Monthly Archives: June 2005

Please remember to remove design-mode settings from web.config before deploying

I do it, so my site should be safe, right? Well it turns out that the answer is “wrong”!!

One of the websites that shares a webserver with my site left CustomErrors=”Off” in their web.config when they deployed their site.

How does this affect me? Well, there was a problem in the machine.config on the server. That website exposed the error because it had the customerrors off which basically does a little stacktrace dump on the webpage. In the particular case, it happened to show the bad line from the machine.config. What was the bad line? It set up impersonation for 4 websites on the server, of course mine being one of them. So browsing to that other website, showed anyone going there the logins and passwords for four domains.

So, now this is not a best practice, it is a rule. There are plenty of web.config settings that should not get to production!! Pay attention. Please.

TechEd Speakers Charity Auction http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=5587400881

my blog is being hacked

okay – there just went the folder with all of my blog images

I am downloading fast and furiously

To whatever a**hole is doing this: Thanks so very much. It would be nice to be able to get some billable work done today. Help my clients. You know, the little things in life.

TechEd Speakers Charity Auction http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=5587400881

New friends at TechEd

This could be an endless post – shout out to so many bloggers I met in person for the first time at TechEd.

First and foremost is Amanda Murphy who I have known virtually for over a year and meeting her was like meeting a younger sister. Amanda runs a user group in St. Johns Newfoundland (practially out in the middle of the ocean). She won one of the INETA Scholarships to TEchEd (after a) the invitation to apply had landed in her junk mail box and b) after I got her to FIND the invite, still almost didn’t apply becasue she thought she would never get it.) Ha. Watch this girl – I think she is definitely an up & comer in the .NET community.

Also, I loved meeting Chris WilliamsJason Olson, seeing a bunch of the guys from MAD Code Camp again (like Frank LaVigne and Jeff Schoolcraft). Lorenzo Barbieri seemed a little surprised that I recognized him – the value of a good blog, having your picture on it and a few years of Italian in college (plus some help from Google language tools). I am going to try to find a GURU shirt for myself.

Oh, of course there are hundreds more. You know who you are! 🙂



TechEd Speakers Charity Auction http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=5587400881

Looking forward to Sam Gentile talk on SOA and Indigo tomorrow at VTdotNET

Here is the abstract for the talk Sam is doing tomorrow night at VTdotNET as our first INETA event of 2005.

There have been a lot of arguments in Blogs and elsewhere lately about SOA and two themes seem to emerge from some: SOA is bogus because there is a lot of hype around it and SOA is bogus because it’s nothing new. We will dispose of both of those arguments early in showing that SOA is a real and excellent way to build loosely coupled, distributed systems despite being over hyped beyond belief There are parts that are not new but what is different is clear focus on services as DISTINCT from objects. After looking at what SOA and SO are, we will looking at how to implement services using WSE3 and .NET 2.0 on the Microsoft platform. The culmination of this approach of course is Indigo and now that Indigo is public we will take a deep dive into Indigo. All throughout, we will focus on a practical approach with simple code demos to reinforce the concepts.



TechEd Speakers Charity Auction http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=5587400881

*Temporarily* turning off comments

Too much comment spam – server problems, etc etc. I am going to do a clean install of the latest dasblog and maybe captcha as well. Ahh, Sundays. I have always gotten gobs of referral spam, but since I don’t show referrers, I didn’t worry. But now the comments spam is coming on fast and furiously.