Sign in
Robert Hensing's Blog
Software Security . . . and stuff.
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
No tags have been created or used yet.
Archive
Archives
December 2008
(1)
November 2008
(2)
October 2008
(11)
September 2008
(13)
August 2008
(6)
July 2008
(11)
June 2008
(24)
May 2008
(11)
April 2008
(15)
March 2008
(15)
February 2008
(11)
January 2008
(7)
December 2007
(9)
November 2007
(15)
October 2007
(23)
September 2007
(18)
August 2007
(8)
July 2007
(13)
June 2007
(10)
May 2007
(12)
April 2007
(8)
March 2007
(5)
February 2007
(4)
January 2007
(7)
December 2006
(5)
November 2006
(6)
September 2005
(1)
July 2005
(1)
March 2005
(4)
February 2005
(6)
January 2005
(8)
November 2004
(1)
October 2004
(2)
August 2004
(2)
July 2004
(1)
TechNet Blogs
>
Robert Hensing's Blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Robert Hensing's Blog
Bluehat V8: Mitigations Unplugged
Posted
over 5 years ago
by
rhensing
1
Comments
I first got to see Matt Miller speak in person a few Bluehat's ago when he was talking about 'Temporal return addresses' . . . ah yes - the talk was entitled "Temporal Chronomancy" according to Mr. Shostack's blog and it was all the way back in 2005....
Robert Hensing's Blog
Interesting stuff and the end is near (for my blog)
Posted
over 5 years ago
by
rhensing
1
Comments
First off - OneCare is dead - long live . . . OneCare . . . err Morro? http://news.cnet.com/8301-1009_3-10101582-83.html?tag=newsLeadStoriesArea.1 Next up - Zune 3.1 is out - download it - love it. http://www.engadget.com/2008/11/18/zune-3-1-update...
Robert Hensing's Blog
This week's Fail Open Goat Award goes to - Credit Card Processing
Posted
over 5 years ago
by
rhensing
1
Comments
http://www.veracode.com/blog/2008/10/credit-cards-failing-open/
Robert Hensing's Blog
Microsoft SideSight?
Posted
over 5 years ago
by
rhensing
1
Comments
Looks cool: http://www.gearlog.com/2008/10/microsofts_sidesight_something.php
Robert Hensing's Blog
SmoothHD
Posted
over 5 years ago
by
rhensing
0
Comments
Akamai / IIS7 / SilverLight 2.0 / VC-1 == HD over broadband happiness. It's sort of cool - the video started off a tad blurry and then got sharper after a few seconds and I didn't have a single glitch. Pretty impressive stuff: http://www.smoothhd.com...
Robert Hensing's Blog
Mass SQL Injection : The Chinese Way
Posted
over 5 years ago
by
rhensing
0
Comments
The blog pretty much speaks for itself: http://www.circleid.com/posts/20081022_sql_injection_attacks_chinese_way/ Client-side browser vulns are of little use without an effective way of spreading them to the victims - unfortunately - it's still relatively...
Robert Hensing's Blog
Out of band security update planned for today (MS08-067)
Posted
over 5 years ago
by
rhensing
1
Comments
Updated 10/23/2008 @ 1:17pm EST We have pushed the update live - here's the direct link to the bulletin: http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx (if it doesn't work for you - keep trying - it will be live real soon now). Also...
Robert Hensing's Blog
Flash 10 & IE8b2 Per Site ActiveX
Posted
over 5 years ago
by
rhensing
1
Comments
So I've got IE8b2 installed on all of my machines and I've noticed that since installing Flash 10 that all web sites now prompt me before running Flash 10! The new gold bar experience users will see when they install Flash 10 on IE8 is described here...
Robert Hensing's Blog
Flash 10 is out - install it like . . . yesterday.
Posted
over 5 years ago
by
rhensing
0
Comments
If I were a bad guy and I wanted to pwn lots of people via the web - I'd probably focus my efforts on ubiquitous software guaranteed to give me a lot of bang for my buck (like Flash and Acrobat). Software like Flash would seem like a good target given...
Robert Hensing's Blog
Win7 to officially be called . . . Win7?
Posted
over 5 years ago
by
rhensing
1
Comments
I actually for once - LOVE that we are keeping the name of the OS simple and leaving it at Win7. I will admit - I was somewhat disappointed when XP's name was announced internally (internally it was known as Whistler) and I was downright horrified when...
Robert Hensing's Blog
MAPP + Exploitability Index == Protected Customers, Better Security Update Prioritization
Posted
over 5 years ago
by
rhensing
1
Comments
Today we officially launched our MAPP program ( http://www.microsoft.com/security/msrc/mapp/partners.mspx ) and at the same time we also started providing exploitability information about our vulnerabilities to the world. These two things are pretty huge...
Robert Hensing's Blog
DayCon II / OSU Security Day / SafeCode
Posted
over 5 years ago
by
rhensing
1
Comments
Welp - just got back from speaking at a couple of events in Dayton, OH. First up was THE Ohio State University security day . . . I delivered my 'targeted attacks' presentation which I've been doing for over 2 years now (everything's the same - only the...
