<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-34422497</id><updated>2011-12-21T05:42:01.821-05:00</updated><category term='fortify'/><category term='reflection'/><category term='billy hoffman'/><category term='panel discussion'/><category term='google ad phishing'/><category term='Risk Management'/><category term='JAVA'/><category term='Web Application Firewall'/><category term='RSA conference'/><category term='SQL Injection'/><category term='Application Security'/><category term='Web Application Scanners'/><category term='Jeremiah Grossman'/><category term='malware'/><category term='Ory Segal'/><category term='RSnake'/><category term='chris shiflett'/><category term='pdp'/><category term='My Experience at Blackhat and DefCon'/><category term='Certification for Web Application Security Professional'/><category term='TRACE'/><category term='WASC'/><category term='ModSecurity'/><category term='ryan barnett'/><category term='Webinspect'/><category term='Ajax'/><category term='amit klien'/><category term='Vulnerability Assessment Tool'/><category term='Andrew Van der Stock'/><category term='samy worm'/><category term='password lockout'/><category term='OWASP'/><category term='Appscan'/><category term='robert auger'/><category term='Saumil Shah'/><category term='SDL'/><category term='Web Application Security Scanner Evaluation Criteria'/><category term='PCI compliance'/><category term='OWASP Projects'/><category term='alex stamos'/><category term='Security Requirements for HTTP'/><category term='CSRF'/><category term='sheeraj'/><category term='Web application security Summit'/><category term='OWASP AppSec India Conference 2008'/><category term='Sniffer'/><category term='Caleb Sima'/><category term='Appsec Conference'/><category term='Quiz'/><category term='Secure Coding'/><category term='The new face of cybercrime'/><category term='New IRS Scam via SMS messages'/><category term='subverting ajax'/><category term='Character filtering'/><category term='hackersafe'/><category term='Javascript'/><category term='RSA Conference Pictures'/><category term='Nish Bhalla'/><category term='SANS'/><category term='Website vulnerability disclosure'/><category term='Web Application Security products vs solutions'/><category term='XST'/><category term='iSECPartners'/><category term='Search'/><category term='IT security world conference'/><category term='Web Application Security meetup RSA conference'/><category term='database security'/><category term='Black hat'/><category term='OWASP WASP AppSec Conference 2007'/><category term='phishing'/><category term='captcha'/><category term='Proof of concept'/><category term='cesar cerrudo'/><category term='Threat Modeling'/><category term='Web Hacking'/><category term='Web Application Security'/><category term='WASC meetup'/><category term='Intellipass'/><category term='webappsec'/><category term='worm'/><category term='top 10 web hacks of 2007'/><category term='source code audit'/><category term='Jeff Williams'/><category term='Session Hijacking'/><category term='stefano di paola'/><category term='scanalert'/><category term='dinis cruz'/><category term='Cookies'/><category term='Breach'/><category term='OWASP Top 10'/><category term='Password'/><category term='XSS'/><category term='WASSEC'/><category term='.NET'/><category term='bill pennington'/><title type='text'>Anurag Agarwals' Threat Modeling Blog</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>86</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-34422497.post-4249171217109573558</id><published>2011-07-31T15:03:00.001-04:00</published><updated>2011-07-31T15:03:30.374-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Quiz'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP Projects'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP Top 10'/><title type='text'>OWASP Top 10 Quiz</title><summary type='text'>We had recently developed a quiz to help an organization test their developer's knowledge of OWASP top 10. I thought it  would be a good idea to make it public and let other organization use it for their development teams as well. This is a very basic quiz but I do plan to add different levels and more questions to it and bring randomness in the questions as well. 

I would greatly appreciate any</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4249171217109573558/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4249171217109573558' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4249171217109573558'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4249171217109573558'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2011/07/owasp-top-10-quiz.html' title='OWASP Top 10 Quiz'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-2994774840853662377</id><published>2011-04-13T10:57:00.000-04:00</published><updated>2011-04-13T10:57:14.661-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Threat Modeling'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><title type='text'>OWASP threat modeling project</title><summary type='text'>We are starting an OWASP threat modeling project to standardize a threat modeling approach which can be used by various companies. During the OWASP portugal summit I had a very meaningful and positive discussion on this topic and got support from a lot of people in the community. You can find out the results of the discussion at the OWASP Threat Modeling project page

If you would like to join </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/2994774840853662377/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=2994774840853662377' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/2994774840853662377'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/2994774840853662377'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2011/04/owasp-threat-modeling-project.html' title='OWASP threat modeling project'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-1513990948143177158</id><published>2010-08-19T17:48:00.000-04:00</published><updated>2010-08-19T18:03:37.817-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='captcha'/><category scheme='http://www.blogger.com/atom/ns#' term='password lockout'/><category scheme='http://www.blogger.com/atom/ns#' term='Intellipass'/><title type='text'>Intellipass - A behavior based password lockout mechanism</title><summary type='text'>I am pleased to announce Intellipass (a behavior based password lockout mechanism). Most of the password lockout mechanism today are static, which  means, they lock a user out after a certain number of incorrect password attempts. This feature is implemented to prevent brute force attempts against the login functionality. Even though this feature does what it’s supposed to, it has its own </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/1513990948143177158/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=1513990948143177158' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1513990948143177158'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1513990948143177158'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2010/08/intellipass-behavior-based-password.html' title='Intellipass - A behavior based password lockout mechanism'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-1691669473297227044</id><published>2010-05-06T18:16:00.000-04:00</published><updated>2010-05-06T18:17:53.074-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='CSRF'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><title type='text'>Free Hands on Workshop on Web Application Security in New York City</title><summary type='text'>Ever wondered how a hacker hacks all these credit cards? Do you think  hacking a website is difficult? What are the skills required to hack a  website?ISSA NY Metro chapter is organizing a 3 hour workshop on  web application security.  This session will show you how easy it is to steal credit card numbers,  SSN, etc by doing a SQL  injection attack or how you can steal passwords, hijack a session</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/1691669473297227044/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=1691669473297227044' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1691669473297227044'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1691669473297227044'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2010/05/free-hands-on-workshop-on-web.html' title='Free Hands on Workshop on Web Application Security in New York City'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-523742447548978457</id><published>2010-05-05T20:21:00.000-04:00</published><updated>2010-05-05T21:47:32.793-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Threat Modeling'/><category scheme='http://www.blogger.com/atom/ns#' term='Risk Management'/><category scheme='http://www.blogger.com/atom/ns#' term='SDL'/><category scheme='http://www.blogger.com/atom/ns#' term='Secure Coding'/><title type='text'>MyAppSecurity - Secure Your Applications</title><summary type='text'>As some of you know that I joined WhiteHat Security as a Director of Education Services since Dec 2007 to build their training division from scratch. Though it has been a very demanding job but it has been very satisfying too. I enjoyed working with various companies, training their developers and QA professionals and resolving their web application security issues. Through training, I not only </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/523742447548978457/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=523742447548978457' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/523742447548978457'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/523742447548978457'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2010/05/myappsecurity-secure-your-applications.html' title='MyAppSecurity - Secure Your Applications'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-6187038725237910545</id><published>2008-08-11T17:02:00.000-04:00</published><updated>2008-08-11T17:05:31.755-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security Scanner Evaluation Criteria'/><category scheme='http://www.blogger.com/atom/ns#' term='WASSEC'/><title type='text'>WASSEC Project Leader Change Announcement</title><summary type='text'>There is going to be a new project leader (Brian Shura : bshura73_at_gmail_dot_com) for WASSEC (Web Application Security Scanner Evaluation Criteria) as of today. The leadership change will help me free up some time to work on other projects.We've identified an excellent candidate who will take over WASSEC from where I left. I have already given him an overview of the project, its status and the </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/6187038725237910545/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=6187038725237910545' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/6187038725237910545'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/6187038725237910545'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/08/wassec-project-leader-change.html' title='WASSEC Project Leader Change Announcement'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-651069847698832533</id><published>2008-06-19T02:31:00.000-04:00</published><updated>2008-06-19T02:50:36.702-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OWASP AppSec India Conference 2008'/><title type='text'>OWASP AppSec India Conference 2008</title><summary type='text'>OWASP Delhi Chapter is hosting a grand application security event in New Delhi, India. With a lot of Executives and business folks also attending the event, it clearly shows the attention web application security is getting in India and I am sure a lot of it could also be because India is one of the major offshore development hub for US projects and most of these companies sending projects </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/651069847698832533/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=651069847698832533' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/651069847698832533'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/651069847698832533'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/06/owasp-appsec-india-conference-2008.html' title='OWASP AppSec India Conference 2008'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_p4tgkwtZjQ8/SFoA2UVqgPI/AAAAAAAAATY/JyvoC4fx3aQ/s72-c/OWASP-2008Appsec-banner.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-4500112153233839346</id><published>2008-06-19T02:30:00.001-04:00</published><updated>2008-06-19T02:30:58.553-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC'/><category scheme='http://www.blogger.com/atom/ns#' term='Breach'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='Black hat'/><title type='text'>WASC OWASP Party @ Blackhat</title><summary type='text'>WASC-OWASP Party at BlackhatBlackhat Vegas is around the corner. Our WASC-OWASP party last year rocked with around 300 people showing up. There was a huge line outside the shadow bar and it was by far the best party at Blackhat last year. If you weren't able to make it last year, do not miss it this time. Get your wristband from breach's booth at Blackhat.Join the leading minds in web application</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4500112153233839346/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4500112153233839346' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4500112153233839346'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4500112153233839346'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/06/wasc-owasp-party-blackhat.html' title='WASC OWASP Party @ Blackhat'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SFn8lFI7cMI/AAAAAAAAATI/ep6Y2T-geuM/s72-c/wasc_owasp_party.