<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>doBoard</title>
	<atom:link href="http://doboard.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://doboard.com</link>
	<description>do... Web Application Security and Development</description>
	<pubDate>Tue, 08 Jul 2008 05:53:46 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>How to Make Application Security Suck Less</title>
		<link>http://doboard.com/2008/06/04/how-to-make-application-security-suck-less/</link>
		<comments>http://doboard.com/2008/06/04/how-to-make-application-security-suck-less/#comments</comments>
		<pubDate>Wed, 04 Jun 2008 11:55:13 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[conferences]]></category>

		<category><![CDATA[DC PHP]]></category>

		<category><![CDATA[DCPHP]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://doboard.com/2008/06/04/how-to-make-application-security-suck-less/</guid>
		<description><![CDATA[Application security sucks because it&#8217;s a wicked hard problem to mix the goals of security and application development within real-life projects.
If application development is about making an app do what it&#8217;s supposed to do, then application security is about making sure an app doesn&#8217;t do what it&#8217;s not supposed to do, despite real world conditions [...]]]></description>
		<wfw:commentRss>http://doboard.com/2008/06/04/how-to-make-application-security-suck-less/feed/</wfw:commentRss>
		</item>
		<item>
		<title>DC PHP Conference &#038; Expo, June 2-4, 2008</title>
		<link>http://doboard.com/2008/04/13/dc-php-conference-expo-june-2-4-2008/</link>
		<comments>http://doboard.com/2008/04/13/dc-php-conference-expo-june-2-4-2008/#comments</comments>
		<pubDate>Sun, 13 Apr 2008 18:33:38 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[conferences]]></category>

		<category><![CDATA[DC PHP]]></category>

		<category><![CDATA[DCPHP]]></category>

		<category><![CDATA[Events]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://doboard.com/?p=16</guid>
		<description><![CDATA[I&#8217;m going to talk about &#8220;How to Make Application Security Suck Less&#8221; at this international conference, hosted locally in Washington, DC.
The keynote speakers will be Kshemendra Paul from OMB, Christopher Jones from Oracle, and Chris Shiflett from OmniTI.
Local PHP agitator Keith Casey will moderate the featured panel discussion on PHP IDEs.  Panelists will be: [...]]]></description>
		<wfw:commentRss>http://doboard.com/2008/04/13/dc-php-conference-expo-june-2-4-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>ShmooCon Memories</title>
		<link>http://doboard.com/2008/03/26/shmoocon-memories/</link>
		<comments>http://doboard.com/2008/03/26/shmoocon-memories/#comments</comments>
		<pubDate>Thu, 27 Mar 2008 02:44:45 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[ShmooCon]]></category>

		<guid isPermaLink="false">http://doboard.com/2008/03/26/shmoocon-memories/</guid>
		<description><![CDATA[I&#8217;ve been procrastinating on writing about the ShmooCon hacker convention, and today the thought bugged me enough to finally do something.
I signed up at Hackers for Charity, formerly known as ihackcharities.org, after originally committing at ShmooCon.  I ran into the founder and legendary hacker Johnny Long in the hallway.
Factoid:  It may be illegal [...]]]></description>
		<wfw:commentRss>http://doboard.com/2008/03/26/shmoocon-memories/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OWASP February 2008</title>
		<link>http://doboard.com/2008/02/08/owasp-february-2008/</link>
		<comments>http://doboard.com/2008/02/08/owasp-february-2008/#comments</comments>
		<pubDate>Sat, 09 Feb 2008 01:44:52 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[OWASP]]></category>

