<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1949747169695871819</id><updated>2011-11-27T15:17:15.915-08:00</updated><category term='OSSC'/><category term='3DES'/><category term='PCI controls'/><category term='PCI'/><category term='CSSLP'/><category term='JCB'/><category term='Arithmetic overflow'/><category term='Application Security'/><category term='RC2'/><category term='S/MIME'/><category term='VISA'/><category term='Cloud security'/><category term='MASTER'/><category term='AMEX'/><category term='PCI DSS'/><category term='Webservices security'/><category term='RSA'/><category term='GFS'/><category term='ACE Security Conference'/><category term='Compliance History'/><category term='RMS'/><category term='WCF'/><category term='DES'/><category term='DISCOVER'/><category term='Laser Combat'/><category term='security consultant'/><category term='XML security issues'/><category term='Tech Ed 2009'/><category term='Runway9'/><category term='s/MIME vs RMS'/><category term='security.'/><category term='Security  checklists'/><category term='PCI and application Security'/><category term='.net web services'/><category term='PCI- Compliane- What it means to Organization'/><title type='text'>Mahavir Sancheti</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>24</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-2786797073426314867</id><published>2009-06-28T12:41:00.000-07:00</published><updated>2009-06-28T12:51:40.841-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Runway9'/><category scheme='http://www.blogger.com/atom/ns#' term='Laser Combat'/><title type='text'>Laser Combat @Ranway9 Hyd</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_WW3GYcyPtzg/SkfItvwShjI/AAAAAAAADKM/ersR-0tTi_s/s1600-h/DSC00785.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 300px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5352467370391799346" border="0" alt="" src="http://2.bp.blogspot.com/_WW3GYcyPtzg/SkfItvwShjI/AAAAAAAADKM/ersR-0tTi_s/s400/DSC00785.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Winning Laser Combat team@ &lt;a href="http://runway9.in/lasercombat-gallery-1.html"&gt;Runway9&lt;/a&gt;. From LtoR - Ravi,Raghu,Mahavir,Anil,Mark,Neha&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-2786797073426314867?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/2786797073426314867/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=2786797073426314867' title='38 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/2786797073426314867'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/2786797073426314867'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2009/06/laser-combat-ranway9-hyd.html' title='Laser Combat @Ranway9 Hyd'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_WW3GYcyPtzg/SkfItvwShjI/AAAAAAAADKM/ersR-0tTi_s/s72-c/DSC00785.JPG' height='72' width='72'/><thr:total>38</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-4534593182318121901</id><published>2009-06-28T12:31:00.000-07:00</published><updated>2009-06-28T12:39:05.516-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud security'/><category scheme='http://www.blogger.com/atom/ns#' term='GFS'/><category scheme='http://www.blogger.com/atom/ns#' term='OSSC'/><title type='text'>Securing Microsoft’s Cloud Infrastructure</title><content type='html'>&lt;div align="justify"&gt;Good white paper on Microsoft take of Cloud Security.&lt;br /&gt;The Online Services Security and Compliance (OSSC) team within the Global Foundation Services (GFS) division builds on the same security principles and processes Microsoft has developed through years of experience managing security risks in&lt;br /&gt;traditional development and operating environments. &lt;a href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf"&gt;More&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-4534593182318121901?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/4534593182318121901/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=4534593182318121901' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/4534593182318121901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/4534593182318121901'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2009/06/securing-microsofts-cloud.html' title='Securing Microsoft’s Cloud Infrastructure'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-8989261012383615138</id><published>2009-05-15T23:42:00.000-07:00</published><updated>2009-05-15T23:44:39.006-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tech Ed 2009'/><title type='text'>I am at Tech Ed 2009@HICC ,Hyderabad India</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_WW3GYcyPtzg/Sg5gqKjthUI/AAAAAAAADIM/QI2YT49xupk/s1600-h/Teched.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 300px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5336308885985527106" border="0" alt="" src="http://2.bp.blogspot.com/_WW3GYcyPtzg/Sg5gqKjthUI/AAAAAAAADIM/QI2YT49xupk/s400/Teched.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;I am at Tech Ed &lt;a href="mailto:2009@HICC"&gt;2009@HICC&lt;/a&gt; ,Hyderabad India&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-8989261012383615138?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/8989261012383615138/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=8989261012383615138' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/8989261012383615138'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/8989261012383615138'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2009/05/i-am-at-tech-ed-2009hicc-hyderabad.html' title='I am at Tech Ed 2009@HICC ,Hyderabad India'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_WW3GYcyPtzg/Sg5gqKjthUI/AAAAAAAADIM/QI2YT49xupk/s72-c/Teched.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-869767127852644324</id><published>2009-04-20T11:54:00.000-07:00</published><updated>2009-04-20T12:14:53.697-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CSSLP'/><title type='text'>CSSLP certified Now.</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_WW3GYcyPtzg/SezJgqq-paI/AAAAAAAADD4/8GUp2zyQfxA/s1600-h/images%5B1%5D.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 82px; FLOAT: left; HEIGHT: 48px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5326854022320006562" border="0" alt="" src="http://3.bp.blogspot.com/_WW3GYcyPtzg/SezJgqq-paI/AAAAAAAADD4/8GUp2zyQfxA/s400/images%5B1%5D.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/_WW3GYcyPtzg/SezJX8uAVZI/AAAAAAAADDw/HwUwpVGl9Sw/s1600-h/images%5B1%5D.jpg"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;I am CSSLP certified now. :)&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-869767127852644324?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/869767127852644324/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=869767127852644324' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/869767127852644324'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/869767127852644324'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2009/04/csslp-certified-now.html' title='CSSLP certified Now.'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_WW3GYcyPtzg/SezJgqq-paI/AAAAAAAADD4/8GUp2zyQfxA/s72-c/images%5B1%5D.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-4536492356212197726</id><published>2009-03-06T23:53:00.000-08:00</published><updated>2009-03-06T23:57:35.641-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security  checklists'/><category scheme='http://www.blogger.com/atom/ns#' term='ACE Security Conference'/><category scheme='http://www.blogger.com/atom/ns#' term='WCF'/><title type='text'>One Place holder for most the security stuff..</title><content type='html'>Thanks to J.D for creating this Place folder for most of the security related stuff..&lt;br /&gt;From J.D Meiers. Blog entry.&lt;br /&gt;"This post is a simple way to get to my stuff on MSDN.  I always get asked how to find my patterns &amp;amp; practices stuff on MSDN.  I always have a hard time finding it.  I'm presenting at our Executive Briefing Center (EBC) today, so now I have a simple response for when I get asked, "OK, so where do we find this?"" &lt;a href="http://blogs.msdn.com/jmeier/archive/2009/02/10/my-projects-on-msdn.aspx"&gt;more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-4536492356212197726?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/4536492356212197726/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=4536492356212197726' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/4536492356212197726'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/4536492356212197726'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2009/03/one-place-holder-for-most-security.html' title='One Place holder for most the security stuff..'