<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/securitysoftware/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>What's on your mind?</title><link>http://www.communities.hp.com/securitysoftware/forums/39.aspx</link><description>General HP Application Security Center discussion forum</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Re: Web Hacking Exposed 2 Webcast</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/1075.aspx</link><pubDate>Wed, 29 Nov 2006 13:35:35 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:1075</guid><dc:creator>nEUrOO</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/1075.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=39&amp;PostID=1075</wfw:commentRss><description>&lt;p&gt;This webcast is very interesting.&lt;br /&gt;I really liked that you pointed out that the &lt;em&gt;configuration&lt;/em&gt; is one of the most important part for the security and not only the classical XSS, SQL Injection etc.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Web Hacking Exposed 2 Webcast</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/1049.aspx</link><pubDate>Mon, 27 Nov 2006 09:49:58 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:1049</guid><dc:creator>caleb</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/1049.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=39&amp;PostID=1049</wfw:commentRss><description>&lt;p&gt;&amp;nbsp; &amp;sect;Samy&amp;rsquo;s explanation&lt;br /&gt;&lt;a href="http://namb.la/popular/"&gt;http://namb.la/popular/&lt;/a&gt; &lt;/p&gt;&lt;p&gt;&amp;sect;Yamanner source code attachment&lt;br /&gt;&lt;a href="http://groovin.net/stuff/yammer.txt"&gt;http://groovin.net/stuff/yammer.txt&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;sect;Earlier Yahoo Mail XSS vulnerability using STYLE onload attribute:&lt;br /&gt;&lt;a href="http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040599.html"&gt;http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040599.html&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;sect;Earlier Yahoo Mail vulnerability using commented &amp;lt;/form&amp;gt;:&lt;br /&gt;&lt;a href="http://www.mcgees.org/2003/07/24/yahoo-mail-exploit/"&gt;http://www.mcgees.org/2003/07/24/yahoo-mail-exploit/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;sect;Yamanner countermeasures reported:&lt;br /&gt;&lt;a href="http://antivirus.about.com/od/virusdescriptions/a/yamanner.htm"&gt;http://antivirus.about.com/od/virusdescriptions/a/yamanner.htm&lt;/a&gt;&lt;br /&gt;&amp;sect;Robert Hansen (RSnake)&amp;rsquo;s XSS Cheat Sheet&lt;br /&gt;&lt;a href="http://ha.ckers.org/xss.html"&gt;http://ha.ckers.org/xss.html&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;sect;SafeHTML (PHP)&lt;br /&gt;&lt;a href="http://directory.fsf.org/all/SafeHTML.html"&gt;http://directory.fsf.org/all/SafeHTML.html&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;sect;&amp;ldquo;How to Prevent XSS in ASP.NET&amp;rdquo;&lt;br /&gt;&lt;a href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnpag2/html/PAGHT000004.asp"&gt;http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnpag2/html/PAGHT000004.asp&lt;/a&gt; &lt;/p&gt;&lt;p&gt;&amp;sect;.NET Framework HttpServerUtility.HtmlEncode Method&lt;br /&gt;&lt;a href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/cpref/html/frlrfSystemWebHttpServerUtilityClassHtmlEncodeTopic.asp"&gt;http://msdn.microsoft.com/library/default.asp?url=/library/en-us/cpref/html/frlrfSystemWebHttpServerUtilityClassHtmlEncodeTopic.asp&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Web Hacking Exposed 2 Webcast</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/980.aspx</link><pubDate>Tue, 21 Nov 2006 15:32:08 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:980</guid><dc:creator>Anonymous</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/980.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=39&amp;PostID=980</wfw:commentRss><description>&lt;p&gt;I just watched the webcast and it was excellent. I plan to show it to my web&amp;nbsp;engineering&amp;nbsp;class next week. &lt;/p&gt;&lt;p&gt;Could you post the list of links here, since that slide isn&amp;#39;t visible long enough to note them.&lt;/p&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p&gt;Mike&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Web Hacking Exposed 2 Webcast</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/842.aspx</link><pubDate>Fri, 10 Nov 2006 11:33:41 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:842</guid><dc:creator>caleb</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/842.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=39&amp;PostID=842</wfw:commentRss><description>&lt;p&gt;We just opened up a new webcast that involves me and Joel Scambray talking about our new book Web Hacking Exposed 2. We throw in some great webhacking examples. Should&amp;nbsp;be fun to watch. If you have any feedback on it let me know&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;&lt;a href="https://download.spidynamics.com/Registration/hackingexp_web.asp"&gt;&lt;font color="#800080"&gt;https://download.spidynamics.com/Registration/hackingexp_web.asp&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>