Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

2/27/2017
02:45 PM
50%
50%

Microsoft Adds Technical Updates to SDL Site

Microsoft releases a new round of updates and technical content additions to its Security Development Lifecycle website.

Microsoft has released a new wave of updates and technical content additions for its Security Development Lifecycle (SDL) website, which contains resources for securely developing and testing software.

These changes affect the SDL Developer Starter Kit, security tooling guidance, and compiler and cryptographic recommendations. Microsoft has consolidated its Security Tools recommendations, replaced BinScope with BinSkim, and published guidance to help developers with cryptography, among other updates. 

"Detailed Cryptographic Recommendations taken from Microsoft internal standards are now available for the first time – providing valuable guidance for developers looking to build cryptography into applications and services in line with Microsoft's own practices," Andrew Marshall, Microsoft's principal security program manager for security engineering wrote in a blog post today announcing the updates. 

The DSL updates are part of a broader investment to improve security at Microsoft, and the company promises additional changes in coming months.

Read more details on the Microsoft blog

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
FortyRock
50%
50%
FortyRock,
User Rank: Apprentice
2/28/2017 | 8:47:15 AM
Re: Proofreading 192.168.l.l
Expect from whom?  Expecting Dark Reading to fix the typo.

Re the doc, this is to serve as formal recommendations for developers.  Correct?  A good start would have been a cover page, and some sort of versioning/document ID/page numbering would have been nice, too. Digitally signed PDF with Microsoft IDd in the metatags would have been nice, too.

 
mikeroch
50%
50%
mikeroch,
User Rank: Apprentice
2/28/2017 | 5:24:38 AM
Re: Proofreading 192.168.l.l
Security is the biggest concern for the safety of the resources, Microsoft has done great job by implementing updates to SDL sites. more updates are also coming soon, let's see what comes as new feature too.

I am excited for new features. @FortyRock, what updates you expect? 
FortyRock
50%
50%
FortyRock,
User Rank: Apprentice
2/27/2017 | 4:32:52 PM
Proofreading
"The DSL updates are part of a broader investment to improve security at Microsoft, and the company promises additional changes in coming months."

SDL perhaps?

Good read otherwise, even though I would have expected something a little more formal looking from them.
RDP Bug Takes New Approach to Host Compromise
Kelly Sheridan, Staff Editor, Dark Reading,  7/18/2019
The Problem with Proprietary Testing: NSS Labs vs. CrowdStrike
Brian Monkman, Executive Director at NetSecOPEN,  7/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-10101
PUBLISHED: 2019-07-23
ServiceStack ServiceStack Framework 4.5.14 is affected by: Cross Site Scripting (XSS). The impact is: JavaScrpit is reflected in the server response, hence executed by the browser. The component is: the query used in the GET request is prone. The attack vector is: Since there is no server-side valid...
CVE-2019-10102
PUBLISHED: 2019-07-23
Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580fef36d36 is affected by: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'). The impact is: Remote code execution with the same privileges as the...
CVE-2019-10102
PUBLISHED: 2019-07-23
Jeesite 1.2.7 is affected by: SQL Injection. The impact is: sensitive information disclosure. The component is: updateProcInsIdByBusinessId() function in src/main/java/com.thinkgem.jeesite/modules/act/ActDao.java has SQL Injection vulnerability. The attack vector is: network connectivity,authenticat...
CVE-2018-18670
PUBLISHED: 2019-07-23
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the adm/config_form_update.php cf_1~10 parameter.
CVE-2018-18672
PUBLISHED: 2019-07-23
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka the adm/board_form_update.php bo_content_head parameter.