<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Insecure Web</title>
	
	<link>http://insecureweb.com</link>
	<description>Insight into web application security</description>
	<lastBuildDate>Wed, 27 May 2009 15:39:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/InsecureWeb" /><feedburner:info uri="insecureweb" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Facebook Phishing site: fbstarter.com</title>
		<link>http://feedproxy.google.com/~r/InsecureWeb/~3/i3LBu1vigk8/</link>
		<comments>http://insecureweb.com/web-security/social-engineering/facebook-phishing-site-fbstartercom/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 16:49:30 +0000</pubDate>
		<dc:creator>Mauvis Ledford</dc:creator>
				<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[facebook]]></category>

		<guid isPermaLink="false">http://insecureweb.com/?p=104</guid>
		<description>I got a Facebook mail from a friend today titled &amp;#8220;Look at this!&amp;#8221; with a link to fbstarter.com.
The site itself, looks just like FaceBook (even the code view and CSS &amp;#8211; screenshot here) &amp;#8211; but the site itself didn&amp;#8217;t seem to offer much except for a login. I put in dummy information and was redirected [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=i3LBu1vigk8:85AGMxo7aiY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=i3LBu1vigk8:85AGMxo7aiY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?i=i3LBu1vigk8:85AGMxo7aiY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=i3LBu1vigk8:85AGMxo7aiY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=i3LBu1vigk8:85AGMxo7aiY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?i=i3LBu1vigk8:85AGMxo7aiY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=i3LBu1vigk8:85AGMxo7aiY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=i3LBu1vigk8:85AGMxo7aiY:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=i3LBu1vigk8:85AGMxo7aiY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?i=i3LBu1vigk8:85AGMxo7aiY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsecureWeb/~4/i3LBu1vigk8" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://insecureweb.com/web-security/social-engineering/facebook-phishing-site-fbstartercom/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://insecureweb.com/web-security/social-engineering/facebook-phishing-site-fbstartercom/</feedburner:origLink></item>
		<item>
		<title>XSS exploits in 8 of AOL’s properties including Engadget, TUAW, and Social Thing enabled sites</title>
		<link>http://feedproxy.google.com/~r/InsecureWeb/~3/ESXUXJTJiEw/</link>
		<comments>http://insecureweb.com/javascript/xss-exploits-in-8-of-aols-properties-including-engadget-tuaw-and-social-thing-enabled-sites/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 15:00:55 +0000</pubDate>
		<dc:creator>Mauvis Ledford</dc:creator>
				<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://insecureweb.com/?p=91</guid>
		<description>Update 05-27-2009: A web developer at AOL is investigating these issues and in the meantime this post has been temporary disabled. It&amp;#8217;ll return for educational purposes when the issues are resolved.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=ESXUXJTJiEw:SR6ARD2jaVc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=ESXUXJTJiEw:SR6ARD2jaVc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?i=ESXUXJTJiEw:SR6ARD2jaVc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=ESXUXJTJiEw:SR6ARD2jaVc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=ESXUXJTJiEw:SR6ARD2jaVc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?i=ESXUXJTJiEw:SR6ARD2jaVc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=ESXUXJTJiEw:SR6ARD2jaVc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=ESXUXJTJiEw:SR6ARD2jaVc:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=ESXUXJTJiEw:SR6ARD2jaVc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?i=ESXUXJTJiEw:SR6ARD2jaVc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsecureWeb/~4/ESXUXJTJiEw" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://insecureweb.com/javascript/xss-exploits-in-8-of-aols-properties-including-engadget-tuaw-and-social-thing-enabled-sites/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://insecureweb.com/javascript/xss-exploits-in-8-of-aols-properties-including-engadget-tuaw-and-social-thing-enabled-sites/</feedburner:origLink></item>
		<item>
		<title>Protected: XSS exploits in 8 of AOL’s properties including Engadget, TUAW, and Social Thing enabled sites</title>
		<link>http://feedproxy.google.com/~r/InsecureWeb/~3/pbjYqMkirWc/</link>
		<comments>http://insecureweb.com/javascript/xss-exploits-in-8-of-aol%e2%80%99s-properties-including-engadget-tuaw-and-social-thing-enabled-sites/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 15:00:28 +0000</pubDate>
		<dc:creator>Mauvis Ledford</dc:creator>
				<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://insecureweb.com/?p=124</guid>
		<description>There is no excerpt because this is a protected post.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=pbjYqMkirWc:mLImYXBqUW8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=pbjYqMkirWc:mLImYXBqUW8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?i=pbjYqMkirWc:mLImYXBqUW8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=pbjYqMkirWc:mLImYXBqUW8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=pbjYqMkirWc:mLImYXBqUW8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?i=pbjYqMkirWc:mLImYXBqUW8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=pbjYqMkirWc:mLImYXBqUW8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=pbjYqMkirWc:mLImYXBqUW8:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InsecureWeb?a=pbjYqMkirWc:mLImYXBqUW8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InsecureWeb?i=pbjYqMkirWc:mLImYXBqUW8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsecureWeb/~4/pbjYqMkirWc" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://insecureweb.com/javascript/xss-exploits-in-8-of-aol%e2%80%99s-properties-including-engadget-tuaw-and-social-thing-enabled-sites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://insecureweb.com/javascript/xss-exploits-in-8-of-aol%e2%80%99s-properties-including-engadget-tuaw-and-social-thing-enabled-sites/</feedburner:origLink></item>
		<item>
		<title>Secure yourself from the recent PDF exploits by disabling JavaScript</title>
		<link>http://feedproxy.google.com/~r/InsecureWeb/~3/DRVTlQsbiCU/</link>
		<comments>http://insecureweb.com/javascript/secure-yourselffrom-the-recent-pdf-exploits-by-disabling-javascript/#comments</comments>
		<pubDate>Sat, 21 Feb 2009 03:35:59 +0000</pubDate>
		<dc:creator>Bryan Migliorisi</dc:creator>
				<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Adobe]]></category>