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-668046388754178055</id><published>2008-04-15T14:48:00.000-04:00</published><updated>2008-04-15T15:11:03.484-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC'/><category scheme='http://www.blogger.com/atom/ns#' term='SANS'/><category scheme='http://www.blogger.com/atom/ns#' term='Web application security Summit'/><title type='text'>Web Application Security Summit</title><summary type='text'>SANS and WASC have organized a Web Application Security Summit in Vegas.Web Application Security SummitJeremiah Grossman, Summit Chairwith Robert “RSnake” Hansen, Gary McGraw, and Caleb SimaJune 2-3, 2008 • Paris Hotel &amp; Casino • Las Vegas, NVOn June 2-3, Various Application Security folks working in the enterprises will share the lessons learned in their application security initiatives. Case </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/668046388754178055/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=668046388754178055' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/668046388754178055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/668046388754178055'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/04/web-application-security-summit.html' title='Web Application Security Summit'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-1093343346475965591</id><published>2008-04-11T19:47:00.001-04:00</published><updated>2008-04-11T20:18:41.512-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RSA Conference Pictures'/><title type='text'>RSA Conference Pictures</title><summary type='text'>RSA Conference 2008 is almost over. As usual there were so many companies showcasing their products and services or in some cases just a little bit of fun like video games, rock climbing, etc.I personally think there were more companies talking about web application security then last year. We still need some more companies with secure SDLC solutions to come out there. In addition, there were </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/1093343346475965591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=1093343346475965591' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1093343346475965591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1093343346475965591'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/04/rsa-conference-pictures.html' title='RSA Conference Pictures'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_p4tgkwtZjQ8/R__93DCS1fI/AAAAAAAAARc/qEcJ95sDHWU/s72-c/DSCN0356.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-2692742491197773056</id><published>2008-04-11T14:26:00.001-04:00</published><updated>2008-04-12T17:19:31.813-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC meetup'/><category scheme='http://www.blogger.com/atom/ns#' term='RSA conference'/><title type='text'>WASC meetup at RSA - pictures</title><summary type='text'>WASC meetup at RSA was a huge success. More then 100 people showed up and it was a lot of fun sharing ideas and experiences with our peers. I am posting some of the pictures I took below.Caleb Sima(HP), Robert Auger(WASC)Neil Daswani (Google), Robi papp (Accuvant)Pool was so much fun.Dawn Van Hoegaerdan (Whitehat Security), Jermiah Grossman,  Rachel Miller (Shift Communiations)Dawn, James(</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/2692742491197773056/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=2692742491197773056' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/2692742491197773056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/2692742491197773056'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/04/wasc-meetup-at-rsa-pictures.html' title='WASC meetup at RSA - pictures'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_p4tgkwtZjQ8/R_-vazCS05I/AAAAAAAAAMs/HB5O0Pls-nM/s72-c/DSCN0326.JPG' height='72' width='72'/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-3004664144641246610</id><published>2008-03-22T21:53:00.000-04:00</published><updated>2008-03-22T22:19:38.159-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><title type='text'>Malware installation attempt via phishing</title><summary type='text'>I got this email yesterday and it immediately caught my attention, maybe due to the recent news about malware being installed via legitimate website. Or maybe most of the previous phishing attempts were about stealing username/passwords. This one is about installing something on their machine (which i am sure is some sort of malware). This might be a shift in the approach and of course it makes a</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/3004664144641246610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=3004664144641246610' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/3004664144641246610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/3004664144641246610'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/03/malware-installation-attempt-via.html' title='Malware installation attempt via phishing'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-4063950396494394839</id><published>2008-03-06T21:13:00.000-05:00</published><updated>2008-03-06T21:28:34.757-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC meetup'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security meetup RSA conference'/><title type='text'>WASC meetup at RSA</title><summary type='text'>RSA conference is around the corner and a lot of people from the webappsec field would be coming over to the conference. This is a perfect opportunity to meet with your peers.  To facilitate that, WASC is organizing a meetup on April 9, 2008 12pm to 2pm. Whitehat Security has graciously accepted to sponsor the event. Please click on the image to see a larger version of the invite.Last year WASC </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4063950396494394839/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4063950396494394839' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4063950396494394839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4063950396494394839'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/03/wasc-meetup-at-rsa.html' title='WASC meetup at RSA'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_p4tgkwtZjQ8/R9ClaHPUGII/AAAAAAAAAKs/UerPG3rgrcY/s72-c/WASC_RSAcoupon.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-5087162669555937401</id><published>2008-02-21T14:15:00.002-05:00</published><updated>2008-02-21T14:24:54.446-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Certification for Web Application Security Professional'/><title type='text'>Certification for Web Application Security Professional</title><summary type='text'>Web Application Security Consortium and SANS  has partnered together to define, train, test and certify the individuals. WASC is a leading web application security organization and SANS is a leader in training and certification. Together they have the subject matter expertise and process expertise to make this a huge success.Why do we need this certification?As more and more software is moving to</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/5087162669555937401/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=5087162669555937401' title='15 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/5087162669555937401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/5087162669555937401'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/02/certification-for-web-application.html' title='Certification for Web Application Security Professional'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>15</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-8881082366354434647</id><published>2008-01-29T17:29:00.000-05:00</published><updated>2008-01-29T17:34:30.305-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='New IRS Scam via SMS messages'/><title type='text'>New IRS Scam via SMS messages</title><summary type='text'>I got a text message today which said likeFrom:TAX@internalrefunding.com------Message-----Subject: NOTICEYou have .30 IRS UNITS pending forrefunding, completethe form usingwww.internalrefunding.com ASAPMy first reaction was "What the f***" but then I started thinking "Could it be IRS?", if yes, then "Why send a SMS?"Then my paranoid mind started working and even though I haven't heard of a scam </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/8881082366354434647/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=8881082366354434647' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/8881082366354434647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/8881082366354434647'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/01/new-irs-scam-via-sms-messages.html' title='New IRS Scam via SMS messages'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-2038330424917623777</id><published>2008-01-23T21:48:00.000-05:00</published><updated>2008-01-24T13:05:49.571-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Requirements for HTTP'/><title type='text'>IETF starts working on security requirements for HTTP</title><summary type='text'>Andre sent me a link on "Security Requirements for HTTP". It is exciting to see at least security issues of HTTP protocol are being addressed by IETF. This is a first draft and they are starting to identify the problems and will address them as a final part of this document.http://www.ietf.org/internet-drafts/draft-ietf-httpbis-security-properties-00.txtRecent IESG practice dictates that IETF </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/2038330424917623777/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=2038330424917623777' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/2038330424917623777'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/2038330424917623777'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/01/ietf-starts-working-on-security.html' title='IETF starts working on security requirements for HTTP'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-5487331453509597497</id><published>2008-01-21T17:10:00.000-05:00</published><updated>2008-01-25T17:52:49.464-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='scanalert'/><category scheme='http://www.blogger.com/atom/ns#' term='hackersafe'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI compliance'/><title type='text'>Do you have to fix XSS vulns to be PCI Compliant? ScanAlert Says No</title><summary type='text'>I was reading Jeremiah's blog about ScanAlert's Response - ScanAlert - XSS is not our problemI had blogged earlier about Should ScanAlert be revoked of their PCI Scanning abilities?The interesting thing here is that if Hacker Safe is not detecting XSS attacks and I can bet they would not be detecting SQL injection attacks as well. So, what part of web application attacks are they trying to detect</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/5487331453509597497/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=5487331453509597497' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/5487331453509597497'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/5487331453509597497'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/01/do-you-have-to-fix-xss-vulns-to-be-pci.html' title='Do you have to fix XSS vulns to be PCI Compliant? ScanAlert Says No'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-1460014308952630706</id><published>2008-01-21T14:16:00.000-05:00</published><updated>2008-01-21T14:25:00.931-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='The new face of cybercrime'/><category scheme='http://www.blogger.com/atom/ns#' term='fortify'/><title type='text'>The Fortification Movie</title><summary type='text'>Last week i went to see the documentary by fortify on "The new face of Cybercrime". I went there thinking that it would be something that shows what cybercrime is all about and how bad guys are breaking into websites to steal credit card numbers, SSN, etc. and selling it on the black market to make money. Basically a visual representation of what we deal with, day in, day out. But it turned out </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/1460014308952630706/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=1460014308952630706' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1460014308952630706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1460014308952630706'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/01/fortification-movie.html' title='The Fortification Movie'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-7402411088983226160</id><published>2008-01-08T14:07:00.001-05:00</published><updated>2008-01-08T14:23:21.390-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='top 10 web hacks of 2007'/><title type='text'>Calling all web hacks of 2007</title><summary type='text'>Jeremiah Grossman is trying to gather all the neat researches behind web hacks of 2007."The hardest part is collecting a rather complete list of references to vote on, they’re all over the place, so that’s the reason for this post. Below is what I’ve gathered so far, and if you know of others, please comment them in with the title and link and I’ll add them. In the next few days the list will be </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/7402411088983226160/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=7402411088983226160' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/7402411088983226160'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/7402411088983226160'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/01/calling-all-web-hacks-of-2007.html' title='Calling all web hacks of 2007'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-2296392251321621515</id><published>2008-01-07T17:18:00.001-05:00</published><updated>2008-01-07T17:56:27.427-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='scanalert'/><category scheme='http://www.blogger.com/atom/ns#' term='hackersafe'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI compliance'/><title type='text'>Should ScanAlert be revoked of their PCI Scanning abilities?