<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: From the Office of &#34;Real World Software Security&#34;</title>
	<atom:link href="http://securitybuddha.com/2008/01/10/from-the-office-of-real-world-software-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://securitybuddha.com/2008/01/10/from-the-office-of-real-world-software-security/</link>
	<description>Security Enlightenment - Mark Curphey</description>
	<pubDate>Thu, 08 Jan 2009 17:00:14 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Oulaaa...Non, le XSS (Cross Site Scripting) n'est PAS une fonctionnalit&#233; ! , CoqBlog</title>
		<link>http://securitybuddha.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11864</link>
		<dc:creator>Oulaaa...Non, le XSS (Cross Site Scripting) n'est PAS une fonctionnalit&#233; ! , CoqBlog</dc:creator>
		<pubDate>Sun, 02 Mar 2008 17:37:13 +0000</pubDate>
		<guid isPermaLink="false">http://securitybuddha.wordpress.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11864</guid>
		<description>[...] du post de Mark Curphey : "  When a customer development team was recently asked to use the AntiXSS library, validate [...]</description>
		<content:encoded><![CDATA[<p>[...] du post de Mark Curphey : &#8220;  When a customer development team was recently asked to use the AntiXSS library, validate [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cry or Smile? You Decide&#8230; &#124; Secure Software Engineering Blog</title>
		<link>http://securitybuddha.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11849</link>
		<dc:creator>Cry or Smile? You Decide&#8230; &#124; Secure Software Engineering Blog</dc:creator>
		<pubDate>Tue, 26 Feb 2008 20:15:46 +0000</pubDate>
		<guid isPermaLink="false">http://securitybuddha.wordpress.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11849</guid>
		<description>[...] Wednesday Mark Curphey emailed me about a conversation his team had with a customer. I see he has now blogged about the conversation. Here&#8217;s an excerpt.  When a customers [sic, you need to learn some [...]</description>
		<content:encoded><![CDATA[<p>[...] Wednesday Mark Curphey emailed me about a conversation his team had with a customer. I see he has now blogged about the conversation. Here&#8217;s an excerpt.  When a customers [sic, you need to learn some [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cry or Smile? You Decide&#8230; &#124; Secure Software Engineering Journal</title>
		<link>http://securitybuddha.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11839</link>
		<dc:creator>Cry or Smile? You Decide&#8230; &#124; Secure Software Engineering Journal</dc:creator>
		<pubDate>Sat, 23 Feb 2008 22:12:11 +0000</pubDate>
		<guid isPermaLink="false">http://securitybuddha.wordpress.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11839</guid>
		<description>[...] Wednesday Mark Curphey emailed me about a conversation his team had with a customer. I see he has now blogged about the conversation. Here&#8217;s an excerpt.  When a customers [sic, you need to learn some [...]</description>
		<content:encoded><![CDATA[<p>[...] Wednesday Mark Curphey emailed me about a conversation his team had with a customer. I see he has now blogged about the conversation. Here&#8217;s an excerpt.  When a customers [sic, you need to learn some [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cry or Smile? You Decide&#8230; &#124; Secure Software Engineering</title>
		<link>http://securitybuddha.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11825</link>
		<dc:creator>Cry or Smile? You Decide&#8230; &#124; Secure Software Engineering</dc:creator>
		<pubDate>Fri, 22 Feb 2008 11:17:34 +0000</pubDate>
		<guid isPermaLink="false">http://securitybuddha.wordpress.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11825</guid>
		<description>[...] Wednesday Mark Curphey emailed me about a conversation his team had with a customer. I see he has now blogged about the conversation. Here&#8217;s an excerpt.  When a customers [sic, you need to learn some [...]</description>
		<content:encoded><![CDATA[<p>[...] Wednesday Mark Curphey emailed me about a conversation his team had with a customer. I see he has now blogged about the conversation. Here&#8217;s an excerpt.  When a customers [sic, you need to learn some [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Real-word CSRF hack &#124; Mike Andrews</title>
		<link>http://securitybuddha.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11651</link>
		<dc:creator>Real-word CSRF hack &#124; Mike Andrews</dc:creator>
		<pubDate>Sat, 19 Jan 2008 06:45:22 +0000</pubDate>
		<guid isPermaLink="false">http://securitybuddha.wordpress.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11651</guid>
		<description>[...] nearly as much as it should.&#160; With all the other &#34;low hanging fruit&#34;, and with examples of cluelessness like this, we&#8217;ll probably see more stories of domain/email/bank accounts/stock trades being [...]</description>
		<content:encoded><![CDATA[<p>[...] nearly as much as it should.&#160; With all the other &quot;low hanging fruit&quot;, and with examples of cluelessness like this, we&#8217;ll probably see more stories of domain/email/bank accounts/stock trades being [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doug Woodall</title>
		<link>http://securitybuddha.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11524</link>
		<dc:creator>Doug Woodall</dc:creator>
		<pubDate>Wed, 16 Jan 2008 00:48:59 +0000</pubDate>
		<guid isPermaLink="false">http://securitybuddha.wordpress.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11524</guid>
		<description>Is this the same as no accountability. Dont fix it till we get in trouble?
