Talks to Universities regarding Secure Development Practices, was Re: [OT] SQL injection attack vectors

2010-09-01 Thread silky
On Thu, Sep 2, 2010 at 3:20 PM, silky wrote: [...] > Even outside of direct "help" from Microsoft, I think any individual > could discuss with OWASP or a similar organisation and come up with a > way to contact Uni's and give a lecture on some industry-experienced > approaches to actually develo

Re: Any LiveMesh users? How get the files back after release of Live Sync?

2010-09-01 Thread David Burela
This happened to me. I had to use a 2nd machine, uninstalled live essentials. installed live mesh. Resynced it all down. copied it over to the other machine to sync it back up into Live Sync. then paved my machine afterwards. On 2 September 2010 15:15, Michael Nemtsev wrote: > Hello, > > > > Vi

Re: [OT] SQL injection attack vectors

2010-09-01 Thread silky
On Thu, Sep 2, 2010 at 2:21 PM, Sam Lai wrote: > Martin, sounds like a sign that they're actually teaching their > students about such attack techniques, which is bad on your end, but > is probably a good thing given the comments here. > > Now that you mentioned uni, I have to say I don't recall e

Any LiveMesh users? How get the files back after release of Live Sync?

2010-09-01 Thread Michael Nemtsev
Hello, Visiting www.mesh.com I realised that MS replaced the Live Mesh client on Live Sync 2010 which can synchronize only with SkyDrive. The challenging I'm experiencing now is how to get my files back from Mesh now?! J There is no client for mesh any longer Michael Nemtsev Microsoft MV

Re: [OT] Ebook Reader

2010-09-01 Thread silky
On Thu, Sep 2, 2010 at 2:28 PM, David Burela wrote: > I had it all in threaded view. > > The original thread finished so I responded. > > Wasn't until 5mins after I posted that I saw that someone had started up a > new thread instead of continuing the previous one :-( Damn that person! But regar

RE: Win Phone 7 RTM

2010-09-01 Thread David Kean
Good to hear. Anyone sharing assets/code between Phone, Silverlight and .NET? From: ozdotnet-boun...@ozdotnet.com [mailto:ozdotnet-boun...@ozdotnet.com] On Behalf Of David Burela Sent: Wednesday, September 01, 2010 9:30 PM To: ozDotNet Subject: Re: Win Phone 7 RTM +1 I've developed a few apps no

Re: Win Phone 7 RTM

2010-09-01 Thread David Burela
+1 I've developed a few apps now; A few side projects and 1 commercial app The tools are excellent! And it is really easy to get an application up and running that actually looks pretty. I am enjoying working with WP7 a lot more than "vanilla silverlight" now. The only thing lacking is native RIA

Re: Win Phone 7 RTM

2010-09-01 Thread Sam Lai
On 2 September 2010 14:18, mike smith wrote: > Well, mine's been auto-updated, twice.  (2.1 and 2.2)  It's a NexusOne. Well that phone's the exception, given Google is the phone's distributor and OS manufacturer, and its status as 'the Google phone'. >> I'm looking forward to a mobile OS that pr

RE: Win Phone 7 RTM

2010-09-01 Thread Nagi, Sunny
I have done couple of apps as well, and yeah WP SDK and inetgration with VS is awesome. One of the major problems that I am facing is that I can only test my app on emulator, and not on real handset :-( From: ozdotnet-boun...@ozdotnet.com [mailto:ozdotnet-bo

Re: [OT] Ebook Reader

2010-09-01 Thread David Burela
I had it all in threaded view. The original thread finished so I responded. Wasn't until 5mins after I posted that I saw that someone had started up a new thread instead of continuing the previous one :-( -David Burela On 2 September 2010 14:23, David Burstin wrote: > Did you not see all of th

RE: Win Phone 7 RTM

2010-09-01 Thread Nick Randolph
I've done quite a bit and so far the tools are awesome - working in VS/Blend kicks the pants off XCode/Interface builder. However, there are some curly bits around tombstoning that suck, as does the lack of real emulator (eg the old WM emulator where you could simulate most of the hardware). Ni

Re: [OT] Ebook Reader

2010-09-01 Thread David Burstin
Did you not see all of the posts yesterday "verdict on kindle/ebook reader"? What was mentioned was that purely in terms of EBook capabilities, the iPad is not as clear/sharp, nor does it have the long battery life. This is due to the iPad's other capabilities, including having a touch screen and

RE: Win Phone 7 RTM

2010-09-01 Thread David Kean
As a matter of interest, who's going to develop for WP7? For those that already have started, how's your experience been? From: ozdotnet-boun...@ozdotnet.com [mailto:ozdotnet-boun...@ozdotnet.com] On Behalf Of Nagi, Sunny Sent: Wednesday, September 01, 2010 9:15 PM To: ozDotNet Subject: RE: Win

