<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Web Input Filtering</title>
	<atom:link href="http://inputfiltering.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://inputfiltering.com</link>
	<description></description>
	<pubDate>Fri, 06 Jun 2008 14:54:12 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Integrating Vulnerability Scanners and Web Application Firewalls</title>
		<link>http://inputfiltering.com/filtering-input/integrating-vulnerability-scanners-and-web-application-firewalls/</link>
		<comments>http://inputfiltering.com/filtering-input/integrating-vulnerability-scanners-and-web-application-firewalls/#comments</comments>
		<pubDate>Fri, 06 Jun 2008 14:54:12 +0000</pubDate>
		<dc:creator>xadmin</dc:creator>
		
		<category><![CDATA[filtering input]]></category>

		<category><![CDATA[application-firewall]]></category>

		<category><![CDATA[application-gateway]]></category>

		<category><![CDATA[appsec]]></category>

		<category><![CDATA[arial]]></category>

		<category><![CDATA[breach-security]]></category>

		<category><![CDATA[copyright]]></category>

		<category><![CDATA[development]]></category>

		<category><![CDATA[game]]></category>

		<category><![CDATA[geneva]]></category>

		<category><![CDATA[m1100-appliance]]></category>

		<category><![CDATA[research]]></category>

		<category><![CDATA[secure programming]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[sentinel]]></category>

		<category><![CDATA[time]]></category>

		<category><![CDATA[virtual]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[web application security]]></category>

		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://inputfiltering.com/input_filtering/integrating-vulnerability-scanners-and-web-application-firewalls/</guid>
		<description><![CDATA[As I mentioned in my previous post - What&#8217;s the Score of the Game - I feel that one of areas where organizations are failing, with regards to web application security, is that there is a lack of communication between the following three &#8230;
]]></description>
			<content:encoded><![CDATA[<p>As I mentioned in my previous post - What&#8217;s the Score of the Game - I feel that one of areas where organizations are failing, with regards to <b>web application security</b>, is that there is a lack of communication between the following three <b>&#8230;</b></p>
]]></content:encoded>
			<wfw:commentRss>http://inputfiltering.com/filtering-input/integrating-vulnerability-scanners-and-web-application-firewalls/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Security Requirements for Software Development</title>
		<link>http://inputfiltering.com/programming/security-requirements-for-software-development/</link>
		<comments>http://inputfiltering.com/programming/security-requirements-for-software-development/#comments</comments>
		<pubDate>Fri, 06 Jun 2008 12:56:00 +0000</pubDate>
		<dc:creator>xadmin</dc:creator>
		
		<category><![CDATA[programming]]></category>

		<category><![CDATA[ability]]></category>

		<category><![CDATA[browser]]></category>

		<category><![CDATA[data]]></category>

		<category><![CDATA[database]]></category>

		<category><![CDATA[development]]></category>

		<category><![CDATA[include-data]]></category>

		<category><![CDATA[include-name]]></category>

		<category><![CDATA[list]]></category>

		<category><![CDATA[my-sunshine]]></category>

		<category><![CDATA[project]]></category>

		<category><![CDATA[requirements]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[security-requirements]]></category>

		<category><![CDATA[semantic]]></category>

		<category><![CDATA[software]]></category>

		<category><![CDATA[software-development]]></category>

		<category><![CDATA[source]]></category>

		<category><![CDATA[storage]]></category>

		<category><![CDATA[system-must]]></category>

		<guid isPermaLink="false">http://inputfiltering.com/input_filtering/security-requirements-for-software-development/</guid>
		<description><![CDATA[For PHP, use  mysql_real_escape_string() if using MySQL, or preferably use PDO which does not require escaping If language is J2EE, documentation of  the J2EE Security Manager settings should be provided Do not use GET requests (URLs) for &#8230;
]]></description>
			<content:encoded><![CDATA[<p>For PHP, use  mysql_real_escape_string() if using MySQL, or preferably use PDO which does not require <b>escaping</b> If language is J2EE, documentation of  the J2EE <b>Security</b> Manager settings should be provided Do not use GET requests (URLs) for <b>&#8230;</b></p>
]]></content:encoded>
			<wfw:commentRss>http://inputfiltering.com/programming/security-requirements-for-software-development/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The Telling of One Billion Ghost Stories (draft) - Part 29</title>
		<link>http://inputfiltering.com/programming/the-telling-of-one-billion-ghost-stories-draft-part-29/</link>
		<comments>http://inputfiltering.com/programming/the-telling-of-one-billion-ghost-stories-draft-part-29/#comments</comments>
		<pubDate>Fri, 06 Jun 2008 02:50:22 +0000</pubDate>
		<dc:creator>xadmin</dc:creator>
		
