CAT.NET ForumWelcome to the CAT.NET CTP. This forum is for you to give us your feedback and suggestions for new and improved functionality in CAT.NET.© 2009 Microsoft Corporation. All rights reserved.Sun, 29 Nov 2009 07:34:14 Zc2f8961e-0110-4a4e-9657-9725e10e0a36http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/e5718bbe-8bad-4f94-bf1f-00e34435d0dbhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/e5718bbe-8bad-4f94-bf1f-00e34435d0dbSunil from Indiahttp://social.msdn.microsoft.com/Profile/en-US/?user=Sunil%20from%20IndiaDo i require a third party firewall for my server?I do not have any ports opened on my Windows Firewall. Do i still require to go for a third party firewall like Sonicwall? What advantage do i get if i go for a third party firewall?<br/>Sun, 29 Nov 2009 07:34:14 Z2009-11-29T07:34:14Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/45109f2e-2984-4556-813c-7fac2e456c02http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/45109f2e-2984-4556-813c-7fac2e456c02lremedihttp://social.msdn.microsoft.com/Profile/en-US/?user=lremediVS 2008 SP1 and CAT.NET(1.1.1.9) as FxCop Rule problemHello, I'm really new with this, and I couldn't find a solution. <br/> This is the situation:<br/> <br/> I've been trying to use CAT.NET, as an FxCop Rule. <br/> I've done everything according to FAQ.rtf document, I've copied <strong>Microsoft.ACESec.CATNet.Core.dll</strong> file, and<strong> \Config</strong> and <strong>\Rules</strong> folder, to <strong>FxCop\Rules</strong> folder (in VS 2008 folder).<br/> I'm able to see the rule (<strong>Interprocedural Dataflow Rules</strong> ) in Code Analysis rule list (Project-&gt;Properties), but when I try to run Code Analysis, I receive an error saying that Microsoft.ACESec.CATNet.Core.dll contains <strong>no FxCop Rules</strong> .<br/> <br/> <strong>CA0053 : <br/> Unable to load rule assembly 'C:\Program Files\Microsoft Visual Studio 9.0\Team Tools\Static Analysis Tools\FxCop\Rules\Microsoft.ACESec.CATNet.Core.dll': The assembly contains no FxCop rules.</strong> <br/> <br/> Any suggestion (magic trick)??<br/> <br/> Thanx, Laureano.<br/>Thu, 26 Nov 2009 13:31:42 Z2009-11-26T13:31:42Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/986b2c7c-2393-4d73-b900-68fba7324903http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/986b2c7c-2393-4d73-b900-68fba7324903mislahttp://social.msdn.microsoft.com/Profile/en-US/?user=mislaEvent 7000I have received several of the following errors in the Event Viewer/Administrative Events:<br/><br/><span lang=EN> <p>&quot;The Windows CardSpace service failed to start due to the following error:</p> <p>The service did not respond to the start or control request in a timely fashion.<br/><br/>Log Name:  System<br/>Source:  Service Control Manager Eventlog Provider<br/>Event ID:  7000<br/>Level:  Error<br/>User:  N/A<br/>OpCode:  Info<br/>Task Category:  None<br/>Key Words:  Classic&quot;<br/><br/>I have checked the Web and am not sure if my computer has been compromised.  Would appreciate any help.  Thanks!<br/><br/><br/>I checked the Web and am not sure which applies.  Can you tell me what this could mean?<br/></p> </span>Sun, 22 Nov 2009 02:34:55 Z2009-11-22T02:34:56Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/c173dee9-6e48-4fd9-b180-b9a2d7327933http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/c173dee9-6e48-4fd9-b180-b9a2d7327933WreckingBall2http://social.msdn.microsoft.com/Profile/en-US/?user=WreckingBall2How do you stop the "Publisher Cannot Be Verified" screen from popping up when your program is being installed? I don't want to change the settings on my computer. Is there something you do in Project &gt; Publish?Sat, 21 Nov 2009 19:51:23 Z2009-11-21T19:51:23Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/998094f7-9891-4c1e-a633-77b347fb8d44http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/998094f7-9891-4c1e-a633-77b347fb8d44stevelloydfalmouthhttp://social.msdn.microsoft.com/Profile/en-US/?user=stevelloydfalmouthWindows 7 antivirusI am about to install Windows 7, I have run my 2009 Norton internet security disc. Norton has flagged up that i dont have Malware/spyware cover.<br/>Ive looked on the microsoft site for software but it says about Vista, which is what im running now, nothing about recommended spyware for 7<br/>Do i have to pay for spyware protection.<br/>What spyware would you reccomend, i spend a lot of time on the internet sometimes the sites see seem i bit iffyFri, 20 Nov 2009 13:39:51 Z2009-11-20T13:39:51Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/248a8e84-0e37-4d24-bfce-8f23c9a84c44http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/248a8e84-0e37-4d24-bfce-8f23c9a84c44dr_csharp_firsthttp://social.msdn.microsoft.com/Profile/en-US/?user=dr_csharp_firstemergency : my page is in attackhi friends some one are attacking my web site,he/she is requesting my site over and over ( his/her IP addrress seems changing randomly )..what can i do ? ThanksWed, 18 Nov 2009 19:12:36 Z2009-11-18T19:12:36Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/918e9976-7f88-4030-9bf7-acb5c812ae5ahttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/918e9976-7f88-4030-9bf7-acb5c812ae5agalpal1958http://social.msdn.microsoft.com/Profile/en-US/?user=galpal1958gaining access to my computer by remote or hackingis there anyway i can look on my computer to see if anyone is trying to gain remote access or<br/>access by any other means, i feel like someone is looking at my information and just checking out<br/>what im looking at on my computer in general<br/>Wed, 18 Nov 2009 14:09:29 Z2009-11-18T14:09:30Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/273a841e-0a1e-425e-8240-2b89dfc48483http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/273a841e-0a1e-425e-8240-2b89dfc48483SFioritohttp://social.msdn.microsoft.com/Profile/en-US/?user=SFioritoRestart this forumCan we please shut this sub-forum down, and restart it under either .NET Development or the VSTS Code Analysis forum?