Welcome to TechNet Blogs Sign in | Join | Help

July 2005 - Posts

Why upgrading the firmware of a router is dangerous and how to add WPA2 support to XP

My colleague John Howard recently added a post talking about upgrading the firmware on his wireless router to add support for WPA2 (Wireless Protected Access 2) - click here to read John's post . As John points out KB893357 provides the required update

How will Network Access Protection be enforced for IPSEC? How to secure IPSEC clients? How does IPSEC work?

We have just released a white paper which explains in detail the plans for Network Access Protection(NAP) to enforce the security of IPSEC clients. NAP will be a very powerful part of Windows Vista and the corresponding server operating system (currently

Microsoft Network Access Protection is available for beta trial

Network Access Protection(NAP) is an exciting technology feature of Windows Vista client and the corresponding server which is still known by it's codename of "longhorn". NAP provides the automated mechanism to assess the policy compliance (health status)

If you really want to understand how Microsoft's implementation of TCP/IP works

John Howard has posted the link to a document which goes into the intricate detail of how Microsoft Windows XP and Server 2003 implement TCP/IP. If you really want to understand exactly how this works and hence how to secure it then click here for the
Posted by Steve Lamb | 3 Comments
Filed under:

How to get hold of Windows Vista Beta 1(code name Longhorn)

As of just a few moments ago there is content on the Windows Vista site which announces the limited availability of Beta 1. The software itself is being released to a limited number of official beta testers and hence you can't browse there and start pulling

Windows Vista Beta 1 Security Features

There's a good white paper which describes the security features of Windows Vista - just click here to access it. The white paper examines how Windows Vista will make it easier to avoid malware spyware and phishing attempts. It also looks at the new way

How to make ISA 2004 work on Windows Server 2003 Service Pack 1

You need to download (and apply!) ISA 2004 Service Pack 1 (which was released back in March) to your ISA 2004 systems for them to work on Windows Server 2003 Service Pack 1. Click here to access the download link. Both service packs provide updates to

Sample scripts to help implement VPN Quarantine

My colleague John Howard is implementing VPN Quarantine at home this weekend! I read his blog entry and figured that he'd find the following link useful as it provides a wide range of scripts which can be used to assess the policy compliance of the client

View MBSA reports on a Visio Diagram

This is quite cool if you have a small network and are using Microsoft Baseline Security Analyser v1.2.1 - support for v2 is due shortly. View MBSA Reports on a Visio Diagram http://go.microsoft.com/?linkid=2716976 The Visio Connector for MBSA lets you

Here are my pictures from TechEd EMEA

Just click here if you'd like to see my photographs from TechEd EMEA
Posted by Steve Lamb | 1 Comments
Filed under: ,

How to create better passwords & What is a PassPhrase anyway?

I've heard Jesper talk about this many times and have used passphrases for a long time myself. The term "password" is in itself misleading as is suggests that a single word will suffice. Many of our companys force us to use absurdly complex passwords

You choose between performance and security

Bill Reid has provided an article for the TechNet Industry Insiders which looks at how to increase the throughput of IIS6 by configuring the web server to only authenticate the inital traffic in the session. Clearly there's a security risk in reducing

Addendum to my last post about Team Foundation Server

Thanks to Rob for setting me straight with regard to my last post about Team Foundation Server. Rob's pointed out that TFS is not actually limited to teams of people greater than five - I added this comment as the strengths of TFS centre around it's source
Posted by Steve Lamb | 0 Comments
Filed under: ,

How important is separation to you when deploying IIS SQL and Team Foundation Server

Rob Caron works for Microsoft Corp. and he's looking for your feedback regarding how important you view separation between IIS, SQL and Team Foundation Server. For those who haven't heard of Team Foundation Server(TFS) it's a part of the upcoming Visual

What is the best way to stop your boss obsessing about the hot security story in the news?

