<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-14492286</id><updated>2011-11-27T15:40:37.366-08:00</updated><title type='text'>Dotsecure Information Security</title><subtitle type='html'>Welcome to Dotsecure Information Security Blogs. This blog is designed for everyone who has the passion for network security, application security or information security in general.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>34</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-14492286.post-116785409003811989</id><published>2007-01-03T11:53:00.000-08:00</published><updated>2007-01-03T11:55:30.193-08:00</updated><title type='text'>Wireless Forensics - Tapping the Air.</title><content type='html'>This is going to be a multi part article. I found this on Securityfocus, thought it would be fun to share.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.securityfocus.com/infocus/1884?ref=rss&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-116785409003811989?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/116785409003811989/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=116785409003811989' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116785409003811989'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116785409003811989'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2007/01/wireless-forensics-tapping-air.html' title='Wireless Forensics - Tapping the Air.'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-116785373223209130</id><published>2007-01-03T11:46:00.000-08:00</published><updated>2007-01-03T11:49:27.883-08:00</updated><title type='text'>SOX 404 SIMPLIFIED. DATABASE CHANGE MANAGEMENT</title><content type='html'>The full article can be found here . &lt;br /&gt;&lt;br /&gt;http://www.dbazine.com/ofinterest/oi-articles/mcquade2&lt;br /&gt;&lt;br /&gt;But here are the highlights. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Changes to the database are widely communicated, and their impacts are known beforehand. &lt;br /&gt;&lt;br /&gt;Installation and maintenance procedure documentation for the DBMS is current. &lt;br /&gt;&lt;br /&gt;Data structures are defined and built as the designer intended them to be. &lt;br /&gt;&lt;br /&gt;Data structure changes are thoroughly tested. &lt;br /&gt;&lt;br /&gt;Users are apprised, and trained if necessary, when database changes imply a change in application behavior. &lt;br /&gt;&lt;br /&gt;The table and column business definitions are current and widely known. &lt;br /&gt;&lt;br /&gt;The right people are involved throughout the application development and operational cycles. &lt;br /&gt;&lt;br /&gt;Any in-house tools are maintained and configured in a disciplined way. &lt;br /&gt;&lt;br /&gt;Application impacts are known prior to the migration of database changes to production. &lt;br /&gt;&lt;br /&gt;Performance is maintained at predefined and acceptable levels. &lt;br /&gt;&lt;br /&gt;The database change request and evaluation system is rational. &lt;br /&gt;&lt;br /&gt;Turn-around time on database changes is predictable. &lt;br /&gt;&lt;br /&gt;Any change to the database can be reversed. &lt;br /&gt;&lt;br /&gt;Database structure documentation is maintained. &lt;br /&gt;&lt;br /&gt;Database system software documentation is maintained. &lt;br /&gt;&lt;br /&gt;Migration through development, test, and especially, production environments is rational. &lt;br /&gt;&lt;br /&gt;Security controls for data access is appropriate and maintained. &lt;br /&gt;&lt;br /&gt;Database reorganizations are planned to minimize business disruption.&lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-116785373223209130?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/116785373223209130/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=116785373223209130' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116785373223209130'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116785373223209130'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2007/01/sox-404-simplified-database-change.html' title='SOX 404 SIMPLIFIED. DATABASE CHANGE MANAGEMENT'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-116784233800927807</id><published>2007-01-03T08:35:00.000-08:00</published><updated>2007-01-03T08:40:20.286-08:00</updated><title type='text'>Scully: SQL DB interface and Brute Forcer</title><content type='html'>Happy New Year Friends. &lt;br /&gt;&lt;br /&gt;I would like to start off the new year blog with a flavor. &lt;br /&gt;&lt;br /&gt;Sensepos has released a new tool today for you all, its called Scully. &lt;br /&gt;&lt;br /&gt;Scully is a client interface to MSSQL and MySQL database servers. No more need for&lt;br /&gt;MSSQL/MySQL client libraries to be installed and no more need to setup an ODBC connection  either. Simply add IP/Hostname, username, password, port and database name and SQL away.&lt;br /&gt;&lt;br /&gt;Scully also performs password brute forcing for MySQL and MSSQL, by clicking "Brute Force" a little window pops out and you simply provide a server,username, port and specify MySQL/MSSQL, then you also provide a txt file list of passwords and click "Start". Scully will quickly attempt to brute force the correct password, one also has the option to set "debug" to view the progress of the brute force.&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-116784233800927807?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/116784233800927807/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=116784233800927807' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116784233800927807'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116784233800927807'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2007/01/scully-sql-db-interface-and-brute.html' title='Scully: SQL DB interface and Brute Forcer'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-116620626425260732</id><published>2006-12-15T10:07:00.000-08:00</published><updated>2006-12-15T10:11:25.806-08:00</updated><title type='text'>SOX 404 Changes? How does this affect the security?</title><content type='html'>&lt;strong&gt;APPROVED &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;1. Easier for foreign companies to withdraw their securities from American markets. &lt;br /&gt;&lt;br /&gt;2. Increase the financial qualifications for investors in hedge funds, to a net worth of $2.5 million from the current standard of $1 million. &lt;br /&gt;&lt;br /&gt;3. The S.E.C. adopted a rule that would save corporations the expense of mailing financial reports and proxy statements by enabling them to communicate with the vast majority of their investors through the Internet. (Investors can continue to receive paper copies of proxies and other material through the mail if they request them.) &lt;br /&gt;&lt;br /&gt;And it proposed rules that would make it easier and less costly for banks to offer brokerage services&lt;br /&gt;&lt;br /&gt;&lt;strong&gt; STILL IN THE WORKS &lt;/strong&gt;&lt;br /&gt;1. Under those new guidelines, prosecutors in the field will now have to obtain permission from senior officials before trying to get companies that are under investigation to waive their attorney-client privilege. &lt;br /&gt;&lt;br /&gt;2. In weighing whether to seek the indictment of a company, the prosecutors will also no longer be permitted to consider whether the company is paying the legal fees of an employee involved in the inquiry. &lt;br /&gt;&lt;br /&gt;3. The changes announced by the commission on Wednesday fell short of what some companies and groups had sought. In the case of the auditing rules, for instance, many businesses had sought an exemption from the requirements of Section 404 of the Sarbanes-Oxley Act. &lt;br /&gt;&lt;br /&gt;4. Instead of a blanket exemption, officials said, the proposed guidance would give many small companies a powerful new tool in restricting their auditors from engaging in what the executives viewed as expensive and unnecessary audits of financial controls that had minimum impact on financial statements. &lt;br /&gt;&lt;br /&gt;5. Under the guidance proposed by the S.E.C., executives would evaluate the design of only those financial controls that might carry the risk of having a material impact on financial statements. Commission officials emphasized that the guidance is being drafted to be less onerous on smaller or less intricate companies.