		<guid isPermaLink="false">http://insecureweb.com/?p=85</guid>
		<description>A recent PDF exploit has been running wild across the internet for the past few days.  Not unlike many other Adobe Acrobat exploits, this one relies on the fact that Acrobat and Acrobat Reader ship with JavaScript enabled by default.  Shame on you, Adobe.
What is interesting about this exploit is that you do not even [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=93BsD2V0"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=XTUSr9kA"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=XTUSr9kA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=qYNUMXHC"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=50" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=U3JY79DM"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=U3JY79DM" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=bp2S0uJx"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=52" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=4U0EcuBm"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=54" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=9wefHPl4"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=9wefHPl4" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsecureWeb/~4/DRVTlQsbiCU" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://insecureweb.com/javascript/secure-yourselffrom-the-recent-pdf-exploits-by-disabling-javascript/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		<feedburner:origLink>http://insecureweb.com/javascript/secure-yourselffrom-the-recent-pdf-exploits-by-disabling-javascript/</feedburner:origLink></item>
		<item>
		<title>Newish web-based PDF attack in the wild (with real exploit code)</title>
		<link>http://feedproxy.google.com/~r/InsecureWeb/~3/A9ySKH8_rEs/</link>
		<comments>http://insecureweb.com/javascript/newish-web-based-pdf-attack-in-the-wild-with-real-exploit-code/#comments</comments>
		<pubDate>Fri, 20 Feb 2009 05:39:04 +0000</pubDate>
		<dc:creator>Mauvis Ledford</dc:creator>
				<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Adobe]]></category>

		<guid isPermaLink="false">http://insecureweb.com/?p=71</guid>
		<description>At work, a client recently contacted us about some random ads that were popping up on their site -  interestingly enough through Adobe Acrobat. While I&amp;#8217;m on a mac and didn&amp;#8217;t experience the popups firsthand, I did pinpoint the problem to come from a hidden iframe located on the page (The client is a news [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=OVffUqCQ"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=KE06ZPWa"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=KE06ZPWa" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=02gHdIBH"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=50" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=v1pmKPjq"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=v1pmKPjq" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=ImjZw3R3"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=52" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=668ymraR"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=54" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=b30YONOH"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=b30YONOH" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsecureWeb/~4/A9ySKH8_rEs" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://insecureweb.com/javascript/newish-web-based-pdf-attack-in-the-wild-with-real-exploit-code/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://insecureweb.com/javascript/newish-web-based-pdf-attack-in-the-wild-with-real-exploit-code/</feedburner:origLink></item>
		<item>
		<title>Password Policies</title>
		<link>http://feedproxy.google.com/~r/InsecureWeb/~3/ICIM42EiGV8/</link>
		<comments>http://insecureweb.com/passwords/password-policies/#comments</comments>
		<pubDate>Wed, 04 Feb 2009 20:46:32 +0000</pubDate>
		<dc:creator>Bryan Migliorisi</dc:creator>
				<category><![CDATA[Passwords]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://www.insecureweb.com/?p=35</guid>
		<description>Poor, or non existent, password policies are leaving too many people open to attack.  In fact, there are many companies and websites who continue to require weak and insecure passwords. Yes, they require them.
I know that my bank does this.  So does American Express and ING Direct.  Try to enter a password with special characters.  [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=2iRbbWem"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=bfV5X8n4"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=bfV5X8n4" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=ZBCNgrfE"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=50" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=NBGVkFtU"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=NBGVkFtU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=ZxsKlHNv"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=52" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=pmflqqjK"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=54" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=elTG3xtt"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=elTG3xtt" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsecureWeb/~4/ICIM42EiGV8" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://insecureweb.com/passwords/password-policies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://insecureweb.com/passwords/password-policies/</feedburner:origLink></item>
		<item>
		<title>Secure your Ajax requests: part 2</title>
		<link>http://feedproxy.google.com/~r/InsecureWeb/~3/EMjQxRKunKo/</link>
		<comments>http://insecureweb.com/web-security/secure-your-ajax-requests-part-2/#comments</comments>
		<pubDate>Fri, 19 Dec 2008 17:55:49 +0000</pubDate>
		<dc:creator>Mauvis Ledford</dc:creator>
				<category><![CDATA[Web Security]]></category>
		<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://www.insecureweb.com/?p=44</guid>
		<description>In the previous post, Bryan showed you how to prevent a JSON payload to be rendered across domains by simply adding a string of text at the beginning of the payload that either 1) invalidates it (script tags are only allowed to pull in valid JavaScript before they do anything) or 2) creates an infinite [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=oEEaUBPg"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=wUmMdgL9"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=wUmMdgL9" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=GrR02jZf"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=50" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=VtyL9EQA"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=VtyL9EQA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=RTSTD1MP"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=52" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=CtEfiRxF"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=54" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=3bUqeOmO"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=3bUqeOmO" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsecureWeb/~4/EMjQxRKunKo" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://insecureweb.com/web-security/secure-your-ajax-requests-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://insecureweb.com/web-security/secure-your-ajax-requests-part-2/</feedburner:origLink></item>
		<item>
		<title>Secure your Ajax requests with jQuery</title>
		<link>http://feedproxy.google.com/~r/InsecureWeb/~3/AD1RqbIYJMc/</link>
		<comments>http://insecureweb.com/javascript/secure-your-ajax-request-with-jquery/#comments</comments>
		<pubDate>Fri, 21 Nov 2008 20:18:00 +0000</pubDate>
		<dc:creator>Bryan Migliorisi</dc:creator>
				<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[LinkedIn]]></category>