<br/><br/>This forum has totally lost all usefulness due to people coming in and trashing it with questions completely unrelated to CAT.NET. So actual CAT.NET users don't have a good place to collaborate or find good information.<br/><br/>Can we just migrate this to a new forum, and move the CAT.NET related threads along with it so as not to lose any information?<br/><br/>Thanks,<br/>SilvioSat, 14 Nov 2009 17:19:58 Z2009-11-14T17:19:58Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/14e4ee94-8675-437d-88da-28446d2f4e1dhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/14e4ee94-8675-437d-88da-28446d2f4e1dMaenghttp://social.msdn.microsoft.com/Profile/en-US/?user=MaengDigital Signature with two HashI have to do Digital Signature for xml document.<br/>In this case, there is difference with regular Digital Signature.<br/>That is element &lt;Reference&gt; is two, and Transform of one of  them is <br/><br/>&lt;ds:Transform Algorithm=&quot;<a href="http://docs.oasis-open.org/wss/oasis-wss-SwAProfile-1.1#Attachment-Content-Signature-Transform">http://docs.oasis-open.org/wss/oasis-wss-SwAProfile-1.1#Attachment-Content-Signature-Transform</a>&quot; /&gt;<br/><br/>And, I guess, cannot use SignedXml Class because, this kind of alogrithm is not supported by .net Framework.<br/>So, I will try to include Crypto Api directly then, extract Sha-1 DigestValue and get SignatureValue by PrivateKey encoding of that.<br/>But I wonder, how to encrypt in this situation? (there are each TWO &lt;Reference&gt; in &lt;SignedInfo&gt; &amp; DigestValue)Tue, 10 Nov 2009 09:03:11 Z2009-11-10T09:03:12Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/e88cba12-14e2-4ffd-94ae-65ce7258c796http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/e88cba12-14e2-4ffd-94ae-65ce7258c796Secnarfhttp://social.msdn.microsoft.com/Profile/en-US/?user=SecnarfSecnarfI recently loaned my computer to a very computer-wise friend whom I no longer trust.  I want to ensure that he cannot access any information etc that I have on my computer now or in the future.  <br/> Is there any way I which I can check if he has access to my computer from his own or any other computer?<br/> I am not very computer literate myself.Mon, 09 Nov 2009 15:15:41 Z2009-11-09T15:15:43Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/603c638c-81f4-40e5-b027-4cd4de4c119ehttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/603c638c-81f4-40e5-b027-4cd4de4c119ePencil53http://social.msdn.microsoft.com/Profile/en-US/?user=Pencil53How can I block other people on a LAN I am on from accessing my computer? Security software and using a router makes no difference. It's not my LAN. <br/>I didn't set it up, I didn't sign up for it, and I never gave anyone permission to use my connection or access my computer. I'm not using a router. I've tried to get my ISP to help but they won't and I've tried everything I could do myself. I'm getting hacked by someone really vicious and it is ruining my life. I need some advice!<br/><br/>Thanx - MUCH<br/>Sun, 08 Nov 2009 08:03:30 Z2009-11-08T08:03:30Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/423a09f2-9125-47de-9981-1039914191c1http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/423a09f2-9125-47de-9981-1039914191c1Pencil53http://social.msdn.microsoft.com/Profile/en-US/?user=Pencil53Please help me quick! I've discovered that everything I do goes directly to my internet history! Every time I open any file, be it documents, pictures or whatever it goes strait to my intertnet history. I don't want it there because I have a hacker and I think they will post or store it somewhere. I don't want it going online! I had a story I was writing once stolen this way. I tried turning off the file sharing but it's still happening.<br/><br/>Thanx, friends!Sun, 08 Nov 2009 07:47:27 Z2009-11-08T07:47:27Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/adeff560-fcbe-48d4-833c-9eb3879e3529http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/adeff560-fcbe-48d4-833c-9eb3879e3529Microapplehttp://social.msdn.microsoft.com/Profile/en-US/?user=MicroappleSecurity-hole in Vista Home Prem.?I was recently checking my security log and i found this: <div><span style="font-family:-webkit-monospace;font-size:medium"><span style="font-size:16px"> <pre>It was logged on an account. Topic: Security ID: SYSTEM Account name: KEVIN-PC $ Account Domain: WORKGROUP Login ID: 0x3e7 Logon Type: 5 New login: Security ID: SYSTEM Account Name: SYSTEM Account Domain: NT AUTHORITY Login ID: 0x3e7 Sign-GUID: (00000000-0000-0000-0000-000000000000) Process information: Process ID: 0x284 Process Name: C: \ Windows \ System32 \ services.exe Network Information: Name of workstation: Address to the source network: -- Source Port: -- Detailed Authentication Information: Logon Process: Advapi Authentication Package: negotiate Transferred services: -- Package Name (NTLM only): -- Key Length: 0 This event is generated when a logon session is created. It is generated on the computer where access was granted. Subject field, enter the account on the local system which requested the logon. This is usually a service that the Server service, or a local process that Winlogon.exe or Services.exe. Logon Type field indicates what type of credentials that were used. The most common types are 2 (interactive) and 3 (network). The fields for the new sign indicates which account the new login was created from, ie the account that was logged on. Network fields indicate where the remote login request came from. The name of the workstation is not always available, and the field can sometimes be empty. The fields with authentication information provides detailed information about this specific logon request. - Sign-GUID is a unique identifier that can be used to coordinate this event with a KDC event. - Beamed services indicate which intermediate services have participated in this logon request. - Package name indicates which under the protocol used among the NTLM protocols. </pre> Is it a hacker that tryies to hack into my system?