</title><summary type='text'>I was passed on this link today about "Hacker Safe Website gets hit by Hacker". For those who don't know, Hacker Safe is a service provided by Scan Alert (which is set to be acquired by McAfee). I am not going to go into the details of how safe are the sites displaying the logo  "Hacker Safe". I don't even want to go into the details of what level of scanning services are provided by ScanAlert </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/2296392251321621515/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=2296392251321621515' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/2296392251321621515'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/2296392251321621515'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2008/01/should-scanalert-be-revoked-of-their.html' title='Should ScanAlert be revoked of their PCI Scanning abilities?'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-4669521920037734548</id><published>2007-11-19T19:49:00.000-05:00</published><updated>2007-11-19T20:26:44.782-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OWASP WASP AppSec Conference 2007'/><title type='text'>AppSec 2007 pictures of breach party</title><summary type='text'>OWASP and WASC AppSec Conference is over and it was by far the best conference i have ever been to. I was able to meet up with so many fantastic people, some of them i have exchanged emails with before and was good to see them in person. The conference topics and the presentation were really good. It was also my first time moderating a panel and it was a great experience. With such a sensitive </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4669521920037734548/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4669521920037734548' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4669521920037734548'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4669521920037734548'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/11/appsec-2007-pictures-of-breach-party.html' title='AppSec 2007 pictures of breach party'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_p4tgkwtZjQ8/R0I0w5RnWFI/AAAAAAAAAKk/tgUxRO5Wqms/s72-c/DSCN0358.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-4071785194687821668</id><published>2007-11-07T14:50:00.000-05:00</published><updated>2007-11-07T14:57:46.288-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PCI compliance'/><title type='text'>Who are the real culprits for PCI compliance?</title><summary type='text'>There was an article in SearchSecurity today on TJX issue.Don't blame PCI DSS for TJX troubles, IT pros sayhttp://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1280854,00.html?track=sy160&amp;asrc=RSS_RSS-10_160Here is an excerpt from the articleThe auditor said TJX passed a PCI DSS check-up, but that the auditor failed to notice some key problems."They had no network monitoring and</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4071785194687821668/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4071785194687821668' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4071785194687821668'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4071785194687821668'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/11/who-are-real-culprits-for-pci.html' title='Who are the real culprits for PCI compliance?'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-272228554470656362</id><published>2007-11-05T19:30:00.001-05:00</published><updated>2007-11-05T19:34:47.883-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Website vulnerability disclosure'/><category scheme='http://www.blogger.com/atom/ns#' term='WASC'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='panel discussion'/><title type='text'>Panel discussion on Website Vulnerability Disclosure during AppSec Conference on Nov 15</title><summary type='text'>As most of you know that OWASP-WASC AppSec Conference is held in ebay between Nov12-Nov15 including the training sessions. There are very many exciting topics to look forward to in the conference and not to forget the vendor parties at the end of the day. One of the things i am excited about is the panel discussion on Website Vulnerability Disclosure (which i will be moderating). We have some </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/272228554470656362/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=272228554470656362' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/272228554470656362'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/272228554470656362'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/11/panel-discussion-on-website.html' title='Panel discussion on Website Vulnerability Disclosure during AppSec Conference on Nov 15'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-8379834977289967531</id><published>2007-11-01T13:42:00.000-04:00</published><updated>2007-11-01T13:44:16.804-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC meetup'/><title type='text'>WASC meetup on Nov 8</title><summary type='text'>Its time for another WASC Meet-Up. As usual this will be an informal gathering. No agenda, slide-ware, or sponsors. Just some like minded people from the security industry getting together to share their stories over beer. Everyone is welcome and it should be a really fun time!Please RSVP by email ASAP, if you haven't done so already, so we can make the proper reservations: anurag dot agarwal at </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/8379834977289967531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=8379834977289967531' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/8379834977289967531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/8379834977289967531'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/11/wasc-meetup-on-nov-8.html' title='WASC meetup on Nov 8'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-4679738315317673450</id><published>2007-09-04T16:45:00.000-04:00</published><updated>2007-09-04T16:52:07.913-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='Appsec Conference'/><title type='text'>OWASP &amp; WASC AppSec 2007</title><summary type='text'>The OWASP/WASC Black Hat cocktail party was so successful it only made sense to join forces again, this for an upcoming conference. OWASP &amp; WASC AppSec 2007 is scheduled for Nov 12 – 15 @ eBay campus in San Jose, California. This will be an entire conference dedicated to web application security and something not to be missed. In fact, we’re a little nervous because the venue might be able to fit</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4679738315317673450/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4679738315317673450' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4679738315317673450'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4679738315317673450'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/09/owasp-wasc-appsec-2007.html' title='OWASP &amp; WASC AppSec 2007'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-5067757149242117998</id><published>2007-09-04T16:40:00.000-04:00</published><updated>2007-09-04T19:57:55.564-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC meetup'/><category scheme='http://www.blogger.com/atom/ns#' term='IT security world conference'/><title type='text'>WASC Meetup at IT Security World Conference on Sep 17</title><summary type='text'>WASC is organizing another Meet-Up during the IT Security World Conference (Sep 17-18) in San Francisco @ O'Neills). As usual this will be an informal gathering. No agenda, slide-ware, or sponsors. Baysec is also organizing a meetup during that time and we are hoping to meet other security professionals from Bay Area. Everyone is welcome and it should be a really fun time!Please RSVP by email </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/5067757149242117998/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=5067757149242117998' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/5067757149242117998'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/5067757149242117998'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/09/wasc-meetup-at-it-security-world.html' title='WASC Meetup at IT Security World Conference on Sep 17'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-1156653743122907432</id><published>2007-08-22T17:04:00.000-04:00</published><updated>2007-08-22T17:05:21.579-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security Scanner Evaluation Criteria'/><category scheme='http://www.blogger.com/atom/ns#' term='WASSEC'/><title type='text'>WASC WASSEC Project - Update</title><summary type='text'>Thank you all for your patience. We have received an overwhelming response from the WASSEC (Web Application Security Scanner Evaluation Criteria) project. To proceed with the project please1. Please email wasc-wassec-subscribe@webappsec.org and reply to confirmation email.2. It is moderated subscription so every contributor has to be approved to send messages to the list.3. Once you are </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/1156653743122907432/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=1156653743122907432' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1156653743122907432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1156653743122907432'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/08/wasc-wassec-project-update.html' title='WASC WASSEC Project - Update'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-6413392174423203563</id><published>2007-08-13T21:49:00.000-04:00</published><updated>2007-08-13T21:51:04.535-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Scanners'/><category scheme='http://www.blogger.com/atom/ns#' term='WASSEC'/><title type='text'>WASC Announcement: 'WASSEC Project' Call for Participants</title><summary type='text'>WASC has announced a new project WASSEC (Web Application Security Scanner Evaluation Criteria). Currently WASC is seeking volunteers from various sections of the community including penetration testers, scanner vendors, security researchers and also end users to contribute to the project.A brief description of the projectThe Web Application Security Evaluation Criteria is a set of guidelines to </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/6413392174423203563/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=6413392174423203563' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/6413392174423203563'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/6413392174423203563'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/08/wasc-announcement-wassec-project-call.html' title='WASC Announcement: &apos;WASSEC Project&apos; Call for Participants'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-1612527359752375619</id><published>2007-08-12T17:17:00.000-04:00</published><updated>2007-08-12T19:45:27.084-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='samy worm'/><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><title type='text'>Did WebApp developers learn from Samy worm?</title><summary type='text'>At the Mozilla Pyjama party during Blackhat, Me and Jeremiah met up with Bubba Gump and he shared with us an interesting story on how he was able to do something similar like Samy worm on another social networking site. His story just goes to show that there are so many other websites which are still getting hacked the same way but either have no clue or are in a denial mode. We asked him to </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/1612527359752375619/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=1612527359752375619' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1612527359752375619'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1612527359752375619'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/08/did-webapp-developers-learnt-from-samy.html' title='Did WebApp developers learn from Samy worm?'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-4616365727381315765</id><published>2007-08-12T16:47:00.000-04:00</published><updated>2007-08-12T17:07:31.568-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='My Experience at Blackhat and DefCon'/><title type='text'>My experience at BlackHat and DefCon</title><summary type='text'>I came back from blackhat and defcon last Sunday. I was there for the entire 9 days (combined blackhat and defcon) and when i came back, I realized why people said 9 days of Vegas are toooo long. It was my first time to Vegas so I didn’t see it earlier but now i have learnt my lesson. :)It had been a very enjoyable experience. Though the party really took off on Tuesday night when most of the </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4616365727381315765/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4616365727381315765' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4616365727381315765'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4616365727381315765'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/08/my-experience-in-blackhat.html' title='My experience at BlackHat and DefCon'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_p4tgkwtZjQ8/Rr9zbJF5igI/AAAAAAAAAHU/u_pJRD2jZg0/s72-c/IMG_2635.