&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-116620626425260732?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/116620626425260732/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=116620626425260732' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116620626425260732'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116620626425260732'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/12/sox-404-changes-how-does-this-affect.html' title='SOX 404 Changes? How does this affect the security?'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-116602775213697684</id><published>2006-12-13T08:31:00.000-08:00</published><updated>2006-12-13T08:48:35.376-08:00</updated><title type='text'>ASP CMD SHELL on ASP 5.1</title><content type='html'>Interesting article was posted by Brett Moore on Security Focus this morning, on how obtain cmd shell on IIS 5.1.&lt;br /&gt;&lt;br /&gt;As we all know such things used to exist for IIS 5.0. I havent yet tested, but this does make sense.&lt;br /&gt;&lt;br /&gt;Here is the full link to the article.&lt;br /&gt;&lt;br /&gt;http://www.securityfocus.com/archive/1/454268&lt;br /&gt;&lt;br /&gt;I wanted to post the source code here, though it seems like google blogger has problems with some of the html tags.&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-116602775213697684?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/116602775213697684/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=116602775213697684' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116602775213697684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116602775213697684'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/12/asp-cmd-shell-on-asp-51.html' title='ASP CMD SHELL on ASP 5.1'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-116585560883266877</id><published>2006-12-11T08:43:00.000-08:00</published><updated>2006-12-11T08:46:49.576-08:00</updated><title type='text'>Microsoft Threat Analysis &amp; Modeling v 2.1</title><content type='html'>Microsoft Threat Analysis and Modeing v 2.1 was just released. &lt;br /&gt;&lt;br /&gt;Microsoft Threat Analysis &amp; Modeling tool allows non-security subject matter experts to enter already known information including business requirements and application architecture which is then used to produce a feature-rich threat model. Along with automatically identifying threats, the tool can produce valuable security artifacts such as:&lt;br /&gt;&lt;br /&gt;- Data access control matrix&lt;br /&gt;- Component access control matrix&lt;br /&gt;- Subject-object matrix&lt;br /&gt;- Data Flow&lt;br /&gt;- Call Flow&lt;br /&gt;- Trust Flow&lt;br /&gt;- Attack Surface&lt;br /&gt;- Focused reports&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Those who are interested may download the tool from:&lt;br /&gt;&lt;br /&gt;http://www.microsoft.com/downloads/thankyou.aspx?familyId=59888078-9daf-4e96-b7d1-944703479451&amp;displayLang=en&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-116585560883266877?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/116585560883266877/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=116585560883266877' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116585560883266877'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116585560883266877'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/12/microsoft-threat-analysis-modeling-v.html' title='Microsoft Threat Analysis &amp; Modeling v 2.1'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-116525430221297449</id><published>2006-12-04T09:45:00.000-08:00</published><updated>2006-12-04T09:45:32.416-08:00</updated><title type='text'>Google Reader (100+)</title><content type='html'>&lt;a href="http://www.google.com/reader/view/"&gt;Google Reader (100+)&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-116525430221297449?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/116525430221297449/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=116525430221297449' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116525430221297449'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116525430221297449'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/12/google-reader-100.html' title='Google Reader (100+)'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-116492648568637376</id><published>2006-11-30T14:39:00.000-08:00</published><updated>2006-11-30T14:41:34.780-08:00</updated><title type='text'>PWDUMPX Encrypted Password Retrieval</title><content type='html'>Penetration testers this is for you!&lt;br /&gt;&lt;br /&gt;http://reedarvin.thearvins.com/tools.html&lt;br /&gt;&lt;br /&gt;The PWDumpX v1.0 tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.&lt;br /&gt;&lt;br /&gt;If an input list of remote systems is supplied, PWDumpX will attempt to obtain the encrypted password hashes and the LSA secrets from each remote Windows system in a multi-threaded fashion (up to 64 systems simultaneously).&lt;br /&gt;&lt;br /&gt;The encrypted password hash information and the LSA secret information from remote Windows systems is encrypted as it is transfered over the network. No data is sent over the network in clear text.&lt;br /&gt;&lt;br /&gt;This tool is a completely re-written version of PWDump3e and LSADump2 which integrates suggestions/bug fixes for PWDump3e and LSADump2 found on various web sites, etc.&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-116492648568637376?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/116492648568637376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=116492648568637376' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116492648568637376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116492648568637376'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/11/pwdumpx-encrypted-password-retrieval.html' title='PWDUMPX Encrypted Password Retrieval'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-116473802805763635</id><published>2006-11-28T10:16:00.000-08:00</published><updated>2006-11-28T10:21:15.006-08:00</updated><title type='text'>Web Application Security Professionals Survey</title><content type='html'>Here is an interesting survey conducted by Jerremiah Grossman of Whitehat Security.&lt;br /&gt;&lt;br /&gt;http://jeremiahgrossman.blogspot.com/2006/11/web-application-security-professionals.html&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-116473802805763635?