Thursday, March 27, 2008

How To Issue A Self-Signed SSL Certificate for Microsoft IIS

Here is the Microsoft KB article with the step-by-step (mostly) instructions on how to install a self-signed SSL Certificate.

If you need a cert that will work for public access, you will need to buy a SSL Certificate from a trusted CA.  Check out this SSL FAQ for more details.

Monday, March 03, 2008

Windows Vista (In)Capable?

Saw a good story on ZDNet about the Windows Vista Capable branding fiasco that is currently sucking the life from Microsoft.

What went wrong? I'll tell you what went wrong: Microsoft execs - starting with Steve Ballmer - don't care enough about their customers. Which is too bad for the thousands of smart, hard working 'softies who do.

Another good blog post about inadequate executes in the CEO and CTO positions at big companies (all too common an issue) called "Time To Go" by the same guy about Steve Ballmer.

Steve Ballmer may be the worst CEO among large tech companies - now that Kevin Rollins got booted from Dell and Sanjay Kumar of CA is in jail. Put him in a room with Steve Jobs of Apple, John Chambers of Cisco and Mark Hurd of HP and he'd look like the bouncer, not a peer. He just isn't in their league and Microsoft is suffering for it.

I could not agree more with both of these posts.  Vista sucks even on good hardware.  Microsoft has grossly over estimated sales, launch date and performance of the OS for customers. 

I, for one, have gone back to XP -- at least all my devices have drivers and my machine is stable again.

Monday, November 12, 2007

Creating Event Log EventID Values Using C# and .Net 2.0

As all good developers do, I try to log my errors.  However, on some machines I can access the event log ("Application" log in this case) and use EventID of 1000 or 0 or other values, however, it is not consistant what is available between Windows 2000, Windows XP, Windows Server 2003.

So I have the following in my Event Log more often that I would like:

The description for Event ID ( 0 ) in Source ( Application Error ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event:  ...

http://www.codeproject.com/dotnet/evtvwr.asp
http://blog.sbsfaq.com/Lists/Posts/Post.aspx?List=269e4081%2Dac58%2D42a6%2D9a54%2D383a6a3fb0d8&ID=49

Tuesday, October 09, 2007

BizTalk 2006 Testing, Interviews & Other Stuff

I have been using BizTalk Server 2006 for a few months now and I thought I'd post some of the things I've been using here.

I hope you have enjoyed this BizTalk Server 2006 Link List.

By the way, BizTalk Server 2006 R2 is on the street now so go check it out.  Death to HWS!

A practical and authentic approach to massively parallel computing

The face of computer science is always changing and the pace of that change increases every day.  One of the huge ongoing changes in today's engineering approach is a shift from single machines, or small clusters of machines, to massive distributed networks containing hundreds, if not thousands, of servers.  Massively parallel and foreign to most people.

Today the Google blog contained an entry called Let a thousand servers bloom about this topic and they reference a really interesting lecture series they are hosting on Google Code for Educators called Cluster Computing and MapReduce which contains video lectures and related course materials from a series of lectures that was taught to Google software engineering interns during the Summer of 2007.

While not part of the Google Blog linked above, Google Code for Educators also has a great lecture on Web Security containing two lectures and a programming assignment that is designed to introduce students to web based security.

Thursday, September 20, 2007

BizTalk 2006, Users, Groups & Troubleshoot

Have you ever needed a full list of the BizTalk 2006 users and groups -- here is one from Microsoft .  If you used that guide Microsoft supplied to install BizTalk 2006, and it did not work (surprise!) you will probably need this BizTalk 2006 Troubleshoot Guide and Tools list.  This dedicated list of BizTalk 2006 troubleshoot utilities is very useful.  And of course, the most common trouble spot with BizTalk 2006 Server is the software components it depends on -- that is why this guide to troubleshoot BizTalk 2006 dependencies is so great!

Tuesday, September 04, 2007

Custom GetContextProperty Functoid

A newer version of the GetContextProperty functiod, and another useful "sister" functiod can be found here, http://www.codeplex.com/ContextAccessor.

Custom GetContextProperty Functoid

How can I get a message context property (promoted property) from a message in a map for use inside of an orchestration?