</span></span></div> <div><span style="font-family:-webkit-monospace;font-size:medium"><span style="font-size:16px"><br/></span></span></div> <div><span style="font-family:-webkit-monospace;font-size:medium"><span style="font-size:16px"><br/></span></span></div>Thu, 06 Aug 2009 10:34:27 Z2009-11-07T17:14:37Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/87399d7b-8c84-48b9-8908-cf7abd3d54b3http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/87399d7b-8c84-48b9-8908-cf7abd3d54b3armin3http://social.msdn.microsoft.com/Profile/en-US/?user=armin3IIS 7 certificatesHello!<br/> <br/> I want to implement this on my site. I want to create certificate and then e-mail it to user. User then install this certificate and he can access site. Anyone without certificate can't access site. Can anyone tell me what is procedure to implement this for free :).<br/> <br/> Thank youThu, 05 Nov 2009 07:50:24 Z2009-11-05T07:50:25Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/9a0fd0ce-d474-460c-885b-436af4d15617http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/9a0fd0ce-d474-460c-885b-436af4d15617joebb3651http://social.msdn.microsoft.com/Profile/en-US/?user=joebb3651Security ConfusionI just DON'T at all understand this!<br/>I have 2 virtual servers on the same machine. Same network, same domain (CTD). I'm working on a website using AJAX/ASP NET 3.5. I wanted to implement aspnet security and that is where all the issues popped up and I am unable to make anything work from an outside browser. If you can help please do so BUT please don't point me at any &quot;great examples&quot;. I have tried at least a dozen of them and none of them work in my configuration. I need a more targeted description applied to my situation. I don't need a first select this from this menu, etc approach. I need a generalized explanation of WHY I'm doing WHAT. I am a fairly competent SQL developer with some experience in other languages. Here are the specifics;<br/><br/>Until I tried to implement security everything worked as I wanted. Since I was on a closed system behind a firewall not even on our corporate network. All my pages correctly loaded data from a SQL Server 2005 instance (CTDB) on a virtual server. I was using the sa account and password to connect to the database from pages on another virtual server WWW. I was working from an admin account in Visual Studio 2008 adm. I created a new page and used a plain login object and created a login/pass in the asp .net configuration tool from the website menu. The login which used the above configuration worked with no issues from Visual Studio. But when I tried to login to the web site outside of VS I entered my login/pass and then got an issue that login failed for sa. I had my net admin create a new user ID specifically for this and changed all the entries in web config and the database configuration to use the new login/pass. I tried again and got the same error FOR SA! But now I get it from Visual Studio AND outside browsers. To make a long story short this is where I now am. I've been trying to make this work for about a week and still can't get it to work. So my questions are these:<br/><br/>What is keeping the new login/pass from working? I can connect using RDC to the server and the SQL server using the new login.<br/><br/>How do I setup the ASPSQLNETPROVIDER to use a SQL database NOT the Access file on the website? Again, I have looked at a bunch of examples and NONE of them make any sense. Isn't there a straightforward example with out all kinds of Form based application. I want this to work from a website not a Forms application.<br/><br/>Is there a way to import my current users table from SQL server to the ASPNETSQLPROVIDER table(s)?<br/><br/>Thanks for any help and guidance that anyone can offer,<br/><br/>Joe B<br/><br/><br/><br/><br/><br/>Tue, 03 Nov 2009 19:24:55 Z2009-11-03T19:24:56Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/376d7454-3f49-4f94-adf3-183bb2e3dcd5http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/376d7454-3f49-4f94-adf3-183bb2e3dcd5Mkabashihttp://social.msdn.microsoft.com/Profile/en-US/?user=MkabashiTrojan downloader 32I have that trojan in mu laptop ,it stops my anti virus Kasperesky from working,and I tried to scan with security essential ,<br/>but it stops in the middle of scanning,and shows a message code  Ox80070005, can you help pleaseMon, 26 Oct 2009 15:30:11 Z2009-10-26T15:30:12Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/23895f48-36be-4a9d-a18a-4137fc759705http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/23895f48-36be-4a9d-a18a-4137fc759705Mr Rockhttp://social.msdn.microsoft.com/Profile/en-US/?user=Mr%20RockHow to retrieve the password from active directory?I know that there is no way to get the password in plain text, because it is written in hashed form on AD, but is there a way to get the hashed password from active directory? <div>I need to validate user against the AD, and then add him to DB, so I need his password, and also I need to know the encryption method that AD uses, so I can encrypt password myself when validating password against DB alone.