
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ent="http://www.purl.org/NET/ENT/1.0/">
	<channel>
		<title>TechEd Bloggers Security</title>
		<link>http://www.msteched.com/online/blogs.aspx</link>
		<description></description>
		<managingEditor>info@indepth-tech.com</managingEditor>
		<lastBuildDate>Tue, 09 Feb 2010 04:31:46 GMT</lastBuildDate>
		<generator>Ashton RssHandler</generator>
		<!--
		<image>
			<url>http://techedbloggers.net/images/TechEd_Bloggers_small.gif</url>
			<title>TechEd Bloggers</title>
			<link>http://TechEdBloggers.net</link>
		</image>
		-->
		
					<item>
						
						<title>Workaround for Communicator 2007 Certificate Error</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22166.item</link>
						<pubDate>Thu, 08 May 2008 21:22:02 GMT</pubDate>
						<author>Desmond Lee</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22166.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3749' ent:classification='BLOG'>Desmond Lee</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22166.item'&gt;Desmond Lee&lt;/a&gt; writes,
"If the issuing CA is trustworthy, such as from an internal PKI source, you can manually import the missing certificate as follows:..." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22166.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Thu, 08 May 2008 21:22:02 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Need Suggestions on File Security Compares</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22090.item</link>
						<pubDate>Fri, 02 May 2008 20:22:08 GMT</pubDate>
						<author>Aaron Tiensivu</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22090.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3229' ent:classification='BLOG'>Aaron Tiensivu</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22090.item'&gt;Aaron Tiensivu&lt;/a&gt; writes,
"Anyone know of a utility out there that can handle about 2 terabytes of file security compares? I don't care about the file contents in this case, only the security that is 'stamped' on both sides....Any help is most appreciated...leave a comment on this entry or shoot me an e-mail." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22090.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Fri, 02 May 2008 20:22:08 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Privacy is in the Eye of the Beholder</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22080.item</link>
						<pubDate>Fri, 02 May 2008 17:01:59 GMT</pubDate>
						<author>Vittorio Bertocci</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22080.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='350' ent:classification='BLOG'>Vittorio Bertocci</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22080.item'&gt;Vittorio Bertocci&lt;/a&gt; writes,
"I think that the law of user control and consent is always a great CRC check; I suggest that we should all work for making its application super easy from the technical standpoint, so that it can be applied consistently whenever necessary..." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22080.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Fri, 02 May 2008 17:01:59 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>BitLocker Drive Preparation Tool Free</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22052.item</link>
						<pubDate>Wed, 30 Apr 2008 15:39:30 GMT</pubDate>
						<author>Aaron Tiensivu</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22052.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3229' ent:classification='BLOG'>Aaron Tiensivu</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22052.item'&gt;Aaron Tiensivu&lt;/a&gt; writes,
"....a very handy tool to have to install Bitlocker on your system after you have already installed an OS to an unencrypted volume...." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22052.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 30 Apr 2008 15:39:30 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Web Server Attacks not related to IIS</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22010.item</link>
						<pubDate>Mon, 28 Apr 2008 17:40:32 GMT</pubDate>
						<author>Microsoft Security Response Center</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22010.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='2386' ent:classification='BLOG'>Microsoft Security Response Center</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22010.item'&gt;Microsoft Security Response Center&lt;/a&gt; writes,
"...these attacks are in no way related to Microsoft Security Advisory ...The attacks are facilitated by SQL injection exploits and are not issues related to IIS 6.0, ASP, ASP.Net or Microsoft SQL technologies. SQL injection attacks enable malicious users to execute commands..." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/22010.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Mon, 28 Apr 2008 17:40:32 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Security Compliance Beta for SCCM </title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21981.item</link>
						<pubDate>Sun, 27 Apr 2008 15:14:42 GMT</pubDate>
						<author>Matthijs Vreeken</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21981.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21981.item'&gt;Matthijs Vreeken&lt;/a&gt; writes,
"It’s not unusual for administrators to use rules in Opsmgr to monitor for significant configuration changes of concern in regulatory compliance, but this is generally not the most effective way to address the problem....That is where the sister product if Operations Manager, System Center Configuration Manager 2007, plays a role in augmenting ACS in the auditing process....Security Compliance Management toolkit provides customers with.... " &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21981.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Sun, 27 Apr 2008 15:14:42 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Prevent IIS Attacks</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21975.item</link>
						<pubDate>Sat, 26 Apr 2008 16:32:25 GMT</pubDate>
						<author>Brian Kelley</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21975.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3399' ent:classification='BLOG'>Brian Kelley</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21975.item'&gt;Brian Kelley&lt;/a&gt; writes,
"The recent slate of attacks on IIS servers don't seem to be an attack directly against IIS or against SQL Server itself....reason we're seeing infections on such a large scale is....If you're using software that either a large community uses or that you purchased, don't assume it's safe.... " &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21975.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Sat, 26 Apr 2008 16:32:25 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Enforcing Out-of-the-box NAP Security Updates</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21973.item</link>
						<pubDate>Fri, 25 Apr 2008 21:10:06 GMT</pubDate>
						<author>Jeff Sigman</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21973.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3862' ent:classification='BLOG'>Jeff Sigman</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21973.item'&gt;Jeff Sigman&lt;/a&gt; writes,
"&lt;img src=&quot;http://napteam.members.winisp.net/WSHV.jpg&quot; align =&quot;right&quot; width=&quot;93&quot; height=&quot;68&quot;&gt;We’ve been getting a lot of questions about how update enforcement using the WSHA/WSHV actually works. The first thing to keep in mind is that the WSHA/WSHV only enforces security updates. The easiest way to discuss update enforcement is to step through each part" &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21973.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Fri, 25 Apr 2008 21:10:06 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Infected Webpage Every 5 Seconds</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21934.item</link>
						<pubDate>Wed, 23 Apr 2008 19:34:10 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21934.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21934.item'&gt;Don Patterson&lt;/a&gt; writes,
"IT security and control firm Sophos has published its latest Security Threat Report, which looks at worldwide cybercrime during the first quarter of 2008. The findings..." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21934.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 23 Apr 2008 19:34:10 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Storm Worm - Blog and Codec Based Attacks</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21911.item</link>
						<pubDate>Tue, 22 Apr 2008 20:10:02 GMT</pubDate>
						<author>Harry Waldron</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21911.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3927' ent:classification='BLOG'>Harry Waldron</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21911.item'&gt;Harry Waldron&lt;/a&gt; writes,