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-2253998303753414037</id><published>2007-07-02T13:58:00.000-04:00</published><updated>2007-07-02T14:31:28.968-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='dinis cruz'/><category scheme='http://www.blogger.com/atom/ns#' term='.NET'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><title type='text'>Reflection on Dinis Cruz</title><summary type='text'>In the last episode of reflection, we have someone who has become a pillar of OWASP. Dinis Cruz is a chief OWASP evangelist and a part of the OWASP board. At OWASP, he organizes events such as the OWASP Autumn of Code, delivers keynotes and advanced technical presentations on OWASP Conferences and leads the OWASP .Net Project where (amongst others) he created the tools: OWASP Report Generator, </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/2253998303753414037/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=2253998303753414037' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/2253998303753414037'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/2253998303753414037'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/07/reflection-on-dinis-cruz.html' title='Reflection on Dinis Cruz'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_p4tgkwtZjQ8/RolEWfXxKnI/AAAAAAAAAHE/zf3U6umx-2c/s72-c/dinis+cruz.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-6660535507445424628</id><published>2007-06-25T00:28:00.000-04:00</published><updated>2007-06-25T00:53:18.580-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='database security'/><category scheme='http://www.blogger.com/atom/ns#' term='cesar cerrudo'/><category scheme='http://www.blogger.com/atom/ns#' term='Application Security'/><title type='text'>Reflection on Cesar Cerrudo</title><summary type='text'>This week on reflection we have someone who has done a lot of database research and published several advisories and presented at Blackhat, CanSecWest and other conferences on database security. Cesar Cerrudo works for his own company “Argeniss” and has contributed a lot to some of the databases to be more secure today. He has also identified a lot of vulnerabilities in Microsoft Windows, </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/6660535507445424628/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=6660535507445424628' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/6660535507445424628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/6660535507445424628'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/06/reflection-on-cesar-cerrudo.html' title='Reflection on Cesar Cerrudo'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_p4tgkwtZjQ8/Rn9JnPUnX8I/AAAAAAAAAG8/oc3qEPeS8-w/s72-c/CesarFoto2.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-4463836478412954194</id><published>2007-06-18T17:58:00.000-04:00</published><updated>2007-06-18T18:04:43.744-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='iSECPartners'/><category scheme='http://www.blogger.com/atom/ns#' term='alex stamos'/><title type='text'>Reflection on Alex Stamos</title><summary type='text'>This week on reflection we have Alex Stamos from iSEC Partners Inc. Alex has been involved in webappsec for sometime now and has presented at Blackhat, ToorCon, OWASP, ISACA, etc. He is a founder and Vice President of Professional Services at iSEC. He is a leading researcher in the field of web application and web services security and is also a co-author of an upcoming book Hacking Exposed Web </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4463836478412954194/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4463836478412954194' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4463836478412954194'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4463836478412954194'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/06/reflection-on-alex-stamos.html' title='Reflection on Alex Stamos'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_p4tgkwtZjQ8/RncBc_UnX7I/AAAAAAAAAG0/tIrsll_AM9I/s72-c/alex_stamos.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-7873029245945460875</id><published>2007-06-11T00:23:00.000-04:00</published><updated>2007-06-18T18:08:28.593-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='pdp'/><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><title type='text'>Reflection on pdp</title><summary type='text'>This week on reflection we have Petko D Petkov (popularly known as pdp). pdp has been active in the webappsec community for sometime now. He has written many articles and published many tools. Two of his more popular tools are Attack API and Technika (firefox extension). He is also a co-author of the book XSS Exploits: Attacks and Defense. Recently he presented on Advanced Web Hacking Revealed in</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/7873029245945460875/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=7873029245945460875' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/7873029245945460875'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/7873029245945460875'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/06/reflection-on-pdp.html' title='Reflection on pdp'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_p4tgkwtZjQ8/RmzQvvUnX6I/AAAAAAAAAGs/AwBmJ2TEGZ4/s72-c/pdp.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-5326809235569130135</id><published>2007-06-06T20:07:00.001-04:00</published><updated>2007-06-06T20:30:37.749-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC meetup'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='Black hat'/><title type='text'>WASC meetup in Blackhat USA 2007</title><summary type='text'>OWASP and WASC have joined hands to have a combined meetup at Blackhat USA 2007 in Las Vegas which was earlier planned as a WASC meetup. Breach Security has stepped forward to sponsor the event.  Please click on the image to see a larger version of the invite. Come and join us for a drink and meet other like minded people from the industry.  NOTE: Those who have already RSVPed need not to RSVP </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/5326809235569130135/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=5326809235569130135' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/5326809235569130135'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/5326809235569130135'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/06/wasc-meetup-in-blackhat-usa-2007.html' title='WASC meetup in Blackhat USA 2007'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_p4tgkwtZjQ8/RmdPBPUnX5I/AAAAAAAAAGk/RRMUWagxWFk/s72-c/WASC-OWASP+meetup.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-3754559061498780665</id><published>2007-06-05T14:21:00.000-04:00</published><updated>2007-06-05T14:23:14.078-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><title type='text'>Any java developers in bay area?</title><summary type='text'>Any java developers in bay area who are interested in working together on some of the research ideas i have in web application security.Most of the development would be in java. Knowledge of javascript is a plus. Knowledge of webapp security field is optional.Interested? contact me on anurag.agarwal@yahoo.com</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/3754559061498780665/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=3754559061498780665' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/3754559061498780665'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/3754559061498780665'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/06/any-java-developers-in-bay-area.html' title='Any java developers in bay area?'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-8976183485247807395</id><published>2007-06-04T16:04:00.000-04:00</published><updated>2007-06-04T16:16:23.193-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Saumil Shah'/><title type='text'>Reflection on Saumil Shah</title><summary type='text'>This week on reflection we have Saumil Shah from net-square Solutions. Saumil has been involed in webappsec community for a long time and is a regular presenter at Blackhat. He focuses on researching vulnerabilities with various e-commerce and web based application systems, system architecture for Net-Square's tools and products, and developing short term training programmes. He specializes in </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/8976183485247807395/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=8976183485247807395' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/8976183485247807395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/8976183485247807395'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/06/reflection-on-saumil-shah.html' title='Reflection on Saumil Shah'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_p4tgkwtZjQ8/RmRzESwRyOI/AAAAAAAAAF8/1eJgtAV4Vak/s72-c/saumil_pic.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-1639489778392111261</id><published>2007-05-28T14:35:00.000-04:00</published><updated>2007-05-28T14:51:38.406-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='subverting ajax'/><category scheme='http://www.blogger.com/atom/ns#' term='stefano di paola'/><title type='text'>Reflection on Stefano Di Paola</title><summary type='text'>This week on reflection we have Stefano Di Paola who caught everyone’s attention through his paper Subverting Ajax which talked about acrobat reader plugin vulnerability and javascript prototype exploit. Those of you who remember, there was a lot of commotion on WASC mailing list at the beginning of this year. Tons of emails going back and forth on a vulnerability which was identified in acrobat </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/1639489778392111261/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=1639489778392111261' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1639489778392111261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1639489778392111261'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/05/reflection-on-stefano-di-paola.html' title='Reflection on Stefano Di Paola'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_p4tgkwtZjQ8/RlshVCwRyNI/AAAAAAAAAF0/YHiPa6uVTrc/s72-c/stefano_di_paola.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-6851150049588445998</id><published>2007-05-25T17:47:00.000-04:00</published><updated>2007-05-25T17:49:17.927-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC meetup'/><category scheme='http://www.blogger.com/atom/ns#' term='Black hat'/><title type='text'>WASC Meetup at Black Hat (USA 2007)</title><summary type='text'>For the third year in a row WASC will be organizing a web application  security meet-up during the BlackHat USA (2007) conference. There's  going to be a lot of webappsec presentations and people in  attendance, likely more than ever, so it's a good opportunity for  those in the community to get together and share some food and  drinks.  This email will serve as a way to gauge the level of  </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/6851150049588445998/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=6851150049588445998' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/6851150049588445998'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/6851150049588445998'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/05/wasc-meetup-at-black-hat-usa-2007.html' title='WASC Meetup at Black Hat (USA 2007)'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-4401385445658966866</id><published>2007-05-21T14:13:00.000-04:00</published><updated>2007-05-29T16:42:04.714-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='ryan barnett'/><title type='text'>Reflection on ryan barnett</title><summary type='text'>This week on reflection we have Ryan Barnett from breach security. Ryan is a well respected figure in web application security and is well known for his book “Preventing Web Attacks with Apache”. He is a faculty member for SANS institute and a WASC officer. He is also the Project Lead for the Center for Internet Security Apache Benchmark Project. Ryan has a passion for web application security </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4401385445658966866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4401385445658966866' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4401385445658966866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4401385445658966866'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/05/reflection-on-ryan-barnett.html' title='Reflection on ryan barnett'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_p4tgkwtZjQ8/RlHhuiwRyMI/AAAAAAAAAFs/q1_3kGmVZHQ/s72-c/ryan+barnet.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-1450916047764694795</id><published>2007-05-15T01:19:00.000-04:00</published><updated>2007-05-21T14:27:46.219-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Caleb Sima'/><title type='text'>Reflection on Caleb Sima</title><summary type='text'>This week on reflection we have caleb sima from SPI dynamics. He is the co-founder and CTO of SPI dynamics. He has been involved with internet security since its very early age and is widely respected in the industry. He is often quoted in various magazines and is called upon for his expert opinions. Caleb’s story tells us we can be what we want to be if only we put our minds to it and channel </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/1450916047764694795/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=1450916047764694795' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1450916047764694795'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1450916047764694795'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/05/reflection-on-caleb-sima.html' title='Reflection on Caleb Sima'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_p4tgkwtZjQ8/RklDPwv9oDI/AAAAAAAAAFk/oXMa5epUz3s/s72-c/C.Sima-Oct06+smaller+version.