Jesper's Blog

Obligatory file photo: I am a Senior Security Strategist in the Security Technology Unit at Microsoft. My job is to explain to our customers how to run Microsoft products securely, and to the extent that it is needed, help the product groups figu

January, 2006

Posts
  • Jesper's Blog

    More security theater, in the air

    • 11 Comments
    Recently I was on yet another flight, trying to get some e-mail done. This time, however, I was answering e-mail offline on my SmartPhone. Of course, the phone was in flight mode so the radio was off. I wouldn't want to "interfere with the aircrafts navigation...
  • Jesper's Blog

    More on Using ISA to Block WMF Attacks

    • 2 Comments
    Jim Harrison has created a very cool script to do much better blocking of the WMF exploit in ISA server. The script is nice because it sets up a policy that actually parses the request body and blocks WMF files that are renamed to something else by using...
  • Jesper's Blog

    Ready! Set! Go...patch your stuff!!!

    • 5 Comments
    OK, you have probably seen it, but the official update for the WMF vulnerability was just posted! The bulletin is titled MS06-001 . The updates are on Windows Update , as well as on the download center. Links to the Download Center updates are in the...
  • Jesper's Blog

    Conscientious Risk Management and WMF

    • 21 Comments
    This past week there have been a lot of questions about the WMF vulnerability, what Microsoft is doing, and what the community should do to protect against it. For many reasons, Microsoft's response to the problem is best left to those who do this for...
Page 1 of 1 (4 items)