Re: [OT] SQL injection attack vectors

2010-09-01 Thread Sam Lai
Martin, sounds like a sign that they're actually teaching their students about such attack techniques, which is bad on your end, but is probably a good thing given the comments here. Now that you mentioned uni, I have to say I don't recall ever being taught anything about SQL or XSS injection tech

Re: Properties

2010-09-01 Thread David Burela
I used to wonder about public fields vs. properties. But it doesn't seem like much of an issue now that you can just write it as a one liner string Name { get; set; } (or by typing *prop* and hitting tab twice) Since that new auto backed properties are so easy, I just use them as my default bec

Re: Win Phone 7 RTM

2010-09-01 Thread mike smith
On 2 September 2010 13:47, Sam Lai wrote: > On 2 September 2010 13:27, mike smith wrote: > > On 2 September 2010 11:53, Nick Randolph wrote: > >> > >> Lol – but RTM != In-Stores-Soon…. You’ve got to allow a couple of months > >> for the rtm build to be round tripped through OEMs, Telcos and bac

Re: [OT] Ebook Reader

2010-09-01 Thread David Burela
I am surprised no one mentioned iPad. I use it to read all of my books / white papers / PDFs / etc. It is the only apple product that I own, and it is the perfect "digital information pad" -David Burela On 25 August 2010 09:58, PENNYCUICK, Chris wrote: > A coworker's father runs this site on t

RE: Win Phone 7 RTM

2010-09-01 Thread Nagi, Sunny
Totally agree with you! One of biggest trump card for apple at this stage is content on offer via their store - applications and media both. Google's massive push in getting developers working on android platform is one of the many steps that it has taken to get more developers developing f

RE: Win Phone 7 RTM

2010-09-01 Thread Nick Randolph
Hmmm, well at least they did with the original iphone. Personally I feel they stopped innovating with the original iphone and that everything since has just been incremental improvements. I've seen more innovation coming out of both Android and WP7 than I do out of Apple. Whilst the iphone 4 set

RE: Win Phone 7 RTM

2010-09-01 Thread Nagi, Sunny
Not all android phones can get automatic updates, like Sony Ericsson x10. Apple with iphone have done a tremendous job in setting a standard and I am sure others will follow. From: ozdotnet-boun...@ozdotnet.com [mailto:ozdotnet-boun...@ozdotnet.com] On Beh

RE: Win Phone 7 RTM

2010-09-01 Thread Nick Randolph
There won’t be WP7 upgrades to existing phones (mostly because they don’t conform to the WP7 hardware requirements, eg 3 front hardware buttons for back, start and search). WP7 has a new update mechanism which means MS can actually roll out updates – in the past this was heavily reliant on OEMs/

Re: Win Phone 7 RTM

2010-09-01 Thread Sam Lai
On 2 September 2010 13:27, mike smith wrote: > On 2 September 2010 11:53, Nick Randolph wrote: >> >> Lol – but RTM != In-Stores-Soon…. You’ve got to allow a couple of months >> for the rtm build to be round tripped through OEMs, Telcos and back to MS J > > That's what I like about Android.  Gets

Re: Win Phone 7 RTM

2010-09-01 Thread mike smith
On 2 September 2010 11:53, Nick Randolph wrote: > Lol – but RTM != In-Stores-Soon…. You’ve got to allow a couple of months > for the rtm build to be round tripped through OEMs, Telcos and back to MS > J > > That's what I like about Android. Gets updated to your existing phone. No matter how man

Re: [OT] SQL injection attack vectors

2010-09-01 Thread silky
On Thu, Sep 2, 2010 at 12:18 PM, Nathan Schultz wrote: > Understood. That's the difference between URL Encoding and HTML Encoding. URL Encoding may not fix it, because, as far as I just tested, you can still escape out of the specific area of within a href='[here]' area. And that's what always ne

Re: [OT] SQL injection attack vectors

2010-09-01 Thread Nathan Schultz
Understood. That's the difference between URL Encoding and HTML Encoding. My point was more in MVC, you have a HtmlHelper class with a bag of goodies. ie: Html.RouteLink() generates a safe URL link. Html.TextBox() generates a safe text-box Html.AntiForgeryToken() generates a token that protects a

RE: Win Phone 7 RTM

2010-09-01 Thread Nick Randolph
Lol - but RTM != In-Stores-Soon You've got to allow a couple of months for the rtm build to be round tripped through OEMs, Telcos and back to MS :) Nick Randolph | Built to Roam | Microsoft MVP - Device Application Development | +61 412 413 425 The information contained in this email is conf