		<guid isPermaLink="false">http://www.insecureweb.com/?p=26</guid>
		<description>Ajax requests suffer from the same Cross Site Request Forgery attack vectors as normal pages.  Many developers assume that a given ajax request will only take place on their site, and therefor skip out on the security.  Not true.
Google found out the hard way when security researcher Jeremiah Grossman uncovered a flaw in [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=IXqFR0B8"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=ppeDdU1G"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=ppeDdU1G" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=9KXUDnuM"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=50" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=qaEJ8p8R"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=qaEJ8p8R" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=Y3wCdPdK"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=52" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=pRznMK5K"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=54" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=w5nsF9cT"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=w5nsF9cT" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsecureWeb/~4/AD1RqbIYJMc" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://insecureweb.com/javascript/secure-your-ajax-request-with-jquery/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		<feedburner:origLink>http://insecureweb.com/javascript/secure-your-ajax-request-with-jquery/</feedburner:origLink></item>
		<item>
		<title>HTTP Methods: GET vs POST</title>
		<link>http://feedproxy.google.com/~r/InsecureWeb/~3/OvEQEAtfiGg/</link>
		<comments>http://insecureweb.com/web-security/http-methods-get-vs-post/#comments</comments>
		<pubDate>Fri, 21 Nov 2008 17:54:01 +0000</pubDate>
		<dc:creator>Bryan Migliorisi</dc:creator>
				<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://www.insecureweb.com/?p=22</guid>
		<description>HyperText Transfer Protocol, or HTTP, is the protocol of the web.  It is what transports data from client to server and back.  The HTTP specification defines several HTTP methods for transferring different types of data.  Most of the methods defined are used for proxys and specialty applications.  HTTP GET and POST [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=gMcnLodJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=d0WD6XjU"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=d0WD6XjU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=GNw0uaBy"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=50" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=jQSnf6mF"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=jQSnf6mF" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=qeqcEX8B"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=52" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=osLt2spE"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=54" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=MzJf06lC"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=MzJf06lC" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsecureWeb/~4/OvEQEAtfiGg" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://insecureweb.com/web-security/http-methods-get-vs-post/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		<feedburner:origLink>http://insecureweb.com/web-security/http-methods-get-vs-post/</feedburner:origLink></item>
		<item>
		<title>An Introduction to Web Application Security</title>
		<link>http://feedproxy.google.com/~r/InsecureWeb/~3/LQD_PFq0HSo/</link>
		<comments>http://insecureweb.com/web-security/an-introduction-to-web-application-security/#comments</comments>
		<pubDate>Sun, 09 Nov 2008 00:51:13 +0000</pubDate>
		<dc:creator>Bryan Migliorisi</dc:creator>
				<category><![CDATA[Web Security]]></category>
		<category><![CDATA[introduction]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://www.insecureweb.com/?p=8</guid>
		<description>When writing a web application, many times developers will focus more on features and usability than anything else  Security is often an afterthought.  Usually, security is only a concern once a vulnerability has been not only discovered, but exploited.  As developers, designers and software architects, we must ensure that the security of [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=INXof4Nf"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=I8D7u9xZ"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=I8D7u9xZ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=q4Er6LzW"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=50" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=884aVer8"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=884aVer8" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=H37tpjjx"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=52" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=Kj3i0xcY"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?d=54" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/InsecureWeb?a=jgLKC2xC"&gt;&lt;img src="http://feeds.feedburner.com/~f/InsecureWeb?i=jgLKC2xC" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InsecureWeb/~4/LQD_PFq0HSo" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://insecureweb.com/web-security/an-introduction-to-web-application-security/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://insecureweb.com/web-security/an-introduction-to-web-application-security/</feedburner:origLink></item>
	</channel>
</rss>