Robert Hensing's Blog
Shostack on "Threat Modeling"
Posted
over 5 years ago
by
rhensing
0
Comments
Adam Shostack is incredibly smart - and he also happens to be responsible for managing the threat modeling aspect of the SDL these days. Here's got a nice 10 page paper here on threat modeling - very much worth the read if you're into that sort of thing...
Robert Hensing's Blog
iPhone running WM 6.1?
Posted
over 5 years ago
by
rhensing
0
Comments
Okay - I'm not sure if this is real or not - but the interview itself is hilarious - the questions the woman asks at the end and the kid's responses are hysterical: http://wmpoweruser.com/?p=1330
Robert Hensing's Blog
SkyFire?!?!?!
Posted
over 5 years ago
by
rhensing
0
Comments
OMG - how is it possible that I JUST today found out about this? http://www.skyfire.com What is it? It's a new FREE (for now) browser for WM phones . . . that doesn't absolutely positively suck. I just installed it on my Q9 smartphone and it rendered...
Robert Hensing's Blog
I'm a PC and I fight for the users . . .
Posted
over 5 years ago
by
rhensing
0
Comments
Tron Guy makes a cameo in our "I'm a PC" video wall: http://media.lifewithoutwalls.com/ugc/t/r/o/tronguy/tronguy_336_252.wmv Here's the algorithm for finding direct links to videos based on user name: http://media.lifewithoutwalls.com/ugc/[1st letter...
Robert Hensing's Blog
Extreme Ad Makeover - We are now entering "the 2nd phase"?
Posted
over 5 years ago
by
rhensing
0
Comments
You know, I have one simple request. And that is if we are to have an ad campaign with sharks, that we have sharks with frickin’ laser beams attached to their heads! http://www.nytimes.com/2008/09/18/business/media/18adco.html?pagewanted=1&_r=1&ei...
Robert Hensing's Blog
Zune 3.0 - Using wifi to download songs right from the ZMP (speed test)
Posted
over 5 years ago
by
rhensing
0
Comments
Today a friend asked me how fast downloading songs / albums from the ZMP was and I had to admit - I wasn't sure. The day the firmware came out I immediately hooked up my Zune to my wifi network at home and then connected to the marketplace and then started...
Robert Hensing's Blog
Zune 3.0 - Insanely great creamy goodness from the Zune team
Posted
over 5 years ago
by
rhensing
1
Comments
So I have a Zune 80 (black) and I freaking love it. The Zune software kicks the living crap out of anything Apple has ever released in terms of quality and functionality and ease of use. The software just works, the Zune just works - it's probably the...
Robert Hensing's Blog
GOVCERT.NL and German authorities recommend against installing Chrome!?
Posted
over 5 years ago
by
rhensing
0
Comments
It was only a matter of time - the first few days worth of bugs were so bad I gave up covering them / reading them and one *has* to question Google's commitment and ability to write secure code: http://www.computerworld.co.ke/articles/2008/09/09/security...
Robert Hensing's Blog
6 on 6? (Hot IE on WM action)
Posted
over 5 years ago
by
rhensing
0
Comments
Whoa . . . a full fledged browser on my Smartphone! Yes please! http://news.cnet.com/8301-13860_3-10039152-56.html?tag=newsLeadStoriesArea.0 Don't get me wrong - the browser on WM6.1 is nice . . . but it's still not all that great - lots of pages...
Robert Hensing's Blog
New Microsoft Ad with Bill and Jerry - it's actually sorta FUNNY!
Posted
over 5 years ago
by
rhensing
0
Comments
And holy crap - it's 4.5 minutes long!!! You can watch the ad in better definition than you can on Youtube by going here (and it looks like down on the timeline we'll have them all up there soon): http://www.microsoft.com/windows/ Okay - I have...
Robert Hensing's Blog
Why I'm not running Chrome anymore (back to IE8 beta 2 for me)
Posted
over 5 years ago
by
rhensing
1
Comments
http://www.milw0rm.com/exploits/6367 Long strings leading to stack overruns? Really Google? Srsly? I guess I have the answer to my questions about whether they have an SDL / or the notion of banned APIs / or automated code scanning stuff . . . I mean...
Robert Hensing's Blog
It begins . . .
Posted
over 5 years ago
by
rhensing
0
Comments
UPDATE : Go here and watch the video - it's higher resolution and better: http://www.microsoft.com/windows/ Our $300MM ad campaign featuring Seinfeld: http://www.techcrunch.com/2008/09/04/first-bill-gatesjerry-seinfeld-advertisement-wheres-the-microsoft...
Robert Hensing's Blog
Breaking out of the Chrome sandbox - 2 interesting vulns in 24 hours? Got IE8? :)
Posted
over 5 years ago
by
rhensing
1
Comments
So it hasn't even been out 24 hours yet but Chrome is, as predicted, getting scrutinized heavily and well . . . it's falling down at a pretty alarming rate (as say compared to say - IE8 beta 2 which has been out longer :)) So yesterday Aviv Raff discovered...
Page 1 of 12 (296 items)
1
2
3
4
5
»