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-7179451597598411600</id><published>2009-02-01T07:39:00.001-08:00</published><updated>2009-02-01T07:42:08.559-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RSA'/><category scheme='http://www.blogger.com/atom/ns#' term='S/MIME'/><category scheme='http://www.blogger.com/atom/ns#' term='RC2'/><category scheme='http://www.blogger.com/atom/ns#' term='3DES'/><category scheme='http://www.blogger.com/atom/ns#' term='DES'/><category scheme='http://www.blogger.com/atom/ns#' term='s/MIME vs RMS'/><category scheme='http://www.blogger.com/atom/ns#' term='RMS'/><title type='text'>S/MIME Vs RMS -Part II</title><content type='html'>&lt;span xmlns=""&gt; &lt;div&gt;&lt;table style="BORDER-COLLAPSE: collapse" border="0"&gt;&lt;colgroup&gt;&lt;col style="WIDTH: 197px"&gt;&lt;col style="WIDTH: 197px"&gt;&lt;col style="WIDTH: 197px"&gt;&lt;/colgroup&gt;&lt;tbody valign="top"&gt;&lt;tr style="BACKGROUND: #4bacc6"&gt;&lt;td style="BORDER-BOTTOM: 2.25pt solid; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: 2.25pt solid; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;Characteristic&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: 2.25pt solid; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: 2.25pt solid; BORDER-RIGHT: medium none"&gt;&lt;p style="TEXT-ALIGN: center"&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;S/MIME&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: 2.25pt solid; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: 2.25pt solid; BORDER-RIGHT: medium none"&gt;&lt;p style="TEXT-ALIGN: center"&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;RMS&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;Strong private key protection&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt;&lt;p&gt;Possible&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt;&lt;p&gt;Not possible&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;Private key storage&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;Disk (user profile), smart card&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;RM Account Certificate&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;usage rights (copy, print, forward)&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt;&lt;p&gt;Yes&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;Data rights can be configured to expire&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;Yes&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt; &lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt; &lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;Ease of use&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;Medium&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;Medium&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;Managerial efforts&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt;&lt;p&gt;High&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt;&lt;p&gt;Medium&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;Symmetric encryption algorithms&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;DES, 3DES, RC2 (Outlook)&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;DES, AES&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;Asymmetric encryption algorithms&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt;&lt;p&gt;RSA&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt;&lt;p&gt;RSA&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;PKI&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;Yes&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;Trust Relationship possible&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt;&lt;p&gt;Yes, through cross certification or sub-ordination&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt;&lt;p&gt;Trust relationships can be configured between RM Servers.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;Compatibility&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;S/MIME, X.509 are cross-platform standards.  S/MIME is implemented in most mail clients.&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;XrML is submitted as standard.  IRM is only implemented in Outlook 2003; view-only functionality available in RMA.  Additional clients can add IRM functionality through RM Client SDK.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;Revocation checking&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt;&lt;p&gt;Done by the client (configurable), encrypted content is still accessible if cert not valid&lt;/p&gt;&lt;/td&gt;&lt;td style="PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #d8d8d8"&gt;&lt;p&gt;Done by the server (when issuing EULs), encrypted content is not accessible once old licenses expire.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="BORDER-BOTTOM: 2.25pt solid; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BACKGROUND: #4bacc6"&gt;&lt;p&gt;&lt;span style="color:white;"&gt;&lt;strong&gt;Expiration behavior&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: 2.25pt solid; PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;Expiration of the user's certificate does not affect decryption of encrypted files, but does prevent subsequent encryption of emails.&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: 2.25pt solid; PADDING-LEFT: 7px; PADDING-RIGHT: 7px"&gt;&lt;p&gt;Expiration of user's RM account certificate will immediately prevent decryption of any existing or new RM-protected information.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-7179451597598411600?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/7179451597598411600/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=7179451597598411600' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/7179451597598411600'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/7179451597598411600'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2009/02/smime-vs-rms-part-ii.html' title='S/MIME Vs RMS -Part II'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-465055150537126819</id><published>2009-01-18T08:24:00.001-08:00</published><updated>2009-01-18T08:26:34.965-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='S/MIME'/><category scheme='http://www.blogger.com/atom/ns#' term='s/MIME vs RMS'/><category scheme='http://www.blogger.com/atom/ns#' term='RMS'/><title type='text'>S/MIME Vs RMS -Part I</title><content type='html'>&lt;span xmlns=""&gt; &lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div&gt;&lt;table style="BORDER-COLLAPSE: collapse" border="0"&gt;&lt;colgroup&gt;&lt;col style="WIDTH: 334px"&gt;&lt;col style="WIDTH: 286px"&gt;&lt;/colgroup&gt;&lt;tbody valign="top"&gt;&lt;tr style="HEIGHT: 43px"&gt;&lt;td style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: #4f81bd 1pt solid; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-family:Times New Roman;font-size:12;color:red;"&gt;S/MIME &lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: #4f81bd 1pt solid; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-family:Times New Roman;font-size:12;color:red;"&gt;RMS &lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="BACKGROUND: #d3dfee; HEIGHT: 34px"&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Provides non-repudiation and identity attestation of the sender&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Provides information usage policy enforcement&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="HEIGHT: 32px"&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Provides for integrity protection and proof of tampering (signature validation)&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Prevents tampering due to encryption&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="BACKGROUND: #d3dfee; HEIGHT: 32px"&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Security boundary may span outside corporate boundaries and firewalls&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Policy persisted with the content&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="HEIGHT: 32px"&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;End to end encryption prevents sniffing and message interception&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;End to end encryption prevents sniffing and message interception &lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="BACKGROUND: #d3dfee; HEIGHT: 32px"&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Cross-platform interoperability and wide application support&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Windows Platform only (98SE and above), CE and Mac next&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="HEIGHT: 32px"&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Two factor authentication for sending and receiving s/mime enabled mail&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Prevents users from using expired content or information &lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="BACKGROUND: #d3dfee; HEIGHT: 32px"&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Strong encryption and very large key sizes&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Fixed encryption key sizes and algorithms &lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="HEIGHT: 57px"&gt;&lt;td style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Limited message compression only in OWA&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: medium none; PADDING-LEFT: 7px; PADDING-RIGHT: 7px; BORDER-TOP: medium none; BORDER-RIGHT: medium none"&gt;&lt;p&gt;&lt;span style="font-size:12;color:#1f497d;"&gt;Provides message compression for all modes &lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-465055150537126819?