Sad.</description>
		<content:encoded><![CDATA[<p>Is this the same as no accountability. Dont fix it till we get in trouble?<br />
Sad.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Liquidmatrix Security Digest &#187; Security Briefing: January 15th</title>
		<link>http://securitybuddha.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11495</link>
		<dc:creator>Liquidmatrix Security Digest &#187; Security Briefing: January 15th</dc:creator>
		<pubDate>Tue, 15 Jan 2008 13:07:10 +0000</pubDate>
		<guid isPermaLink="false">http://securitybuddha.wordpress.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11495</guid>
		<description>[...] From the Office of &#8220;Real World Software Security&#8221; [...]</description>
		<content:encoded><![CDATA[<p>[...] From the Office of &#8220;Real World Software Security&#8221; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Franchu&#8217;s lair &#187; Seguridad web, esa gran asignatura pendiente</title>
		<link>http://securitybuddha.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11363</link>
		<dc:creator>Franchu&#8217;s lair &#187; Seguridad web, esa gran asignatura pendiente</dc:creator>
		<pubDate>Sun, 13 Jan 2008 09:02:53 +0000</pubDate>
		<guid isPermaLink="false">http://securitybuddha.wordpress.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11363</guid>
		<description>[...] lo que me ha llevado a escribir este post, es la entrada From the Office of &#8220;Real World Software Security&#8221; en la que tras recomendarle a un cliente utilizar una librería antiXSS el cliente [...]</description>
		<content:encoded><![CDATA[<p>[...] lo que me ha llevado a escribir este post, es la entrada From the Office of &#8220;Real World Software Security&#8221; en la que tras recomendarle a un cliente utilizar una librería antiXSS el cliente [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dre</title>
		<link>http://securitybuddha.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11338</link>
		<dc:creator>dre</dc:creator>
		<pubDate>Sat, 12 Jan 2008 21:09:25 +0000</pubDate>
		<guid isPermaLink="false">http://securitybuddha.wordpress.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11338</guid>
		<description>@ Alun Jones:

Well, not really.  Stored-XSS and HTML Injection are the same thing.  Reflected-XSS is more like a few things, some of which include: parameter/form-based/cookie tampering in the HTTP header to include a script that will execute code on the client-side, while no code is executed or injected on the server-side.  Reflected-XSS also includes script code inside binaries or in other places (e.g. Flash/QuickTime/media files, or images, or cache files) besides just HTTP header injections.  DOM-based XSS is XSS on the client-side DOM (Javascript injected Javascript)!

I do think we're going to need to start redefining XSS.  Many XSS tools today only look for Javascript.  But there are also other languages, including VBScript, Applescript, Actionscript, Silverlight (and other RIA frameworks) -- and most evil of all -- HTML, XHTML, CSS, XML, etc.</description>
		<content:encoded><![CDATA[<p>@ Alun Jones:</p>
<p>Well, not really.  Stored-XSS and HTML Injection are the same thing.  Reflected-XSS is more like a few things, some of which include: parameter/form-based/cookie tampering in the HTTP header to include a script that will execute code on the client-side, while no code is executed or injected on the server-side.  Reflected-XSS also includes script code inside binaries or in other places (e.g. Flash/QuickTime/media files, or images, or cache files) besides just HTTP header injections.  DOM-based XSS is XSS on the client-side DOM (Javascript injected Javascript)!</p>
<p>I do think we&#8217;re going to need to start redefining XSS.  Many XSS tools today only look for Javascript.  But there are also other languages, including VBScript, Applescript, Actionscript, Silverlight (and other RIA frameworks) &#8212; and most evil of all &#8212; HTML, XHTML, CSS, XML, etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mcurphey</title>
		<link>http://securitybuddha.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11293</link>
		<dc:creator>mcurphey</dc:creator>
		<pubDate>Sat, 12 Jan 2008 08:51:33 +0000</pubDate>
		<guid isPermaLink="false">http://securitybuddha.wordpress.com/2008/01/10/from-the-office-of-real-world-software-security/#comment-11293</guid>
		<description>I am just a native Englishman. Grammar fixed guvnor.</description>
		<content:encoded><![CDATA[<p>I am just a native Englishman. Grammar fixed guvnor.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