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-4497240588169123784</id><published>2007-05-14T01:14:00.000-04:00</published><updated>2007-05-14T01:28:54.649-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='google ad phishing'/><title type='text'>Phishing using google ads</title><summary type='text'>I received an interesting phishing email today. Whenever I receive any such email I hover my mouse over the link to see the actual url behind the link. In this particular case, it caught my attention. It was pointing to google.com. I was a little bit surprised then I copied the actual url behind the link separately to see where is it pointing. Be careful before you click on the url.Here is a copy</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4497240588169123784/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4497240588169123784' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4497240588169123784'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4497240588169123784'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/05/i-received-interesting-phishing-email.html' title='Phishing using google ads'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-905913782029559435</id><published>2007-05-07T01:06:00.000-04:00</published><updated>2007-05-07T01:22:31.370-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='Cookies'/><category scheme='http://www.blogger.com/atom/ns#' term='JAVA'/><title type='text'>Reading cookies from the server using Java</title><summary type='text'>Last two posts have been about running TRACE on the host server.Running TRACE on the server using Java from within the browser Part 1http://myappsecurity.blogspot.com/2007/04/using-java-from-within-browsers.htmlRunning TRACE on the server using Java from within the browser Part 2http://myappsecurity.blogspot.com/2007/05/running-trace-on-server-using-java-from.htmlIn this post, we will see how to </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/905913782029559435/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=905913782029559435' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/905913782029559435'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/905913782029559435'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/05/reading-cookies-from-server-using-java.html' title='Reading cookies from the server using Java'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-3402879142693449323</id><published>2007-05-07T01:01:00.000-04:00</published><updated>2007-05-07T01:06:32.605-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='XST'/><category scheme='http://www.blogger.com/atom/ns#' term='TRACE'/><category scheme='http://www.blogger.com/atom/ns#' term='JAVA'/><title type='text'>Running TRACE on the server using Java from within the browser Part 2</title><summary type='text'>In the previous post on running TRACE on the server using java from within the browser, the approach was using java.net.Socket. In this approach, we are using java.net.UrlConnectionThere are certain limitations with this approach1.If the TRACE is disabled on the server, firefox will give PrivilegeException2.It the HTTP is disabled on the web server then it will give PrivilegeException3.It will </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/3402879142693449323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=3402879142693449323' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/3402879142693449323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/3402879142693449323'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/05/running-trace-on-server-using-java-from.html' title='Running TRACE on the server using Java from within the browser Part 2'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-2202016383729554136</id><published>2007-05-06T22:55:00.000-04:00</published><updated>2007-05-29T16:43:08.403-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='bill pennington'/><title type='text'>Reflection on Bill Pennington</title><summary type='text'>This week on reflection, we have Bill Pennington from Whitehat Security. Bill had been involved in web application security for a long time and has performed numerous web application assessments and is currently involved in research and development at Whitehat Security. He has spoken at industry events like blackhat, ISSA LA and OWASP Silicon Valley chapter and has contributed to or co-authored </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/2202016383729554136/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=2202016383729554136' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/2202016383729554136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/2202016383729554136'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/05/reflection-on-bill-pennington.html' title='Reflection on Bill Pennington'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_p4tgkwtZjQ8/Rj6VuQv9oCI/AAAAAAAAAFc/NoXv2bIdhcg/s72-c/billnlily.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-277281700426942440</id><published>2007-05-04T15:21:00.000-04:00</published><updated>2007-05-04T15:24:38.985-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC meetup'/><title type='text'>WASC meetup at JavaOne on May 10</title><summary type='text'>Alright guys!! WASC is having another meetup at JavaOne. From what i have heard this time we have a lot of people joining us. So come on and meet the guys and share a thought or two over a beerHere is a copy of the post from Jeremiah's BlogWASC is organizing a Meet-Up during the JavaOne Conference (May 8-11 @ San Francisco Moscone Center). As usual this will be an informal gathering. No agenda, </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/277281700426942440/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=277281700426942440' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/277281700426942440'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/277281700426942440'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/05/wasc-meetup-at-javaone-on-may-10.html' title='WASC meetup at JavaOne on May 10'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-5568500929576352597</id><published>2007-04-30T17:25:00.000-04:00</published><updated>2007-04-30T17:29:42.437-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='XST'/><category scheme='http://www.blogger.com/atom/ns#' term='JAVA'/><title type='text'>Using Java from within browser's javascript to exploit web application vulnerabilities Part 1</title><summary type='text'>Last weekend jeremiah showed me a code snippet where he was able to run TRACE method on a server using java from javascript. Though it was a little slow but it did the job. He asked me if there is a way to make it run faster. I did some work and using jdk1.4 API, I was able to get the job done a lot faster. I always knew that we can run java from javascript but it never crossed my mind that I can</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/5568500929576352597/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=5568500929576352597' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/5568500929576352597'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/5568500929576352597'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/04/using-java-from-within-browsers.html' title='Using Java from within browser&apos;s javascript to exploit web application vulnerabilities Part 1'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-7303744447437026409</id><published>2007-04-30T02:32:00.000-04:00</published><updated>2007-05-29T16:43:52.586-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='Andrew Van der Stock'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><title type='text'>Reflection on Andrew Van Der Stock</title><summary type='text'>This week on reflection we have Andrew Van der Stock. Andrew is very active in webappsec industry through OWASP and is involved in a lot of activities including OWASP top ten or OWASP Guide, etc. He has contributed a lot to webappsec field, more so in terms of research and awareness on securing the applications rather then exploiting them. He used to be based out of Australia and has recently </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/7303744447437026409/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=7303744447437026409' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/7303744447437026409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/7303744447437026409'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/04/reflection-on-andrew-van-der-stock.html' title='Reflection on Andrew Van Der Stock'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_p4tgkwtZjQ8/RjWPxgv9oAI/AAAAAAAAAFM/8XAzQQtdwDU/s72-c/ajv.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-4989885168071971788</id><published>2007-04-23T18:32:00.000-04:00</published><updated>2007-04-23T19:58:05.134-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC meetup'/><title type='text'>WASC Meetup - April 18 - pictures</title><summary type='text'>Sorry for the delay in this post. Last wednesday we had our WASC meetup in sunnyvale. Unfortunately the date coincided with OWASP san francisco chapter meeting and some infosec conference in toronto so we did not get as much attendance we expected but still some of us showed up. Jeremiah had already mentioned on his blog that everyone has to buy a beer for someone they havent met before. :)Before</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4989885168071971788/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4989885168071971788' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4989885168071971788'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4989885168071971788'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/04/wasc-meetup-april-18-pictures.html' title='WASC Meetup - April 18 - pictures'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_p4tgkwtZjQ8/Ri055WAvFvI/AAAAAAAAAEs/P7CXhn0imPM/s72-c/wasc6.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-6233726318030852013</id><published>2007-04-23T14:06:00.000-04:00</published><updated>2007-05-29T16:44:46.425-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='Nish Bhalla'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><title type='text'>Reflection on Nish Bhalla</title><summary type='text'>This week on reflection we have Nish Bhalla from SecurityCompass. Nish has been around the block for a long time and used to work for FoundStone before starting his own company. He is a specialist in product testing, code reviews, web application testing, host and network reviews. He has presented in various conferences, published articles, contributed and co-authored several books. He takes </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/6233726318030852013/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=6233726318030852013' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/6233726318030852013'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/6233726318030852013'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/04/reflection-on-nish-bhalla.html' title='Reflection on Nish Bhalla'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_p4tgkwtZjQ8/Riz1z2AvFpI/AAAAAAAAAD8/rYd2byv4D40/s72-c/Nish_Head.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-6577508691471550621</id><published>2007-04-16T03:11:00.000-04:00</published><updated>2007-05-29T16:40:27.191-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='Appscan'/><category scheme='http://www.blogger.com/atom/ns#' term='Ory Segal'/><title type='text'>Reflection on Ory Segal</title><summary type='text'>This week on reflection we have Ory Segal of Watchfire. Ory has been involved in the webappsec from its very early days. He has published several whitepapers, articles and advisories. He has contributed to security standards like WASC Threat Classification and WASC Firewall Evaluation Criteria. He has spoken at various conferences and security events and is very reputed amongst the web </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/6577508691471550621/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=6577508691471550621' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/6577508691471550621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/6577508691471550621'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/04/reflection-on-ory-segal.html' title='Reflection on Ory Segal'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_p4tgkwtZjQ8/RiMiRkDpw5I/AAAAAAAAAD0/RgaXewn4QrU/s72-c/ory+segal.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-7482199497362484284</id><published>2007-04-10T15:04:00.000-04:00</published><updated>2007-04-10T15:06:19.738-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WASC meetup'/><title type='text'>WASC Meetup in bay area</title><summary type='text'>Its a beerfest guys. put it on your calendarNormally we hold WASC Meet-Ups during large conferences (RSA/ BlackHat) where a lot of web application security people are at same  place at the same time. Around the S.F. Bay Area there's enough  webappsec people that we we no longer need that excuse. So we're  going to plan a WASC Meet-Up inviting those in the local community to  drop by.  