Category Archives: Operating Systems and Application Security

What When DEP Shuts Down Windows Explorer?

Microsoft introduced Data Execution Prevention (DEP). DEP is a security feature that can help prevent damage to your computer from viruses and other security threats. DEP can help protect your computer by monitoring programs to make sure they use system … Continue reading

Share
Posted in Operating Systems and Application Security | 2 Comments

Ophcrack – Rainbow Tables Based Password Cracker

If you think your passwords are strong enough, think twice. They are probably not. Ophcrack is a Windows password cracker based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with … Continue reading

Share
Posted in Operating Systems and Application Security, Security Research, Software Security, Tools and Utilities | Leave a comment

PKI Enhancements in Windows

Windows has included strong, platform-wide support for public key infrastructure (PKI) since the release of Windows 2000. That release included the first native certificate-authority capability, introduced auto-enrollment, and provided support for smart-card authentication. In Windows XP and Windows Server 2003, … Continue reading

Share
Posted in Cryptography, Operating Systems and Application Security | Leave a comment

WordPress 2.2.2 and 2.0.11

On August 5, 2007 WordPress team announced two security-related releases available for both users of our main 2.2 branch and the legacy 2.0 branch. See: WordPress › Blog » WordPress 2.2.2 and 2.0.11. I’ve upgraded my blog today to 2.2.2 and … Continue reading

Share
Posted in Internet Security, Operating Systems and Application Security, Software Security | 6 Comments

Security Developer Center: Threat Modeling

Microsoft Application Threat Modeling is a critical security activity, enabling effective application risk management during the SDLC and beyond. Application Threat Modeling is enforced as part of the Security Development Lifecycle for IT (SDL-IT) at Microsoft. Boeing develops their line … Continue reading

Share
Posted in Operating Systems and Application Security, Secure Programming, Threats, Vulnerabilities, Attacks | Leave a comment

Windows Vista Integrity Mechanism Technical Reference

How theory has been applied in practice – Peter Brundrett, the PM behind the integrity levels work in Windows Vista has written a very detailed whitepaper on the subject: Windows Vista Integrity Mechanism Technical Reference.

Share
Posted in Operating Systems and Application Security | Leave a comment

Microsoft admits Vista failure!?

Sounds unbelievable but read: Microsoft admits Vista failure, Abandoning the Vista Ship and Commentary on Vista Security and the Microsoft Monopoly.

Share
Posted in Operating Systems and Application Security | 3 Comments

2006 Operating System Vulnerability Summary

This is long article but worth of reading:  OmniNerd – Articles: 2006 Operating System Vulnerability Summary. If you haven’t time to read complete article, read: Closing      While there are an enormous variety of operating systems to choose from, only … Continue reading

Share
Posted in Operating Systems and Application Security | Leave a comment

BioPassword Authentication Scheme

Identity theft is a growing problem and fight against it is very important. One possible idea and question is: Can the speed at which user types be used to determine whether he/she is allowed to view bank account details or … Continue reading

Share
Posted in Operating Systems and Application Security, Security Research, Tools and Utilities | Leave a comment

Vista: About UAC and DEP confusion

There has been a large amount of confusion and concern out there about Vista’s new user security model especially about UAC and DEP mechanisms.  User Account Control (UAC) is a new security mechanism introduced in Vista, whose primary goal is … Continue reading

Share
Posted in Operating Systems and Application Security | Leave a comment