
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ent="http://www.purl.org/NET/ENT/1.0/">
	<channel>
		<title>TechEd Bloggers Identity, Access, and Security</title>
		<link>http://www.msteched.com/online/blogs.aspx</link>
		<description></description>
		<managingEditor>info@indepth-tech.com</managingEditor>
		<lastBuildDate>Tue, 09 Feb 2010 08:55:30 GMT</lastBuildDate>
		<generator>Ashton RssHandler</generator>
		<!--
		<image>
			<url>http://techedbloggers.net/images/TechEd_Bloggers_small.gif</url>
			<title>TechEd Bloggers</title>
			<link>http://TechEdBloggers.net</link>
		</image>
		-->
		
					<item>
						
						<title>Private Cloud Security is no Security at All</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28296.item</link>
						<pubDate>Wed, 03 Feb 2010 17:33:26 GMT</pubDate>
						<author>Sam Johnston</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28296.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='4524' ent:classification='BLOG'>Sam Johnston</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28296.item'&gt;Sam Johnston&lt;/a&gt; writes,
"...don't take it for granted that private cloud offerings are secure, and in the unlikely event that the systems themselves are secure, don't assume you or your provider can run them in a more secure fashion than a &quot;public&quot; cloud provider could. Incidents like this go a long way towards realising one of my predictions for 2010...in that Private clouds will be discredited by year end..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28296.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 03 Feb 2010 17:33:26 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Scenarios Using ADFS with Amazon EC2</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28115.item</link>
						<pubDate>Thu, 14 Jan 2010 19:06:29 GMT</pubDate>
						<author>Steve Riley</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28115.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3949' ent:classification='BLOG'>Steve Riley</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28115.item'&gt;Steve Riley&lt;/a&gt; writes,
"...release of a whitepaper written by David Chappell that explores these federation scenarios in more detail. David begins [with] your Amazon EC2 resources are placed in an Amazon Virtual Private Cloud (VPC) and joined to your own corporate domain; here, there’s no use of ADFS. Then he illustrates the two scenarios...and shows how it would work with both ADFS 1.1 and ADFS 2.0..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28115.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Thu, 14 Jan 2010 19:06:29 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Apply Security Update if You are Using Windows Embedded CE 6.0</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28108.item</link>
						<pubDate>Wed, 13 Jan 2010 19:59:39 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28108.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28108.item'&gt;Don Patterson&lt;/a&gt; writes,
"...Rereleased this bulletin to add Windows Embedded CE 6.0 to affected software. The new update for Windows Embedded CE 6.0..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28108.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 13 Jan 2010 19:59:39 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Windows Security Risk on Embedded OpenType Font Engine</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28092.item</link>
						<pubDate>Tue, 12 Jan 2010 21:18:59 GMT</pubDate>
						<author>Microsoft Security Response Center</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28092.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='2386' ent:classification='BLOG'>Microsoft Security Response Center</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28092.item'&gt;Microsoft Security Response Center&lt;/a&gt; writes,
"...Critical bulletin affecting all versions of Windows. The bulletin, MS10-001, addresses one vulnerability in the Embedded OpenType Font Engine and is Critical on Windows 2000. For all other versions of Windows...The following risk and impact slide reflects the aggregate severity and exploitability index rating for this bulletin..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28092.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 12 Jan 2010 21:18:59 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Fix for OCS 2007, NTLM and Edge Server Login Problems</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28083.item</link>
						<pubDate>Tue, 12 Jan 2010 06:47:01 GMT</pubDate>
						<author>Aaron Tiensivu</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28083.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3229' ent:classification='BLOG'>Aaron Tiensivu</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28083.item'&gt;Aaron Tiensivu&lt;/a&gt; writes,
"...If NTLM is “broken” inside the domain between domain controllers and OCS servers (front End/edge), the Office Communicator client will act as if the user entered an invalid username or password. The error message on the client computer is very misleading and everyone external will not be able to log in...verall, assuming all your software and operating systems on your network work properly with NTLMv2, I recommend..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28083.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 12 Jan 2010 06:47:01 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Security Advisory for Adobe Reader and Acrobat - January 7, 2010</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/28063.item</link>
						<pubDate>Fri, 08 Jan 2010 00:36:01 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/28063.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28063.item'&gt;Don Patterson&lt;/a&gt; writes,
"...Among other issues, this update will resolve a critical vulnerability in Adobe Reader and Acrobat 9.2 and earlier (CVE-2009-4324) on Windows, Macintosh and UNIX. There are reports that this issue is being actively exploited in the wild; the exploit targets" &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/28063.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Fri, 08 Jan 2010 00:36:01 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Client and Cloud Security whitepaper Download</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27898.item</link>