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/116473802805763635/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=116473802805763635' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116473802805763635'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/116473802805763635'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/11/web-application-security-professionals.html' title='Web Application Security Professionals Survey'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-115075894221816164</id><published>2006-06-19T16:14:00.000-07:00</published><updated>2006-06-19T16:15:42.680-07:00</updated><title type='text'>AJAX Security Basics</title><content type='html'>Here is a great Ajax Security article which was posted on securityfocus.com.&lt;br /&gt;&lt;br /&gt;&lt;a class="menu_template1" href="http://www.securityfocus.com/infocus/1868"&gt;http://www.securityfocus.com/infocus/1868&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-115075894221816164?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/115075894221816164/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=115075894221816164' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/115075894221816164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/115075894221816164'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/06/ajax-security-basics.html' title='AJAX Security Basics'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-114670153949129124</id><published>2006-05-03T17:07:00.000-07:00</published><updated>2006-05-03T17:12:19.903-07:00</updated><title type='text'>Effective Security Enables Powerful decisions</title><content type='html'>&lt;strong&gt;Effective Security enables Powerful decisions.&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Information is NOT Power. Timely access to accurate information can give the holder the ability to make powerful decisions.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;Effective Information Technology can enable the required flow of information. Inappropriate Information Security Policies, Processes, application of controls and lack of awareness can stifle Effective Information Technology. Effective Security is the corollary of this position as it's proactive and encompasses every aspect of information flow throughout an organization together with customer’s partners and suppliers.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Avoiding risk is not an option for today’s users of technology. Measuring risk and mitigating threats to a point that you are comfortable with leads to Effective Security. Everyone (and every business) has a different perception and appetite for risk. Many use risk taking as a fundamental competitive advantage.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Effective Security can facilitate Effective Information Technology thereby enabling businesses and individuals to realize their potential - doing more with less risk.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;----------------------------------------------------------------------------------------&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Obtained from Steve Lambs' blog &lt;/span&gt;&lt;a href="http://www.blogger.com/post-create.g?blogID=14492286"&gt;&lt;span style="font-size:85%;"&gt;http://www.blogger.com/post-create.g?blogID=14492286&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-114670153949129124?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/114670153949129124/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=114670153949129124' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/114670153949129124'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/114670153949129124'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/05/effective-security-enables-powerful.html' title='Effective Security Enables Powerful decisions'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-114669236274523961</id><published>2006-05-03T14:33:00.000-07:00</published><updated>2006-05-03T14:39:51.256-07:00</updated><title type='text'>10 Security Risks to Live By</title><content type='html'>&lt;div align="left"&gt;&lt;span style="font-size:85%;"&gt;1. Security is not black and white.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;2: The road to least privilege is a long one.&lt;br /&gt;&lt;br /&gt;3: Sacrificing security for compatibility is a bad idea&lt;br /&gt;&lt;br /&gt;4: Using the Windows Power Users group is never an answer to least privilege.&lt;br /&gt;&lt;br /&gt;5: Your enterprise is only as secure as your most- and least-technical users.&lt;br /&gt;&lt;br /&gt;6: "Not knowing" is often your biggest exposure point.&lt;br /&gt;&lt;br /&gt;7: If you trust a single piece of security technology to do everything, you’re making a big mistake.&lt;br /&gt;&lt;br /&gt;8: Any vendor who claims "100% security" is probably lying to you.&lt;br /&gt;&lt;br /&gt;9: Not deploying updates is expensive.&lt;br /&gt;&lt;br /&gt;10: The next big thing probably won’t do it all.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Be prepared. Be proactive. Be secure.&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The excerpts of this article was obtained from the May volume of Microsoft Technet Magazine. The full article can be viewed at &lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;a href="http://www.microsoft.com/technet/technetmag/issues/2006/05/ReduceRisk/default.aspx"&gt;http://www.microsoft.com/technet/technetmag/issues/2006/05/ReduceRisk/default.aspx&lt;/a&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-114669236274523961?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/114669236274523961/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=114669236274523961' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/114669236274523961'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/114669236274523961'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/05/10-security-risks-to-live-by.html' title='10 Security Risks to Live By'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-114669151638404249</id><published>2006-05-03T14:19:00.000-07:00</published><updated>2006-05-03T14:31:38.103-07:00</updated><title type='text'>Tips for Security Active Directory</title><content type='html'>1. Document What You Have&lt;br /&gt;2. Control Your Administration&lt;br /&gt;3. Limit the Number of Administrators&lt;br /&gt;4. Test Group Policy Settings&lt;br /&gt;5. Use Separate Administrative Accounts&lt;br /&gt;6. Restrict Elevated Built-In Groups&lt;br /&gt;7. Use a Dedicated Terminal Server for Administration&lt;br /&gt;8. Disable Guest and Rename Administrator&lt;br /&gt;9. Limit Access to the Administrator Account&lt;br /&gt;10. Watch the DSRM Password&lt;br /&gt;11. Enforce Strong Password Rules&lt;br /&gt;12. Protect the Service Account’s Password&lt;br /&gt;13. Make Sure that Each DC is Physically Secure&lt;br /&gt;14. Minimize Unnecessary Services and Open Ports&lt;br /&gt;15. Make the DC Time Source Secure&lt;br /&gt;16. Audit Important Events&lt;br /&gt;17. Use IPsec&lt;br /&gt;18. Don’t Store LAN Manager Hash Values&lt;br /&gt;19. Don’t Forget Your Business Practices&lt;br /&gt;&lt;br /&gt;This was obtained from May volume of Microsoft Technet Magazine. The full article can be obtained by visiting&lt;br /&gt;&lt;br /&gt;http://www.microsoft.com/technet/technetmag/issues/2006/05/SmartTips/default.aspx&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-114669151638404249?