		<guid isPermaLink="false">http://doboard.com/2008/02/08/owasp-february-2008/</guid>
		<description><![CDATA[At my first local OWASP meeting, Andre Ludwig presented on &#8220;&#8230;the intersection between web application security and the attackers mindset.&#8221;
Doug Wilson and Mark Bristow were very active participants and just happened to have a laptop with the same presentation and security demo I saw them use at Refresh DC a couple months ago.  Very [...]]]></description>
		<wfw:commentRss>http://doboard.com/2008/02/08/owasp-february-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>CapSec January 2008</title>
		<link>http://doboard.com/2008/01/31/capsec-january-2008/</link>
		<comments>http://doboard.com/2008/01/31/capsec-january-2008/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 17:56:39 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[CapSec]]></category>

		<guid isPermaLink="false">http://doboard.com/2008/02/01/capsec-january-2008/</guid>
		<description><![CDATA[After work today I walked to The Brickskeller and enjoyed a couple beers with a few of the CapSec group including Doug Wilson.
One thing we discussed was that with tech groups formed around common interests, like web development, linux, or security, it&#8217;s very easy for people to stick with what and who they know.  [...]]]></description>
		<wfw:commentRss>http://doboard.com/2008/01/31/capsec-january-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>20 Hacker Tricks for Attacking Web Apps</title>
		<link>http://doboard.com/2008/01/21/20-hacker-tricks-for-attacking-web-apps/</link>
		<comments>http://doboard.com/2008/01/21/20-hacker-tricks-for-attacking-web-apps/#comments</comments>
		<pubDate>Mon, 21 Jan 2008 09:57:37 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[DC PHP]]></category>

		<category><![CDATA[talks]]></category>

		<guid isPermaLink="false">http://doboard.com/2008/01/21/20-hacker-tricks-for-attacking-web-apps/</guid>
		<description><![CDATA[At the DC PHP Developers Group meeting on January 9th I had the pleasure of giving my very first talk to a tech group.
Since other people have given excellent talks focusing on a few top attack methods, I tried to give a broader survey to show some of the diversity of the hacking mindset.  [...]]]></description>
		<wfw:commentRss>http://doboard.com/2008/01/21/20-hacker-tricks-for-attacking-web-apps/feed/</wfw:commentRss>
		</item>
		<item>
		<title>What Is Security, Really?</title>
		<link>http://doboard.com/2007/11/12/what-is-security-really/</link>
		<comments>http://doboard.com/2007/11/12/what-is-security-really/#comments</comments>
		<pubDate>Tue, 13 Nov 2007 01:00:10 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Availability]]></category>

		<category><![CDATA[Confidentiality]]></category>

		<category><![CDATA[controls]]></category>

		<category><![CDATA[CSRF]]></category>

		<category><![CDATA[hacking]]></category>

		<category><![CDATA[Integrity]]></category>

		<category><![CDATA[requirements]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[SQL injection]]></category>

		<category><![CDATA[web development]]></category>

		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://doboard.com/2007/11/12/what-is-security-really/</guid>
		<description><![CDATA[You get a different answer each time depending on who you listen to:

"It's simple - patches, firewalls, anti-virus and the latest security products."  

<em>The product vendors would like you to believe that.</em>

"Preventing and fixing known security holes like XSS, SQL injection and CSRF."  

<em>A good web developer might say that.</em>

"Efficiently detecting and blocking hacking attempts."  

<em>Spoken like someone who has been in the trenches.  Whack-a-mole at Internet speed.</em>

"Complying with security rules and requirements."  

<em>Smells like bureaucrats.  Hopefully the thousands (!) of requirements aren't constantly changing, poorly written, contradictory, or ill-conceived...</em>

With more variations than we can count, there has to be a better way to get a handle on security.  So what's the bottom line?]]></description>
		<wfw:commentRss>http://doboard.com/2007/11/12/what-is-security-really/feed/</wfw:commentRss>
		</item>
		<item>
		<title>DC PHP Conference 2007 - Security Highlights</title>
		<link>http://doboard.com/2007/11/12/dc-php-conference-2007-security-highlights/</link>
		<comments>http://doboard.com/2007/11/12/dc-php-conference-2007-security-highlights/#comments</comments>
		<pubDate>Tue, 13 Nov 2007 00:15:11 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Chris Shiflett]]></category>