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/465055150537126819/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=465055150537126819' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/465055150537126819'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/465055150537126819'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2009/01/smime-vs-rms-part-i.html' title='S/MIME Vs RMS -Part I'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-6443978456682510411</id><published>2009-01-06T23:15:00.000-08:00</published><updated>2009-01-06T23:22:10.445-08:00</updated><title type='text'>Threat Model of "Star Wars"</title><content type='html'>Death Star Threat Modeling –&lt;br /&gt;&lt;br /&gt;Part 1- &lt;a href="http://www.youtube.com/watch?v=x0HfHmRN9x4"&gt;http://www.youtube.com/watch?v=x0HfHmRN9x4&lt;/a&gt;&lt;br /&gt;Part 2-  &lt;a href="http://www.youtube.com/watch?v=OHnXsL4Z3vo"&gt;http://www.youtube.com/watch?v=OHnXsL4Z3vo&lt;/a&gt;&lt;br /&gt;Part -3  &lt;a href="http://www.youtube.com/watch?v=ZWT_5TGZ5h4"&gt;http://www.youtube.com/watch?v=ZWT_5TGZ5h4&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-6443978456682510411?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/6443978456682510411/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=6443978456682510411' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/6443978456682510411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/6443978456682510411'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2009/01/blog-post.html' title='Threat Model of &quot;Star Wars&quot;'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-8215553401763336091</id><published>2008-12-21T07:25:00.000-08:00</published><updated>2008-12-21T07:57:30.445-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security.'/><category scheme='http://www.blogger.com/atom/ns#' term='Arithmetic overflow'/><title type='text'>One of the costly Arthimatic overflow bug resulting in a loss of more than US$370 million</title><content type='html'>One of the costly &lt;span style="color:#ff0000;"&gt;Arithmetic overflow&lt;/span&gt; bug resulting in a loss of more than &lt;span style="color:#ff9900;"&gt;US$370 million.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Ariane 5 &lt;/strong&gt;Flight spacecraft crash in June 1996.&lt;br /&gt;&lt;br /&gt;"Because of the different flight path, a data conversion from a &lt;span style="color:#ff9900;"&gt;64-bit floating point to 16-bit signed integer value caused a hardware exception&lt;/span&gt; (more specifically,&lt;span style="color:#ff0000;"&gt;&lt;strong&gt; an arithmetic overflow&lt;/strong&gt;&lt;/span&gt;, as the floating point number had a value too large to be represented by a 16-bit signed integer). Efficiency considerations had led to the disabling of the software handler (in Ada code) for this error trap, although other conversions of comparable variables in the code remained protected. This led to a cascade of problems, culminating in destruction of the entire flight. "&lt;br /&gt;&lt;br /&gt;Source &lt;a href="http://en.wikipedia.org/wiki/Ariane_5_Flight_501"&gt;Wikipedia&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-8215553401763336091?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/8215553401763336091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=8215553401763336091' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/8215553401763336091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/8215553401763336091'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/12/one-of-costlist-arthimatic-overflow.html' title='One of the costly Arthimatic overflow bug resulting in a loss of more than US$370 million'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-5798326156074746416</id><published>2008-10-31T09:38:00.000-07:00</published><updated>2008-10-31T09:40:28.539-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='XML security issues'/><title type='text'>Common security issues in XML,XSLT,XSD files</title><content type='html'>Here is some of the issues related XML,XLST,XSD. I know It is very rough list.&lt;br /&gt;&lt;br /&gt;&lt;a name="OLE_LINK2"&gt;&lt;/a&gt;&lt;a name="OLE_LINK1"&gt;&lt;/a&gt;·         Do validate all user inputs for XML/HTML/Script Tags-XML Injection&lt;br /&gt;&lt;br /&gt;·         Before creating an XML, data should be properly encoded to avoid XML injection. (Hacker can inject malicious script in the CDATA section)&lt;br /&gt;&lt;br /&gt;·         XML data should be validated using a native .Net class to ensure that it does not contain any malicious data.&lt;br /&gt;&lt;br /&gt;·         Serving XML/XSLT/XSD files over HTTP&lt;br /&gt;&lt;br /&gt;·         Clear text secrets in XML files&lt;br /&gt;&lt;br /&gt;·         XML Output Escaping Turned off&lt;br /&gt;&lt;br /&gt;·         XML files in the web root&lt;br /&gt;&lt;br /&gt;·         SQL injection using invalidated user inputs.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-5798326156074746416?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/5798326156074746416/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=5798326156074746416' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/5798326156074746416'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/5798326156074746416'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/10/common-security-issues-in-xmlxsltxsd.html' title='Common security issues in XML,XSLT,XSD files'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-1192088390822058832</id><published>2008-10-31T09:25:00.000-07:00</published><updated>2008-10-31T09:28:51.584-07:00</updated><title type='text'>Interesting Example!!!  Security ROI: Fact or Fiction?</title><content type='html'>Interesting Example!!!&lt;br /&gt;&lt;br /&gt;Security ROI: Fact or Fiction?&lt;br /&gt;&lt;br /&gt;Airport security. Assume that all the new airport security measures increase the waiting time at airports by—and I'm making this up—30 minutes per passenger. There were 760 million passenger boarding in the United States in 2007. This means that the extra waiting time at airports has cost us a collective 43,000 years of extra waiting time. Assume a 70-year life expectancy, and the increased waiting time has "killed" 620 people per year—930 if you calculate the numbers based on 16 hours of awake time per day. So the question is: If we did away with increased airport security, would the result be more people dead from terrorism or fewer?&lt;br /&gt;&lt;br /&gt;From &lt;a href="http://www.csoonline.com/article/446866/Security_ROI_Fact_or_Fiction_?page=1"&gt;CSOnline.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-1192088390822058832?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/1192088390822058832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=1192088390822058832' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/1192088390822058832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/1192088390822058832'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/10/interesting-example-security-roi-fact.html' title='Interesting Example!!!  Security ROI: Fact or Fiction?'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-2370088377464101170</id><published>2008-09-28T10:15:00.000-07:00</published><updated>2008-09-28T10:25:10.043-07:00</updated><title type='text'>ACE TEAM@ACE CONFERENCE-REDMOND WA</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_WW3GYcyPtzg/SN-83YTsWII/AAAAAAAACKE/MmkbdnAPxaw/s1600-h/DSC_3707.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; DISPLAY: block; CURSOR: hand" id="BLOGGER_PHOTO_ID_5251123350141163650" border="0" alt="" src="http://3.bp.blogspot.com/_WW3GYcyPtzg/SN-83YTsWII/AAAAAAAACKE/MmkbdnAPxaw/s400/DSC_3707.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Here is the Team Snap after ACE &lt;a href="mailto:Conference@Redmond"&gt;Conference@Redmond&lt;/a&gt;. Entier 4 days are full of security sessions ,presentations, Hands on different tools.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-2370088377464101170?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/2370088377464101170/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=2370088377464101170' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/2370088377464101170'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/2370088377464101170'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/09/ace-teamace-conference-redmond-wa.html' title='ACE TEAM@ACE CONFERENCE-REDMOND WA'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_WW3GYcyPtzg/SN-83YTsWII/AAAAAAAACKE/MmkbdnAPxaw/s72-c/DSC_3707.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-928071629327596965</id><published>2008-08-03T03:56:00.000-07:00</published><updated>2008-08-03T04:02:16.047-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ACE Security Conference'/><title type='text'>10-15th August : ACE Conference</title><content type='html'>Attending ACE Security &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_0"&gt;Conference&lt;/span&gt; in Redmond, WA,USA. 11&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;th&lt;/span&gt;- 15&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;th&lt;/span&gt; August 2008. attending more than 100+ Security Professionals from all over the world. Once of its kind of footstep of BLACKHAT.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-928071629327596965?