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/114669151638404249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=114669151638404249' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/114669151638404249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/114669151638404249'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/05/tips-for-security-active-directory.html' title='Tips for Security Active Directory'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-113838358393728951</id><published>2006-01-27T09:34:00.000-08:00</published><updated>2006-01-27T09:39:44.223-08:00</updated><title type='text'>Overview: Application Security Testing Procedures</title><content type='html'>* Understanding the product and its architecture        &lt;br /&gt; * Identifying possible attack vectors&lt;br /&gt; * Preparation of test cases&lt;br /&gt; * Vulnerability Research &amp; Discovery&lt;br /&gt; * Exploitation of vulnerabilities found&lt;br /&gt; * Compilation of final security testing report&lt;br /&gt; * Final discussions of bug findings and fixes&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-113838358393728951?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/113838358393728951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=113838358393728951' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113838358393728951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113838358393728951'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/01/overview-application-security-testing.html' title='Overview: Application Security Testing Procedures'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-113769904842449303</id><published>2006-01-19T11:29:00.000-08:00</published><updated>2006-01-19T11:31:38.306-08:00</updated><title type='text'>FBI: 2005 Computer Crime Survey</title><content type='html'>The FBI has published their 2005 computer crime survey, with responses from over 2,000 public and private organizations located across four U.S. states.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.fbi.gov/publications/ccs2005.pdf"&gt;http://www.fbi.gov/publications/ccs2005.pdf&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-113769904842449303?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/113769904842449303/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=113769904842449303' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113769904842449303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113769904842449303'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/01/fbi-2005-computer-crime-survey.html' title='FBI: 2005 Computer Crime Survey'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-113760309222911357</id><published>2006-01-18T08:51:00.000-08:00</published><updated>2006-01-18T08:52:20.173-08:00</updated><title type='text'>5 Mistakes of Vulnerability Management</title><content type='html'>1. Scanning but failing to act on results&lt;br /&gt;&lt;br /&gt;2. Thinking that patching is the same as vulnerability management&lt;br /&gt;&lt;br /&gt;3. Believing that vulnerability management is only a technical problem&lt;br /&gt;&lt;br /&gt;4. Assessing a vulnerability without looking at the whole picture&lt;br /&gt;&lt;br /&gt;5. Not believing in Zero day vulnerabilities.&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-113760309222911357?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/113760309222911357/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=113760309222911357' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113760309222911357'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113760309222911357'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/01/5-mistakes-of-vulnerability-management_18.html' title='5 Mistakes of Vulnerability Management'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-113752188319925818</id><published>2006-01-17T10:08:00.000-08:00</published><updated>2006-01-17T10:44:05.823-08:00</updated><title type='text'>Secure Anonymous Browsing Made Simple</title><content type='html'>Anonym.OS is an OpenBSD 3.8 Live CD with strong tools for anonymizing and encrypting connections. Standard network applications are provided and configured to take advantage of the tor &lt;strong&gt;onion &lt;/strong&gt;routing network.&lt;br /&gt;&lt;br /&gt;Onion Routing is a technique for pseudonymous (or anonymous) communication over a computer network, developed by David Goldschlag, Michael Reed, and Paul Syverson. It is based on David Chaum's Mix networks, though it includes a number of advances and modifications. Among these modifications is the concept of "routing onions", which encode routing information in a set of encrypted layers. &lt;br /&gt;&lt;br /&gt;AnonymOS is based on &lt;strong&gt;Tor&lt;/strong&gt;. Tor is a toolset for a wide range of organizations and people that want to improve their safety and security on the Internet. Using Tor can help you anonymize web browsing and publishing, instant messaging, IRC, SSH, and other applications that use the TCP protocol. Tor also provides a platform on which software developers can build new applications with built-in anonymity, safety, and privacy features.&lt;br /&gt;&lt;br /&gt;To download AnonymOS and browse anonymously and security visit kaos theory security project website:  &lt;a href="http://theory.kaos.to/home.html"&gt;http://theory.kaos.to/home.html&lt;/a&gt;"&lt;br /&gt;&lt;br /&gt;In summary, as wired indicated in their article &lt;a href="http://www.wired.com/news/technology/internet/0,70017-0.html?tw=wn_tophead_1"&gt;Anonymity on a Disk&lt;/a&gt;Anonym.OS is so easy to use, that you can hand it to your grandmother and send her off on her own to the local Starbucks.&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-113752188319925818?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/113752188319925818/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=113752188319925818' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113752188319925818'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113752188319925818'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2006/01/secure-anonymous-browsing-made-simple.html' title='Secure Anonymous Browsing Made Simple'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-113200663647085476</id><published>2005-11-14T14:15:00.000-08:00</published><updated>2005-11-14T14:18:41.680-08:00</updated><title type='text'>ISO 27001 Officially Published</title><content type='html'>Information security is a complex area, demanding standards to address specific aspects. These are currently addressed by ISO 17799 and the emerging ISO 27001.&lt;br /&gt;&lt;br /&gt;ISO 17799 is a code of practice for information security. It details hundreds of specific controls which may be applied to secure information and related assets. It comprises 115 pages organized over 15 major sections.&lt;br /&gt;&lt;br /&gt;ISO 27001 is a specification for an Information Security Management System, sometimes abbreviated to ISMS. It is the foundation for third party audit and certification. It comprises 34 pages over 8 major sections.&lt;br /&gt;&lt;br /&gt;Both standards are intended to apply to all organizations, whether commercial or otherwise, and should assist anyone with responsibility for managing information security&lt;br /&gt;&lt;br /&gt;&lt;a href="http://17799.standardsdirect.org/"&gt;http://17799.standardsdirect.org/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-113200663647085476?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/113200663647085476/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=113200663647085476' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113200663647085476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113200663647085476'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/11/iso-27001-officially-published.html' title='ISO 27001 Officially Published'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-113200650752929680</id><published>2005-11-14T14:14:00.000-08:00</published><updated>2005-11-14T14:15:07.636-08:00</updated><title type='text'>Web Application Evaluation Criteria Released</title><content type='html'>Web Application Evaluation Criteria has been released by OWASP and may be downloaded from here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.webappsec.org/projects/waf_evaluation/v1/wafec-draft-1-20051007.pdf"&gt;http://www.webappsec.org/projects/waf_evaluation/v1/wafec-draft-1-20051007.pdf&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-113200650752929680?