"Storm has once again turned its eye to the blogging community, specifically the Blogspot.com community. Several blogger sites with random or very quirky names have been sporting a love theme, Storm style. These sites appear to..." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21911.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 22 Apr 2008 20:10:02 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Adobe Products BMP Vulnerability</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21909.item</link>
						<pubDate>Tue, 22 Apr 2008 20:03:02 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21909.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21909.item'&gt;Don Patterson&lt;/a&gt; writes,
"...reported in multiple Adobe products....The vulnerability is caused due to a boundary error when handling BMP files. This can be exploited to cause a buffer overflow via a BMP file having..." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21909.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 22 Apr 2008 20:03:02 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Cross-Site Scripting Flaw - XSS</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21905.item</link>
						<pubDate>Tue, 22 Apr 2008 19:13:27 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21905.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21905.item'&gt;Don Patterson&lt;/a&gt; writes,
"...The content in this case targeted cross-site scripting flaw (XSS), an exceedingly common type of vulnerability that can be used to automatically redirect Web browsers viewing the affected page to another site...." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21905.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 22 Apr 2008 19:13:27 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>The TechEd 2008 Security Show</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21850.item</link>
						<pubDate>Thu, 17 Apr 2008 18:18:40 GMT</pubDate>
						<author>Kai Axford</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21850.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3874' ent:classification='BLOG'>Kai Axford</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21850.item'&gt;Kai Axford&lt;/a&gt; writes,
"You have spoken and we have listened...I'm going to be delivering not one, not two, but FOUR sessions on the TechEd Online stage...My goal for these episodes is..." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21850.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Thu, 17 Apr 2008 18:18:40 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Fix for XML Core Services 4.0 SP 2 Failed Security Update</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21827.item</link>
						<pubDate>Tue, 15 Apr 2008 21:42:34 GMT</pubDate>
						<author>Jeff Guillet</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21827.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='4032' ent:classification='BLOG'>Jeff Guillet</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21827.item'&gt;Jeff Guillet&lt;/a&gt; writes,
"I recently built up a new Hyper-V virtual domain environment based on a single server image. Unfortunately, my base image had a problem downloading and installing the Security Update for Microsoft XML Core Services 4.0 Service Pack 2....Here's what the event logs looked like:..To fix this issue, download the update from Microsoft and manually install it." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21827.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 15 Apr 2008 21:42:34 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Surprise! Stolen Hardware Basis for Most Breaches</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21749.item</link>
						<pubDate>Wed, 09 Apr 2008 19:01:49 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21749.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21749.item'&gt;Don Patterson&lt;/a&gt; writes,
"While the number of unique variants of malicious software more than quadrupled in 2007, lost laptops and storage devices -- not malicious software -- were the most common cause of a data breaches, security firm Symantec said in its latest Internet Security Threat Report released on Tuesday. The report, based on data from more than 40,000 network devices..." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21749.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 09 Apr 2008 19:01:49 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Checking for Pointer Math</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21743.item</link>
						<pubDate>Wed, 09 Apr 2008 17:46:46 GMT</pubDate>
						<author>David LeBlanc</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21743.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='4203' ent:classification='BLOG'>David LeBlanc</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21743.item'&gt;David LeBlanc&lt;/a&gt; writes,
"...Someone pointed out that it isn't sufficient to check for whether the pointer math wrapped, but that we also need to check that the resulting pointer is in our buffer. They then came to the possibly erroneous conclusion that really all you had to do was to check whether the resulting index was in range. The real problem with this is that there's so many different scenarios that I don't see a one size fits all technique....
Where the comment is absolutely correct is that if we're just doing a simple de-reference (get the nth element), then all we have to do is determine if n is somewhere in the array...." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21743.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 09 Apr 2008 17:46:46 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>5 Security Elements I plus 4A</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21742.item</link>
						<pubDate>Wed, 09 Apr 2008 17:00:46 GMT</pubDate>
						<author>Kai Axford</author>
						<category>Editor's Picks</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21742.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3874' ent:classification='BLOG'>Kai Axford</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21742.item'&gt;Kai Axford&lt;/a&gt; writes,
"&lt;img src=&quot;http://blogs.technet.com/blogfiles/kaiaxford/WindowsLiveWriter/RSA2008Day1CraigMundieandOmarosa_11FE3/CraigMundieRSA_thumb.jpg&quot; align =&quot;right&quot; width=&quot;98&quot; height=&quot;67&quot;&gt;The discussion was really around the concept of this concept we refer to &quot;I + 4A&quot; which stands for &quot;Identity + Access, Authentication, Authorization, Access Control and Audit&quot; which are the 5 major security elements that help establish trust. The whitepaper is designed to get people to engage us...You're not going to get any &quot;Microsoft marketing&quot; in this whitepaper....let us know...is this on the right track or where does this concept need to be revised" &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21742.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Wed, 09 Apr 2008 17:00:46 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Security Bulletins for April 8, 2008</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21736.item</link>
						<pubDate>Tue, 08 Apr 2008 22:49:23 GMT</pubDate>
						<author>Don Patterson</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21736.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3926' ent:classification='BLOG'>Don Patterson</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21736.item'&gt;Don Patterson&lt;/a&gt; writes,
"These updates must be downloaded from the microsoft.com download center or Windows Update. See the individual bulletins for details. Because some malicious messages attempt to masquerade as official Microsoft security notices, it is recommended that you physically type the URLs into your web browser and not click on the hyperlinks provided." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21736.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 08 Apr 2008 22:49:23 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Phishing Attacks disguised as Microsoft Security Bulletin releases</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21732.item</link>
						<pubDate>Tue, 08 Apr 2008 22:21:09 GMT</pubDate>
						<author>Harry Waldron</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21732.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3927' ent:classification='BLOG'>Harry Waldron</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21732.item'&gt;Harry Waldron&lt;/a&gt; writes,
"Emails with the subject line of &quot;Critical Patch Released: Microsoft Security Bulletin MS08-64738&quot; should be deleted as malware could be automatically downloaded and silently installed on vulnerable PCs...." &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21732.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Tue, 08 Apr 2008 22:21:09 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
					<item>
						