It'll be an</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/7482199497362484284/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=7482199497362484284' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/7482199497362484284'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/7482199497362484284'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/04/wasc-meetup-in-bay-area.html' title='WASC Meetup in bay area'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-1002679171496033763</id><published>2007-04-06T13:47:00.000-04:00</published><updated>2007-04-29T17:23:33.463-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='chris shiflett'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><title type='text'>Reflection on Chris Shiflett</title><summary type='text'>This week on reflection we have Chris Shiflett. One of the very few people who have been blogging on webappsec for a long time and I am sure is amongst the top 10 visited blog on web application security. His knowledge on web application security is tremendous and his blog is a goldmine for people who are looking to learn and understand various types of web application vulnerabilities and their </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/1002679171496033763/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=1002679171496033763' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1002679171496033763'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1002679171496033763'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/04/reflection-on-chris-shiflett.html' title='Reflection on Chris Shiflett'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_p4tgkwtZjQ8/RhaH5xI-3YI/AAAAAAAAADs/n2TaK9tPkFA/s72-c/chris-shiflett.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-8268351249800585395</id><published>2007-03-30T16:28:00.000-04:00</published><updated>2007-04-29T17:18:47.907-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Jeff Williams'/><title type='text'>Reflection on Jeff Williams</title><summary type='text'>This week on reflection need no introduction. Jeff Williams, is one of the major contributors in webappsec community. He has written many whitepapers, spoken at many conferences including Secure Software Summit, OWASP conferences, ISSA InfoSec Conference, NSA High Confidence Software and Systems Conference (HCSS), JavaOne, National Computer Security Conference (NCSC), etc, written many tools </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/8268351249800585395/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=8268351249800585395' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/8268351249800585395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/8268351249800585395'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html' title='Reflection on Jeff Williams'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_p4tgkwtZjQ8/Rg14P6YvO7I/AAAAAAAAADk/ni6Mr2tjyKg/s72-c/jwilliams.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-7619976289500984434</id><published>2007-03-23T01:15:00.000-04:00</published><updated>2007-04-29T17:17:54.990-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='robert auger'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><title type='text'>Reflection on Robert Auger</title><summary type='text'>This week on Reflection we have someone who has contributed to the webappsec community in many different ways. We all know Robert Auger through http://www.cgisecurity.com/. CGI Security is one of the very early website on the topic and has a wealth of information on web application security. Robert is also a Co-Founder of the Web Application Security Consortium and a founder and moderator of the </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/7619976289500984434/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=7619976289500984434' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/7619976289500984434'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/7619976289500984434'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/03/reflection-on-robert-auger.html' title='Reflection on Robert Auger'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_p4tgkwtZjQ8/RgNrIF0AWmI/AAAAAAAAADY/WbKMlPCV4qY/s72-c/robert.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-5231022666289309374</id><published>2007-03-17T03:04:00.000-04:00</published><updated>2007-03-23T01:32:11.717-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='billy hoffman'/><title type='text'>Reflection on Billy Hoffman</title><summary type='text'>This week on Reflection we have a very young guy from the webappsec field. Billy Hoffman is a lead security researcher for SPI dynamics where he works on discovering and automating web application vulnerabilities and improving their crawling technology. He has presented at a lot of conferences including (ToorCon, Black Hat, etc). Billy’s knowledge on Ajax is tremendous and he has written many </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/5231022666289309374/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=5231022666289309374' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/5231022666289309374'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/5231022666289309374'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/03/reflection-on-billy-hoffman.html' title='Reflection on Billy Hoffman'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_p4tgkwtZjQ8/RfuTTbftZoI/AAAAAAAAADI/0VqjRJpQQtA/s72-c/billy+hoffman.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-7639433596759206443</id><published>2007-03-09T01:01:00.000-05:00</published><updated>2007-03-17T03:56:07.476-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='sheeraj'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><title type='text'>Reflection on Sheeraj Shah</title><summary type='text'>This week on Reflection we have another big contributor to webappsec field. Sheeraj Shah is a founder of Net Square Solutions where he performs consulting, training and R&amp;D activities. He has done a lot of research on web application and web services security. Sheeraj started with web application security in mid 2000 when he was working on WebLogic application server and discovered some </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/7639433596759206443/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=7639433596759206443' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/7639433596759206443'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/7639433596759206443'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/03/reflection-on-sheeraj-shah.html' title='Reflection on Sheeraj Shah'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_p4tgkwtZjQ8/RfD4dbftZnI/AAAAAAAAADA/RnzyUxqmJZo/s72-c/sheeraj.bmp' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-3280585335320729239</id><published>2007-03-02T01:25:00.000-05:00</published><updated>2007-03-17T03:57:08.256-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Firewall'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='ModSecurity'/><title type='text'>Reflection on Ivan Ristic</title><summary type='text'>If we hear so much about web application firewalls and their role as a first line of defense in protecting our web applications, a large amount of credit has to go to Ivan Ristic. Ivan Ristic is the creator of ModSecurity (an open source web application firewall and intrusion detection/prevention engine). He started playing in the webappsec space sometime around 2002 and working seriously since </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/3280585335320729239/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=3280585335320729239' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/3280585335320729239'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/3280585335320729239'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/03/reflection-on-ivan-ristic.html' title='Reflection on Ivan Ristic'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_p4tgkwtZjQ8/RefDsnJgB2I/AAAAAAAAAC0/BM-rb0YTFOI/s72-c/ivanristic-photo-large.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-3255184007332324975</id><published>2007-02-25T17:18:00.000-05:00</published><updated>2007-02-25T17:34:13.206-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><title type='text'>Separating actual urls hidden behind the link can help reduce phishing</title><summary type='text'>Lately i have been getting a lot of phishing emails in my inbox. Over the years yahoo has done a good job in redirecting those to spam folders. Of course every now and then one or two might slip through the cracks but its only until recently when i started getting a lot of phishing emails in my inbox. Emails for washington mutual, paypal, bank of america, etc. It didnt matter if i have an account</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/3255184007332324975/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=3255184007332324975' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/3255184007332324975'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/3255184007332324975'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/02/separating-actual-urls-hidden-behind.html' title='Separating actual urls hidden behind the link can help reduce phishing'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-9079221393035390385</id><published>2007-02-23T02:14:00.000-05:00</published><updated>2007-03-02T02:58:52.630-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='Jeremiah Grossman'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><title type='text'>Reflection on Jeremiah Grossman</title><summary type='text'>Today’s personality is again well known for its contribution to the world of web application security. Jeremiah Grossman is an expert in webappsec and is a CTO and a co-founder of Whitehat Security. He is also a founding member of Web Application Security Consortium. Jeremiah started hacking around 1991-92 but it was only until 2000, he took it as a profession when he was working for yahoo where </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/9079221393035390385/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=9079221393035390385' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/9079221393035390385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/9079221393035390385'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/02/reflection-on-jeremiah-grossman.html' title='Reflection on Jeremiah Grossman'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_p4tgkwtZjQ8/Rd6VPOWoWhI/AAAAAAAAACk/z2afT-7xDPE/s72-c/jeremiah.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-4641176579540498912</id><published>2007-02-20T03:07:00.000-05:00</published><updated>2007-02-20T03:18:09.821-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PCI compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='source code audit'/><title type='text'>Compliance - is it worth the money?</title><summary type='text'>While surfing through the net i found a posting on compliancehttp://bestsecurity.blogspot.com/2007/02/compliance-audit-is-not-substantive.htmlThough it was more of a ranting on the compliance but it certainly made me think my experience on PCI compliance.I do agree that compliance has a place in the industry. In my experience, had it not been for compliance, many companies have not paid attention</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4641176579540498912/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4641176579540498912' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4641176579540498912'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4641176579540498912'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/02/compliance-is-it-worth-money.html' title='Compliance - is it worth the money?'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-1229797422186192914</id><published>2007-02-15T13:45:00.000-05:00</published><updated>2007-02-23T03:05:09.657-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webappsec'/><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><category scheme='http://www.blogger.com/atom/ns#' term='RSnake'/><title type='text'>Reflection on RSnake</title><summary type='text'>If you have heard of XSS cheat sheet or http://ha.ckers.org/ then you already know him. His name is Robert Hansen or more popularly known as RSnake. If there is any mention of XSS, there is a big chance RSnake’s name or its cheat sheet is mentioned along with it. His contribution in the web application security awareness is legendary. On two of his many web sites (http://ha.ckers.org/ and http://</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/1229797422186192914/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=1229797422186192914' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1229797422186192914'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/1229797422186192914'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/02/reflection-on-rsnake.html' title='Reflection on RSnake'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_p4tgkwtZjQ8/RdSqv4vm5mI/AAAAAAAAACQ/QvCukM8eB0Q/s72-c/rsnake.