<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The Industry Insiders : Security</title><link>http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx</link><description>Tags: Security</description><dc:language>en-GB</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Treat all input as Evil until proved otherwise - how to prevent code injection</title><link>http://blogs.technet.com/industry_insiders/archive/2008/04/07/treat-all-input-as-evil-until-proved-otherwise-how-to-prevent-code-injection.aspx</link><pubDate>Mon, 07 Apr 2008 17:56:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3031729</guid><dc:creator>Steve Lamb</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/3031729.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=3031729</wfw:commentRss><description>&lt;P&gt;&lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/438836.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/438836.aspx"&gt;Adrian J. Beasley&lt;/A&gt; has provided us with another excellent article titled &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/a-general-defence-against-injection-attacks-on-websites.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/a-general-defence-against-injection-attacks-on-websites.aspx"&gt;A General Defence Against Injection Attacks on Websites&lt;/A&gt;&amp;nbsp;written in his inimitable fashion tackling the challenging subject of how to validate user&amp;nbsp;input.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3031729" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category></item><item><title>Windows 2008 protection from Accidental deletion</title><link>http://blogs.technet.com/industry_insiders/archive/2007/10/31/windows-2008-protection-from-accidental-deletion.aspx</link><pubDate>Wed, 31 Oct 2007 19:18:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2296410</guid><dc:creator>jamesone</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/2296410.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=2296410</wfw:commentRss><description>&lt;P&gt;Many thanks to &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/richard-siddaway.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/richard-siddaway.aspx"&gt;Richard Siddaway&lt;/A&gt; for his &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/windows-server-2008-protection-from-accidental-deletion.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/windows-server-2008-protection-from-accidental-deletion.aspx"&gt;article on protecting AD objects from Accidental Deletion.&lt;/A&gt; Well worth a read if you've ever deleted the wrong thing from AD. &lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2296410" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Enterprise+Management/default.aspx">Enterprise Management</category><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Articles/default.aspx">Articles</category><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Powershell/default.aspx">Powershell</category></item><item><title>Be proactive: Information Security as a Business Enabler</title><link>http://blogs.technet.com/industry_insiders/archive/2007/08/29/be-proactive-information-security-as-a-business-enabler.aspx</link><pubDate>Wed, 29 Aug 2007 23:14:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1760047</guid><dc:creator>Steve Lamb</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/1760047.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=1760047</wfw:commentRss><description>Thanks to &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/paul-vincent.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/paul-vincent.aspx"&gt;Paul Vincent&lt;/A&gt; for contributing his article &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/information-security-the-business-enabler.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/information-security-the-business-enabler.aspx"&gt;Information Security; The Business Enabler&lt;/A&gt;. Paul goes on to explain how information security is much more than setting every security control you can lay your hands on.&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1760047" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category></item><item><title>ID: Who do you think you are?</title><link>http://blogs.technet.com/industry_insiders/archive/2007/08/22/id-who-do-you-think-you-are.aspx</link><pubDate>Wed, 22 Aug 2007 11:08:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1760014</guid><dc:creator>Steve Lamb</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/1760014.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=1760014</wfw:commentRss><description>Thanks to &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/craig-murphy.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/craig-murphy.aspx"&gt;Craig Murphy&lt;/A&gt; for contributing his article titled &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/who-do-you-think-you-are.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/who-do-you-think-you-are.aspx"&gt;Who Do You Think You Are?&lt;/A&gt; - it's well worth a read. He talks about identity from the perspective of a variety of vendors and applications.&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1760014" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category></item><item><title>How to make sense of anti-virus reviews</title><link>http://blogs.technet.com/industry_insiders/archive/2007/08/20/how-to-make-sense-of-anti-virus-reviews.aspx</link><pubDate>Mon, 20 Aug 2007 11:10:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1764572</guid><dc:creator>Steve Lamb</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/1764572.