During the course of my conversations with people at TechEd last week on item came up time and again - many of you work with people who panic when there's a high profile security story in the news - the result is that you are tasked with interrupting

Check out the audio from Seth's talk at the Marketing Soiree

<This post has been edited to attribute the image accordingly> The Marketing Soiree was a very interesting community event. The audio of Seth Godin's talk together with the Q&A is available here . He had fun with each person that wished to ask
Posted by Steve Lamb | 3 Comments
Filed under: ,

There's more to life than just a firewall

Duane put's it quite nicely in his post - there's definately far more to security that just a single technical solution. Let's face it, many firewalls merely route traffic from one interface to another having decided whether to allow the traffic based

Are there no limits to how low malware authors will go?

I'm staggered that there's a Trojan which is transmitted by email which purports to be information of the recent terrorist activity in London. Thanks to Matt Dickins' comment which made me aware of this. The details are here . Apologies to those who'd
Posted by Steve Lamb | 0 Comments

Steve Balmer talks about Blogging

Check out Eileen's post by clicking here to read about Steve Balmer's views on Blogging... Steve was interviewed by the Channel9 team who are well known for wandering around Microsoft Campus in Redmond with a video camera and few boundaries. The full
Posted by Steve Lamb | 1 Comments
Filed under: ,

Marketing Soiree / Geek Dinner tomorrow night in London

I'm looking forward to tomorrow night's Marketing Soiree which is taking place in London. Full details of the event can be found here . Hugh MacLeod and Seth Godin organised the event and set up the wiki - over 150 people are expected :-). Hugh and Seth
Posted by Steve Lamb | 0 Comments
Filed under: , ,

Why on Earth are there Parrots living in the wild in Amsterdam?

Travelling from my hotel to TechEd I've been walking through Vondelpark - a place festooned with more high speed hazards(otherwise known as Bicycles!) than I've ever seen before! In the trees there were many Green Parrots which were sqwarking everywhere
Posted by Steve Lamb | 2 Comments
Filed under:

A really unflattering picture of me at TechEd!

This picture was taken following our Malware chalk 'n' talk last night @ TechEd EMEA. I really enjoyed the session. As you can see - the room was rather warm!

TechEd - At last a conference venue that has good physical security

Don't get carried away by the title to this post - no conference venue is going to have good physical security by it's very nature of allowing admission to members of the public and the shear scale - most important the impact of a security violation at

Microsoft Baseline Security Analyser - MBSA 2 is available

In case you're new to MBSA it's a security scanner which you can download(for free), install it on a machine in your environment and gather information regarding missing patches and updates. You require Administrator rights on the target machines to obtain

I'm taking my life in my hands just walking around @ TechEd!

Mat has posted a great article explaining about the dangers of walking around in Amsterdam. We're just not used to Trams Bikes and Cars coming seemly from every possible direction. Read his post here to find out more - it's funny.
Posted by Steve Lamb | 1 Comments
Filed under:

What's TechEd EMEA like?

I've worked for Microsoft for two and a half years and yet this is the first time I've been to TechEd. I flew in yesterday and was fortunate to meet several speakers from the security track. I discovered the delights of Tequila WITH Tobasco - thanks Brian.
Posted by Steve Lamb | 2 Comments
Filed under:

Apologies to Michael Kalbe

Sorry Michael - by mistake I missed your name off the description in my earlier post about the Malware Chalk and Talk. Michael is co-presenting the Anti-spyware & Malware security Chalk and Talks at TechEd. I recommend you check out his blog to learn
Posted by Steve Lamb | 0 Comments
Filed under:

If you're going to TechEd EMEA then do come and say Hi

I'm going to be at TechEd EMEA all next week and would love to meet as many of you as possible to debate the best ways to defeat the nasties that threaten the integrity of our business transactions. I'll be on email pretty frequently and can be found

View the recording of Mark Russinovich's TechEd session titled Understanding and Fighting Malware: Viruses, Spyware and Rootkits

Click here to view the recording of Mark Russinovich's TechEd breakout session, Understanding and Fighting Malware: Viruses, Spyware and Rootkits , it was one of the top 10-rated sessions at TechEd, viewed live by over 1000 TechEd attendees and webcast
 
Page view tracker