		<category><![CDATA[programming]]></category>

		<category><![CDATA[culture]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[doumeki]]></category>

		<category><![CDATA[emergency]]></category>

		<category><![CDATA[entertainment]]></category>

		<category><![CDATA[girl]]></category>

		<category><![CDATA[guilty-gear]]></category>

		<category><![CDATA[hallway]]></category>

		<category><![CDATA[june-2008]]></category>

		<category><![CDATA[kurogane]]></category>

		<category><![CDATA[language]]></category>

		<category><![CDATA[music]]></category>

		<category><![CDATA[rallamajoop]]></category>

		<category><![CDATA[sakura]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[syaoran]]></category>

		<category><![CDATA[technology]]></category>

		<category><![CDATA[thread]]></category>

		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://inputfiltering.com/input_filtering/the-telling-of-one-billion-ghost-stories-draft-part-29/</guid>
		<description><![CDATA[Few resources were being wasted on an escape tunnel that would rarely be used. The far end brought them to a set of double doors, these ones opening with no more than a simple latch. Once inside, further high security had been made &#8230;
]]></description>
			<content:encoded><![CDATA[<p>Few resources were being wasted on an <b>escape</b> tunnel that would rarely be used. The far end brought them to a set of double doors, these ones opening with no more than a simple latch. Once inside, further high <b>security</b> had been made <b>&#8230;</b></p>
]]></content:encoded>
			<wfw:commentRss>http://inputfiltering.com/programming/the-telling-of-one-billion-ghost-stories-draft-part-29/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Top 10 Linux Commands Anyone Can Use</title>
		<link>http://inputfiltering.com/programming/top-10-linux-commands-anyone-can-use/</link>
		<comments>http://inputfiltering.com/programming/top-10-linux-commands-anyone-can-use/#comments</comments>
		<pubDate>Fri, 06 Jun 2008 01:24:07 +0000</pubDate>
		<dc:creator>xadmin</dc:creator>
		
		<category><![CDATA[programming]]></category>

		<category><![CDATA[appsec]]></category>

		<category><![CDATA[archives]]></category>

		<category><![CDATA[article]]></category>

		<category><![CDATA[categories]]></category>

		<category><![CDATA[command]]></category>

		<category><![CDATA[commands]]></category>

		<category><![CDATA[conclusion]]></category>

		<category><![CDATA[copyright]]></category>

		<category><![CDATA[file]]></category>

		<category><![CDATA[lawsuit]]></category>

		<category><![CDATA[linux]]></category>

		<category><![CDATA[linux-commands]]></category>

		<category><![CDATA[linux-security]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[recent-entries]]></category>

		<category><![CDATA[secure]]></category>

		<category><![CDATA[ubuntu]]></category>

		<category><![CDATA[utility]]></category>

		<category><![CDATA[web application security]]></category>

		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://inputfiltering.com/input_filtering/top-10-linux-commands-anyone-can-use/</guid>
		<description><![CDATA[This command receives input from STDIN (Standard Input) and allows  you to page through the output. This is useful with the command mentioned above. What if you have too much data for your shellâ€™s output buffer? You canâ€™t scroll up. &#8230;
]]></description>
			<content:encoded><![CDATA[<p>This command receives <b>input</b> from STDIN (Standard <b>Input</b>) and allows  you to page through the output. This is useful with the command mentioned above. What if you have too much data for your shellâ€™s output buffer? You canâ€™t scroll up. <b>&#8230;</b></p>
]]></content:encoded>
			<wfw:commentRss>http://inputfiltering.com/programming/top-10-linux-commands-anyone-can-use/feed/</wfw:commentRss>
		</item>
		<item>
		<title>DoS attacks using wildcards</title>
		<link>http://inputfiltering.com/filtering-input/dos-attacks-using-wildcards/</link>
		<comments>http://inputfiltering.com/filtering-input/dos-attacks-using-wildcards/#comments</comments>
		<pubDate>Thu, 05 Jun 2008 20:05:11 +0000</pubDate>
		<dc:creator>xadmin</dc:creator>
		