		<category><![CDATA[conferences]]></category>

		<category><![CDATA[CSRF]]></category>

		<category><![CDATA[Damien Seguy]]></category>

		<category><![CDATA[DC PHP]]></category>

		<category><![CDATA[Ed Finkler]]></category>

		<category><![CDATA[Eli White]]></category>

		<category><![CDATA[hacked]]></category>

		<category><![CDATA[Inspekt]]></category>

		<category><![CDATA[Keith Casey]]></category>

		<category><![CDATA[PHP]]></category>

		<category><![CDATA[PHPSecInfo]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://doboard.com/2007/11/12/dc-php-conference-2007-security-highlights/</guid>
		<description><![CDATA[This year&#8217;s conference had a fairly heavy dose of security.
Chris Shiflett&#8217;s keynote, &#8220;Security 2.0&#8243;, included nice discussions of XSS (cross-site scripting) and CSRF (cross-site request forgery) with an AJAX scenario.
Ed Finkler presented on the PHPSecInfo project, a tool to scan the PHP environment for security issues, and Inspekt, a PHP library to protect applications from [...]]]></description>
		<wfw:commentRss>http://doboard.com/2007/11/12/dc-php-conference-2007-security-highlights/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Q &#038; A:  Risk of Duplicates When Using MD5?</title>
		<link>http://doboard.com/2007/11/12/q-a-risk-of-duplicates-when-using-md5/</link>
		<comments>http://doboard.com/2007/11/12/q-a-risk-of-duplicates-when-using-md5/#comments</comments>
		<pubDate>Mon, 12 Nov 2007 21:49:20 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
		
		<category><![CDATA[Q &amp; A]]></category>

		<category><![CDATA[DC PHP]]></category>

		<category><![CDATA[hash]]></category>

		<category><![CDATA[hash_hmac]]></category>

		<category><![CDATA[HMAC]]></category>

		<category><![CDATA[MD5]]></category>

		<category><![CDATA[mhash]]></category>

		<category><![CDATA[PHP]]></category>

		<category><![CDATA[Q&amp;A]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[SHA]]></category>

		<category><![CDATA[SHA-256]]></category>

		<guid isPermaLink="false">http://doboard.com/2007/11/12/q-a-risk-of-duplicates-when-using-md5/</guid>
		<description><![CDATA[Yes, MD5 can produce hash collisions in a very small percentage of cases.  For many uses this shouldn&#8217;t be significant, but for security there are better options.
I prefer the SHA-2 series, referred to as SHA-224/256/384/512, because the algorithms are strong and widely supported.
If you need the hashes to be un-guessable then I&#8217;d recommend hashing [...]]]></description>
		<wfw:commentRss>http://doboard.com/2007/11/12/q-a-risk-of-duplicates-when-using-md5/feed/</wfw:commentRss>
		</item>
		<item>
		<title>DC PHP Conference 2007</title>
		<link>http://doboard.com/2007/11/06/dc-php-conference-2007/</link>
		<comments>http://doboard.com/2007/11/06/dc-php-conference-2007/#comments</comments>
		<pubDate>Wed, 07 Nov 2007 04:52:08 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Chris Shiflett]]></category>

		<category><![CDATA[conferences]]></category>

		<category><![CDATA[DC PHP]]></category>

		<category><![CDATA[PHP]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://doboard.com/2007/11/06/dc-php-conference-2007/</guid>
		<description><![CDATA[I&#8217;m going to the DC PHP Conference 2007 in Washington, DC, November 7-9.  The keynote will be &#8220;Security 2.0&#8243; by Chris Shiflett.  Looking forward to seeing the PHP security guru in action, and I&#8217;ll probably run into several members of the DC PHP Developers Group.
]]></description>
		<wfw:commentRss>http://doboard.com/2007/11/06/dc-php-conference-2007/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