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/928071629327596965/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=928071629327596965' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/928071629327596965'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/928071629327596965'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/08/10-15th-august-ace-conference.html' title='10-15th August : ACE Conference'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-8980875351693762992</id><published>2008-06-30T08:48:00.000-07:00</published><updated>2008-06-30T09:00:22.704-07:00</updated><title type='text'>Key Configuration areas to look during Security Reviews.</title><content type='html'>&lt;p&gt;&lt;br /&gt;I categorize them in 3 buckets&lt;br /&gt;1) Web server Configurations&lt;br /&gt;2) Database Configurations&lt;br /&gt;3) Application Level Configurations&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#cc0000;"&gt;Database Configurations&lt;/span&gt;&lt;/strong&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Installation Considerations for Production Servers &lt;/li&gt;&lt;li&gt;Patches and Updates &lt;/li&gt;&lt;li&gt;Protocols Accounts &lt;/li&gt;&lt;li&gt;Shares &lt;/li&gt;&lt;li&gt;Ports &lt;/li&gt;&lt;li&gt;Auditing and Logging &lt;/li&gt;&lt;li&gt;Files and Directories &lt;/li&gt;&lt;li&gt;Services &lt;/li&gt;&lt;li&gt;Registry &lt;/li&gt;&lt;li&gt;SQL Server Database Objects &lt;/li&gt;&lt;li&gt;SQL Server Security &lt;/li&gt;&lt;li&gt;SQL Server Users &lt;/li&gt;&lt;li&gt;SQL Server Logins &lt;/li&gt;&lt;li&gt;&lt;div align="left"&gt;SQL Server Roles &lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p align="left"&gt;&lt;strong&gt;&lt;span style="color:#cc0000;"&gt;Web Server Configurations&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;IIS Lockdown&lt;/li&gt;&lt;li&gt;Patches and Updates &lt;/li&gt;&lt;li&gt;Services &lt;/li&gt;&lt;li&gt;Accounts &lt;/li&gt;&lt;li&gt;Protocols &lt;/li&gt;&lt;li&gt;Files and Directories &lt;/li&gt;&lt;li&gt;Ports &lt;/li&gt;&lt;li&gt;Shares &lt;/li&gt;&lt;li&gt;Registry &lt;/li&gt;&lt;li&gt;Sites and Virtual Directories &lt;/li&gt;&lt;li&gt;Auditing and Logging &lt;/li&gt;&lt;li&gt;Script Mappings &lt;/li&gt;&lt;li&gt;IIS Metabase &lt;/li&gt;&lt;li&gt;ISAPI Filters &lt;/li&gt;&lt;li&gt;Server Certificates &lt;/li&gt;&lt;li&gt;Code Access Security &lt;/li&gt;&lt;li&gt;Machine.config &lt;/li&gt;&lt;li&gt;&lt;div align="left"&gt;Other Check Points &lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p align="left"&gt;&lt;span style="color:#cc0000;"&gt;&lt;strong&gt;Application Level Configurations&lt;/strong&gt; &lt;/p&gt;&lt;ul&gt;&lt;/span&gt;&lt;li&gt;Web Server &lt;/li&gt;&lt;li&gt;IIS Specific &lt;/li&gt;&lt;li&gt;SQL Server Specific &lt;/li&gt;&lt;li&gt;Source Code &lt;/li&gt;&lt;li&gt;Auditing and Logging &lt;/li&gt;&lt;li&gt;ASP.Net 2.0 Specific Issues &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-8980875351693762992?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/8980875351693762992/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=8980875351693762992' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/8980875351693762992'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/8980875351693762992'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/06/key-configuration-areas-to-look-during.html' title='Key Configuration areas to look during Security Reviews.'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-1338541190043225877</id><published>2008-05-21T09:00:00.000-07:00</published><updated>2008-05-21T09:05:35.512-07:00</updated><title type='text'>I joined Microsoft India this month</title><content type='html'>i happy to share that this  month i joined Microsoft india. it is like dream come true.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-1338541190043225877?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/1338541190043225877/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=1338541190043225877' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/1338541190043225877'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/1338541190043225877'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/05/i-joined-microsoft-india-this-month.html' title='I joined Microsoft India this month'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-229167366209498555</id><published>2008-04-22T12:12:00.000-07:00</published><updated>2008-04-22T12:19:12.680-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PCI controls'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI and application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Application Security'/><title type='text'></title><content type='html'>&lt;p id="do:x"&gt;&lt;/p&gt;&lt;p id="ck2q" align="center"&gt;&lt;/p&gt;&lt;p id="yc0w" align="center"&gt;&lt;span id="h5.7"&gt;&lt;b id="aop:"&gt;&lt;span id="ztuq"   style="font-size:100%;color:#a64d79;"&gt;PCI Standards and Application Security.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="id7." align="center"&gt;&lt;/p&gt;&lt;p id="o8no" align="center"&gt;&lt;/p&gt;&lt;p id="e4tq" align="justify"&gt;&lt;span id="xoi4"  style="color:#9900ff;"&gt;&lt;span id="jx7-"&gt;&lt;span id="zyjl"&gt;&lt;span id="ca68"&gt;&lt;span id="yncy"  style="color:#9900ff;"&gt;From my experience i am tried to identified the Controls/Requirement which come under Application Security bucket. This are the major controls, apart from that there are other controls which comes under different bucket's like Infrastructure Security, Process , Physical Security etc.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="hx9c"&gt;&lt;/p&gt;&lt;p id="mpw_"&gt;&lt;/p&gt;&lt;p id="eod:"&gt;&lt;/p&gt;&lt;span id="o4lh"&gt;&lt;p id="p.82"&gt;&lt;span id="z8zv"&gt;&lt;span id="n12r"  style="color:#9900ff;"&gt;Requirement 6.3.7, 6.5, 6.6 , 11.3.2 talks about Application Security&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote id="g5ck" dir="ltr"&gt;&lt;span id="q4_q"&gt;&lt;span id="eqw5"  style="color:#9900ff;"&gt;PCI DSS Requirements &lt;/span&gt;- &lt;/span&gt;&lt;span id="demz"&gt;&lt;span id="pe7b"  style="color:#ff0000;"&gt;Application security&lt;/span&gt;&lt;/span&gt; &lt;blockquote id="x:dy" dir="ltr" style="MARGIN-RIGHT: 0px"&gt;&lt;div class="O1" id="tygc" align="justify"&gt;&lt;span id="k4bk"  style="color:#9900ff;"&gt;&lt;span id="hnnp"&gt;&lt;span id="shjk"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span id="lndy"&gt;6.3.7 Review custom code prior to release to production or customers, to identify potential coding vulnerabilities.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="O1" id="xy.." align="justify"&gt;&lt;/div&gt;&lt;div class="O1" id="d1b0" align="justify"&gt;&lt;span id="hh7o"  style="color:#9900ff;"&gt;&lt;span id="jmy8"&gt;&lt;span id="ohgz"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span id="g3wf"&gt;6.5 Develop web software and applications based on secure coding guidelines such as the Open Web Application Security Project. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="O1" id="rbg5" align="justify"&gt;&lt;span id="qs8j"  style="color:#9900ff;"&gt;&lt;span id="vzb2"&gt;Review custom application code to identify coding vulnerabilities&lt;/span&gt; &lt;/span&gt;&lt;/div&gt;&lt;div class="O1" id="nlhf" align="justify"&gt;&lt;/div&gt;&lt;div class="O1" id="di70" align="justify"&gt;&lt;span id="tj.1"  style="color:#9900ff;"&gt;&lt;span id="x53-"&gt;&lt;span id="cfbz"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span id="pkaf"&gt;6.6 Ensure that all web-facing applications are protected against known attacks by applying either of the following methods:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote id="amph" dir="ltr" style="MARGIN-RIGHT: 0px"&gt;&lt;div class="O3" id="ch26" align="justify"&gt;&lt;span id="k1.0"  style="color:#9900ff;"&gt;&lt;span id="w.:d"&gt;&lt;span id="zpgi"&gt;–&lt;/span&gt;&lt;/span&gt;&lt;span id="ue40"&gt;Having all custom application code reviewed for common vulnerabilities by an organization that specializes in application security&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="O3" id="x-bx" align="justify"&gt;&lt;span id="uwi9"  style="color:#9900ff;"&gt;&lt;span id="gs4_"&gt;&lt;span id="qdb8"&gt;–&lt;/span&gt;&lt;/span&gt;&lt;span id="qawr"&gt;Installing an application layer firewall in front of web-facing applications.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;p id="bv1s"&gt;&lt;span id="xo5j"&gt;&lt;span id="g2.w"  style="color:#9900ff;"&gt;PCI DSS Requirement&lt;/span&gt; -&lt;/span&gt;&lt;span id="iom1"&gt;&lt;span id="i1_y"  style="color:#ff0000;"&gt;Integrating Security in Software Develpoment Life cycle&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote id="i_0a" dir="ltr" style="MARGIN-RIGHT: 0px"&gt;&lt;div class="O1" id="xre2"&gt;&lt;span id="acuu"  style="color:#9900ff;"&gt;&lt;span id="zc90"&gt;&lt;span id="c5-1"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span id="dnkz"&gt;6 Develop and maintain secure systems and applications&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;p id="z8kp"&gt;&lt;span id="g5bf"&gt;&lt;span id="f:t9"  style="color:#9900ff;"&gt;PCI DSS Requirement&lt;/span&gt; -&lt;/span&gt;&lt;span id="w6:s"&gt;&lt;span id="c6z5"  style="color:#ff0000;"&gt;Application Penetration Testing&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote id="vt50" dir="ltr" style="MARGIN-RIGHT: 0px"&gt;&lt;div class="O1" id="y13y"&gt;&lt;span id="dps8"  style="color:#9900ff;"&gt;&lt;span id="z13b"&gt;&lt;span id="o:8u"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span id="arth"&gt;11.3 Perform application-layer penetration tests at least yearly&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote id="w960" dir="ltr" style="MARGIN-RIGHT: 0px"&gt;&lt;div class="O3" id="bozs"&gt;&lt;span id="q.t8"  style="color:#9900ff;"&gt;&lt;span id="vmul"&gt;&lt;span id="xbni"&gt;–&lt;/span&gt;&lt;/span&gt;&lt;span id="bmav"&gt;11.3.2 Application-layer penetration tests.