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/113200650752929680/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=113200650752929680' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113200650752929680'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113200650752929680'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/11/web-application-evaluation-criteria.html' title='Web Application Evaluation Criteria Released'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-113200619656710754</id><published>2005-11-14T14:08:00.000-08:00</published><updated>2005-11-14T14:13:02.376-08:00</updated><title type='text'>List of Common Web Application Problems</title><content type='html'>1. Brute Force Attacks&lt;br /&gt;2. Insufficient Authentication&lt;br /&gt;3. Insufficient Authorisation&lt;br /&gt;4. Weak Password Recovery Validation&lt;br /&gt;5. Credential/Session Prediction&lt;br /&gt;6. Insufficient Session Expiration&lt;br /&gt;7. Session Fixation&lt;br /&gt;8. Content Spoofing / Cross-Site Scripting&lt;br /&gt;9. Command Execution / Buffer Overflow / OS Commanding / Format String Attack&lt;br /&gt;10. LDAP Injection / SQL Injection&lt;br /&gt;11. SSI Injection&lt;br /&gt;12. XPath Injection&lt;br /&gt;13. Directory Indexing&lt;br /&gt;14. Information Leakage&lt;br /&gt;15. Path Traversal&lt;br /&gt;16. Predictable Resource Location&lt;br /&gt;17. Abuse of Functionality&lt;br /&gt;18. Denial of Service&lt;br /&gt;19. Insufficient Anti-Automation&lt;br /&gt;20. Insufficient Process Validation&lt;br /&gt;21. NTLM Authentication Connection Sharing&lt;br /&gt;22. Insecure Indexing&lt;br /&gt;23. DOM-based XSS&lt;br /&gt;24. Cross-Site Request Forgery&lt;br /&gt;25. HTTP Response Splitting&lt;br /&gt;26. HTTP Request Smuggling&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-113200619656710754?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/113200619656710754/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=113200619656710754' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113200619656710754'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/113200619656710754'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/11/list-of-common-web-application.html' title='List of Common Web Application Problems'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112896742752475420</id><published>2005-10-10T11:02:00.000-07:00</published><updated>2005-10-10T11:03:47.530-07:00</updated><title type='text'>Aligning IT Security with Business Goals</title><content type='html'>Here is a great article from SOX Journal on how to align IT Security with Business Goals.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.s-ox.com/Feature/detail.cfm?ArticleID=1070"&gt;http://www.s-ox.com/Feature/detail.cfm?ArticleID=1070&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112896742752475420?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112896742752475420/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112896742752475420' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112896742752475420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112896742752475420'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/10/aligning-it-security-with-business.html' title='Aligning IT Security with Business Goals'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112715095368508502</id><published>2005-09-19T10:12:00.000-07:00</published><updated>2005-09-19T10:33:09.836-07:00</updated><title type='text'>Eight Best Preactices For User Acess Security</title><content type='html'>• Implement automatic PC session locking.&lt;br /&gt;• Implement login failure lockout.&lt;br /&gt;• Implement strong authentication.&lt;br /&gt;&lt;br /&gt;• Limit and monitor user sessions for any given identity.&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;• Provide users with the time of their last login and teach them to review it and recognize the signs of a compromise.&lt;br /&gt;&lt;br /&gt;• Ensure the "principle of least privilege."&lt;br /&gt;• Ensure that obsolete accounts are removed or disabled.&lt;br /&gt;• Control hostile code.&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112715095368508502?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112715095368508502/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112715095368508502' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112715095368508502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112715095368508502'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/09/eight-best-preactices-for-user-acess.html' title='Eight Best Preactices For User Acess Security'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112650797885495040</id><published>2005-09-11T23:50:00.000-07:00</published><updated>2005-09-11T23:52:58.860-07:00</updated><title type='text'>How To Get Your Network Hacked in 10 Easy Steps.</title><content type='html'>1. Run unhardened applications&lt;br /&gt;2. Log on everywhere as a domain admin&lt;br /&gt;3. Open lots of holes in the firewall&lt;br /&gt;4. Allow unrestricted internal traffic&lt;br /&gt;5. Allow all outbound traffic&lt;br /&gt;6. Don't harden servers&lt;br /&gt;7. Use lame passwords&lt;br /&gt;8. Use high level service accounts, in multiple places&lt;br /&gt;9. Assume everything is OK&lt;br /&gt;10. Don't patch anything.&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112650797885495040?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112650797885495040/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112650797885495040' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112650797885495040'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112650797885495040'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/09/how-to-get-your-network-hacked-in-10.html' title='How To Get Your Network Hacked in 10 Easy Steps.'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112412796199656343</id><published>2005-08-15T10:42:00.000-07:00</published><updated>2005-08-15T10:46:02.003-07:00</updated><title type='text'>Common Vulnerability Scoring System v1.0</title><content type='html'>&lt;span style="font-size:85%;"&gt;To date, a number of commercial computer security vendors and not-for-profit organizations have developed, promoted, and implemented systems to rank information system vulnerabilities. Unfortunately, there is no cohesion or interoperability among those systems and they are limited in scope as to what they cover. This document proposes an open and universal vulnerability scoring system to address and solve these shortcomings, with the ultimate goal of promoting a common language to discuss vulnerability severity and impact.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt; &lt;a href="http://www.first.org/cvss/cvss-guide.html"&gt;&lt;span style="font-size:85%;"&gt;http://www.first.org/cvss/cvss-guide.html&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112412796199656343?