Using the Custom GetContextProperty Functoid, of course!

Sunday, April 29, 2007

Yahoo Search Advertising is a FRAUD

I blogged a few weeks ago about my renewed interest in Yahoo Sponsored Search in my "Dear Yahoo" post.  At the time, I thought that perhaps Yahoo was turning a corner in the online advertising sphere and might have finally figured it out.  I have now, after spending $220 USD and one entire month advertising with them, realized how wrong I was. 

Yahoo's online search ad placement system is horrible.

In fact, I suspect the majority of the site traffic generated by a Yahoo ad is actually fraud.
  Google Analytics is a powerful tool and I could teach a class on it at this point -- I've been using it since it was released and I have gone to seminars and taken classes.  So, I spent a few hours focused on Yahoo traffic analysis.  As it turns out, the "visitors" from Yahoo are (98%) fraud generated by Yahoo's content placement site.  Probably ad-placement scammers buying ads from Yahoo and then using "pay to browse" or automated methods to fire the ads and collect my money.

I am getting a 1.05PPV (pages viewed per visit)  traffic load from Yahoo traffic.  That means that 94.55% of the visitors are viewing only the first page after the ad link and then closing the browser -- a sure sign of fraud from the source.  All my legitimate traffic ( Google, TheKnot, WeddingChannel, CraigsList, Yahoo Organic Search) averages a bounce rate (immediate exit) of around 3.85 which is low, to be sure, but does not mean fraud.  The bounce rate for my average traffic is only 22%.

In addition, Yahoo is reporting that I get about 10 visitors a day from their ads.  I am finding about 10% of the traffic I am being billed for actually makes it to my site.  I suspect part of this is that most of the scammers have found a way to trigger the ads in an automated fashion that does not actually request pages from my site -- they're just getting Yahoo to record the click and never even downloading pages from CoryTrese.com

Other key terms I might use to describe Yahoo Sponsored Search include "click fraud", "fraud", "deception", "sucks", "lies", "terrible", "illegal", "unfair", "deceptive business practices" and maybe some other words I won't use on my blog.

Monday, April 09, 2007

Top 10 Security Vulnerabilities in .NET Configuration Files

Developers often concentrate on writing secure code but leave security vulnerabilities in application configuration files. Discover the most common configuration security problems—and how to avoid them.
by Bryan Sullivan

Top 10 Security Vulnerabilities in .NET Configuration Files

Wednesday, February 28, 2007

ASP.Net 2.0 Complex User Controls and External JavaScript

If you are anything like me, you're spending a lot of time working with ASP.Net 2.0 building complex user controls.

For example, you might need to have a large piece of JavaScript included as an external resource, not emitted into the .aspx page.  This page has a detailed step-by-step guide on how to embedded URL accessible resources into a control.

Or perhaps, also like me, you are making use of the System.Web.UI.Masterpage namespace and are wondering about passing objects between content and master pages.  Well, this page has a detailed step-by-step guide on how to pass information between Content and Master pages in ASP.Net 2.0.

Tuesday, January 23, 2007

XSD and MSXML 4.0 SP2

Upgrading your XSD to parse on a release of the Microsoft XML Parser 4.0? Using XSD (XML Schema?) Having trouble?

Check this page about conformance to XSD specifications within the Microsoft XML Parser 4.0 software.

For example, might be generating the error:

'all' is not the only particle in a group, or is being used as an extension

Thursday, January 11, 2007

Secure ASPSESSIONID Cookies in IIS 4, 5 and 6.0

>From this great page on Microsoft's Help and Support Site:

When you use Active Server Pages (ASP) in Internet Information Server (IIS) 4.0 or Internet Information Services (IIS) 5.0, a session cookie is sent to a user's browser. This cookie identifies the user for the time that they are on the site. These cookies are sometimes called memory cookies, because they are never stored on the user's hard drive like a regular cookie. In reality, this is an additional header that is sent to the browser. Anytime a Web site sends additional information such as this, the browser is required to send it back with each request (provided the server name does not change). The following is an example of an ASP Session Cookie:
Set-Cookie: ASPSESSIONIDGQQGGLIC=HKEDPNNBNBBKMOCFFBEIJENM; path=/
HTTP is a stateless protocol, which means that every time a user connects to a Web site it is just like the first time they connected to the Web server. This is a problem in an environment where you store server-side information for users. The session cookie is a means of performing such tasks.

