<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>doBoard &#187; Security</title>
	<atom:link href="http://doboard.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://doboard.com</link>
	<description>do... Web Application Development and Security</description>
	<lastBuildDate>Wed, 28 Jul 2010 22:30:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Who Says PHP Security Sucks?</title>
		<link>http://doboard.com/2009/11/24/who-says-php-security-sucks/</link>
		<comments>http://doboard.com/2009/11/24/who-says-php-security-sucks/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 11:41:05 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://doboard.com/?p=90</guid>
		<description><![CDATA[Who would say such a thing? Obviously we can&#8217;t let that stand. It&#8217;s time to bust some myths while raising our own game to the next level. (An earlier version was published in php&#124;architect, April 2009) Aside from the trolls who frequent forums and blogs, it&#8217;s mainly the enterprise community which carries the lingering perception, [...]]]></description>
		<wfw:commentRss>http://doboard.com/2009/11/24/who-says-php-security-sucks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ShmooCon Memories</title>
		<link>http://doboard.com/2008/03/26/shmoocon-memories/</link>
		<comments>http://doboard.com/2008/03/26/shmoocon-memories/#comments</comments>
		<pubDate>Thu, 27 Mar 2008 02:44:45 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ShmooCon]]></category>
		<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://doboard.com/2008/03/26/shmoocon-memories/</guid>
		<description><![CDATA[I&#8217;ve been procrastinating on writing about the ShmooCon hacker convention, and today the thought bugged me enough to finally do something. I signed up at Hackers for Charity, formerly known as ihackcharities.org, after originally committing at ShmooCon. I ran into the founder and legendary hacker Johnny Long in the hallway. Factoid: It may be illegal [...]]]></description>
		<wfw:commentRss>http://doboard.com/2008/03/26/shmoocon-memories/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>OWASP February 2008</title>
		<link>http://doboard.com/2008/02/08/owasp-february-2008/</link>
		<comments>http://doboard.com/2008/02/08/owasp-february-2008/#comments</comments>
		<pubDate>Sat, 09 Feb 2008 01:44:52 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://doboard.com/2008/02/08/owasp-february-2008/</guid>
		<description><![CDATA[At my first local OWASP meeting, Andre Ludwig presented on &#8220;&#8230;the intersection between web application security and the attackers mindset.&#8221; Doug Wilson and Mark Bristow were very active participants and just happened to have a laptop with the same presentation and security demo I saw them use at Refresh DC a couple months ago. Very [...]]]></description>
		<wfw:commentRss>http://doboard.com/2008/02/08/owasp-february-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CapSec January 2008</title>
		<link>http://doboard.com/2008/01/31/capsec-january-2008/</link>
		<comments>http://doboard.com/2008/01/31/capsec-january-2008/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 17:56:39 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CapSec]]></category>
		<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://doboard.com/2008/02/01/capsec-january-2008/</guid>
		<description><![CDATA[After work today I walked to The Brickskeller and enjoyed a couple beers with a few of the CapSec group including Doug Wilson. One thing we discussed was that with tech groups formed around common interests, like web development, linux, or security, it&#8217;s very easy for people to stick with what and who they know. [...]]]></description>
		<wfw:commentRss>http://doboard.com/2008/01/31/capsec-january-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>20 Hacker Tricks for Attacking Web Apps</title>
		<link>http://doboard.com/2008/01/21/20-hacker-tricks-for-attacking-web-apps/</link>
		<comments>http://doboard.com/2008/01/21/20-hacker-tricks-for-attacking-web-apps/#comments</comments>
		<pubDate>Mon, 21 Jan 2008 09:57:37 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[DC PHP]]></category>
		<category><![CDATA[talks]]></category>
		<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://doboard.com/2008/01/21/20-hacker-tricks-for-attacking-web-apps/</guid>
		<description><![CDATA[At the DC PHP Developers Group meeting on January 9th I had the pleasure of giving my very first talk to a tech group. Since other people have given excellent talks focusing on a few top attack methods, I tried to give a broader survey to show some of the diversity of the hacking mindset. [...]]]></description>
		<wfw:commentRss>http://doboard.com/2008/01/21/20-hacker-tricks-for-attacking-web-apps/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>What Is Security, Really?</title>
		<link>http://doboard.com/2007/11/12/what-is-security-really/</link>
		<comments>http://doboard.com/2007/11/12/what-is-security-really/#comments</comments>
		<pubDate>Tue, 13 Nov 2007 01:00:10 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Availability]]></category>
		<category><![CDATA[Confidentiality]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[CSRF]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Integrity]]></category>
		<category><![CDATA[requirements]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[web development]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://doboard.com/2007/11/12/what-is-security-really/</guid>
		<description><![CDATA[You get a different answer each time depending on who you listen to:

"It's simple - patches, firewalls, anti-virus and the latest security products."  

<em>The product vendors would like you to believe that.</em>

"Preventing and fixing known security holes like XSS, SQL injection and CSRF."  

<em>A good web developer might say that.</em>

"Efficiently detecting and blocking hacking attempts."  

<em>Spoken like someone who has been in the trenches.  Whack-a-mole at Internet speed.</em>

"Complying with security rules and requirements."  

<em>Smells like bureaucrats.  Hopefully the thousands (!) of requirements aren't constantly changing, poorly written, contradictory, or ill-conceived...</em>

With more variations than we can count, there has to be a better way to get a handle on security.  So what's the bottom line?]]></description>
		<wfw:commentRss>http://doboard.com/2007/11/12/what-is-security-really/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