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;p id="k-vt"&gt;&lt;span id="gvf-"&gt;&lt;span id="irfh"&gt;&lt;span id="wkf:"&gt;&lt;span id="vqoy"&gt;&lt;span id="bi8m"  style="color:#a64d79;"&gt;&lt;span id="klmi"  style="font-size:100%;"&gt;&lt;b id="fvyt"&gt;Common Top 10 web Vulnerabilities – PCI Equivalence&lt;/b&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="azq9"&gt;&lt;/p&gt;&lt;p id="mjab"&gt;&lt;span id="gcvu"  style="color:#9900ff;"&gt;&lt;span id="q5oy"&gt;&lt;span id="v2n9"&gt;Major Vulnerabilities mention in PCI DSS Requirement 6.5&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="djdw"&gt;&lt;/p&gt;&lt;span id="rvcq"&gt;&lt;span id="e4qw"&gt;&lt;blockquote id="bi:1" dir="ltr" style="MARGIN-RIGHT: 0px"&gt;&lt;p id="vqhh"&gt;&lt;span id="kfbb"  style="color:#9900ff;"&gt;&lt;span id="ma7y"&gt;&lt;span id="wp40"&gt;§&lt;/span&gt;&lt;/span&gt;&lt;span id="cebb"&gt;6.5.1 &lt;/span&gt;&lt;span id="k8-v"&gt;Unvalidated&lt;/span&gt;&lt;span id="kjcb"&gt; input&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="wax."&gt;&lt;span id="z2wl"  style="color:#9900ff;"&gt;&lt;span id="yv-x"&gt;&lt;span id="qu6e"&gt;§&lt;/span&gt;&lt;/span&gt;&lt;span id="kwuy"&gt;6.5.2 &lt;/span&gt;&lt;span id="ulc0"&gt;Broken access control &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="cbn."&gt;&lt;span id="xni0"  style="color:#9900ff;"&gt;&lt;span id="r5lm"&gt;&lt;span id="mk0."&gt;§&lt;/span&gt;&lt;/span&gt;&lt;span id="r.sz"&gt;6.5.3 &lt;/span&gt;&lt;span id="d-7u"&gt;Broken authentication and session management &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="yimi"&gt;&lt;span id="thka"  style="color:#9900ff;"&gt;&lt;span id="xow1"&gt;&lt;span id="fvcp"&gt;§&lt;/span&gt;&lt;/span&gt;&lt;span id="uca9"&gt;6.5.4 &lt;/span&gt;&lt;span id="vpid"&gt;Cross-site scripting (XSS) attacks&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="lwuy"&gt;&lt;span id="qbh-"  style="color:#9900ff;"&gt;&lt;span id="kxav"&gt;&lt;span id="uabd"&gt;§&lt;/span&gt;&lt;/span&gt;&lt;span id="acrh"&gt;6.5.5 &lt;/span&gt;&lt;span id="qz9h"&gt;Buffer overflows&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="s7o0"&gt;&lt;span id="biga"  style="color:#9900ff;"&gt;&lt;span id="qwtj"&gt;&lt;span id="x7zt"&gt;§&lt;/span&gt;&lt;/span&gt;&lt;span id="x2di"&gt;6.5.6 &lt;/span&gt;&lt;span id="fr_e"&gt;Injection flaws (for example,  Xpath injection ,SQL injection)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="i4kr"&gt;&lt;span id="kr60"  style="color:#9900ff;"&gt;&lt;span id="p:fa"&gt;&lt;span id="xoke"&gt;§&lt;/span&gt;&lt;/span&gt;&lt;span id="w6t_"&gt;6.5.7 &lt;/span&gt;&lt;span id="ahfe"&gt;Improper error handling&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="knu."&gt;&lt;span id="yg6e"  style="color:#9900ff;"&gt;&lt;span id="zjgv"&gt;&lt;span id="fg:b"&gt;§&lt;/span&gt;&lt;/span&gt;&lt;span id="x.mf"&gt;6.5.8 &lt;/span&gt;&lt;span id="xy-8"&gt;Insecure storage&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="wlhj"&gt;&lt;span id="tu4j"  style="color:#9900ff;"&gt;&lt;span id="l3l2"&gt;&lt;span id="w9j7"&gt;§&lt;/span&gt;&lt;/span&gt;&lt;span id="g0uz"&gt;6.5.9 &lt;/span&gt;&lt;span id="fzpx"&gt;Denial of service&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p id="eedz"&gt;&lt;span id="mm5c"  style="color:#9900ff;"&gt;&lt;span id="tm0_"&gt;&lt;span id="v.b7"&gt;§&lt;/span&gt;&lt;/span&gt;&lt;span id="s.6:"&gt;6.5.10 &lt;/span&gt;&lt;span id="ewuo"&gt;Insecure configuration management&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p id="f0n:"&gt;Reference &lt;a id="ocj1" href="https://www.pcisecuritystandards.org/pdfs/navigating_pci_dss_v1-1.pdf"&gt;https://www.pcisecuritystandards.org/pdfs/navigating_pci_dss_v1-1.pdf&lt;/a&gt;&lt;/p&gt;&lt;p id="u7jy"&gt;&lt;a id="e6::" href="http://www.owasp.org/index.php/Top_10_2004"&gt;http://www.owasp.org/index.php/Top_10_2004&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-229167366209498555?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/229167366209498555/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=229167366209498555' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/229167366209498555'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/229167366209498555'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/04/pci-standards-and-application-security.html' title=''/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-7393941165278463413</id><published>2008-04-19T06:23:00.000-07:00</published><updated>2008-04-19T06:28:22.612-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MASTER'/><category scheme='http://www.blogger.com/atom/ns#' term='AMEX'/><category scheme='http://www.blogger.com/atom/ns#' term='DISCOVER'/><category scheme='http://www.blogger.com/atom/ns#' term='VISA'/><category scheme='http://www.blogger.com/atom/ns#' term='JCB'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI'/><category scheme='http://www.blogger.com/atom/ns#' term='Compliance History'/><title type='text'>History before PCI- DSS- Compliance</title><content type='html'>&lt;div id="mhad" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt; &lt;/div&gt;&lt;div id="c0yl" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt;&lt;b id="dm4p"&gt;PCI DSS&lt;/b&gt; stands for &lt;b id="r3xf"&gt;Payment Card Industry Data Security Standards.&lt;/b&gt; &lt;div id="pls8" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt;The Payment Card Industry Security Standards Council was formed, and on the 15 December 2004 by Following Five major compaines.&lt;/div&gt;&lt;div id="jvou" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt;&lt;img id="g7hd" style="WIDTH: 109px; HEIGHT: 82px" height="77" src="http://docs.google.com/File?id=dg2zwnf2_2hbq8fqgd_b" width="149" /&gt;&lt;img id="oa:i" style="WIDTH: 98px; HEIGHT: 80px" height="91" src="http://docs.google.com/File?id=dg2zwnf2_3gw7bttgx_b" width="98" /&gt;&lt;img id="s0p6" style="WIDTH: 117px; HEIGHT: 79px" height="90" src="http://docs.google.com/File?id=dg2zwnf2_5fqhj4thn_b" width="131" /&gt;&lt;a id="jncs" href="http://images.google.com/imgres?imgurl=http://toursofvietnam.com/card_images/JCB-Card3.jpg&amp;amp;imgrefurl=http://toursofvietnam.com/&amp;amp;h=400&amp;amp;w=640&amp;amp;sz=76&amp;amp;hl=en&amp;amp;start=4&amp;amp;sig2=V2S3qdm2clK6iaBUn7K3CA&amp;amp;um=1&amp;amp;tbnid=rxjc1D8nadskMM:&amp;amp;tbnh=86&amp;amp;tbnw=137&amp;amp;ei=Y_EJSKyTOp6CswLglsmxDA&amp;amp;prev=/images%3Fq%3DJCB%2BCard%26um%3D1%26hl%3Den%26safe%3Doff%26rls%3Dcom.microsoft:*:IE-SearchBox"&gt;&lt;img id="b5wc" style="BORDER-RIGHT: 1px solid; BORDER-TOP: 1px solid; BORDER-LEFT: 1px solid; WIDTH: 116px; BORDER-BOTTOM: 1px solid; HEIGHT: 77px" height="86" src="http://tbn0.google.com/images?q=tbn:rxjc1D8nadskMM:http://toursofvietnam.com/card_images/JCB-Card3.jpg" width="137" /&gt;&lt;/a&gt;&lt;a id="kgfs" href="http://images.google.com/imgres?imgurl=http://www.partyjumprentals.com/Digital%2520%2520Visa%2520Logo.jpg&amp;amp;imgrefurl=http://www.partyjumprentals.com/&amp;amp;h=468&amp;amp;w=809&amp;amp;sz=59&amp;amp;hl=en&amp;amp;start=9&amp;amp;sig2=G-tAe4JQkEQ3mUJu2lILGA&amp;amp;um=1&amp;amp;tbnid=f9vTfr5I9uPlDM:&amp;amp;tbnh=83&amp;amp;tbnw=143&amp;amp;ei=rvEJSK3GKI6qswKQhcWjDA&amp;amp;prev=/images%3Fq%3Dvisa%2Blogo%26um%3D1%26hl%3Den%26safe%3Doff%26rls%3Dcom.microsoft:*:IE-SearchBox%26sa%3DX"&gt;&lt;img id="kdtj" style="BORDER-RIGHT: 1px solid; BORDER-TOP: 1px solid; BORDER-LEFT: 1px solid; WIDTH: 114px; BORDER-BOTTOM: 1px solid; HEIGHT: 77px" height="83" src="http://tbn0.google.com/images?q=tbn:f9vTfr5I9uPlDM:http://www.partyjumprentals.com/Digital%2520%2520Visa%2520Logo.jpg" width="143" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div id="nm4l" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt;Initially this compaines have there own security program.&lt;/div&gt;&lt;ol id="csjb"&gt;&lt;ol id="pds1"&gt;&lt;li id="aigv"&gt;&lt;div id="wqk1" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt;&lt;a class="mw-redirect" id="qkvj" title="Visa (company)" href="http://en.wikipedia.org/wiki/Visa_%28company%29"&gt;Visa&lt;/a&gt; Card Information Security Program&lt;/div&gt;&lt;/li&gt;&lt;li id="fg0q"&gt;&lt;div id="h7ty" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt;&lt;a id="th8s" title="MasterCard" href="http://en.wikipedia.org/wiki/MasterCard"&gt;MasterCard&lt;/a&gt; Site Data Protection&lt;/div&gt;&lt;/li&gt;&lt;li id="o4uf"&gt;&lt;div id="fz0l" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt;&lt;a id="bprk" title="American Express" href="http://en.wikipedia.org/wiki/American_Express"&gt;American Express&lt;/a&gt; Data Security Operating Policy&lt;/div&gt;&lt;/li&gt;&lt;li id="w1bs"&gt;&lt;div id="fuzl" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt;&lt;a id="v2vg" title="Discover Card" href="http://en.wikipedia.org/wiki/Discover_Card"&gt;Discover&lt;/a&gt; Information and Compliance&lt;/div&gt;&lt;/li&gt;&lt;li id="mobd"&gt;&lt;div id="prap" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt;&lt;a id="d7_n" title="Japan Credit Bureau" href="http://en.wikipedia.org/wiki/Japan_Credit_Bureau"&gt;JCB&lt;/a&gt; Data Security Program&lt;/div&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;div id="df6-" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt;&lt;/div&gt;&lt;div id="o5ja" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt;&lt;/div&gt;&lt;div id="x:dd" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 1em; PADDING-TOP: 1em; TEXT-ALIGN: left"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-7393941165278463413?