						<title>Turning Security Principles Useful</title>
						<link>http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21709.item</link>
						<pubDate>Mon, 07 Apr 2008 22:11:47 GMT</pubDate>
						<author>JD Meier</author>
						<category>Security</category>
						<guid isPermaLink="true">http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21709.item</guid>
						<ent:cloud ent:href="http://teched.indepthtalk.net">
						
								<ent:topic ent:id='3979' ent:classification='BLOG'>JD Meier</ent:topic>
							
								<ent:topic ent:id='4558' ent:classification='SECT'>Security</ent:topic>
							
						</ent:cloud>

<description>	
&lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21709.item'&gt;JD Meier&lt;/a&gt; writes,
"....This is simply a baseline set of principles so that you don't have to start from scratch.  You can build on this set and tailor for your specific context.  I find that while having a set of principles helps, that you can't stop there.  To share the knowledge and help others use the information, it's important to encapsulate the principles in patterns as well as show concrete examples" &lt;a href='http://teched.indepthtalk.net/TechEd2007/Tracks/Security/21709.item'&gt;more&lt;/a&gt;
&lt;div style="color:black;font-size:10px;font-style:italic;margin-top:2px;margin-bottom:-2px" &gt;Mon, 07 Apr 2008 22:11:47 GMT&lt;/div&gt;
&lt;hr/&gt;
&lt;small&gt;

&lt;/small&gt;
</description>
	


					</item>
				
	</channel>
</rss>