<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Kirk Jackson's Page of Words - SharePoint</title>
    <link>http://pageofwords.com/blog/</link>
    <description>Run the ink across this page of words</description>
    <language>en-us</language>
    <copyright>Kirk Jackson</copyright>
    <lastBuildDate>Thu, 17 Mar 2011 22:42:33 GMT</lastBuildDate>
    <generator>newtelligence dasBlog 1.9.6264.0</generator>
    <managingEditor>kirkj@paradise.net.nz</managingEditor>
    <webMaster>kirkj@paradise.net.nz</webMaster>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=71a380b8-fcef-4f01-afa5-5ea542948c18</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,71a380b8-fcef-4f01-afa5-5ea542948c18.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,71a380b8-fcef-4f01-afa5-5ea542948c18.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=71a380b8-fcef-4f01-afa5-5ea542948c18</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">I presented at the <a href="http://www.sharepointconference.co.nz/nz2011/">NZ
SharePoint conference</a> yesterday. It was a pretty impressive event - kudos to Debbie
and the organising team.<br /><br />
My talk was split into two parts: what are some of the risks in running a SharePoint
site; and how can you protect against them.<br /><br />
The risks I covered were cross-site scripting and malicious file uploads - MIME sniffing
in IE, the recent MHTML attack and the ever-present risk of malicious PDF documents.
The key takeaway is that any file uploaded could be malicious, and to think of how
to mitigate those risks.<br /><br />
In the 'protection' section, I covered some SharePoint development best practices
and stepped through SharePoint specifics on how to protect against XSS and CSRF. SharePoint
has some pretty good protections built in the box, but if we're building our own web-parts
we need to be vigilant.<br /><br />
The presentation should shortly be available from the conference website, with a video
in a month or so. If you've got any questions please feel free to email me or get
in touch.<br /><p></p><a href="http://pageofwords.com/blog/content/binary/2011-03-17-NZSPC-KirkJackson.pdf">2011-03-17-NZSPC-KirkJackson.pdf
(2.9 MB)</a><br /><br />
Cheers,<br /><br />
Kirk<br /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=71a380b8-fcef-4f01-afa5-5ea542948c18" /></body>
      <title>SharePoint Conference NZ - Is your SharePoint under threat?</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,71a380b8-fcef-4f01-afa5-5ea542948c18.aspx</guid>
      <link>http://pageofwords.com/blog/2011/03/17/SharePointConferenceNZIsYourSharePointUnderThreat.aspx</link>
      <pubDate>Thu, 17 Mar 2011 22:42:33 GMT</pubDate>
      <description>I presented at the &lt;a href="http://www.sharepointconference.co.nz/nz2011/"&gt;NZ SharePoint
conference&lt;/a&gt; yesterday. It was a pretty impressive event - kudos to Debbie and the
organising team.&lt;br&gt;
&lt;br&gt;
My talk was split into two parts: what are some of the risks in running a SharePoint
site; and how can you protect against them.&lt;br&gt;
&lt;br&gt;
The risks I covered were cross-site scripting and malicious file uploads - MIME sniffing
in IE, the recent MHTML attack and the ever-present risk of malicious PDF documents.
The key takeaway is that any file uploaded could be malicious, and to think of how
to mitigate those risks.&lt;br&gt;
&lt;br&gt;
In the 'protection' section, I covered some SharePoint development best practices
and stepped through SharePoint specifics on how to protect against XSS and CSRF. SharePoint
has some pretty good protections built in the box, but if we're building our own web-parts
we need to be vigilant.&lt;br&gt;
&lt;br&gt;
The presentation should shortly be available from the conference website, with a video
in a month or so. If you've got any questions please feel free to email me or get
in touch.&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;a href="http://pageofwords.com/blog/content/binary/2011-03-17-NZSPC-KirkJackson.pdf"&gt;2011-03-17-NZSPC-KirkJackson.pdf
(2.9 MB)&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;
Cheers,&lt;br&gt;
&lt;br&gt;
Kirk&lt;br&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=71a380b8-fcef-4f01-afa5-5ea542948c18" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,71a380b8-fcef-4f01-afa5-5ea542948c18.aspx</comments>
      <category>Security;SharePoint</category>
    </item>
  </channel>
</rss>