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/7393941165278463413/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=7393941165278463413' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/7393941165278463413'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/7393941165278463413'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/04/history-before-pci-dss-compliance-pci.html' title='History before PCI- DSS- Compliance'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-1872900584494017826</id><published>2008-04-19T03:46:00.000-07:00</published><updated>2008-04-19T06:30:29.128-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PCI DSS'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI controls'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI- Compliane- What it means to Organization'/><category scheme='http://www.blogger.com/atom/ns#' term='Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI'/><title type='text'>PCI- Compliance - What it means to Organization</title><content type='html'>&lt;a href="http://bp3.blogger.com/_WW3GYcyPtzg/SAnfAH9ML3I/AAAAAAAACBM/6bs3abLl_Qo/s1600-h/PCI.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5190925238749900658" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://bp3.blogger.com/_WW3GYcyPtzg/SAnfAH9ML3I/AAAAAAAACBM/6bs3abLl_Qo/s400/PCI.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;What is PCI- DSS?&lt;/div&gt;&lt;div&gt;The Payment Card Industry (PCI) Data Security Standard (DSS) is a worldwide standard mandated by Visa and MasterCard for the protection and Security of cardholder information.&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;To whom it applies &lt;div&gt;"Any organization that processes credit card information, including merchants and third-party service providers that store, process or transmit credit card/debit card data "&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Standards and requirements for data security&lt;/li&gt;&lt;li&gt;Non-legislative, but enforceable through Fines&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;PCI DSS-“&lt;span style="color:#6666cc;"&gt;&lt;strong&gt;Digital Dozen&lt;/strong&gt;&lt;/span&gt;”&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color:#66cccc;"&gt;Build and Maintain a Secure Network&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;1: Install and maintain a firewall configuration to protect cardholder data&lt;br /&gt;2: Do not use vendor-supplied defaults for system passwords and other security parameters&lt;br /&gt;&lt;span style="font-size:130%;color:#66cccc;"&gt;Protect Cardholder Data&lt;br /&gt;&lt;/span&gt;3: Protect stored cardholder data&lt;br /&gt;4: Encrypt transmission of cardholder data across open, public networks&lt;br /&gt;&lt;span style="color:#66cccc;"&gt;&lt;span style="font-size:130%;"&gt;Maintain a Vulnerability Management Program&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;5: Use and regularly update anti-virus software&lt;br /&gt;6: Develop and maintain secure systems and applications&lt;br /&gt;&lt;span style="color:#66cccc;"&gt;&lt;span style="font-size:130%;"&gt;Implement Strong Access Control Measures&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;7: Restrict access to cardholder data by business need-to-know&lt;br /&gt;8: Assign a unique ID to each person with computer access&lt;br /&gt;9: Restrict physical access to cardholder data&lt;br /&gt;&lt;span style="font-size:130%;color:#66cccc;"&gt;Regularly Monitor and Test Networks&lt;/span&gt;&lt;br /&gt;10: Track and monitor all access to network resources and cardholder data&lt;br /&gt;11: Regularly test security systems and processes&lt;br /&gt;&lt;span style="font-size:130%;color:#66cccc;"&gt;Maintain an Information Security Policy&lt;br /&gt;&lt;/span&gt;12: Maintain a policy that addresses information security&lt;/div&gt;&lt;div&gt;&lt;br /&gt;To Become a PCI Compliance we need Classify them in different buckets&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;No “&lt;span style="color:#ff0000;"&gt;single technology&lt;/span&gt;” makes company PCI compliant. Above figure shows the broad classification of all 12 Requirement controls.&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;Continue in part -2&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-1872900584494017826?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/1872900584494017826/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=1872900584494017826' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/1872900584494017826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/1872900584494017826'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/04/pci-compliane-what-it-means-to.html' title='PCI- Compliance - What it means to Organization'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_WW3GYcyPtzg/SAnfAH9ML3I/AAAAAAAACBM/6bs3abLl_Qo/s72-c/PCI.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-5505796717669737193</id><published>2008-03-03T01:08:00.001-08:00</published><updated>2008-03-03T01:08:10.600-08:00</updated><title type='text'>SAP Security</title><content type='html'>					&lt;div&gt;&lt;br /&gt;						&lt;h3&gt;SAP Security Assessment V3 English&lt;/h3&gt;&lt;br /&gt;						From: &lt;a href="http://www.slideshare.net/fseineldin/"&gt;fseineldin&lt;/a&gt;, 6 months ago&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;						&lt;div style="width:425px;text-align:left" id="__ss_100319"&gt;&lt;object style="margin:0px" width="425" height="355"&gt;&lt;param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=sap-security-assessment-v3-english1942"/&gt;&lt;param name="allowFullScreen" value="true"/&gt;&lt;param name="allowScriptAccess" value="always"/&gt;&lt;embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=sap-security-assessment-v3-english1942" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;"&gt;&lt;a href="http://www.slideshare.net/?src=embed"&gt;&lt;img src="http://static.slideshare.net/swf/logo_embd.png" style="border:0px none;margin-bottom:-5px" alt="SlideShare"/&gt;&lt;/a&gt; | &lt;a href="http://www.slideshare.net/fseineldin/sap-security-assessment-v3-english-100319?src=embed" title="View 'SAP Security Assessment V3 English' on SlideShare"&gt;View&lt;/a&gt; | &lt;a href="http://www.slideshare.net/upload?src=embed"&gt;Upload your own&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;						SAP Security Assessment framework&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;						&lt;a href="http://www.slideshare.net/fseineldin/sap-security-assessment-v3-english-100319"&gt;SlideShare Link&lt;/a&gt;&lt;br /&gt;					&lt;/div&gt;&lt;br /&gt;				&lt;img style="visibility:hidden;width:0px;height:0px;" border=0 width=0 height=0 src="http://counters.gigya.com/wildfire/CIMP/JnB*PTEyMDQ1MzU1NzM*MDAmcD*xMDE5MSZkPSZuPWJsb2dnZXI=.jpg" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-5505796717669737193?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/5505796717669737193/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=5505796717669737193' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/5505796717669737193'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/5505796717669737193'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/03/sap-security.html' title='SAP Security'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-8796094036690769583</id><published>2008-02-08T09:22:00.000-08:00</published><updated>2008-04-19T05:49:27.085-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Webservices security'/><category scheme='http://www.blogger.com/atom/ns#' term='security consultant'/><category scheme='http://www.blogger.com/atom/ns#' term='.net web services'/><title type='text'>COMMONLY FOUND SECURITY ISSUESS IN WEB SERVICES . NET CODE</title><content type='html'>COMMONLY FOUND WEB SERVICES ISSUES IN .NET CODE.&lt;br /&gt;&lt;br /&gt;Check the following areas in web services form security point of view&lt;br /&gt;· Input validation&lt;br /&gt;· Authentication&lt;br /&gt;· Authorization&lt;br /&gt;· Information Disclosure&lt;br /&gt;· Auditing &amp;amp; Logging&lt;br /&gt;· Unnecessary protocol&lt;br /&gt;· Communication Channels&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1. Inadequate Input Validation in IBUYSPY webservices&lt;br /&gt;--------------------------------------------------------&lt;br /&gt;NONE of the inputs accepted by the ANY of the web methods are validated before being sent to the business methods.&lt;br /&gt;Although there is currently no well known vulnerability that can be exploited, input validation is required as per policy.