</div> <div>Thanks.</div>Mon, 26 Oct 2009 11:03:18 Z2009-10-26T11:03:19Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/a96facb8-f3b6-468b-8f3b-47b478762f0fhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/a96facb8-f3b6-468b-8f3b-47b478762f0fmarkm208http://social.msdn.microsoft.com/Profile/en-US/?user=markm208DES Initialization Vector in C#<div>I am trying to decrypt (using the DES algorithm) data that comes from a third party in C# code. There are plenty of examples here and elsewhere that have helped me out. The problem is that I don't know what to use for the 'initialization vector'. The initialization vector is required. I believe the third party uses CBC mode.</div> <div><br/></div> <div>The third party supplied a tool for use on the command line (DES.EXE, which I believe is an out-of-the-box build of the libdes library v4.01) which only requires that you supply an encryption key. So, I can decrypt fine with the command line tool. However, I would rather not spawn a process to run the tool from my code.</div> <div><br/></div> <div>My question is how do I generate/find that initialization vector. I am 99.9% sure it can be done from looking at other posts but I can't figure it out. I talked to the third party and they said they do not support that approach. In other words, they would not help me. Any help I can get here would be greatly appreciated.</div>Sun, 25 Oct 2009 20:01:05 Z2009-10-25T20:01:05Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/08aafa50-488a-4411-8faf-2fa36298cbfchttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/08aafa50-488a-4411-8faf-2fa36298cbfcManojBohttp://social.msdn.microsoft.com/Profile/en-US/?user=ManojBoCertificate ProblemI have created a certificate having my windows mobile connected &amp; added acertificate using Device Security Manager<br/> &amp; disconnected my device  . <br/>Then from my certificate mannager I deleted that certificate . <br/>Now from next time when ever I am trying to connect my device it is asking me to install that cetificate.<br/> Currently I don't have that certifcate &amp; from my visual studio I can't connect to my device .Pls guide me .Sat, 12 Sep 2009 05:48:36 Z2009-10-24T11:09:40Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/ba745d15-89fa-464b-b715-003a2c802747http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/ba745d15-89fa-464b-b715-003a2c802747inamsattihttp://social.msdn.microsoft.com/Profile/en-US/?user=inamsattiportable execution file format<span style="font-size:12pt;font-family:'Times New Roman','serif'">Microsoft Windows follows an executable file format called the PE (Portable Executable) files. A typical virus / mal-code tries to alter the file and inject malicious code in the file so that it would run during the life time of the program. By studying the file format indicate how this may be averted or what mechanisms are in place already to avoid it. Furthermore what modifications / mechanism do you suggest which may make changes to on-disk executable difficult if not impossible.<br style=""><br style=""></span>Tue, 20 Oct 2009 14:00:22 Z2009-10-24T10:52:15Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/3032812a-a1b3-4428-966e-b2dc37d6981bhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/3032812a-a1b3-4428-966e-b2dc37d6981bDonBgood612http://social.msdn.microsoft.com/Profile/en-US/?user=DonBgood612virus<p>My computer reciently atarted to display a virus warning telling me it was infected and now no mater what I try I can't stop it. what can I do?</p>Sat, 19 Sep 2009 17:00:29 Z2009-10-24T10:33:31Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/9bda9a45-8397-488d-9fc9-1578067bf231http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/9bda9a45-8397-488d-9fc9-1578067bf231KevinEarleyhttp://social.msdn.microsoft.com/Profile/en-US/?user=KevinEarleyKey cannot be null error<p>When trying to run cat.net against any of our main projects, I get a key cannot be null error.  It seems to work with are utility programs.  I am not sure wether it is project size or has something to do with having multiple projects in the solution that reference each other, or code that is common in all our projects.  Does anybody have any ideas?  Thanks.<br/><br/><br/>C:\Program Files\Microsoft\CAT.NET&gt;catnetcmd /file:c:\soskbsource\nc_branch\proj<br/>ects\soskb.main\bin\soskb.main.exe<br/>Microsoft (R) Code Analysis Tool for .NET (CAT.NET) Version 1.1.1.9<br/>Copyright (C) Microsoft Corporation.  All rights reserved.</p> <p>Running in 32-bit mode</p> <p>9/30/2009 9:36:57 AM:Info : Starting analysis [1 modules]<br/>9/30/2009 9:36:57 AM:Info : Analyzing module Soskb.Main...<br/>Key cannot be null.