<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>doBoard &#187; CSRF</title>
	<atom:link href="http://doboard.com/tag/csrf/feed/" rel="self" type="application/rss+xml" />
	<link>http://doboard.com</link>
	<description>do... Web Application Development and Security</description>
	<lastBuildDate>Thu, 24 Feb 2011 20:51:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>What Is Security, Really?</title>
		<link>http://doboard.com/2007/11/12/what-is-security-really/</link>
		<comments>http://doboard.com/2007/11/12/what-is-security-really/#comments</comments>
		<pubDate>Tue, 13 Nov 2007 01:00:10 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Availability]]></category>
		<category><![CDATA[Confidentiality]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[CSRF]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Integrity]]></category>
		<category><![CDATA[requirements]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[web development]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://doboard.com/2007/11/12/what-is-security-really/</guid>
		<description><![CDATA[You get a different answer each time depending on who you listen to:

"It's simple - patches, firewalls, anti-virus and the latest security products."  

<em>The product vendors would like you to believe that.</em>

"Preventing and fixing known security holes like XSS, SQL injection and CSRF."  

<em>A good web developer might say that.</em>

"Efficiently detecting and blocking hacking attempts."  

<em>Spoken like someone who has been in the trenches.  Whack-a-mole at Internet speed.</em>

"Complying with security rules and requirements."  

<em>Smells like bureaucrats.  Hopefully the thousands (!) of requirements aren't constantly changing, poorly written, contradictory, or ill-conceived...</em>

With more variations than we can count, there has to be a better way to get a handle on security.  So what's the bottom line?]]></description>
		<wfw:commentRss>http://doboard.com/2007/11/12/what-is-security-really/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DC PHP Conference 2007 &#8211; Security Highlights</title>
		<link>http://doboard.com/2007/11/12/dc-php-conference-2007-security-highlights/</link>
		<comments>http://doboard.com/2007/11/12/dc-php-conference-2007-security-highlights/#comments</comments>
		<pubDate>Tue, 13 Nov 2007 00:15:11 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Chris Shiflett]]></category>
		<category><![CDATA[conferences]]></category>
		<category><![CDATA[CSRF]]></category>
		<category><![CDATA[Damien Seguy]]></category>
		<category><![CDATA[DC PHP]]></category>
		<category><![CDATA[Ed Finkler]]></category>
		<category><![CDATA[Eli White]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[Inspekt]]></category>
		<category><![CDATA[Keith Casey]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHPSecInfo]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://doboard.com/2007/11/12/dc-php-conference-2007-security-highlights/</guid>
		<description><![CDATA[This year&#8217;s conference had a fairly heavy dose of security. Chris Shiflett&#8217;s keynote, &#8220;Security 2.0&#8243;, included nice discussions of XSS (cross-site scripting) and CSRF (cross-site request forgery) with an AJAX scenario. Ed Finkler presented on the PHPSecInfo project, a tool to scan the PHP environment for security issues, and Inspekt, a PHP library to protect [...]]]></description>
		<wfw:commentRss>http://doboard.com/2007/11/12/dc-php-conference-2007-security-highlights/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