&lt;br /&gt;&lt;br /&gt;Example:--&lt;br /&gt;IBUYSPY \App_Code\OrderCancel.cs(58):&lt;br /&gt;[WebMethod]&lt;br /&gt;public IBUYSPY.Utility ProcessCancel(string orderId, string[] itemId, string itemStatusReasonCode)&lt;br /&gt;{&lt;br /&gt;const string LOGSOURCE = " IBUYSPY.Utility.ProcessCancel";&lt;br /&gt;IBUYSPY.Utility omResult = new Utility.Result();&lt;br /&gt;CancelOrder order = new CancelOrder();&lt;br /&gt;try&lt;br /&gt;{&lt;br /&gt;int retVal = order.ProcessCancel(orderId, itemId, itemStatusReasonCode);&lt;br /&gt;&lt;br /&gt;IBUYSPY.Utility \App_Code\PaymentWebService.cs(41):&lt;br /&gt;public IBUYSPY.Utility ProcessCharge(string serviceRequestNumber)&lt;br /&gt;{&lt;br /&gt;try&lt;br /&gt;{&lt;br /&gt;IBUYSPY.PaymentService PaymentService = new Payment.PaymentService();&lt;br /&gt;IBUYSPY.Result Result = PaymentService.ProcessCharge("",serviceRequestNumber);&lt;br /&gt;&lt;br /&gt;==================&lt;br /&gt;Recommendations&lt;br /&gt;==================&lt;br /&gt;Perform input validations for all user inputs.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2. Hard-coded default namespace http://www.tempuri.org should not be used&lt;br /&gt;-------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Hard-coded default namespace http://www.tempuri.org should not be used. The logic in this code allows for the possibility that this default namespace could be returned in two places.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;==================&lt;br /&gt;Recommendations&lt;br /&gt;==================&lt;br /&gt;&lt;br /&gt;Each XML Web Service needs a unique namespace in order for client applications to distinguish it from other services on the Web. By default, ASP.Net Web Services use http://tempuri.org/ for this purpose. While this suitable for XML Web Services under development, published services should use a unique, permanent namespace.&lt;br /&gt;&lt;br /&gt;Your XML Web Service should be identified by a namespace that you control. For example, you can use your company's Internet domain name as part of the namespace. Although many namespaces look like URLs, they need not point to actual resources on the Web.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3. WebServices configured to communicate over cleartext http channel&lt;br /&gt;--------------------------------------------------------------------------------------------&lt;br /&gt;IBUYSPY.asmx configured to communicate over cleartext http channel which leads to data integrity and confidentiality issues (data is HBI).&lt;br /&gt;&lt;br /&gt;File &gt;&gt;app.comfig, web.config, master.config&lt;br /&gt;&lt;br /&gt;==================&lt;br /&gt;Recommendations&lt;br /&gt;==================&lt;br /&gt;Configure IBUYSPY.asmx to communicate only over https.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;4. Consuming Web Services using Basic Authentication&lt;br /&gt;-------------------------------------------------------------------------------------------------------------&lt;br /&gt;Consuming Web Services using Basic Authentication. This application consumes webservices using basic authentication for which a domain account is hardcoded in code. Also, since the web service is not under SSL, this is subject to network eavesdropping.&lt;br /&gt;&lt;br /&gt;Code Excerpts:&lt;br /&gt;--------------------------&lt;br /&gt;service.Credentials = new System.Net.NetworkCredential (UserName, Password, Domain);&lt;br /&gt;Files:- IBUYSPY\Callout\GetSystemUserInfo.cs&lt;br /&gt;===============&lt;br /&gt;Recommendation:&lt;br /&gt;===============&lt;br /&gt;-- Use Digest or NTLM.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;5. Information disclosure through web-service files&lt;br /&gt;------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;The web service is configured to allow execution of the Documentation protocol, which when enabled provides the WSDL documentation with all the necessary information to communicate with the web service.&lt;br /&gt;WSDL documentation reveals descriptive information about web services. Descriptive information such as that produced by appending? WSDL to a web services file (.asmx) may be considered an information leakage security risk when the web service is intended for private consumption only.&lt;br /&gt;&lt;br /&gt;==================&lt;br /&gt;Recommendations&lt;br /&gt;==================&lt;br /&gt;&lt;br /&gt;- Authorize access to WSDL files using NTFS permissions.&lt;br /&gt;- Remove WSDL files from Web server.&lt;br /&gt;- Disable the documentation protocols to prevent the dynamic generation of WSDL&lt;br /&gt;&lt;br /&gt;Disable non required protocols, such as Documentation in the appropriate ASP.NET configuration file to prevent attackers from easily obtaining required syntax for interacting with the target web service. Ensure fix is implemented in production.&lt;br /&gt;The following example shows the web Services configuration element added to a Web.config file to disable the automatic generation of browser-friendly documentation:&lt;br /&gt;&lt;webservices&gt;&lt;br /&gt;&lt;protocols&gt;&lt;br /&gt;&lt;remove name="Documentation"&gt;&lt;br /&gt;&lt;/protocols&gt;&lt;br /&gt;&lt;/webservices&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;6. Unsafe methods exposed as WebMethod / web-services :&lt;br /&gt;---------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;The web-methods allow the callers elevated privileges as the web-services uses a fixed identity without any impersonation and the identity is also a part of the power users group on the server.&lt;br /&gt;&lt;br /&gt;Using these methods any user can download any file to which he does not have access to, and can execute any SP query and get access to data.&lt;br /&gt;&lt;br /&gt;The following methods are unsafe:&lt;br /&gt;GetFile (allows users unauthorized access to any file which can be accessed by the service account which belongs to power user group)&lt;br /&gt;GetListContent, GetPromoListContent, GetListItemCount, ModifiyListItem,DeleteListItem, Eventlog&lt;br /&gt;&lt;br /&gt;==================&lt;br /&gt;Recommendations&lt;br /&gt;==================&lt;br /&gt;&lt;br /&gt;Remove the vulnerable methods&lt;br /&gt;Restrict them with proper authorization and input validation controls&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;7. Configuration Error Brock - Default IUSR account used for web services&lt;br /&gt;------------------------------------------------------------------------------&lt;br /&gt;Brock - Default IUSR account used for web services&lt;br /&gt;Rename default IUSR account or use other account for local web service. IUSR_BROCK account&lt;br /&gt;&lt;br /&gt;8. Design Recommendation&lt;br /&gt;----------------------------------------&lt;br /&gt;&lt;br /&gt;Bicep.asmx and BV.asmx should not be hosted in the trusted domain, and must be hosted in the throw away domain. These two web services are at the core of the functionality, they interact with the back end system and when give page data return the translated pages. A malicious user can send requests to the SOAP APIs and cause the translation to occur in the domain. Although the translation needs to occur and the pages needs to be loaded using the process by Translate.js. However, it is possible to start a translation and then request the page ID from the SOAP API.&lt;br /&gt;&lt;br /&gt;There is no known way to create SOAP requests from an external domain. However, as we have mentioned to segregate the trusted and untrusted data handlers, it is recommended to move these Web Services to the throw away domain as well.&lt;br /&gt;NOTE: It is also recommended to put the physical path as a static server side parameter, instead of evaluating at run time, as there might be some future exploits against using HTTPContext Object.&lt;br /&gt;&lt;br /&gt;Global.ascx&lt;br /&gt;Line 12:&lt;br /&gt;&lt;br /&gt;Statics.PhysicalServerPath = Context.Request.PhysicalApplicationPath;&lt;br /&gt;&lt;br /&gt;==================&lt;br /&gt;Recommendations&lt;br /&gt;==================&lt;br /&gt;&lt;br /&gt;This is used to dynamically load the binaries using kernel32.dll's LoadLibrary Native function.&lt;br /&gt;&lt;br /&gt;9. Web service configured to use multiple communication protocols (ie. HttpGet, and HttpPost)&lt;br /&gt;---------------------------------------------------------------------------------------------------&lt;br /&gt;The web service permits HTTP-GET, HTTP-POST, and SOAP requests. If the web service uses SOAP messages, disable HTTP-GETs and HTTP-POSTs at a machine level(machine.config). To minimize the attack surface of the web service, disable those request methods not used by the web service.&lt;br /&gt;&lt;br /&gt;==================&lt;br /&gt;Recommendations&lt;br /&gt;==================&lt;br /&gt;Disable HTTP-GET and HTTP-POST if not required by the web service.&lt;br /&gt;&lt;br /&gt;This can be achieved by disabling in machine.config.&lt;br /&gt;&lt;br /&gt;In machine.config, the following is present by default:&lt;br /&gt;&lt;br /&gt;&lt;protocols&gt;&lt;br /&gt;&lt;add name="HttpSoap"&gt;&lt;br /&gt;&lt;add name="HttpPost"&gt;&lt;br /&gt;&lt;add name="HttpGet"&gt;&lt;br /&gt;&lt;/protocols&gt;&lt;br /&gt;&lt;br /&gt;So to disable HttpGet and HttpPost in machine.config, comment out the HttpPost and HttpGet lines&lt;br /&gt;&lt;br /&gt;&lt;protocols&gt;&lt;br /&gt;&lt;add name="HttpSoap"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/protocols&gt;&lt;br /&gt;&lt;br /&gt;NOTE: If either of these communication protocols need to be enabled for other web services it is possible to add them back per web service in each web service's web.config file by creating a &lt;webservices&gt;and adding support for these protocols with the &lt;protocol&gt;and &lt;add&gt;elements.