		<category><![CDATA[filtering input]]></category>

		<category><![CDATA[application]]></category>

		<category><![CDATA[calendar]]></category>

		<category><![CDATA[code]]></category>

		<category><![CDATA[cricket]]></category>

		<category><![CDATA[data]]></category>

		<category><![CDATA[database]]></category>

		<category><![CDATA[festivals]]></category>

		<category><![CDATA[finance]]></category>

		<category><![CDATA[iit-nbspmadness]]></category>

		<category><![CDATA[internet]]></category>

		<category><![CDATA[programming]]></category>

		<category><![CDATA[recent-posts]]></category>

		<category><![CDATA[recent-readers]]></category>

		<category><![CDATA[search]]></category>

		<category><![CDATA[secure code]]></category>

		<category><![CDATA[secure programming]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[sql-injection]]></category>

		<category><![CDATA[technology]]></category>

		<category><![CDATA[thelastpaladin]]></category>

		<guid isPermaLink="false">http://inputfiltering.com/input_filtering/dos-attacks-using-wildcards/</guid>
		<description><![CDATA[Say, your web application processes all this data and shows it back to the user, and your code doesnâ€™t  check number of records that has been asked for, then your application is also affected. An application level DoS. &#8230;
]]></description>
			<content:encoded><![CDATA[<p>Say, your <b>web application</b> processes all this data and shows it back to the user, and your code doesnâ€™t  check number of records that has been asked for, then your application is also affected. An application level DoS. <b>&#8230;</b></p>
]]></content:encoded>
			<wfw:commentRss>http://inputfiltering.com/filtering-input/dos-attacks-using-wildcards/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Re: Best practice for validation</title>
		<link>http://inputfiltering.com/filtering-input/re-best-practice-for-validation/</link>
		<comments>http://inputfiltering.com/filtering-input/re-best-practice-for-validation/#comments</comments>
		<pubDate>Thu, 05 Jun 2008 07:26:21 +0000</pubDate>
		<dc:creator>xadmin</dc:creator>
		
		<category><![CDATA[filtering input]]></category>

		<category><![CDATA[browser]]></category>

		<category><![CDATA[can-enable]]></category>

		<category><![CDATA[frame-setting]]></category>

		<category><![CDATA[math-max]]></category>

		<category><![CDATA[nabble-custom]]></category>

		<category><![CDATA[nabble-embed]]></category>

		<category><![CDATA[nabble-get]]></category>

		<category><![CDATA[nabble-init]]></category>

		<category><![CDATA[nabble-knows]]></category>

		<category><![CDATA[nabble-page]]></category>

		<category><![CDATA[nabble-post]]></category>

		<category><![CDATA[nabble-set]]></category>

		<category><![CDATA[secure code]]></category>

		<category><![CDATA[shown-because]]></category>

		<category><![CDATA[skin]]></category>

		<category><![CDATA[topic]]></category>

		<category><![CDATA[var-back]]></category>

		<category><![CDATA[var-rows]]></category>

		<category><![CDATA[var-topic]]></category>

		<category><![CDATA[your-browser]]></category>

		<guid isPermaLink="false">http://inputfiltering.com/input_filtering/re-best-practice-for-validation/</guid>
		<description><![CDATA[Zend_Form handles input filtering, so it can be dropped in as a > replacement for Zend_Filter_Input (another option you didn&#8217;t specify) as > an input filter for your model. Just because Zend_Form _can_ render &#8230;
]]></description>
			<content:encoded><![CDATA[<p>Zend_Form handles <b>input filtering</b>, so it can be dropped in as a > replacement for Zend_Filter_Input (another option you didn&#8217;t specify) as > an input filter for your model. Just because Zend_Form _can_ render <b>&#8230;</b></p>
]]></content:encoded>
			<wfw:commentRss>http://inputfiltering.com/filtering-input/re-best-practice-for-validation/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PHP Security / SQL Security - Part 1</title>
		<link>http://inputfiltering.com/programming/php-security-sql-security-part-1/</link>
		<comments>http://inputfiltering.com/programming/php-security-sql-security-part-1/#comments</comments>
		<pubDate>Thu, 05 Jun 2008 07:23:00 +0000</pubDate>
		<dc:creator>xadmin</dc:creator>
		