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=1764572</wfw:commentRss><description>&lt;P&gt;Thanks to &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/david-harley.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/david-harley.aspx"&gt;David Harley&lt;/A&gt; for sharing some of his vast experience of the anti-virus industry in his article titled &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/insider-s-guide-to-comparative-anti-virus-reviews.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/insider-s-guide-to-comparative-anti-virus-reviews.aspx"&gt;An Insider's Guide to Comparative Anti-virus Reviews&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;David explains in detail how independant labs evaluate software and includes links and guidance for further research.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/industry_insiders/pages/david-harley.aspx"&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1764572" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category></item><item><title>The wonders of Software Restriction Policies and PowerShell Code Signing</title><link>http://blogs.technet.com/industry_insiders/archive/2007/08/17/the-wonders-of-software-restriction-policies-and-powershell-code-signing.aspx</link><pubDate>Fri, 17 Aug 2007 17:55:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1770367</guid><dc:creator>Steve Lamb</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/1770367.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=1770367</wfw:commentRss><description>&lt;P&gt;Thanks to &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/438836.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/438836.aspx"&gt;Adrian J. Beasley&lt;/A&gt; for providing yet another excellent&amp;nbsp;article, this one's titled &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/software-restriction-policies-and-powershell-code-signing.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/software-restriction-policies-and-powershell-code-signing.aspx"&gt;Software Restriction Policies and PowerShell Code Signing&lt;/A&gt;&amp;nbsp;- Adrian provides a wealth of practical advice how to make the most of one of the most powerful yet under used security features of Windows XP, Server 2000, Server 2003 and Windows Vista&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1770367" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Powershell/default.aspx">Powershell</category></item><item><title>To secure your documents, or not, that's the question</title><link>http://blogs.technet.com/industry_insiders/archive/2007/08/15/to-secure-your-documents-or-not-that-s-the-question.aspx</link><pubDate>Wed, 15 Aug 2007 20:43:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1759446</guid><dc:creator>Steve Lamb</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/1759446.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=1759446</wfw:commentRss><description>&lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/adam-vero.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/adam-vero.aspx"&gt;Adam Vero&lt;/A&gt; is our newest contributor. I encourage you to read his pragmatic advice for securing information is his post titled &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/don-t-secure-your-documents.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/don-t-secure-your-documents.aspx"&gt;Don't Secure Your Documents&lt;/A&gt;. His proactive "security as an enabler" perspective makes a refreshing read.&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1759446" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category></item><item><title>How to extend your Cryptographic Service Provider infrastructure</title><link>http://blogs.technet.com/industry_insiders/archive/2007/04/03/test-please-ignore.aspx</link><pubDate>Tue, 03 Apr 2007 17:20:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:708400</guid><dc:creator>Steve Lamb</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/708400.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=708400</wfw:commentRss><description>&lt;P&gt;&lt;A href="http://blogs.technet.com/industry_insiders/articles/438836.aspx" mce_href="http://blogs.technet.com/industry_insiders/articles/438836.aspx"&gt;Adrian&lt;/A&gt; has written another enlightening article tackling the often confusing subject of &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/installing-new-cryptographic-service-providers.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/installing-new-cryptographic-service-providers.aspx"&gt;Installing New Cryptographic Service Providers&lt;/A&gt; with aplomb. His article explains in some detail how CSPs work to integrate devices such as smart cards with the underlying Windows Operating System.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=708400" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category></item><item><title>Creating Subject Alternative Name Certificates with Certificate Server</title><link>http://blogs.technet.com/industry_insiders/archive/2007/03/23/creating-subject-alternative-name-certificates-with-certificate-server.aspx</link><pubDate>Fri, 23 Mar 2007 17:57:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:695195</guid><dc:creator>Eileen_Brown</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/695195.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=695195</wfw:commentRss><description>&lt;P&gt;&lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/Brian-Reid.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/Brian-Reid.aspx"&gt;Brian Reid&lt;/A&gt; has written an interesting piece about using Powershell to create certificate requests for other web sites that can be uploaded to Certificate Server.&amp;nbsp; This allows you to have a certificate for more than one domain name.&amp;nbsp; Brian uses Exchange 2007 extensions to Powershell to achieve this.&amp;nbsp; It's yet another example of how powerful Powershell is to achieve the things you want to do...&lt;/P&gt;
