<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>doBoard &#187; PHP</title>
	<atom:link href="http://doboard.com/tag/php/feed/" rel="self" type="application/rss+xml" />
	<link>http://doboard.com</link>
	<description>do... Web Application Development and Security</description>
	<lastBuildDate>Wed, 28 Jul 2010 22:30:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Who Says PHP Security Sucks?</title>
		<link>http://doboard.com/2009/11/24/who-says-php-security-sucks/</link>
		<comments>http://doboard.com/2009/11/24/who-says-php-security-sucks/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 11:41:05 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://doboard.com/?p=90</guid>
		<description><![CDATA[Who would say such a thing? Obviously we can&#8217;t let that stand. It&#8217;s time to bust some myths while raising our own game to the next level. (An earlier version was published in php&#124;architect, April 2009) Aside from the trolls who frequent forums and blogs, it&#8217;s mainly the enterprise community which carries the lingering perception, [...]]]></description>
		<wfw:commentRss>http://doboard.com/2009/11/24/who-says-php-security-sucks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>See You at ZendCon 2009</title>
		<link>http://doboard.com/2009/10/06/see-you-at-zendcon-2009/</link>
		<comments>http://doboard.com/2009/10/06/see-you-at-zendcon-2009/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 13:03:06 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[conferences]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://doboard.com/?p=84</guid>
		<description><![CDATA[I&#8217;m looking forward to seeing everyone at ZendCon 2009, &#8220;the premier PHP conference&#8221;. I was selected to present a session: Enterprise-Class PHP Security Oxymoron no more! Learn what high-stakes organizations expect when evaluating the security of PHP applications. We&#8217;ll cover formal standards and processes, and tips on how to successfully navigate through the minefield.]]></description>
		<wfw:commentRss>http://doboard.com/2009/10/06/see-you-at-zendcon-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Who Says PHP Security Sucks?&#8221; Published in php&#124;architect</title>
		<link>http://doboard.com/2009/04/29/who-says-php-security-sucks-published-in-phparchitect/</link>
		<comments>http://doboard.com/2009/04/29/who-says-php-security-sucks-published-in-phparchitect/#comments</comments>
		<pubDate>Wed, 29 Apr 2009 13:04:44 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://doboard.com/?p=69</guid>
		<description><![CDATA[You heard right &#8211; my first article in print is in the April 2009 issue of php&#124;architect. The title isn&#8217;t just a rhetorical question; I actually describe who would say such a thing about PHP security. I also explain what about this perception is distorted and what isn&#8217;t &#8211; and how the PHP community can [...]]]></description>
		<wfw:commentRss>http://doboard.com/2009/04/29/who-says-php-security-sucks-published-in-phparchitect/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DC PHP Conference 2007 &#8211; Security Highlights</title>
		<link>http://doboard.com/2007/11/12/dc-php-conference-2007-security-highlights/</link>
		<comments>http://doboard.com/2007/11/12/dc-php-conference-2007-security-highlights/#comments</comments>
		<pubDate>Tue, 13 Nov 2007 00:15:11 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Chris Shiflett]]></category>
		<category><![CDATA[conferences]]></category>
		<category><![CDATA[CSRF]]></category>
		<category><![CDATA[Damien Seguy]]></category>
		<category><![CDATA[DC PHP]]></category>
		<category><![CDATA[Ed Finkler]]></category>
		<category><![CDATA[Eli White]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[Inspekt]]></category>
		<category><![CDATA[Keith Casey]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHPSecInfo]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://doboard.com/2007/11/12/dc-php-conference-2007-security-highlights/</guid>
		<description><![CDATA[This year&#8217;s conference had a fairly heavy dose of security. Chris Shiflett&#8217;s keynote, &#8220;Security 2.0&#8243;, included nice discussions of XSS (cross-site scripting) and CSRF (cross-site request forgery) with an AJAX scenario. Ed Finkler presented on the PHPSecInfo project, a tool to scan the PHP environment for security issues, and Inspekt, a PHP library to protect [...]]]></description>
		<wfw:commentRss>http://doboard.com/2007/11/12/dc-php-conference-2007-security-highlights/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Q &amp; A:  Risk of Duplicates When Using MD5?</title>
		<link>http://doboard.com/2007/11/12/q-a-risk-of-duplicates-when-using-md5/</link>
		<comments>http://doboard.com/2007/11/12/q-a-risk-of-duplicates-when-using-md5/#comments</comments>
		<pubDate>Mon, 12 Nov 2007 21:49:20 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Q & A]]></category>
		<category><![CDATA[DC PHP]]></category>
		<category><![CDATA[hash]]></category>
		<category><![CDATA[hash_hmac]]></category>
		<category><![CDATA[HMAC]]></category>
		<category><![CDATA[MD5]]></category>
		<category><![CDATA[mhash]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Q&A]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SHA]]></category>
		<category><![CDATA[SHA-256]]></category>
		<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://doboard.com/2007/11/12/q-a-risk-of-duplicates-when-using-md5/</guid>
		<description><![CDATA[Yes, MD5 can produce hash collisions in a very small percentage of cases. For many uses this shouldn&#8217;t be significant, but for security there are better options. I prefer the SHA-2 series, referred to as SHA-224/256/384/512, because the algorithms are strong and widely supported. If you need the hashes to be un-guessable then I&#8217;d recommend [...]]]></description>
		<wfw:commentRss>http://doboard.com/2007/11/12/q-a-risk-of-duplicates-when-using-md5/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>DC PHP Conference 2007</title>
		<link>http://doboard.com/2007/11/06/dc-php-conference-2007/</link>
		<comments>http://doboard.com/2007/11/06/dc-php-conference-2007/#comments</comments>
		<pubDate>Wed, 07 Nov 2007 04:52:08 +0000</pubDate>
		<dc:creator>Barry</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Chris Shiflett]]></category>
		<category><![CDATA[conferences]]></category>
		<category><![CDATA[DC PHP]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://doboard.com/2007/11/06/dc-php-conference-2007/</guid>
		<description><![CDATA[I&#8217;m going to the DC PHP Conference 2007 in Washington, DC, November 7-9. The keynote will be &#8220;Security 2.0&#8243; by Chris Shiflett. Looking forward to seeing the PHP security guru in action, and I&#8217;ll probably run into several members of the DC PHP Developers Group.]]></description>
		<wfw:commentRss>http://doboard.com/2007/11/06/dc-php-conference-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