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-8958527098344594974</id><published>2007-02-13T15:22:00.000-05:00</published><updated>2007-02-10T08:20:50.139-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security products vs solutions'/><title type='text'>I dont want a product, I want a solution</title><summary type='text'>RSA Expo is over, and it was good to see a lot of Web application security products being showcased there. The awareness about Web application security is increasing, and a lot of companies are coming out with new products to protect Web applications. Such products include network and Web application firewalls, identity management, auditing tools, Web application security tools and encryption </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/8958527098344594974/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=8958527098344594974' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/8958527098344594974'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/8958527098344594974'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/02/i-dont-want-product-i-want-solution.html' title='I dont want a product, I want a solution'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-4708327043810358273</id><published>2007-02-08T23:22:00.000-05:00</published><updated>2007-07-02T14:32:59.560-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reflection'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='amit klien'/><title type='text'>Reflection on Amit Klein</title><summary type='text'>For those who are in the web application security field need no introduction to his name. He is an expert and by far one of the best in web application security space. He is one of the early starters of the field and has played a major role in the awareness of webappsec. His contribution ranges from not only identifying vulnerabilities and publishing them but also contributing towards standards </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/4708327043810358273/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=4708327043810358273' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4708327043810358273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/4708327043810358273'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/02/reflection-on-amit-klein.html' title='Reflection on Amit Klein'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_p4tgkwtZjQ8/RolEzfXxKoI/AAAAAAAAAHM/iyHiAzugXQs/s72-c/amit_klein.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-133495183474772864</id><published>2007-02-07T21:30:00.000-05:00</published><updated>2007-02-09T13:42:38.090-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security meetup RSA conference'/><title type='text'>WASC meetup during RSA conference</title><summary type='text'>Today at WASC meetup, quite a lot of crowd turned out and it was fun meeting a lot of players from the application security field. Here are some of the pictures from the meetup. You will see people like Jeremiah Grossman, RSnake, Arian Evans (Whitehat), Billy Hoffman (SPI), Robert Auger (cgisecurity.net), etc You can view more pictures at Jeremiah's blog</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/133495183474772864/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=133495183474772864' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/133495183474772864'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/133495183474772864'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/02/today-at-wasc-meetup-quite-lot-of-crowd.html' title='WASC meetup during RSA conference'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_p4tgkwtZjQ8/RcqN5ZAOCrI/AAAAAAAAABM/TXIKSHuPpFs/s72-c/DSCN0318.JPG' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-118775305585802376</id><published>2007-01-30T19:36:00.000-05:00</published><updated>2007-01-30T21:05:09.035-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ajax'/><category scheme='http://www.blogger.com/atom/ns#' term='Password'/><category scheme='http://www.blogger.com/atom/ns#' term='Proof of concept'/><title type='text'>Target password cracking - code explained</title><summary type='text'>This is the explanation of the source code from my last posting about targeted password cracking - Proof of concept ---- Start Code -----/******Global variables defined in this module ajax_request - To store the XMLHttpRequest object.autofill - This string will be used to send variations of password to detect the password policy and what other characters are allowed.success_response - This string</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/118775305585802376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=118775305585802376' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/118775305585802376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/118775305585802376'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/01/target-password-cracking-code-explained.html' title='Target password cracking - code explained'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-8253709539324899235</id><published>2007-01-30T04:08:00.000-05:00</published><updated>2007-02-01T01:16:50.690-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Character filtering'/><category scheme='http://www.blogger.com/atom/ns#' term='Ajax'/><category scheme='http://www.blogger.com/atom/ns#' term='Password'/><title type='text'>Targeted password cracking - Proof of concept</title><summary type='text'>This is a proof of concept to exploit the registration functionality of a website to build targeted password cracking engine. I am using Ajax to automatically detect the parameters which are submitted for a successful password and automatically resubmitting the modified passwords. Of course other technologies can be used for the same. I think I can safely assume that by now we all understand the </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/8253709539324899235/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=8253709539324899235' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/8253709539324899235'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/8253709539324899235'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/01/targeted-password-cracking-proof-of.html' title='Targeted password cracking - Proof of concept'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-117001395674500583</id><published>2007-01-28T14:51:00.000-05:00</published><updated>2007-01-28T14:52:36.756-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Application Security'/><title type='text'>Sample Shopcart application</title><summary type='text'>In my experience i have seen a lot of developers being clueless about what application security is and how they unknowingly left a door open for the bad guys in their application. They don't have much idea about how application are open to these vulnerabililties  (like XSS, SQL injection, session hijacking, etc), how they are exploited and what changes they need to make in their coding style to </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/117001395674500583/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=117001395674500583' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/117001395674500583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/117001395674500583'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/01/sample-shopcart-application.html' title='Sample Shopcart application'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116953572075712108</id><published>2007-01-23T01:58:00.000-05:00</published><updated>2007-01-23T17:03:56.790-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><title type='text'>XSS filter to protect from XSS attacks</title><summary type='text'>Here are the excerpts from the chilling effectGrossman, who founded his own research company, WhiteHat, claims XSS vulnerabilities can be found in 70 percent of websites. RSnake goes further. "I know Jeremiah says seven of 10. I'd say there's only one in 30 I come across where the XSS isn't totally obvious. I don't know of a company I couldn't break into [using XSS]."If you apply Grossman's </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116953572075712108/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116953572075712108' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116953572075712108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116953572075712108'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/01/xss-filter-to-protect-from-xss-attacks.html' title='XSS filter to protect from XSS attacks'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116902498712527800</id><published>2007-01-17T04:05:00.000-05:00</published><updated>2007-01-17T04:27:31.423-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Sniffer'/><category scheme='http://www.blogger.com/atom/ns#' term='Ajax'/><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><title type='text'>Ajax Sniffer - Prrof of concept</title><summary type='text'>NOTE - The original idea was discussed by Stefano Di Paola in his paper Subverting Ajax. I have simply created a working proof of concept of ajax based sniffer. I have taken the same files as I demonstrated in ajax worm PoC. You can see the demo at http://www.attacklabs.comLet’s take a look at how to create an ajax based sniffer.In order to create a sniffer we need to do two things1. Override the</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116902498712527800/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116902498712527800' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116902498712527800'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116902498712527800'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/01/ajax-sniffer-prrof-of-concept.html' title='Ajax Sniffer - Prrof of concept'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116841556113674909</id><published>2007-01-10T02:49:00.000-05:00</published><updated>2007-01-10T03:20:49.953-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><title type='text'>Breaking the Same Origin barrier of Javascript</title><summary type='text'>NOTE: I dont want javascript to be executed so in the sample code below, you will see that i will remove the &lt;&gt; tags from the script element.Same Origin Policy of browsersOften times we have heard that Javascript cannot send requests to another domain. That is because of the same origin policy implemented in the browsers. The same origin policy of the browsers prevents document or script loading </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116841556113674909/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116841556113674909' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116841556113674909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116841556113674909'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2007/01/breaking-same-origin-barrier-of.html' title='Breaking the Same Origin barrier of Javascript'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116596702316143236</id><published>2006-12-12T18:33:00.000-05:00</published><updated>2006-12-12T18:43:43.163-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Search'/><category scheme='http://www.blogger.com/atom/ns#' term='Application Security'/><title type='text'>Did you SEEC it yet?</title><summary type='text'>I am pleased to announce SEEC - An application security search engine. This search engine is powered by google and is application security specific. It is still in beta release.  You can access it here - SEECWhy SEEC?well, SEC is short for security and SEEK means to find, hence SEEC (find within security)Please do leave your comments and feedback on what your thoughts are on SEEC. Also, few weeks</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116596702316143236/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116596702316143236' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116596702316143236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116596702316143236'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/12/did-you-seec-it-yet.html' title='Did you SEEC it yet?'