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;10. Web services send sensitive error messages to client&lt;br /&gt;------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;This is a pervasive issue with the application. The web services do not send generic messages the thick client. This fix requires code level changes within the server component.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The recommended solution to preserve both data confidentiality and troubleshooting capabilities is to store detail application exceptions locally on the server while providing the user with a generalized error message.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;11. Verbose Error Messages in: IBUYSPY webservices&lt;br /&gt;-------------------------------------------------&lt;br /&gt;The following web services will be called by different clients for charging/ refund etc.&lt;br /&gt;In ALL the web methods exception handling is implemented this way:-&lt;br /&gt;[WebMethod]&lt;br /&gt;public IBUYSPY.Result ProcessChargeTransaction(string orderId, string serviceRequestNumber)&lt;br /&gt;{&lt;br /&gt;try&lt;br /&gt;{&lt;br /&gt;IBUYSPY.PaymentService PaymentService = new IBUYSPY.PaymentService();&lt;br /&gt;IBUYSPY.Result omResult = PaymentService.ProcessCharge(orderId, serviceRequestNumber);&lt;br /&gt;&lt;br /&gt;return Result;&lt;br /&gt;}&lt;br /&gt;catch (SoapException ex)&lt;br /&gt;{&lt;br /&gt;throw ex;&lt;br /&gt;}&lt;br /&gt;catch (Exception ex)&lt;br /&gt;{&lt;br /&gt;throw ex;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;This will result in verbose error messages being returned to the end user in case of an exception.&lt;br /&gt;&lt;br /&gt;==================&lt;br /&gt;Recommendations&lt;br /&gt;==================&lt;br /&gt;&lt;br /&gt;Unless required by business, throw exceptions that include generic error messages.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;12. Insufficient logging controls in IBUYSPY webservices&lt;br /&gt;-------------------------------------------------------&lt;br /&gt;The following web services will be called by different clients for charging/ refund etc.&lt;br /&gt;From a logging perspective it is important to know exactly which client asked for the transaction for an order.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;==================&lt;br /&gt;Recommendations&lt;br /&gt;==================&lt;br /&gt;Authenticate the caller. Authorize to make sure the caller is allowed to call the service.&lt;br /&gt;Once action is taken, log the caller's identity against the action taken. This is important for scenarios where the caller may later repudiate calling the service and taking the action.&lt;br /&gt;&lt;br /&gt;b) Multi-tiered applications MUST track and push, from beginning to end, all information necessary to audit transactions. This MUST occur from the original connection to the system, through authentication and/or impersonation, to the end of the interaction.&lt;br /&gt;&lt;br /&gt;Verified. The serial number of the client certificate used to authorize the caller has been logged as part of the call.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-8796094036690769583?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/8796094036690769583/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=8796094036690769583' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/8796094036690769583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/8796094036690769583'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/02/commonly-found-security-issuess-in-web.html' title='COMMONLY FOUND SECURITY ISSUESS IN WEB SERVICES . NET CODE'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-7873369120350845938</id><published>2008-02-01T11:00:00.000-08:00</published><updated>2008-02-01T11:03:41.345-08:00</updated><title type='text'>You can add me in Linked in contacts</title><content type='html'>&lt;a href="http://www.linkedin.com/pub/4/611/739"&gt;http://www.linkedin.com/pub/4/611/739&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-7873369120350845938?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/7873369120350845938/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=7873369120350845938' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/7873369120350845938'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/7873369120350845938'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/02/you-can-add-me-in-linked-in-contacts.html' title='You can add me in Linked in contacts'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-2554489164513152868</id><published>2008-02-01T10:56:00.000-08:00</published><updated>2008-02-01T10:58:31.782-08:00</updated><title type='text'>One more Security Blog which i started long back in 2004</title><content type='html'>This blog is related to .NET Security&lt;br /&gt;&lt;br /&gt;&lt;a href="http://dotnetsecurity.blogspot.com/"&gt;http://dotnetsecurity.blogspot.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-2554489164513152868?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/2554489164513152868/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=2554489164513152868' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/2554489164513152868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/2554489164513152868'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/02/one-more-security-blog-which-i-started.html' title='One more Security Blog which i started long back in 2004'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-8078501063289686422</id><published>2008-02-01T10:52:00.000-08:00</published><updated>2008-02-01T10:55:12.040-08:00</updated><title type='text'>My other Database security blogs</title><content type='html'>Database realated security blog&lt;br /&gt;&lt;br /&gt;&lt;a href="http://sqlsecurity.blogspot.com/"&gt;http://sqlsecurity.blogspot.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-8078501063289686422?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/8078501063289686422/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=8078501063289686422' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/8078501063289686422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/8078501063289686422'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2008/02/my-other-database-security-blogs.html' title='My other Database security blogs'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1949747169695871819.post-9211518022632643781</id><published>2007-08-21T20:41:00.000-07:00</published><updated>2007-08-21T21:18:39.094-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security consultant'/><title type='text'>About Me</title><content type='html'>Protect &lt;strong&gt;&lt;span style="color:#3366ff;"&gt;&lt;span style="color:#ff6600;"&gt;Confidentiality&lt;/span&gt;,&lt;span style="color:#ccffff;"&gt; &lt;/span&gt;&lt;span style="color:#cccccc;"&gt;Integrity, and&lt;/span&gt; &lt;/span&gt;&lt;span style="color:#33ff33;"&gt;Availability&lt;/span&gt; &lt;/strong&gt;of information and information systems. Advise and engineer secure solutions for business opportunities. Learn and experience, mentor and share.&lt;br /&gt;&lt;br /&gt;The Three words are my part of daily &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_0"&gt;calender&lt;/span&gt;.by now you understand what is my profession, i am &lt;strong&gt;&lt;span style="color:#6633ff;"&gt;&lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_1"&gt;security&lt;/span&gt; consultant.&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#6633ff;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;Around Six years of overall IT experience for &lt;strong&gt;Fortune 100 Inc&lt;/strong&gt; in which includes Three+ years of experience in &lt;strong&gt;Application Security&lt;/strong&gt;. In depth knowledge of &lt;strong&gt;&lt;span style="color:#3333ff;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Appsec&lt;/span&gt;, Code Reviews, Design Reviews, Deployment reviews, Threat modeling, Risk Assessment.&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#3333ff;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="color:#333333;"&gt;Working  &lt;/span&gt;&lt;a href="http://blogs.msdn.com/ace_team/default.aspx"&gt;&lt;span style="color:#333333;"&gt;ACE Team&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#333333;"&gt; from past 3+ years and reviewed more then 100+ Enterprise Level applications with more then 4000+ man hours of Experience in Appsec.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1949747169695871819-9211518022632643781?l=mahavirsancheti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mahavirsancheti.blogspot.com/feeds/9211518022632643781/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1949747169695871819&amp;postID=9211518022632643781' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/9211518022632643781'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1949747169695871819/posts/default/9211518022632643781'/><link rel='alternate' type='text/html' href='http://mahavirsancheti.blogspot.com/2007/08/about-me.html' title='About Me'/><author><name>Mahavir Sancheti</name><uri>http://www.blogger.com/profile/02186965805732189684</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