						<pubDate>Tue, 15 Dec 2009 17:22:49 GMT</pubDate>
						<author>Georgeo Pulikkathara</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27898.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='1092' ent:classification='BLOG'>Georgeo Pulikkathara</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27898.item'&gt;Georgeo Pulikkathara&lt;/a&gt; writes,
"...security guidance from Microsoft Trustworthy Computing on client + Cloud security...talks about client + cloud security in today’s environment,and what you need to consider before taking off for the cloud..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27898.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 15 Dec 2009 17:22:49 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>ACS Noise Filter: Translating Server Security EventIDs to Windows Server 2008</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27873.item</link>
						<pubDate>Mon, 14 Dec 2009 13:26:30 GMT</pubDate>
						<author>Marnix Wolf</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27873.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
								<ent:topic ent:id='4807' ent:classification='BLOG'>Marnix Wolf</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27873.item'&gt;Marnix Wolf&lt;/a&gt; writes,
"...what if you are designing an ACS solution for Windows Server 2008 servers? Yes, you can apply the filter as stated in those very same documents. But it won’t work...I ran the same ‘formula’ against the other matching EventIDs and the same number came out! Time for a test. I took a non-matched W2K03 Security EventID..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27873.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Mon, 14 Dec 2009 13:26:30 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Securing Windows Live When Using ASP.NET MVC</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27815.item</link>
						<pubDate>Wed, 09 Dec 2009 18:05:45 GMT</pubDate>
						<author>Angus Logan</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27815.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='2756' ent:classification='BLOG'>Angus Logan</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27815.item'&gt;Angus Logan&lt;/a&gt; writes,
"I’ve been working with some of our centralized Windows Live security and privacy folks recently. These guys are super skilled...lessons learnt about securing Windows Live when using ASP.NET MVC...." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27815.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 09 Dec 2009 18:05:45 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>4 Microsoft Security Notifications - December 8, 2009</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27798.item</link>
						<pubDate>Tue, 08 Dec 2009 23:27:28 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27798.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27798.item'&gt;Don Patterson&lt;/a&gt; writes,
"...Vulnerability in Internet Explorer Could Allow Remote Code Execution...Credential Relaying Attacks on Integrated Windows Authentication...Extended Protection for Authentication...Security Enhancements for the Indeo Codec..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27798.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 08 Dec 2009 23:27:28 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Deep Linking Your Way Out of Home Realm Discovery</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27761.item</link>
						<pubDate>Fri, 04 Dec 2009 00:51:46 GMT</pubDate>
						<author>Vittorio Bertocci</author>
						<category>SOA and Business Processes</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27761.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='350' ent:classification='BLOG'>Vittorio Bertocci</ent:topic>
							
								<ent:topic ent:id='4546' ent:classification='SECT'>SOA and Business Processes</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27761.item'&gt;Vittorio Bertocci&lt;/a&gt; writes,
"This method is not a solution to home realm discovery, rather it is a “shortcut” that piggybacks on existing home real discovery solutions which must be in place for this to work. Furthermore, this has to be arranged by every partner and relies completely on the fact that the users will access the application through the specially crafter URL as opposed to..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27761.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Fri, 04 Dec 2009 00:51:46 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>MS Security Bulletin Dec 2009 - 3 Critical 3 Important</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27760.item</link>
						<pubDate>Thu, 03 Dec 2009 19:42:55 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27760.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27760.item'&gt;Don Patterson&lt;/a&gt; writes,
"This is an advance notification of security bulletins that Microsoft is intending to release on December 8, 2009.  3 Rated Critial and 3 Rated Important..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27760.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Thu, 03 Dec 2009 19:42:55 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Better Way to Synchronize a Remote Replica By Using a Proxy Provider</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27706.item</link>
						<pubDate>Tue, 01 Dec 2009 01:36:50 GMT</pubDate>
						<author>David P</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27706.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='2675' ent:classification='BLOG'>David P</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27706.item'&gt;David P&lt;/a&gt; writes,
"There's a better way! A more efficient method is to use a proxy provider on the local computer. The proxy provider sends metadata and data to a provider that runs on the remote computer, allowing the bulk of synchronization processing to be distributed to..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27706.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 01 Dec 2009 01:36:50 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>New IE 6/7 Vulnerabilities - Move to IE8 More Secure</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27684.item</link>