<br/>Parameter name: key</p>Wed, 30 Sep 2009 13:41:57 Z2009-10-18T17:18:51Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/99bb57fc-ce34-4963-9d0b-b03f5d0c058ahttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/99bb57fc-ce34-4963-9d0b-b03f5d0c058abluezerkhttp://social.msdn.microsoft.com/Profile/en-US/?user=bluezerkUnable to download patches from download.microsoft.com when it is replaced with IP address (IP address is obtained via nslookup)Hi all, i'm trying to set up a proxy server to allow pc in our internal network to download patches from download.microsoft.com. The proxy server is configured to translate URLs to IP address, e.g. www.microsoft.com to 207.46.192.254 and so on. Everything worked fine (from www.microsoft.com/technet/security/current.aspx) until the download part. If we replace download.microsoft.com with the nslookup IP address, we get a HTTP 400 error. For e.g., we can download a specific patch using <span style="font-family: Arial; color: navy; font-size: x-small;"><span style="font-family: Arial; color: navy; font-size: 10pt;"><a title="blocked::http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe" href="http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe" title="blocked::http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe">http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe</a> ,</span> </span> but when we use <span style="font-family: Arial; color: navy; font-size: x-small;"><span style="font-family: Arial; color: navy; font-size: 10pt;"><a title="blocked::http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe" href="http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe" title="blocked::http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe">http://</a> </span> </span> <a title="blocked::http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe" href="http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe" title="blocked::http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe">124.155.222.50</a> <span style="font-family: Arial; color: navy; font-size: x-small;"><span style="font-family: Arial; color: navy; font-size: 10pt;"><a title="blocked::http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe" href="http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe" title="blocked::http://download.microsoft.com/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe">/download/E/9/1/E9177048-A278-476F-8A1A-81C68AC24E7C/WindowsServer2003-KB967723-x86-ENU.exe</a> </span> </span> , we get a HTTP 400 error.<br /> <br /> I think the problem lies with IP address for download.microsoft.com. The IP addresses that we found for download.microsoft.com are 124.155.222.50 and 124.155.222.65 (via nslookup). Can anyone enlighten me please?<br /> Thanks so much in advance!<br /> <br /> PS: I'm sorry if I posted on the wrong forum.Fri, 09 Oct 2009 02:04:36 Z2009-10-12T06:59:39Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/8871c59d-2dfb-469e-877f-3ddae2013f03http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/8871c59d-2dfb-469e-877f-3ddae2013f03tjruskahttp://social.msdn.microsoft.com/Profile/en-US/?user=tjruskaWhen will CAT.Net be production ready?When will this be out of CTP and be in either RC or Production ready? I want to leverage this in our daily build process but our security team is skeptical about using a security scan tool that is still in CTP.<br /> <br /> TomFri, 09 Oct 2009 19:22:30 Z2009-10-09T19:22:31Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/40cb0a4e-05a1-4774-a8c0-2e63c8d02bd2http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/40cb0a4e-05a1-4774-a8c0-2e63c8d02bd2Flash_Gordonhttp://social.msdn.microsoft.com/Profile/en-US/?user=Flash_GordonGraphical User Interface: It was like playing a mmorg but for monitoring people surfing the internet!I have a question about the graphical user interface internet, the one that you punch in someones digital ID into the open field and it tunnels you directly into their house(computer).&nbsp; I was wondering if anyone has ever used it before or how you use it?&nbsp; There is the M.O.M avatar for all personal computers which is a middle aged female it looked like, with sometimes&nbsp;a avatar 50% in size reduction following her which is a teredo.&nbsp; The male avatars are server or domain controller computer's.<br /><br />So if that rings a bell to anybody let me know and if you want to see screen shots and or other documentation send me a note!<hr class="sig">hrm, The mousepen wont work in this field!Mon, 05 Oct 2009 14:17:05 Z2009-10-05T14:17:05Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/b095b112-56aa-4ce9-af45-3c76727d8f5chttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/b095b112-56aa-4ce9-af45-3c76727d8f5cbluelzdhttp://social.msdn.microsoft.com/Profile/en-US/?user=bluelzdHow does the Geneva implement the SSO with the passive STS?Hi<br/> <br/> Now I am learning the WIF(Geneva), however I could not find any official paper that to say &quot;How does the Geneva implement the SSO with the passive STS&quot;, I can guess something however I want to hear the official explain like a white paper.<br/>Tue, 29 Sep 2009 01:20:13 Z2009-09-29T01:20:14Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/6f3bd365-e81b-4bef-a9a4-e73bf37976dchttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/6f3bd365-e81b-4bef-a9a4-e73bf37976dcLaxmilal Menariahttp://social.msdn.microsoft.com/Profile/en-US/?user=Laxmilal%20MenariaExe is not working after signing with SignToolHello everyone, <br/> <br/> I have created a Java application &amp; bundled it in Jar file.<br/> After that I have create exe with JSmooth &amp; signed it. Its working perfectly fine. But now I want to switch from Jsmooth to Launch4j, this also creating exe like Jsmooth. The exe is working fine, but after signing with Signtool, its shows me error about INVALID Jar, so I think Signtool is not able to sign the exe created by launch4j. So what should I do ?<br/> <br/> <br/> Please suggest me, I am using following batch file to sign the exe.