Security Unlocked

Securing Redirections with Mike Macelletti


Listen Later

In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by Mike Macelletti from Microsoft’s MSRC Vulnerabilities and Mitigations team to explore Redirection Guard, a powerful mitigation designed to tackle a long-standing class of file path redirection vulnerabilities in Windows. Mike shares how his interest in security began, the journey behind developing Redirection Guard, and how it's helping reduce a once-common bug class across Microsoft products. He also explains how the feature works, why it's impactful, and what developers can do to adopt it. Plus, a few fun detours into Solitaire hacking, skiing, and protein powder. 

 

 

In This Episode You Will Learn:  

 

  • What Redirection Guard is and how it helps prevent file system vulnerabilities 
  • How Microsoft identifies and addresses common bug classes across their ecosystem 
  • Why some vulnerabilities still slip past Redirection Guard and what’s out of scope 

 

Some Questions We Ask: 

 

  • What is a junction and how is it different from other redirects? 
  • How does Redirection Guard decide which shortcuts to block? 
  • Are there vulnerabilities Redirection Guard doesn’t cover? 

   

  

Resources:      

View Mike Macelletti on LinkedIn     

View Wendy Zenone on LinkedIn   

View Nic Fillingham on LinkedIn  

 

  

Related Microsoft Podcasts:   

  

  • Microsoft Threat Intelligence Podcast   
  • Afternoon Cyber Tea with Ann Johnson   
  • Uncovering Hidden Risks   

  

  

Discover and follow other Microsoft podcasts at microsoft.com/podcasts   

Hosted on Acast. See acast.com/privacy for more information.

...more
View all episodesView all episodes
Download on the App Store

Security UnlockedBy Microsoft

  • 4
  • 4
  • 4
  • 4
  • 4

4

56 ratings


More shows like Security Unlocked

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,976 Listeners

Risky Business by Patrick Gray

Risky Business

361 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

626 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

366 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,006 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

312 Listeners

Click Here by Recorded Future News

Click Here

408 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,879 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

166 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

127 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

43 Listeners

The BlueHat Podcast by Microsoft

The BlueHat Podcast

13 Listeners