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112412796199656343/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112412796199656343' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112412796199656343'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112412796199656343'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/08/common-vulnerability-scoring-system.html' title='Common Vulnerability Scoring System v1.0'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112412246183543390</id><published>2005-08-15T09:10:00.000-07:00</published><updated>2005-08-15T09:14:21.836-07:00</updated><title type='text'>Checklist for Securing Your Wireless Networks</title><content type='html'>&lt;p&gt;&lt;span style="font-size:85%;"&gt;Change the default SSID for each wireless network access point device.&lt;br /&gt;&lt;br /&gt;Disable automatic SSID broadcast.&lt;br /&gt;&lt;br /&gt;Turn on WEP encryption.&lt;br /&gt;&lt;br /&gt;Research upgrading your wireless network encryption to WPA/TKIP.&lt;br /&gt;&lt;br /&gt;Filter the MAC address of your network card.&lt;br /&gt;&lt;br /&gt;Change all default user names and passwords for new network access devices.&lt;br /&gt;&lt;br /&gt;Change the default IP subnet that your wireless router is preset to (192.168.1.0).&lt;br /&gt;&lt;br /&gt;Disable DHCP IP address generation.&lt;br /&gt;&lt;br /&gt;Implement firewall protection between the wireless network and other networks and between the wireless network and the internet&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112412246183543390?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112412246183543390/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112412246183543390' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112412246183543390'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112412246183543390'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/08/checklist-for-securing-your-wireless.html' title='Checklist for Securing Your Wireless Networks'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112412188552980594</id><published>2005-08-15T08:44:00.000-07:00</published><updated>2005-08-15T09:04:45.536-07:00</updated><title type='text'>Top 5 Tools for Every Security Admin</title><content type='html'>Security administrators whose  intents are  to secure their organization's network(s) should have these 5 tools in their tool box which are also used by well known hackers.&lt;br /&gt;&lt;br /&gt; &lt;strong&gt;Nessus&lt;/strong&gt; &lt;span style="font-size:85%;"&gt;is the world's most popular open-source vulnerability scanner used in over 75,000 organizations world-wide. &lt;/span&gt;&lt;a href="http://www.nessus.org"&gt;&lt;span style="font-size:85%;"&gt;http://www.nessus.org&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt; Nmap &lt;/strong&gt;&lt;span style="font-size:85%;"&gt;is a free open source utility for network exploration or security auditing. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics. Nmap runs on most types of computers and both console and graphical versions are available. &lt;a href="http://www.insecure.org"&gt;http://www.insecure.org&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;NetStumbler&lt;/strong&gt; &lt;span style="font-size:85%;"&gt;is a tools for windows that allows you to to detect Wireless&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Local Area Networks (WLANs) using 802.11b and 802.11g.&lt;strong&gt;  &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;&lt;a href="http://www.netstumbler.com/downloads"&gt;http://www.netstumbler.com/downloads&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;NetView&lt;/strong&gt; &lt;span style="font-size:85%;"&gt;is a suite of three security tools for the system administrator or home user. NetView scans IP addresses for available Windows File &amp; Print Sharing resources, PortScan scans IP addresses for listening TCP ports, and WebBrute scans web directories that are protected with HTTP authentication, testing the strength of the users' passwords. This suite is freeware penetration analysis software that will run on your Windows workstation. &lt;/span&gt;&lt;span style="font-size:85%;"&gt;http://www.rawlogic.com/netview. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;Winhex&lt;/strong&gt; &lt;span style="font-size:85%;"&gt;is a universal hexadecimal editor, particularly helpful in the realm of &lt;/span&gt;&lt;span style="font-size:85%;"&gt;computer forensics&lt;/span&gt;&lt;span style="font-size:85%;"&gt;, &lt;/span&gt;&lt;span style="font-size:85%;"&gt;data rocovery&lt;/span&gt;&lt;span style="font-size:85%;"&gt;, low-level data processing, and IT security. An advanced tool for everyday and emergency use: inspect and edit all kinds of files, recover deleted files or lost data from hard drives with corrupt file systems or from digital camera &lt;/span&gt;&lt;span style="font-size:85%;"&gt;cards. &lt;a href="http://www.x-ways.net/winhex/index-m.html"&gt;http://www.x-ways.net/winhex/index-m.html&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112412188552980594?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112412188552980594/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112412188552980594' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112412188552980594'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112412188552980594'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/08/top-5-tools-for-every-security-admin.html' title='Top 5 Tools for Every Security Admin'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112362261295121743</id><published>2005-08-09T14:19:00.000-07:00</published><updated>2005-08-09T14:23:32.956-07:00</updated><title type='text'>August 2005 Critical Microsoft Vulnerabilities</title><content type='html'>Critical Vulnerabilities&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:85%;"&gt;Microsoft Security Bulletin MS05-038&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=45781"&gt;Cumulative Security Update for Internet Explorer (896727)&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Vulnerabilities exist in Internet Explorer, the most severe of these could allow an attacker to take complete control of an affected system.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;strong&gt;Microsoft Security Bulletin MS05-039&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=48900"&gt;Vulnerability in Plug and Play Could Allow Remote Code Execution and Elevation of Privilege (899588)&lt;/a&gt;&lt;br /&gt;A remote code execution vulnerability exists in Plug and Play (PnP) that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Microsoft Security Bulletin MS05-043&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=48902"&gt;Vulnerability in Print Spooler Service Could Allow Remote Code Execution (896423)&lt;/a&gt;&lt;br /&gt;A vulnerability exists in the Print Spooler service that could allow remote code execution&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112362261295121743?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112362261295121743/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112362261295121743' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112362261295121743'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112362261295121743'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/08/august-2005-critical-microsoft.html' title='August 2005 Critical Microsoft Vulnerabilities'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112309178425675274</id><published>2005-08-03T10:48:00.000-07:00</published><updated>2005-08-03T10:56:24.263-07:00</updated><title type='text'>New Domain Foot Printing Tool</title><content type='html'>&lt;p&gt;&lt;span style="font-size:85%;"&gt;SpiderFoot is a free, open-source, domain foot-printing tool. Given one or multiple domain names. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;It will scrape the websites on that domain, as well as search Google, Netcraft, Whois and DNS to build up &lt;/span&gt;&lt;span style="font-size:85%;"&gt;information like:  &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:85%;"&gt;                                    Subdomains &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;                                    Affiliates &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;                                    Web server versions &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;                                    Users (i.e. /~user) &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;                                    Similar domains &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;                                    Email addresses &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;                                    Netblocks&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;hr /&gt;&lt;br /&gt;&lt;div align="left"&gt;&lt;/hr&gt;&lt;strong&gt;&lt;span style="font-size:85%;"&gt;Project Homepage&lt;/span&gt;&lt;/strong&gt;: &lt;a href="http://www.binarypool.com/spiderfoot/"&gt;http://www.binarypool.com/spiderfoot/&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;To download the tool please visit&lt;/strong&gt;:&lt;/span&gt; &lt;a href="http://prdownloads.sourceforge.net/spiderfoot/SpiderFoot-0.01b.zip?download"&gt;http://prdownloads.sourceforge.net/spiderfoot/SpiderFoot-0.01b.zip?downloa&lt;span style="color:#000000;"&gt;d&lt;/span&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112309178425675274?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112309178425675274/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112309178425675274' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112309178425675274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112309178425675274'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/08/new-domain-foot-printing-tool.html' title='New Domain Foot Printing Tool'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112293007089993650</id><published>2005-08-01T14:00:00.000-07:00</published><updated>2005-08-01T16:18:10.010-07:00</updated><title type='text'>Major Categories of Web Application Security</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Network Security&lt;/strong&gt; Assessment: Conducting Passive and/or Active assessment using open source and commerical tools such as Nessus, Retina, Qualys to find network based vulnerabilities.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;"Black-box" testing:&lt;/strong&gt; Black Box penetration involves the security of your application(s) or network(s)without any ‘insider’ knowledge of your organization.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;"&lt;strong&gt;White-box" testing:&lt;/strong&gt; Performing testing with inside knowledge of the target.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Code Scanning: &lt;/strong&gt;Scanning raw source code looking for weaknesses which may lead to potential applicaiton vulnerabilities. This process should be implimented within (SDLC) software development life cycle.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Binary Scanning:&lt;/strong&gt; Same concept of code scanning, except using Manual and Automated tools to find vulenrabilities within compiled applications.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Database Security Assessment:&lt;/strong&gt; Identifying potential security exposures in database via Manual and Automated tools such as WebScarab, Achilles, Acunetix Web Application Scanner etc.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Web Services Security Assessment: &lt;/strong&gt;Web services are programatic interfaces for application to application communication. An important characteristic of web services is that the interaction will be instantaneous, since interaction will be more from application to application rather than from humans to applications. Web Services Security Assessment is ensuring all web services which are combined to interact together, interact in secure fashion.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;strong&gt;Security Information Management Systems (SIMS):&lt;/strong&gt; Mechanism of collecting event log data from security devices and helping users make sense of it through a common management console. SIM tools generally consist of server software, agents installed either on servers or security devices, and a central management console.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112293007089993650?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112293007089993650/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112293007089993650' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112293007089993650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112293007089993650'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/08/major-categories-of-web-application.html' title='Major Categories of Web Application Security'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112292869628570755</id><published>2005-08-01T13:35:00.000-07:00</published><updated>2005-08-01T13:38:16.290-07:00</updated><title type='text'>Intorudction to TCP Wrappers</title><content type='html'>&lt;span style="font-size:85%;"&gt;TCP Wrappers works by interposing an additional layer, or wrapper, between client and server. This article looks at how this package can be used to enhance the security of a networking system.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://lue.dyn.dhs.org/2005/20050726164809.html"&gt;&lt;span style="font-size:85%;"&gt;http://lue.dyn.dhs.org/2005/20050726164809.html&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112292869628570755?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112292869628570755/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112292869628570755' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112292869628570755'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112292869628570755'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/08/intorudction-to-tcp-wrappers.html' title='Intorudction to TCP Wrappers'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112292780789505714</id><published>2005-08-01T13:21:00.000-07:00</published><updated>2005-08-01T13:23:27.900-07:00</updated><title type='text'>TRIKE - A CONCEPTUAL FRAMEWORK FOR THREAT MODELING</title><content type='html'>Trike is a unified conceptual framework for security auditing from a&lt;br /&gt;risk management perspective through the generation of threat models&lt;br /&gt;in a reliable, repeatable manner. A security auditing team can use it&lt;br /&gt;to completely and accurately describe the security characteristics of&lt;br /&gt;a system from its highlevel architecture to its low-level&lt;br /&gt;implementation details.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.net-security.org/dl/articles/Trike_v1_Methodology_Document-draft.pdf"&gt;http://www.net-security.org/dl/articles/Trike_v1_Methodology_Document-draft.pdf&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112292780789505714?