<br/> <br/> set File1=LM.exe<br/> <br/> set TimeURL=http://timestamp.comodoca.com/authenticode<br/> set StorePass=demo111<br/> <br/> signtool.exe sign /f SignCode\LM.p12 /p %StorePass% /v /t %TimeURL% &quot;%File1%&quot; <br/> signtool.exe verify /v /a  &quot;%File1%&quot;<br/> <br/> <br/> Thanks in advance, <br/> Laxmilal Menaria<br/> <br/>Thu, 24 Sep 2009 05:28:04 Z2009-09-24T05:28:05Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/85394bd6-e605-48ca-8ddb-745c72af62c0http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/85394bd6-e605-48ca-8ddb-745c72af62c0pedrumjhttp://social.msdn.microsoft.com/Profile/en-US/?user=pedrumjVB preventing software to be crackeddear all<br/> <br/> We have a construction company and I  am designing a program in Visual basics for it. This program is intended to be installed <em><span style="text-decoration:underline">only</span> </em> on the computers in our office ( its not going to be distributed ).  There is always a risk that one of our employees will take our software and distribute it . Is there anyway to prevent this. If not how can we make this as difficult as possible??<br/> <br/> any help or references would be most appreciated.Sat, 19 Sep 2009 11:07:41 Z2009-09-19T11:07:41Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/cb590815-4175-4cd1-952e-241b6e1b3c36http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/cb590815-4175-4cd1-952e-241b6e1b3c36CrazyBughttp://social.msdn.microsoft.com/Profile/en-US/?user=CrazyBugCan i create a custom Folder under the program files directory on vistaHello everyone,<br/>I have built an appliaction in c++ that must run in a user level to be able to retrieve some particular informations.<br/>The problem is that i want this application to write to a folder under the program files directory. <br/>Is it possible to <span style="font-family:Arial;font-size:13px;white-space:pre">customize </span>the folder's security rights to solve this<br/>The application must run on vista and xp.<br/>Please help, thank youThu, 10 Sep 2009 16:02:32 Z2009-09-11T10:02:34Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/d3418d25-d07c-4ff6-848f-c6a9cd29407ehttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/d3418d25-d07c-4ff6-848f-c6a9cd29407eDackeryhttp://social.msdn.microsoft.com/Profile/en-US/?user=DackeryI want to remove the fake program called Windows Protection suite for free of charge.I have this program called Windows protection Suite that has just appeared on my computer.I don't know how I got this program but it is causing proplems for my computer.It has slowed down speed wise ,and is interupting anything I do online.I need to remove this program.I have AVg but it hasn't helped remove this program.Sat, 29 Aug 2009 18:19:04 Z2009-09-10T22:10:44Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/7f4917e7-5ff5-407c-847c-5209d95b1e68http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/7f4917e7-5ff5-407c-847c-5209d95b1e68Jarek88http://social.msdn.microsoft.com/Profile/en-US/?user=Jarek88Time of execution of RsaDecrypt by cmck.exe<pre class=WNPost style="word-wrap:break-word">Dear All, I have one question. How long is period of execution of tests of this function by the cmck exec CardRsaDecrypt Positive module ? Thank You. Jarek</pre>Thu, 10 Sep 2009 06:08:57 Z2009-09-10T06:08:58Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/46d446f0-d46e-40ed-a884-19ca0a624eeehttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/46d446f0-d46e-40ed-a884-19ca0a624eeepaulmhttp://social.msdn.microsoft.com/Profile/en-US/?user=paulmCAT.NET and Anti-XSS 3.0Might CAT.NET recognize the protection of the <a title="Anti-XSS Security Runtime Engine (SRE)" href="http://blogs.msdn.com/securitytools/archive/tags/Anti-XSS/default.aspx">Anti-XSS Security Runtime Engine (SRE)</a> module, some day ?  Verifying that SRE is properly configured !Mon, 07 Sep 2009 02:28:50 Z2009-09-07T02:28:51Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/0cf257fc-edfd-44a9-be90-299c5a36211fhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/0cf257fc-edfd-44a9-be90-299c5a36211fCrazyBughttp://social.msdn.microsoft.com/Profile/en-US/?user=CrazyBugmonitoring browsersWhat is the best way to monitor web pages beeing visited (when, for how long .. ) and web browsers' events, not only for Internet Explorer but also for other web browsers. Thanks in advance :)Wed, 29 Jul 2009 13:19:07 Z2009-09-03T21:38:06Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/19279c48-79c4-464d-83eb-075c8cbfdaaehttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/19279c48-79c4-464d-83eb-075c8cbfdaaevisamalhttp://social.msdn.microsoft.com/Profile/en-US/?user=visamalInstall updates for your computerHiya,<br/>I am not '.net' user. <br/>Window update ask me to install the upate &quot;Microsoft .NET Framework 3.5 Family Update (KB951847) X86&quot;<br/>Also it is saying 'Security' update!?!<br/>I am just wondering... how .net framework 3.5 is related to my desktop security!?!<br/>Is it something like... Marketing/ forcing the user to install .net framework and let their system die (make system slow)?<br/>Can anyone help on this?<br/><br/>Thanks in advance.<br/><br/>-Visamal.Sun, 09 Aug 2009 16:49:07 Z2009-09-03T21:16:51Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/319c5665-5638-457f-b4f1-1ad2adc89c28http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/319c5665-5638-457f-b4f1-1ad2adc89c28jaianthhttp://social.msdn.microsoft.com/Profile/en-US/?user=jaianthNeed help in recovering my image files which are encrypted in Microsoft myprivate folder 1.0Hello, I have microsoft myprivate folder 1.0 installed in my old laptop. Due to virus attack, its Operating system got corrupted.  Some how I have recovered all the important files. But I have very rare and important files saved in myprivate folder.  I am able to copy and recover those to external HDD, but not able to open those files. Please tell me how to recover those files, they are very rare and important files.  Please help me open those files.  Please let me know any software to open those files. Please help me out.