Re: [OT] SQL injection attack vectors

2010-09-01 Thread silky
On Thu, Sep 2, 2010 at 11:47 AM, Nathan Schultz wrote: > I'm a little surprised by comments that most dev's wouldn't know what a SQL > Injection attack was. Most developers I've worked with have a class with > some kind with a function to sanitizing data against SQL Injection. > > These days you d

Re: [OT] SQL injection attack vectors

2010-09-01 Thread Nathan Schultz
I'm a little surprised by comments that most dev's wouldn't know what a SQL Injection attack was. Most developers I've worked with have a class with some kind with a function to sanitizing data against SQL Injection. These days you don't see them used so often as SQL Parameters / Linq to SQL / Ent

debugging whilst pausing and 'cannot evaluate expression'

2010-09-01 Thread Wallace Turner
using VisualStudio2010; After attaching to a Process and pressing Pause (Break-All), you switch to the desired thread and use the Quick Watch window to check out some data, say MySingletonClass.Instance.Data Sometimes I either get this Values Cannot evaluate expression

sql server 2008 change data capture and friends

2010-09-01 Thread silky
Hello Fellow Programmers, For some reason it just occured to me that SQL server should keep it's own svn-type history of changes, as that would make versioning awesome. And it so happens that SQL 2008 kind of does this via "Change Data Capture" ( http://msdn.microsoft.com/en-us/library/bb522489.a

Win Phone 7 RTM

2010-09-01 Thread Greg Low (GregLow.com)
Interesting to note that Windows Phone 7 went to RTM this morning. Regards, Greg

RE: Charting with WPF and Linq

2010-09-01 Thread Dylan Tusler
Well, in the end, I've managed to get it working using the series DataContext. I'm still operating very much in the C# paradigm, and still (even in VS2010) find working in XAML a frustrating experience. If you're not doing it every day, all day, it is quite hard to gain much fluency, and too eas

RE: [OT] SQL injection attack vectors

2010-09-01 Thread Martin Hungerford
Corneliu, I currently work as a Uni and we recently had an attempted SQL injection attack show up in the logs. It was the first I have seen in reality and we all exclaimed over the log trace. Thanks for the application, we'll give it a go J Martin From: ozdotnet-boun...@ozdotnet.com [mailt

Re: [OT] SQL injection attack vectors

2010-09-01 Thread Corneliu I. Tusnea
Sam, I do a lot of work in this field and yes, developers without any knowledge of what SQL Injection (or even XSS) is are the main culprit. Even with the current "tools" (.net, asp.net..) SQL Injection and XSS are very common. I've seen loads of production apps with potential issues but, as long

Re: verdict on kindle/ebook reader?

2010-09-01 Thread silky
On Wed, Sep 1, 2010 at 5:56 PM, Ken Schaefer wrote: > On the DX, the writing is quite small (on an A4 page) if you don't zoom in. > > Prior to the DX I had a Sony PRS505, which is about the same size as the > kindle > (not sure if the screen resolution is lower or higher) and I found that > imag

RE: verdict on kindle/ebook reader?

2010-09-01 Thread Ken Schaefer
On the DX, the writing is quite small (on an A4 page) if you don't zoom in. Prior to the DX I had a Sony PRS505, which is about the same size as the kindle (not sure if the screen resolution is lower or higher) and I found that images and tables would just be cropped. Text, obviously, could be r

Re: verdict on kindle/ebook reader?

2010-09-01 Thread silky
On Wed, Sep 1, 2010 at 5:23 PM, Ken Schaefer wrote: > The small kindle is very light and quite small. The DX, I think, would be > the smallest you could get to read A4 PDFs (at least in portrait mode) I was kind of noticing the page size thing. The books I'm thinking of are obviously technical (A

Re: [OT] SQL injection attack vectors

2010-09-01 Thread mike smith
On 1 September 2010 15:06, Craig van Nieuwkerk wrote: > > > > I don't see how any legitimate programmer could claim to be unaware of > > such an issue; it's a core concept about how programming works. They > > may as well be confused that comments don't compile. > > > > Of the hundred plus develo

RE: verdict on kindle/ebook reader?

2010-09-01 Thread Ken Schaefer
The small kindle is very light and quite small. The DX, I think, would be the smallest you could get to read A4 PDFs (at least in portrait mode) Cheers Ken From: ozdotnet-boun...@ozdotnet.com [mailto:ozdotnet-boun...@ozdotnet.com] On Behalf Of David Burstin Sent: Wednesday, 1 September 2010 11: