<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/securitysoftware/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Following the White Rabbit Blog - All Comments</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/default.aspx</link><description>web application security risk hacking blog metrics compliance</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>re: SaaS: The Definitive Cliff Notes on Web Security Delivered</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/07/22/saas-app-sec-delivered.aspx#93755</link><pubDate>Wed, 22 Jul 2009 06:13:03 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:93755</guid><dc:creator>GK</dc:creator><description>&lt;p&gt;Hi RafaLos,&lt;/p&gt;
&lt;p&gt;Enjoyed reading your post. In addition to disadvantages you mentioned, I would like to mention one more- &lt;/p&gt;
&lt;p&gt;When you use SaaS model you are trusting one vendor, basically, you are putting all your eggs in one basket. Quality of security review becomes dependent on competency of vendor. Classically, you could use &amp;quot;ring token&amp;quot; topology to get flavor of what other vendors have to offer (by choosing different vendors for different applications).Therefore, it becomes very important to carefully choose SaaS vendor. &lt;/p&gt;
&lt;p&gt;Cheers,&lt;/p&gt;
&lt;p&gt;GK&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=93755" width="1" height="1"&gt;</description></item><item><title>re: Input Validation Strategy - Black vs. White -listing</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2008/06/26/blacklisting-an-arms-race-we-can-t-win.aspx#93697</link><pubDate>Thu, 16 Jul 2009 21:42:27 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:93697</guid><dc:creator>Erik Čerpnjak</dc:creator><description>&lt;p&gt;I found the article to become a very good guide on how my future input checking will look like. You have made a good point in not be able to detect all possible permutations of bad input and exclude them. As i have read everywhere on the internet, specialist in matters of security are also pending in the direction to use white lists. Some also say that using both approaches is THE most safe way of cheching whether an input is safe to execute or not. But probably everyone should ask themself if the application really needs both approaches - if time,effort and money is not an issue then it is safe to say that integrating both is not a bad idea.&lt;/p&gt;
&lt;p&gt;So thank you for this article.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=93697" width="1" height="1"&gt;</description></item><item><title>re: The Problem of "Too Many Problems"</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/06/24/the-problem-of-quot-too-many-problems-quot.aspx#90316</link><pubDate>Thu, 25 Jun 2009 20:21:09 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:90316</guid><dc:creator>patrick</dc:creator><description>&lt;p&gt;i hate WAF with a passion&lt;/p&gt;
&lt;p&gt;but in this particular case, i would have plugged a WAF in fron the said vulnerable website as a compensatory (and temporary) control&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=90316" width="1" height="1"&gt;</description></item><item><title>re: Raising the Bar? Flash Encryption, Obfuscation</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/04/20/raising-the-bar-flash-encryption-obfuscation.aspx#89106</link><pubDate>Thu, 23 Apr 2009 15:32:29 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89106</guid><dc:creator>Ammar Mardawi</dc:creator><description>&lt;p&gt;While your post is great and very informative on many sides, it is misleading in two important points.&lt;/p&gt;
&lt;p&gt;First, an obfuscator&amp;#39;s main objective is to protect the intellectual property within the code. It prevents decompilers from generating anything useful at all and makes revese-engineering requires longer time making it not feasible. Security through obscurity is a secondary objective. As bad as many may argue this option can be, it is still cheap to implement and does not heart.&lt;/p&gt;
&lt;p&gt;The second thing, there is no such thing as de-obfuscation. Obfuscation is (at least should be) irreversible. The Flash Player will run the obfuscated code directly and does not require a deobfuscation step. For example, when an obfuscator renames identifiers in the code to meaningless names, the Flash Player will not mind that.&lt;/p&gt;
&lt;p&gt;Again, I think your post is great and very informative.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89106" width="1" height="1"&gt;</description></item><item><title>Raising the Bar? Flash Encryption, Obfuscation - Following the &amp;#8230; |</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/04/20/raising-the-bar-flash-encryption-obfuscation.aspx#89097</link><pubDate>Thu, 23 Apr 2009 00:24:08 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89097</guid><dc:creator>Raising the Bar? Flash Encryption, Obfuscation - Following the … |</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Raising the Bar? Flash Encryption, Obfuscation - Following the &amp;amp;#8230; |&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89097" width="1" height="1"&gt;</description></item><item><title>Raising the Bar? Flash Encryption, Obfuscation - Following the &amp;#8230; |</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/04/20/raising-the-bar-flash-encryption-obfuscation.aspx#89096</link><pubDate>Thu, 23 Apr 2009 00:24:05 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89096</guid><dc:creator>Raising the Bar? Flash Encryption, Obfuscation - Following the … |</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Raising the Bar? Flash Encryption, Obfuscation - Following the &amp;amp;#8230; |&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89096" width="1" height="1"&gt;</description></item><item><title>Topics about Communitys  &amp;raquo; Archive   &amp;raquo; Raising the Bar? Flash Encryption, Obfuscation - Following the &amp;#8230;</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/04/20/raising-the-bar-flash-encryption-obfuscation.aspx#89093</link><pubDate>Wed, 22 Apr 2009 22:30:51 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89093</guid><dc:creator>Topics about Communitys  » Archive   » Raising the Bar? Flash Encryption, Obfuscation - Following the …</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Topics about Communitys &amp;nbsp;&amp;amp;raquo; Archive &amp;nbsp; &amp;amp;raquo; Raising the Bar? Flash Encryption, Obfuscation - Following the &amp;amp;#8230;&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89093" width="1" height="1"&gt;</description></item><item><title>re: OWASP, Security Bloggers Finalist and more</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/04/09/owasp-security-bloggers-finalist-and-more.aspx#88890</link><pubDate>Fri, 10 Apr 2009 03:23:57 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:88890</guid><dc:creator>Scott Wright</dc:creator><description>&lt;p&gt;Congratulations! ...and I&amp;#39;m glad you enjoyed your time in Canada. Thanks for making the effort to visit. &lt;/p&gt;
&lt;p&gt;Scott&lt;/p&gt;
&lt;p&gt;The Streetwise Security Coach&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=88890" width="1" height="1"&gt;</description></item><item><title>re: News Flash: phpBB Massive Hack</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2008/05/13/News-Flash_3A00_-phpBB-Massive-Hack.aspx#88198</link><pubDate>Wed, 04 Mar 2009 23:35:53 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:88198</guid><dc:creator>Lauren</dc:creator><description>&lt;p&gt;I think it&amp;#39;s shocking that opensource software has so many vulnerabilities, phpbb especially. More care should be taken from the outset to ensure security in my opinion.&lt;/p&gt;
&lt;p&gt;- Lauren&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=88198" width="1" height="1"&gt;</description></item><item><title>re: QA Lesson - Defect vs. Vulnerability</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/02/03/qa-lesson-defect-vs-vulnerability.aspx#88053</link><pubDate>Tue, 24 Feb 2009 15:47:29 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:88053</guid><dc:creator>Clerkendweller</dc:creator><description>&lt;p&gt;I saw a comment today on an e-marketing website which referred to a defect/vulnerability as a &amp;quot;usability flaw&amp;quot;:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://econsultancy.com/blog/3346-ryanair-freaks-out-at-blogger-disses-wordpress-shoots-foot" rel="nofollow" target="_new"&gt;econsultancy.com/.../3346-ryanair-freaks-out-at-blogger-disses-wordpress-shoots-foot&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It was interesting to see the security problem being defined in a way that marketers could relate to, and reminded me of the discussion here.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=88053" width="1" height="1"&gt;</description></item><item><title>re: An Unfortunate Case of Learned Behavior</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/02/10/an-unfortunate-case-of-learned-behavior.aspx#87881</link><pubDate>Thu, 12 Feb 2009 04:28:06 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:87881</guid><dc:creator>RafalLos</dc:creator><description>&lt;p&gt;@arshan:&lt;/p&gt;
&lt;p&gt;&amp;quot;chortle&amp;quot;&lt;/p&gt;
&lt;p&gt; Origin:&lt;/p&gt;
&lt;p&gt;b. chuckle and snort; coined by Lewis Carroll in Through the Looking-Glass (1871)&lt;/p&gt;
&lt;p&gt;...that's either an incredibly clever reference on the White Rabbit theme, or ... *shrug*. &amp;nbsp;Either way, I'm not sure I fully understand your comment?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=87881" width="1" height="1"&gt;</description></item><item><title>re: An Unfortunate Case of Learned Behavior</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/02/10/an-unfortunate-case-of-learned-behavior.aspx#87876</link><pubDate>Wed, 11 Feb 2009 19:53:25 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:87876</guid><dc:creator>Matt </dc:creator><description>&lt;p&gt;This is what I&amp;#39;ve been preaching for years. I work at a vulnerability management software company and the prospects I speak with expect my solution to be the end-all beat all for all their network security needs and get frustrated when it&amp;#39;s not. &lt;/p&gt;
&lt;p&gt;What people need to realize is software won&amp;#39;t replace a human, and a human can&amp;#39;t necessarily replace software either. The phrase I always come back to is &amp;quot;vulnerability management program.&amp;quot; It&amp;#39;s not a solution, its not an analyst, it&amp;#39;s a combination of both and then some.&lt;/p&gt;
&lt;p&gt;Great Insight!&lt;/p&gt;
&lt;p&gt;-Matt&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=87876" width="1" height="1"&gt;</description></item><item><title>re: An Unfortunate Case of Learned Behavior</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/02/10/an-unfortunate-case-of-learned-behavior.aspx#87872</link><pubDate>Wed, 11 Feb 2009 16:28:03 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:87872</guid><dc:creator>arshan</dc:creator><description>&lt;p&gt;&amp;gt; 4. You believe that people are more effective than tools in security vulnerability detection&lt;/p&gt;
&lt;p&gt;chortle, legitimacy--&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=87872" width="1" height="1"&gt;</description></item><item><title>re: An Unfortunate Case of Learned Behavior</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/02/10/an-unfortunate-case-of-learned-behavior.aspx#87869</link><pubDate>Wed, 11 Feb 2009 14:41:12 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:87869</guid><dc:creator>Susanna</dc:creator><description>&lt;p&gt;How true. I so enjoy your posting and comments on webappsec.org. You are providing sensible, practical and implementable (if that&amp;#39;s a word) advice.&lt;/p&gt;
&lt;p&gt;Thanks again!!&lt;/p&gt;
&lt;p&gt;S&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=87869" width="1" height="1"&gt;</description></item><item><title>re: An Unfortunate Case of Learned Behavior</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/02/10/an-unfortunate-case-of-learned-behavior.aspx#87853</link><pubDate>Tue, 10 Feb 2009 23:40:16 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:87853</guid><dc:creator>Christian</dc:creator><description>&lt;p&gt;Great post Rafal. The whole people/process/tools approach is almost an underlying principle for everything! A * principle.&lt;/p&gt;
&lt;p&gt;This is definitely one of those things that you just have to keep on repeating to yourself and your colleagues and everyone around like a mantra.&lt;/p&gt;
&lt;p&gt;Cheers,&lt;/p&gt;
&lt;p&gt;C.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=87853" width="1" height="1"&gt;</description></item></channel></rss>