<br/>Fri, 21 Aug 2009 16:41:29 Z2009-09-03T20:20:51Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/048f51de-4990-4e4e-af55-59fa9bd76664http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/048f51de-4990-4e4e-af55-59fa9bd76664tiger.liuhttp://social.msdn.microsoft.com/Profile/en-US/?user=tiger.liuHow can I disable the "Security Warning" message box when add a CA to the current user's root CA storeWhen using CertAddCertificateContextToStore to add a CA into “ROOT” CA store of Current User,that will pop up a security warning  message box. <div>Is there any way to disable it?</div> <div><br/></div> <div>There is a workaround of this issue, To write the CA into registry directly .</div> <div>HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\Certificates\36D786132AB6562784FAE4F72461A7BD1558131E.</div> <div>The key {36D786132AB6562784FAE4F72461A7BD1558131E} is the thumbprint of this CA,while ,what its binary{Blob} value is? What's the relation between CA and the {Blob} value?</div> <div><br/></div> <div>Thanks</div> <div>Tiger</div>Mon, 17 Aug 2009 02:34:28 Z2009-09-03T16:47:58Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/1011103e-29b6-4886-a345-59084303f30fhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/1011103e-29b6-4886-a345-59084303f30fflufficornhttp://social.msdn.microsoft.com/Profile/en-US/?user=flufficornWhy do I get different CAT.NET results in these similar cases?I think I might gain a lot more understanding of CAT.NET if someone could explain the difference in behavior for some similar pretty similar data flows:<br/> <br/> I created a C# Web Application Project in VS2005 with a single Default.aspx page whose .cs file looks like this:<br/> <br/> <pre lang="x-c#">using System; using System.Data; using System.Data.SqlClient; namespace CatSite { public partial class _Default : System.Web.UI.Page { protected void Page_Load(object sender, EventArgs e) { string fooStr = Request[&quot;Foo&quot;]; SqlCommand cmd = new SqlCommand(fooStr); } static string IndirectlyUntaint(string s) { return UntaintTools.UntaintTools.UntaintString(s); } } } namespace UntaintTools { public class UntaintTools { public static string UntaintString(string s) { return s; } } }</pre> <br/> If I run the Sql Injection ruleset on this website, it picks up a problem originating in fooStr, which makes sense. Similarly, if I use the following Page_Load instead:<br/> <br/> <pre lang="x-c#"> protected void Page_Load(object sender, EventArgs e) { string barStr = Request[&quot;Bar&quot;]; SqlCommand cmd2 = new SqlCommand(UntaintTools.UntaintTools.UntaintString(barStr)); }</pre> <br/> then it reports a sql vulnerability originating with barStr, which also makes sense.<br/> <br/> However, if I use this Page_load:<br/> <br/> <pre lang="x-c#"> protected void Page_Load(object sender, EventArgs e) { string bazStr = Request[&quot;Baz&quot;]; SqlCommand cmd3 = new SqlCommand(IndirectlyUntaint(bazStr)); }</pre> then no sql vulnerability is reported. I know CAT.NET is going to have some false negatives, but is there an easy-to-comprehend reason why this would be one of them? Is calling a method via a second method different in some critical way from calling a method directly?<br/>Tue, 01 Sep 2009 17:43:43 Z2009-09-01T17:43:43Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/8aacde12-3764-44f9-86da-8b6031384e34http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/8aacde12-3764-44f9-86da-8b6031384e34flufficornhttp://social.msdn.microsoft.com/Profile/en-US/?user=flufficornHelp clarify how the CAT.NET BuiltinFilters work?I really like how you can open up C:\Program Files\microsoft\CAT.NET\Rules and inspect the rules that CAT.NET is using, and even modify them. As I've tried to modify the default rulesets slightly to produce fewer false positives with my codebase, though, I've realized that things aren't quite as intuitive as they first appeared. As such, I'm wondering if we could get some clarification on how Filters work. Here are some particular questions:<br/> <br/> The PrimitiveReturnTypes filter is declared like so:<br/> <pre lang=x-xml> &lt;!-- Ignore data flow paths that have primitive return types --&gt; &lt;BuiltinFilter name=&quot;PrimitiveReturnTypes&quot; description=&quot;Primitive Data Type&quot;&gt; &lt;Action&gt;Ignore&lt;/Action&gt; &lt;/BuiltinFilter&gt;</pre> I understand what it might mean for a method to have a primitive return type (e.g. a method that returns an int, string, bool, etc.), but I'm not sure I understand what it would mean for a data flow path to have a primitive return type. Are there any example? One thing that surprised me was that disabling this filter didn't seem to change the number of potential vulnerabilities detected in my application. It would be nice if you could ultimately document which particular types count as primitive too.<br/> <br/> The DatabaseQueryResult filter is declared like this:<br/> <pre lang=x-xml> &lt;!-- By default, we ignore data flow paths that contain data that is retrieved from the database. This is because we cannot assume the format of the schema or the type of data queried. --&gt; &lt;BuiltinFilter name=&quot;DatabaseQueryResult&quot; description=&quot;Ignore results from DB queries&quot;&gt; &lt;Action&gt;Ignore&lt;/Action&gt; &lt;/BuiltinFilter&gt;</pre> This filter is enabled in the SqlInjection.xml ruleset by default, and yet I get a number of results in my sql injection error report where the source vector is listed as &quot;Database&quot;. Does this make sense? It looks to me like if this filter were enabled, that would get rid of all vector=Database hits in the error report.