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112292780789505714/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112292780789505714' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112292780789505714'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112292780789505714'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/08/trike-conceptual-framework-for-threat.html' title='TRIKE - A CONCEPTUAL FRAMEWORK FOR THREAT MODELING'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112291802726631594</id><published>2005-08-01T10:18:00.000-07:00</published><updated>2005-08-01T11:08:52.173-07:00</updated><title type='text'>Minimum Security Requirements For  Federal Information Systems</title><content type='html'>NIST have put a draft paper on minimum security requirements for federal information systems. You may find the PDF version of the document on the NIST site: &lt;a href="http://www.csrc.nist.gov/publications/drafts/FIPS-200-ipd-07-13-2005.pdf"&gt;http://www.csrc.nist.gov/publications/drafts/FIPS-200-ipd-07-13-2005.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"Specifications for Minimum Security Requirements", is probably the most useful portion of the document starting on page 2. The document covers 17 areas of importance to Information Security, ranging from (AC) Access Control to (SI) System and Information Integrity.&lt;br /&gt;&lt;br /&gt;Definately is worth to take a look at.&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112291802726631594?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112291802726631594/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112291802726631594' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112291802726631594'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112291802726631594'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/08/minimum-security-requirements-for.html' title='Minimum Security Requirements For  Federal Information Systems'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112137916335389438</id><published>2005-07-14T15:08:00.000-07:00</published><updated>2005-07-14T15:12:43.363-07:00</updated><title type='text'>Free Fault Injection Test Tools</title><content type='html'>&lt;span style="font-family:times new roman;font-size:85%;"&gt;WebScarab (HTTPush, Exodus)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;Paros Proxy&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;Burp Spider&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;Burp Proxy&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;SPIKE Proxy&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;SPIKE&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;Achilles Proxy&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;Odysseus Proxy&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;Webstretch Proxy&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;Absinthe &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;NGS SQL Injection Inference Tool &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;Sensepost Wikto (Google cached fault-finding)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;Foundstone Sitedigger (Google cached fault-finding)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:85%;"&gt;Athena (SnakeLabs)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112137916335389438?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112137916335389438/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112137916335389438' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112137916335389438'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112137916335389438'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/07/free-fault-injection-test-tools.html' title='Free Fault Injection Test Tools'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14492286.post-112136685512462082</id><published>2005-07-14T11:39:00.000-07:00</published><updated>2005-07-14T11:50:39.693-07:00</updated><title type='text'>Web Application Security Resources</title><content type='html'>&lt;span style="font-family:arial;font-size:85%;"&gt;General Application Security Documentation:&lt;/span&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.cgisecurity.com/lib/" target="_blank"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.cgisecurity.com/lib/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;SQL Injection:&lt;/span&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.cgisecurity.com/development/sql.shtml" target="_blank"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.cgisecurity.com/development/sql.shtml&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;Cross Site Scripting:&lt;/span&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.cgisecurity.com/development/xss.shtml" target="_blank"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.cgisecurity.com/development/xss.shtml&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;Web Services:&lt;/span&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.cgisecurity.com/ws/" target="_blank"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.cgisecurity.com/ws/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;AJAX:&lt;/span&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.cgisecurity.com/ajax/" target="_blank"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.cgisecurity.com/ajax/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;Web Server Security:&lt;/span&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.cgisecurity.com/webservers/" target="_blank"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.cgisecurity.com/webservers/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;Web Application Server Security:&lt;/span&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.cgisecurity.com/appservers/" target="_blank"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.cgisecurity.com/appservers/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;Database Security:&lt;/span&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.cgisecurity.com/database/" target="_blank"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.cgisecurity.com/database/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;OWASP:&lt;/span&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.owasp.org" target="_blank"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.owasp.org&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;SQL Server Security:&lt;/span&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.sqlsecurity.com" target="_blank"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.sqlsecurity.com&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;The Web Application Security Consortium Threat Classifications:&lt;/span&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.webappsec.org/projects/threat/" target="_blank"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.webappsec.org/projects/threat/&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;link rel="service.feed" type="application/atom+xml" title="Atom" href="http://dotsecure.blogspot.com/atom.xml" /&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14492286-112136685512462082?l=dotsecure.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dotsecure.blogspot.com/feeds/112136685512462082/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14492286&amp;postID=112136685512462082' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112136685512462082'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14492286/posts/default/112136685512462082'/><link rel='alternate' type='text/html' href='http://dotsecure.blogspot.com/2005/07/web-application-security-resources.html' title='Web Application Security Resources'/><author><name>Martin M</name><uri>http://www.blogger.com/profile/08322260527723479995</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
