, you are part of the problem and don’t know what you did to cause it.
A site devoted to discussing techniques that promote quality and ethical practices in software development.
Sunday, January 24, 2010
Web Security article & tutorial
This is an excellent article on web security providing an excellent tutorial on this topic. This is worth considering:
Labels:
Web Service
Thursday, January 21, 2010
Cooking your own EllipseCOM
During a conversation with a reader on my blog post, it has come to my attention that I have missed a key piece of information with respect to MIMSX.
In order for one to build one's own aggregation server, apart from following the recipe you also need to use a version of MIMSX that is at least of version 2.2.4.2 or later. Earlier version contains an internal setting bug making it an invalid candidate to aggregate.
Unfortunately, one cannot tell from a COM component's registered attributes or type library if it is supporting aggregation. You need to build the aggregation server to see if you can successfully create the aggregated component and wired up the query interface mechanism.
Also during instantiation, you must create an instance of the aggregation server and then query the interface of IMimsxServer; you do not create an instance of MIMSX.
In order for one to build one's own aggregation server, apart from following the recipe you also need to use a version of MIMSX that is at least of version 2.2.4.2 or later. Earlier version contains an internal setting bug making it an invalid candidate to aggregate.
Unfortunately, one cannot tell from a COM component's registered attributes or type library if it is supporting aggregation. You need to build the aggregation server to see if you can successfully create the aggregated component and wired up the query interface mechanism.
Also during instantiation, you must create an instance of the aggregation server and then query the interface of IMimsxServer; you do not create an instance of MIMSX.
Labels:
COM Programming
Tuesday, January 19, 2010
My view on the effectiveness of antivirus software is vindicated
I have always formed the opinion that antivirus is a very ineffective and blunt device in protecting one from being attacked. This is not to say that I am flirting carelessly with danger on the Internet. What I am saying is that there are far better and efficient way to protect oneself than to rely on antivirus software.
Recent attack on Google in China invoked a number of comments and postmortem analysis and one of them has vindicated my view,
Recent attack on Google in China invoked a number of comments and postmortem analysis and one of them has vindicated my view,
nCircle's Storms believes that one "lesson from this breach is that antivirus software really is dead. For quite a while it's been the least effective tool in the IT enterprise security toolset because it's only effective against known malware. It only takes one piece of customized malware to infiltrate your network."Antivirus is often like looking in the rear vision mirror. It is totally useless until its database has been updated.
In my e-mails with Kurtz he wasn't as bold about declaring the death of antivirus tools, but he did suggest a new approach as well. "There are technologies like whitelisting--McAfee Application Control, that would have prevented successful exploitation of this zero day and many others--without signatures. Companies really need to start augmenting their blacklisting with whitelisting protection technologies."
Labels:
Anti-Virus,
Malware,
Security,
Trojan
Fujitsu has slate tablets before even Apple considering it
Fujitsu has released several slate tablets many years before Apple even has considered it. They just did not put an 'i' in front of the slate and did not impose all sorts of constrains on the owner.
Labels:
Tablet PC
Monday, January 18, 2010
App Store?
Many in the blog-space and media seem to have Apple's App Store undue recognition as something new and innovative. What a load of myopic view!
Handango has been selling software for PDA and Smartphone way before iPhone was even on a drawing board.
Handango has been selling software for PDA and Smartphone way before iPhone was even on a drawing board.
Thursday, January 14, 2010
How do you secure your .Net Application?
Here is a very comprehensive set of guidelines to show how to secure your .Net application after it has been developed.
Guidelines to develope secure ADO.Net application
This is a very comprehensive set of guidelines in making your ADO.Net secure.
Writing a secure ADO.NET application involves more than avoiding common coding pitfalls such as not validating user input. An application that accesses data has many potential points of failure that an attacker can exploit to retrieve, manipulate, or destroy sensitive data. It is therefore important to understand all aspects of security, from the process of threat modeling during the design phase of your application, to its eventual deployment and ongoing maintenance.
Subscribe to:
Posts (Atom)