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116543746927731950</id><published>2006-12-06T15:33:00.000-05:00</published><updated>2006-12-17T04:01:10.496-05:00</updated><title type='text'>Survey on Application Security Vulnerability Assessment process</title><summary type='text'>Today jeremiah posted the third round of his monthly survey on web application security professionals. http://jeremiahgrossman.blogspot.com/2006/12/web-application-security-professionals.htmlThe results of the first two are available here[1] Nov. 2006http://jeremiahgrossman.blogspot.com/2006/11/web-application-security-professionals.html[2] Oct. 2006http://jeremiahgrossman.blogspot.com/2006/10/</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116543746927731950/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116543746927731950' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116543746927731950'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116543746927731950'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/12/survey-on-application-security.html' title='Survey on Application Security Vulnerability Assessment process'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116513910357273061</id><published>2006-12-03T04:43:00.000-05:00</published><updated>2006-12-07T04:40:55.996-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Session Hijacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Ajax'/><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><title type='text'>Ajax Worm - Proof of Concept</title><summary type='text'>Few weeks ago I demonstrated a Proof of Concept of how easy it is to create an Ajax worm which hijacks a user session and redirects all the user activity through itself. The idea is simply to be able to control and monitor the user activity on a website by inserting the malicious script into the visiting user's session using XSS. I have been advocating for some time now, the extent of damage that</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116513910357273061/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116513910357273061' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116513910357273061'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116513910357273061'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/12/ajax-worm-proof-of-concept.html' title='Ajax Worm - Proof of Concept'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116405085026901775</id><published>2006-11-20T14:07:00.000-05:00</published><updated>2006-12-03T14:48:48.476-05:00</updated><title type='text'>Correction - Comparison between Appscan and Webinspect</title><summary type='text'>In my last posting, i discussed about some of the difference between appscan and webinspect. Ory Segal from watchfire pointed out a few areas which could have been interpreted wrongly as well. I have made changes to the original post and i am posting it separately for those who have already read it or if it is stored in cache somewhere.View the actual attack during a scan session: Webinspect </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116405085026901775/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116405085026901775' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116405085026901775'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116405085026901775'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/11/correction-comparison-between-appscan.html' title='Correction - Comparison between Appscan and Webinspect'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116259255275907562</id><published>2006-11-03T14:23:00.000-05:00</published><updated>2006-12-04T15:01:36.113-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Appscan'/><category scheme='http://www.blogger.com/atom/ns#' term='Webinspect'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability Assessment Tool'/><title type='text'>Comparison between Appscan vs Webinspect</title><summary type='text'>Last month I got a chance to evaluate the two popular vulnerability assessment tools Webinspect and Appscan and I wanted to share my findings with others. As you will notice, currently I have published only few technical comparison I will add more to it sooner. This comparison is strictly between Appscan 6.5 and Webinspect 6.2. Both the companies have since come with a beta release of a new </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116259255275907562/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116259255275907562' title='21 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116259255275907562'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116259255275907562'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/11/comparison-between-appscan-vs.html' title='Comparison between Appscan vs Webinspect'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>21</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116188739548558668</id><published>2006-10-26T14:25:00.000-04:00</published><updated>2006-10-26T14:50:11.036-04:00</updated><title type='text'>Don't let your Web app help spammers</title><summary type='text'>We've all been plagued by unsolicited commercial email -- also known as spam. In fact, the Washington Post reported that spam may soon account for half of all U.S. email traffic. Lets look at ways on how we can protect our email address from the spammers. read the complete article here</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116188739548558668/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116188739548558668' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116188739548558668'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116188739548558668'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/10/dont-let-your-web-app-help-spammers.html' title='Don&apos;t let your Web app help spammers'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116058836874047008</id><published>2006-10-11T13:37:00.000-04:00</published><updated>2006-10-11T13:39:28.753-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ajax'/><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><title type='text'>How Ajax makes it easier to steal information from your clipboard</title><summary type='text'>Cut Copy Paste has always been an important part of our digital life. Developers, as well as regular users, can't live without it. Regular users use it routinely to copy and paste information such as passwords and credit card numbers from one form to another. Office employees use it all the time when creating documents. There's no denying our reliance on the Copy and Paste functionality of the </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116058836874047008/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116058836874047008' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116058836874047008'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116058836874047008'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/10/how-ajax-makes-it-easier-to-steal.html' title='How Ajax makes it easier to steal information from your clipboard'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116034072249213180</id><published>2006-10-08T16:47:00.000-04:00</published><updated>2006-10-08T18:04:35.433-04:00</updated><title type='text'>Taking the battle to the phishers</title><summary type='text'>"University of Illinois at Chicago is working with some financial institutions (he can't say which) on the anti-phishing agent, so there is commercial interest. "We'll be providing them complex code, user names, and passwords," he says. "And they will be able to see the phishing traffic" and disable it and track the phishers for eventual prosecution, for instance. "This would be really </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116034072249213180/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116034072249213180' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116034072249213180'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116034072249213180'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/10/taking-battle-to-phishers.html' title='Taking the battle to the phishers'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116019176108982455</id><published>2006-10-06T23:04:00.001-04:00</published><updated>2006-10-06T23:42:16.450-04:00</updated><title type='text'>Court OKs NSA wiretapping</title><summary type='text'>http://www.wired.com/news/wireservice/0,71911-0.html?tw=wn_technology_security_3"The Bush administration can continue its warrantless surveillance program while it appeals a judge's ruling that the program is unconstitutional, a federal appeals court ruled Wednesday.""The program monitors international phone calls and e-mails to or from the United States involving people the government suspects </summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116019176108982455/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116019176108982455' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116019176108982455'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116019176108982455'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/10/court-oks-nsa-wiretapping.html' title='Court OKs NSA wiretapping'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116019052225324111</id><published>2006-10-06T23:04:00.000-04:00</published><updated>2006-10-06T23:08:42.260-04:00</updated><title type='text'>Is Microsoft changing?</title><summary type='text'>http://wired.com/wired/archive/14.10/microsoft.htmlSomething different from security but if all the chief security architect could be as Ray Ozzie, 75% of the security attacks we are seeing today wont be possible at all.</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116019052225324111/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116019052225324111' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116019052225324111'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116019052225324111'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/10/is-microsoft-changing.html' title='Is Microsoft changing?'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116018772164259177</id><published>2006-10-06T22:18:00.000-04:00</published><updated>2006-10-06T22:22:01.650-04:00</updated><title type='text'>How safe is “hacker safe”</title><summary type='text'>ID Thieves Turn Sights on Smaller E-BusinessesThis article raises so many questions but the biggest of them all is how effective are these sites which are providing this kind of “hacker safe” services and who is to verify what level of services they are providing. For all we know, it’s just a false sense of security as we found out in this case. The companies, who are totally not aware of what to</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116018772164259177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116018772164259177' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116018772164259177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116018772164259177'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/10/how-safe-is-hacker-safe.html' title='How safe is “hacker safe”'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116018655349678137</id><published>2006-10-06T21:56:00.000-04:00</published><updated>2006-10-06T22:02:33.496-04:00</updated><title type='text'>Google victim of click fraud</title><summary type='text'>This time it was google’s turn to play victim of click fraud.http://www.theregister.co.uk/2006/10/06/google_adsense_worm/</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116018655349678137/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116018655349678137' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116018655349678137'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116018655349678137'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/10/google-victim-of-click-fraud.html' title='Google victim of click fraud'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-116018618679593538</id><published>2006-10-06T21:54:00.000-04:00</published><updated>2006-10-06T21:56:26.803-04:00</updated><title type='text'>RE: Privacy group takes US to court over email spying</title><summary type='text'>post: http://www.theregister.co.uk/2006/10/06/eff_sues_us_govt/What I would like to know is if US govt. can state it for the record, that they are only using it to monitor terrorist communications and NOTHING ELSE. They have claimed that they are using it to track terrorist communications but I don’t know if they have said only terrorist communication and nothing else?</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/116018618679593538/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=116018618679593538' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116018618679593538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/116018618679593538'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/10/re-privacy-group-takes-us-to-court.html' title='RE: Privacy group takes US to court over email spying'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-115998655544799540</id><published>2006-10-04T14:26:00.000-04:00</published><updated>2006-10-04T14:29:15.463-04:00</updated><title type='text'>To open source or not to open source</title><summary type='text'>Yahoo allows outsiders to innovate on Yahoo e-mailYahoo has decided to open the underlying code of yahoo mail to outside programmers. Now this can be a good thing and a bad thing. Of course we will see a lot more  applications built on top of yahoo mail, but then it is a also a nightmare from the security point of view. On one side, since the source code is allowed access they are more vulnerable</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/115998655544799540/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=115998655544799540' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/115998655544799540'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/115998655544799540'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/10/to-open-source-or-not-to-open-source.html' title='To open source or not to open source'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34422497.post-115992201629278434</id><published>2006-10-03T20:28:00.000-04:00</published><updated>2006-10-03T20:37:02.943-04:00</updated><title type='text'>Taking passwords to the grave</title><summary type='text'>Interesting story on the passwords.http://news.com.com/Taking+passwords+to+the+grave/2100-1025_3-6118314.htmlit brings up an interesting twist to the whole password saga by raising a question, whether we should store them in our will. Though it has a valid reason but then isnt that against what we preach.</summary><link rel='replies' type='application/atom+xml' href='http://myappsecurity.blogspot.com/feeds/115992201629278434/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34422497&amp;postID=115992201629278434' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/115992201629278434'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34422497/posts/default/115992201629278434'/><link rel='alternate' type='text/html' href='http://myappsecurity.blogspot.com/2006/10/taking-passwords-to-grave.html' title='Taking passwords to the grave'/><author><name>Anurag Agarwal</name><uri>http://www.blogger.com/profile/00132226679618654350</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_p4tgkwtZjQ8/SYTzgKVAa0I/AAAAAAAAAcc/8R_CKEuuvQs/S220/DSCN0012.JPG'/></author><thr:total>0</thr:total></entry></feed>