						<pubDate>Wed, 25 Nov 2009 19:36:21 GMT</pubDate>
						<author>Harry Waldron</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27684.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3927' ent:classification='BLOG'>Harry Waldron</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27684.item'&gt;Harry Waldron&lt;/a&gt; writes,
"...Please be careful at all websites and move to IE8 if possible as it's more secure. Many AV products have..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27684.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 25 Nov 2009 19:36:21 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Updated RIA and WIF Samples</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27668.item</link>
						<pubDate>Tue, 24 Nov 2009 21:03:41 GMT</pubDate>
						<author>Eugenio Pace</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27668.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3149' ent:classification='BLOG'>Eugenio Pace</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27668.item'&gt;Eugenio Pace&lt;/a&gt; writes,
"...configured for Windows integrated security...The app has an “auto-provisioning” feature that automatically registers external users into the application. There’s a stored procedure that will try to locate the user name in the database (Users table), and if it is not found, it will simply add a new record:..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27668.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 24 Nov 2009 21:03:41 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Security Advisory Released on IE 6 &amp; 7</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27662.item</link>
						<pubDate>Tue, 24 Nov 2009 20:34:38 GMT</pubDate>
						<author>Microsoft Security Response Center</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27662.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='2386' ent:classification='BLOG'>Microsoft Security Response Center</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27662.item'&gt;Microsoft Security Response Center&lt;/a&gt; writes,
"...We just released Security Advisory 977981 concerning an issue affecting Internet Explorer 6 and Internet Explorer 7 that could lead to remote code execution. At this time, we are not aware of any active attacks seeking to use this vulnerability...I want to point out that Internet Explorer 8..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27662.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 24 Nov 2009 20:34:38 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Keyboard Shortuct Tip Accesses Your Admin Rights</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27555.item</link>
						<pubDate>Thu, 12 Nov 2009 19:56:24 GMT</pubDate>
						<author>Kurt Roggen</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27555.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3689' ent:classification='BLOG'>Kurt Roggen</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27555.item'&gt;Kurt Roggen&lt;/a&gt; writes,
"...here is an easy way to gain access to your administrative rights (read: admin token) with a keyboard shortcut...This avoids the typical right-click “Run as Administrator” action..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27555.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Thu, 12 Nov 2009 19:56:24 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Hashing Alone is Not a Life Saver</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27553.item</link>
						<pubDate>Thu, 12 Nov 2009 19:06:53 GMT</pubDate>
						<author>Prabath Siriwardena</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27553.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='4403' ent:classification='BLOG'>Prabath Siriwardena</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27553.item'&gt;Prabath Siriwardena&lt;/a&gt; writes,
"...Hashing is a one way - irreversible algorithm which is used to store passwords in databases...The hacker who has access to your database can still replace your hashed password with a hash he caculated with a clear text known to him. Then he can login to your account with the clear text known to him - because..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27553.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Thu, 12 Nov 2009 19:06:53 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Nov 2009 Security Bulletins Affect Windows - Win Server - Office</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27523.item</link>
						<pubDate>Tue, 10 Nov 2009 22:30:03 GMT</pubDate>
						<author>Microsoft Security Response Center</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27523.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='2386' ent:classification='BLOG'>Microsoft Security Response Center</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27523.item'&gt;Microsoft Security Response Center&lt;/a&gt; writes,
"...released six security bulletins addressing a total of 15 vulnerabilities. Four affect Windows and Windows Server and two affect Microsoft Office products (Excel and Word). As we do every month, we have prepared our Risk &amp; Impact and our Deployment Priority guidance..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27523.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 10 Nov 2009 22:30:03 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Outlook Web Access Social Engineering Malware Scam</title>
						<link>http://teched.indepthtalk.net/TechEd/Tracks/Security/27258.item</link>
						<pubDate>Thu, 15 Oct 2009 18:48:01 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Identity, Access, and Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd/Tracks/Security/27258.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27258.item'&gt;Don Patterson&lt;/a&gt; writes,
"...discovered a new wave of malicious attacks claiming to be an update for Microsoft Outlook Web Access (OWA). Victims receive a message leading to a site to apply mailbox settings which were supposedly changed due to a &quot;security upgrade.&quot; The especially dangerous thing..." &lt;a href='http://teched.indepthtalk.net/TechEd/Tracks/Security/27258.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Thu, 15 Oct 2009 18:48:01 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
	</channel>
</rss>