&lt;P&gt;His article is &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/creating-subject-alternative-name-certificates-with-microsoft-certificate-server.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/creating-subject-alternative-name-certificates-with-microsoft-certificate-server.aspx"&gt;here&lt;/A&gt;... &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=695195" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Exchange/default.aspx">Exchange</category><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Messaging+_2600_amp_3B00_+Collaboration/default.aspx">Messaging &amp;amp; Collaboration</category></item><item><title>Certificate Server Enterprise Edition and Smart Cards</title><link>http://blogs.technet.com/industry_insiders/archive/2006/12/11/certificate-server-enterprise-edition-and-smart-cards.aspx</link><pubDate>Mon, 11 Dec 2006 12:08:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:551301</guid><dc:creator>Steve Lamb</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/551301.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=551301</wfw:commentRss><description>&lt;P&gt;&lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/438836.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/438836.aspx"&gt;Adrian Beasley&lt;/A&gt;&amp;nbsp;wrote a wonderful article on &lt;A class="" href="http://blogs.technet.com/industry_insiders/pages/certificate-server-enterprise-edition-and-smart-cards.aspx" mce_href="http://blogs.technet.com/industry_insiders/pages/certificate-server-enterprise-edition-and-smart-cards.aspx"&gt;Certificate Server Enterprise Edition and Smartcards&lt;/A&gt; - I particularly like it as he explains WHY each component is required rather than just diving into the detail - which he makes an excellent job of too.&lt;/P&gt;
&lt;P&gt;I have edited this post as the original one had the article itself here rather than this introduction - this meant that those of you who scroll through the blog expressed frustration that the screen was somewhat cluttered.&lt;/P&gt;
&lt;P&gt;Adrian's original post was one of the most popular on the entire site - in my view that's due to the practical way he tackled a complex subject. By all means hit the "comment" button and share your views.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=551301" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Articles/default.aspx">Articles</category></item><item><title>Public Key Infrastructure (PKI) Benefits - Why PKI?</title><link>http://blogs.technet.com/industry_insiders/archive/2006/06/26/438899.aspx</link><pubDate>Mon, 26 Jun 2006 19:41:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:438899</guid><dc:creator>Steve Lamb</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/438899.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=438899</wfw:commentRss><description>&lt;P&gt;&lt;A href="http://blogs.technet.com/industry_insiders/articles/438836.aspx"&gt;Adrian&lt;/A&gt; has written a short article enumerating many of the security threats that can be mitigated using asymmetric encryption. Click &lt;A href="http://blogs.technet.com/industry_insiders/articles/438895.aspx"&gt;here&lt;/A&gt; to read Adrian's overview of the benefits of&amp;nbsp;PKI&lt;/P&gt;
&lt;P&gt;As Adrian goes on to explain, Public Key Infrastructure technologies can be used to attest the identity, integrity and confidentiality of information, systems and individuals. &lt;/P&gt;
&lt;P&gt;Encrypting File System (EFS), Secure Messaging (S/MIME) and Internet Protocol Security (IPsec) are three incredibly power technologies that take advantage of asymmetric cryptography.&lt;/P&gt;
&lt;P&gt;It's a suprisingly easy read and at only a couple of pages it's well worth a read.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=438899" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category></item><item><title>Make Sense of Public Key Infrastructure</title><link>http://blogs.technet.com/industry_insiders/archive/2006/06/26/438841.aspx</link><pubDate>Mon, 26 Jun 2006 13:17:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:438841</guid><dc:creator>Steve Lamb</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/438841.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=438841</wfw:commentRss><description>&lt;P&gt;&lt;A href="http://blogs.technet.com/industry_insiders/articles/438836.aspx"&gt;Adrian&lt;/A&gt; has written a &lt;A href="http://blogs.technet.com/industry_insiders/articles/438837.aspx"&gt;wonderful overview of how Public Key Infrastructure words&lt;/A&gt;. If you don't know your certificate from your asymmetric widget then this is an excellent place to find out how it all hangs together.&lt;/P&gt;
&lt;P&gt;Adrian provided the following introduction:&lt;/P&gt;
