Skip to main content
MSRC

BlueHat

Predicting the Future - Microsoft Launches an “Exploitability Index”

Tuesday, August 05, 2008

Handle: Silver Surfer IRL: Mike Reavey Rank: Director, MSRC Likes: Warm weather, Battlestar Galactica, and responsibly reported vulnerabilities Dislikes: Rain, Rain without end, Clouds with potential for rain, reality TV, and unpatched vulns Hey all – Mike Reavey here. I’ve been with the Microsoft Security Response Center (MSRC) for over five years now, and working in security for over a decade.

Security through Collaboration: Microsoft Active Protections Program

Tuesday, August 05, 2008

Handle: Cap’n Steve IRL: Steve Adegbite Rank: Senior Security Program Manager Lead Likes: Reverse Engineering an obscene amount of code and ripping it up on a snowboard Dislikes: Not much but if you hear me growl…run Yut!!! Nothing like a motivating US Marine Corps yell to get your attention. Hey Steve Adegbite here, just wanted to drop some words and give you my perspective on some of the News we (Microsoft) announced this morning.

Black Hat 2008: What it Means, What to Expect

Monday, August 04, 2008

Handle: The Crushman IRL: Andrew Cushman Rank: Security Director Likes: Cranberry juice (thanks Jay!) Dislikes: Super helpful hotel desk clerks (thanks Raoul?) Hey Andrew Cushman here… It’s that time of year, August in Vegas, time for the big show, it’s Black Hat time… Along with the vivid memories of crowded briefing rooms, the critical mass of security talent, great side conversations, and the ever present “ching-ching” of slot machines - this year, it brings up thoughts of where Microsoft, the Microsoft Security Response Center (MSRC) and our commitment to Trustworthy Computing (TwC) have been and keen anticipation of where we’re going.

Defend the Flag: Roguery Abounds!

Monday, August 04, 2008

Handle: k8e IRL: Katie Moussouris Rank: Senior Security Program Manager Likes: Cool vulns (responsibly disclosed of course), girls with soldering irons, Spanish tapas, quantum teleportation Dislikes: Rudeness, socks-n-sandals, licorice The air was thick with adrenaline and action as the teams battled each other for the top spot at Microsoft’s Defend the Flag (DTF) training at Black Hat USA.

Welcome to the new MSRC Ecosystem Strategy (EcoStrat) Team Blog

Monday, August 04, 2008

Handle: Security Blanki IRL: Sarah Blankinship Rank: Senior Security Strategist Lead Likes: Vuln wrangling, teams of rivals, global climate change - the hotter the better Dislikes: Slack jawed gawkers (girls are geeks too!), customers @ risk, egos One researcher, one community, one hacker at a time we are building a community-based defense to help secure our customers, our partners and the Internet.

THE BUSINESS OF PUTTING US OUT OF BUSINESS

Friday, August 01, 2008

Let me tell you about a great business plan I ran into recently. It’s not the traditional “we’re all going to make millions” operation, but it has some characteristics you’ll relate to if you have ever tried to pitch a startup idea to a VC … This is a business that has remarkably innovative financing and sales/marketing operations.

Title: A Buddhist Monk Goes Up to a Hot Dog Vendor…

Friday, July 18, 2008

…and says “Make me one with everything.” Aside from that fact that most hot dog vendors don’t carry Tofu Pups, we’re taking this joke seriously for the next iteration of BlueHat, and giving you some attack content as well as talking about proactive defense. Coming this October, the BlueHat team will partner with the SDL team to create two full days of content, the first day focusing on new attacks and the emerging threat horizon, and the second day focusing on steps we can take as software architects, developers, testers, and maintainers to make code more secure in the first place.

XSSFilter in Internet Explorer 8.0

Wednesday, July 02, 2008

Hello everyone, this is Robert “RSnake” Hansen. It’s been a while since I’ve talked with the BlueHat folks but only because I’ve been busy behind the scenes working on some cool stuff with the Microsofties. I was pleasantly surprised to hear I am now allowed to talk about one of the things I have helped work on.

Blue Hawaii

Thursday, June 19, 2008

After a whirlwind trip to beautiful Honolulu, Hawaii to give the Day 2 keynote at ShakaCon, I am finally back to reality here at Microsoft. More on that shortly, from another blog… Right here, right now, BlueHat video interviews with the speakers are available. From “Bad Sushi: Beating Phishers at Their Own Game” with our own Billy Rios to “Token Kidnapping” with Cesar Cerrudo of Argeniss – get an exclusive sneak peek into what really happened at BlueHat v7.

"Mr. Miller Goes to Washington"

Friday, May 09, 2008

Hi, Charlie Miller here. I was asked to come out to BlueHat to participate in a panel discussion about the vulnerability economy and selling exploits and such. Hopefully the folks who sat through us arguing for an hour got something out of it. I enjoyed it. When I’m not out shining a light onto the dark world of exploit sales, I’m usually spending my time looking for bugs in software, particularly with fuzzers.