A problem can occur if developers decide to store confidential or sensitive information in the session. For example, if a developer writes a piece of ASP code that requests a user's credit card number, the developer can store this information in a session variable (session variables are linked to the session cookie) on the server. The user can then browse to a page that lists the information they entered (for example, an authorization page or an order confirmation page). The credit card (when the list is generated) may be pulled from a session variable. If so, this information may be at risk.


The Help and Support page linked to above covers IIS 4.0 and 5.0, however, the command that it lists at the end:

NOTE: After you apply the patch, run the following commands to enable secure cookies (this example enables them for site 1):\

cd c:\inetpub\AdminScripts
cscript adsutil.vbs set w3svc/1/AspKeepSessionIDSecure 1

Is correct for all versions of IIS.  For version 6.0 of IIS simply run that command and the ASPSESSIONID cookie will be set to secure.

Tuesday, January 09, 2007

IEs4Linux, Support for IE7

I have blogged about this project before, but it is good enough to blog about again.  The project, called ies4linux exists to support installing and running multiple original versions of IE (5.0, 5.5, 6.0, 7.0) under Linux using Wine and CAB files.  Another good blog entry on Web Expose talks in detail about IE 7.0 support and has a good thread of comments from early testers and adopters.

IE on Linux.  Never would have guessed that one back in 1999, would ya?  =)

Saturday, January 06, 2007

10 Best Extensions for Everyone's Favorite Browse

I was reading some random reviews of the last FireFox 2.0 release and hit this link on CNet showing a list of the "10 best firefox extensions" ... some of the choices are terrible, but some are rather good. I already use a few of them...

Thursday, December 28, 2006

C# Class Picturebox Improved for Aspect Ratio & Photograph Display in .Net

The key difference between Picturebox and the Photobox class implemented in this blog entry is that the Photobox class supports aspect ratio scaling and is appropriate for displaying photographs in an application.

Tuesday, December 26, 2006

SSL and TSL Essentials

By now, we are growing accustomed to the staggering success of the Internet and digital commerce performed over it. Millions of people—with billions of dollars—rely on the Web to execute critical transactions every day. All of those transactions require trust.

Users must trust the authenticity of the Web site; users must trust that their sensitive information remains confidential as it traverses the Internet and users must trust that no malicious hacker has modified their requests.

Security technology provides that trust. And on the Web, the Secure Sockets Layer (SSL) protocol is THE security technology.

Read the rest here at www.NetworkSystemDesignLine.com

Thanks for reading,

Cory Trese
cory.trese@gmail.com
http://www.corytrese.com/

Thursday, December 21, 2006

Interview with Joyce Park

Joyce Park is the co-founder and CTO of Renkoo.  I saw this blog entry, and interview with Joyce Park from Friendster and it has a series of questions about getting shitcanned for blogging.  I think a more interesting topic is blogging after you get shitcanned, something I know a little bit about.  But unlike this person, I gave in and edited my entries.

Wednesday, December 20, 2006

Google Kills SOAP?

From Google Deprecates Their SOAP Search API:

The AJAX Search API is great for web applications and users that want to bling their blog, but does not provide the flexibility of the SOAP API. I am surprised that it has not been replaced with a GData API instead. The developer community has been discussing this and do not seem happy with the change. Discussion on the forums have pointed out that Yahoo! has a REST Search API. Live Search also has a SOAP API available.

This worries me.  What is Google doing?  Trying to kill off developer mind share?

Tuesday, December 19, 2006

ASP.Net 1.1 Does Not Stop XSS or Cross-Site Scripting

The built in protection in ASP.Net 1.1 is broken.

The "ValidateInput()" method does not work.  It ignores null characters and so does IE.  So, all your 'ValidatePageInput="true"' does nothing.  You are not safe.

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnaspp/html/scriptingprotection.asp

Write your own HTTPModule or buy mine.