<br/> <br/> The CallToMethod filter looks like this:<br/> <br/> <pre lang=x-xml> &lt;BuiltinFilter name=&quot;CallToMethod&quot; description=&quot;Parameterized SQL&quot;&gt; &lt;Arguments&gt; &lt;Argument&gt;System.Data.SqlClient&lt;/Argument&gt; &lt;Argument&gt;SqlParameter&lt;/Argument&gt; &lt;Argument&gt;.ctor&lt;/Argument&gt; &lt;/Arguments&gt; &lt;Action&gt;Ignore&lt;/Action&gt; &lt;/BuiltinFilter&gt;</pre> It looks like the Arguments to CallToMethod are supposed to be namespace, class, and method. Can you confirm this? If a class has overloaded methods (i.e. methods with the same name but different signatures), how are you supposed to specify which overload you want? Is the filer supposed to apply equally to all overloads? Are there any tricks here? For example, are there any circumstances under which a method you instructed CAT.NET to ignore would nonetheless show up in one of the dataflow paths in your final vulnerability report?<br/>Tue, 01 Sep 2009 17:11:35 Z2009-09-01T17:11:36Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/a8f472db-a250-445a-9e49-c3e5c9211275http://social.msdn.microsoft.com/Forums/en-US/catnet/thread/a8f472db-a250-445a-9e49-c3e5c9211275dmm3http://social.msdn.microsoft.com/Profile/en-US/?user=dmm3credential provider (32 vs 64 bit)Can a credential provider built as a 32 bit app execute without modification on a windows vista/7.0 64 bit platform?<br/><br/>thanks<br/>dmmThu, 27 Aug 2009 16:22:49 Z2009-08-27T16:22:49Zhttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/3b7bbdfa-3e1c-437f-860f-128a45949b1ahttp://social.msdn.microsoft.com/Forums/en-US/catnet/thread/3b7bbdfa-3e1c-437f-860f-128a45949b1aharsh_1988http://social.msdn.microsoft.com/Profile/en-US/?user=harsh_1988decryption of file but runtime errorm having problem wid dis code....it is giving error at run time dat stream is not writabl....plz help<br/> using System;<br/> <br/> using System.Collections.Generic;<br/> <br/> <br/> using System.Text;<br/> <br/> using System.IO;<br/> <br/> using System.Security.Cryptography;<br/> <br/>  <br/> <br/>  <br/> <br/> namespace DataEncryption<br/> <br/> {<br/> <br/>     class Program<br/> <br/>     {<br/> <br/>         static void Main(string[] args)<br/>         {<br/>             Console.Write(&quot;Source:&quot;);<br/>             String input = Console.ReadLine();<br/> <br/>             <br/>             Console.Write(&quot;Destination:- C:\\encryp.txt &quot;);<br/>             Console.Write(&quot;Destination:- C:\\decryp.txt &quot;);<br/>             <br/> <br/>             string encryp = @&quot;C:\encryp.txt&quot;;<br/>             // step1: Create the stream objects<br/> <br/>             FileStream inputStream = new FileStream(input, FileMode.Open, FileAccess.Read);<br/> <br/>             FileStream outputStream = new FileStream(encryp, FileMode.OpenOrCreate, FileAccess.Write);<br/> <br/>             //step2: Create the symmetric algorithm object<br/> <br/>             SymmetricAlgorithm myAlgo = new RijndaelManaged();<br/> <br/>             //step3: Specify the key<br/> <br/>             myAlgo.GenerateKey();<br/> <br/>             //Read the unencrypted data<br/> <br/>             byte[] fileData = new byte[inputStream.Length];<br/> <br/>             inputStream.Read(fileData, 0, (int)inputStream.Length);<br/> <br/>             //step4:  Create the ICrypto transform object<br/> <br/>             ICryptoTransform encryptor = myAlgo.CreateEncryptor();<br/> <br/>             //step5: Create the CryptoStream object<br/> <br/>             CryptoStream encryptStream = new CryptoStream(outputStream, encryptor, CryptoStreamMode.Write);<br/> <br/>             //step6: Write the contents to the crypto stream<br/> <br/>             encryptStream.Write(fileData, 0, fileData.Length);<br/> <br/>             encryptStream.Close();<br/> <br/>             inputStream.Close();<br/> <br/>             outputStream.Close();<br/>            <br/> <br/>             //decryption<br/>             <br/>            <br/>                 string decryp = @&quot;c:\decryp.txt&quot;;<br/>                 // step1: Create the stream objects<br/> <br/>                 FileStream deinputStream = new FileStream(encryp, FileMode.Open, FileAccess.Read);<br/> <br/>                 FileStream deoutputStream = new FileStream(decryp, FileMode.OpenOrCreate, FileAccess.Write);<br/>                 //step2: Create the symmetric algorithm object<br/>                 <br/>                 //SymmetricAlgorithm myAlgo1 = new RijndaelManaged();<br/>                 //step3: Specify the key<br/> <br/>                myAlgo.GenerateKey();<br/>                <br/>                 <br/>                 //Read the encrypted data<br/>                byte[] fileData1 = new byte[deinputStream.Length];<br/>                 deinputStream.Read(fileData1, 0, (int)deinputStream.Length);<br/>                 //step4:  Create the ICrypto transform object<br/> <br/>                 ICryptoTransform dncryptor = myAlgo.CreateDecryptor();<br/>                 //step5: Create the CryptoStream object<br/> <br/>                 CryptoStream dncryptStream = new CryptoStream(deinputStream, dncryptor, CryptoStreamMode.Write);<br/> <br/>                 //step6: Write the contents to the crypto stream<br/> <br/>                 dncryptStream.Write(fileData1, 0, fileData1.Length);<br/>                 //dncryptStream.Write(fileData1, 0, fileData1.Length);<br/>                 <br/>                 dncryptStream.Close();<br/>                 deinputStream.Close();<br/>                 deoutputStream.Close();<br/>                 Console.ReadKey();<br/>            <br/>         }<br/>     }<br/> <br/> }Wed, 26 Aug 2009 16:50:52 Z2009-08-26T16:50:53Z