&lt;P class=MsoPlainText style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT face=Consolas&gt;"These documents were written at the request of colleagues at a recent client; technically savvy guys but unfamiliar with PKI. Hence the rather demotic tone. I have been concerned to clarify aspects which caused me much confusion when I was learning the topic, in particular to keep very distinct the technology - asymmetric cryptography - which makes the whole thing possible, and the administrative process - PKI and all the rest - which controls it."&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=438841" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category></item><item><title>The Pro's and Con's of System Lockdown</title><link>http://blogs.technet.com/industry_insiders/archive/2005/12/28/416502.aspx</link><pubDate>Wed, 28 Dec 2005 16:59:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:416502</guid><dc:creator>Steve Lamb</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/416502.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=416502</wfw:commentRss><description>&lt;P&gt;&lt;a href="http://blogs.technet.com/industry_insiders/articles/Rodney_Buike.aspx"&gt;Rodney Buike&lt;/A&gt; has written a thought provoking article about the challenges of locking down production systems whilst ensuring they still perform their intended business function. I'm sure that many of you who've worked in the field of Information Security have experienced such difficulties. "If I turn this feature off will&amp;nbsp;the system still perform"?&lt;/P&gt;
&lt;P&gt;&lt;a href="http://blogs.technet.com/industry_insiders/articles/416376.aspx"&gt;Click here&lt;/A&gt; to read Rodney's article for yourself.&lt;/P&gt;
&lt;P&gt;For those of you wishing to take the guesswork out of system lock down I suggest taking a look at Security Configuration Wizard (SCW) which is a feature of Windows Server 2003 Service Pack 1 - you can read more about it by clicking &lt;A href="http://www.microsoft.com/scw"&gt;here&lt;/A&gt;&amp;nbsp;- it's free and very effective.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=416502" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category></item><item><title>Free Microsoft Support resources</title><link>http://blogs.technet.com/industry_insiders/archive/2005/10/19/microsoft-support.aspx</link><pubDate>Wed, 19 Oct 2005 16:24:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:412715</guid><dc:creator>Eileen_Brown</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/412715.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=412715</wfw:commentRss><description>&lt;P&gt;&lt;FONT face=Verdana size=2&gt;&lt;a href="http://blogs.technet.com/industry_insiders/articles/Blake_Handler.aspx"&gt;Blake&lt;/A&gt; has compiled an amazing collection of all of the support resources, newsgroups, how to articles, team blogs and tips and published it &lt;a href="http://blogs.technet.com/industry_insiders/articles/Free_Microsoft_support.aspx"&gt;here&lt;/A&gt;...&amp;nbsp; This must have taken an amazing amount of time to review and research and is just about the most comprehensive collection of resources on one page that I've ever seen.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;Read, and &lt;a href="http://blogs.technet.com/industry_insiders/articles/Free_Microsoft_support.aspx"&gt;bookmark this collection of tips here&lt;/A&gt;.&amp;nbsp; An absolutely fantastic job.&amp;nbsp; Thank you Blake...&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=412715" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Messaging+_2600_+Collaboration/default.aspx">Messaging &amp; Collaboration</category><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Platform/default.aspx">Platform</category><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Interoperability/default.aspx">Interoperability</category><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Data/default.aspx">Data</category><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Enterprise+Management/default.aspx">Enterprise Management</category></item><item><title>What to do in the case of a security compromise</title><link>http://blogs.technet.com/industry_insiders/archive/2005/08/15/409186.aspx</link><pubDate>Mon, 15 Aug 2005 17:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:409186</guid><dc:creator>Steve Lamb</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/industry_insiders/comments/409186.aspx</comments><wfw:commentRss>http://blogs.technet.com/industry_insiders/commentrss.aspx?PostID=409186</wfw:commentRss><description>&lt;P&gt;&lt;a href="http://blogs.technet.com/industry_insiders/articles/408825.aspx"&gt;Harlan Carvey&lt;/A&gt; has written an interesting article examining misconceptions around incident response - specifically how you deal with a security breach. Like Harlan I've heard many people advocate booting a compromised machine off a LINUX boot disk to perform forensics - there are many drawbacks with this approach as you can read in the article. Getting to the root cause of the compromise is something which is often overlooked in the rush to restore service to the business. Like most things planning HOW you will recover IN ADVANCE is well worth the effort.&lt;/P&gt;
&lt;P&gt;You can read Harlan's article by &lt;a href="http://blogs.technet.com/industry_insiders/articles/408826.aspx"&gt;clicking here&lt;/A&gt;. Please post comments to share your experience.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=409186" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/industry_insiders/archive/tags/Security/default.aspx">Security</category></item></channel></rss>