November 2009 Blog Posts

“Hi I’m a security researcher” or “Hi I’m a bad reporter”

I don’t know if I should laugh or cry. The Register this morning screamed the headline “IE bug leaks private details from 50m PDF files”. Bad Microsoft! Naughty Microsoft! Errr no, bollocks really. The information leak in question comes from the fact that IE puts a footer in documents which have the URL the document was from. if you’ve loaded an HTML file from a local directory on your machine, or a network path then that URL is used in the footer. I can’t make up my mind if the problem...

posted @ Tuesday, November 24, 2009 10:49 AM | Feedback (3)

Anti-XSS begins its evolution. And other new toys.

Mark Curphey has obviously been whipping his team into a frenzy and a new version of CAT.NET, along with WPL and WACA have been announced. They’re all in CTP and available from Connect. WPL is the evolution of AntiXSS, which is turning into a nice basis for a web application firewall (ok, it’s a stupid marketing term I know, but with the Security Runtime Engine and the new extensibility features it will allow you to build something that sits between your app and the evil internet and protects you. That’s not an excuse for getting it right in the...

posted @ Friday, November 20, 2009 11:04 AM | Feedback (1)

DDD Scotland Call for Speakers open

This is just to let you know that Developer Day Scotland 2010 is now officially announced and looking for speakers (and there’s a new web site too). If you’d like to submit any sessions please head on over to the site and submit the sessions you want to give. http://scottishdevelopers.com/2009/11/20/developer-day-scotland-2010/   Technorati Tags: DDDScotland,DDD Scotland,McDDD

posted @ Friday, November 20, 2009 9:47 AM | Feedback (0)