		<category><![CDATA[programming]]></category>

		<category><![CDATA[ajax]]></category>

		<category><![CDATA[browser]]></category>

		<category><![CDATA[code]]></category>

		<category><![CDATA[command]]></category>

		<category><![CDATA[data]]></category>

		<category><![CDATA[database]]></category>

		<category><![CDATA[filtering input]]></category>

		<category><![CDATA[html]]></category>

		<category><![CDATA[include-data]]></category>

		<category><![CDATA[include-name]]></category>

		<category><![CDATA[linux]]></category>

		<category><![CDATA[loop-values]]></category>

		<category><![CDATA[problems]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[sql]]></category>

		<category><![CDATA[sql-injection]]></category>

		<category><![CDATA[user]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[web application security]]></category>

		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://inputfiltering.com/input_filtering/php-security-sql-security-part-1/</guid>
		<description><![CDATA[Combining the above techniques to provide stripping of tags, escaping of special shell characters,  entity-quoting of HTML and regular expression-based input validation, it is possible to construct secure web scripts with relatively &#8230;
]]></description>
			<content:encoded><![CDATA[<p>Combining the above techniques to provide stripping of tags, <b>escaping</b> of special shell characters,  entity-quoting of HTML and regular expression-based <b>input</b> validation, it is possible to construct secure web scripts with relatively <b>&#8230;</b></p>
]]></content:encoded>
			<wfw:commentRss>http://inputfiltering.com/programming/php-security-sql-security-part-1/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PHP / SQL Security - Part 2</title>
		<link>http://inputfiltering.com/security/php-sql-security-part-2/</link>
		<comments>http://inputfiltering.com/security/php-sql-security-part-2/#comments</comments>
		<pubDate>Thu, 05 Jun 2008 07:22:00 +0000</pubDate>
		<dc:creator>xadmin</dc:creator>
		
		<category><![CDATA[security]]></category>

		<category><![CDATA[ajax]]></category>

		<category><![CDATA[collaboration]]></category>

		<category><![CDATA[command]]></category>

		<category><![CDATA[data]]></category>

		<category><![CDATA[database]]></category>

		<category><![CDATA[entire]]></category>

		<category><![CDATA[file]]></category>

		<category><![CDATA[frameworks]]></category>

		<category><![CDATA[include-data]]></category>

		<category><![CDATA[include-name]]></category>

		<category><![CDATA[language]]></category>

		<category><![CDATA[linux]]></category>

		<category><![CDATA[php-frameworks]]></category>

		<category><![CDATA[sql]]></category>

		<category><![CDATA[sql-injection]]></category>

		<category><![CDATA[the-database]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[web application security]]></category>

		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://inputfiltering.com/input_filtering/php-sql-security-part-2/</guid>
		<description><![CDATA[In the previous article, I looked at processing and securing user input when it is to be redisplayed or executed as PHP code. Now its time to consider entering that data into a database, and cover the security issues which arise when &#8230;
]]></description>
			<content:encoded><![CDATA[<p>In the previous article, I looked at processing and securing <b>user input</b> when it is to be redisplayed or executed as PHP code. Now its time to consider entering that data into a database, and cover the <b>security</b> issues which arise when <b>&#8230;</b></p>
]]></content:encoded>
			<wfw:commentRss>http://inputfiltering.com/security/php-sql-security-part-2/feed/</wfw:commentRss>
		</item>
		<item>
		<title>RailsConf 2008 Recap</title>
		<link>http://inputfiltering.com/programming/railsconf-2008-recap/</link>
		<comments>http://inputfiltering.com/programming/railsconf-2008-recap/#comments</comments>
		<pubDate>Tue, 03 Jun 2008 21:41:45 +0000</pubDate>
		<dc:creator>xadmin</dc:creator>
		
		<category><![CDATA[programming]]></category>

		<category><![CDATA[apple]]></category>

		<category><![CDATA[chicago]]></category>

		<category><![CDATA[coding]]></category>

		<category><![CDATA[concert]]></category>

		<category><![CDATA[conference]]></category>

		<category><![CDATA[database]]></category>

		<category><![CDATA[datamapper]]></category>

		<category><![CDATA[guitar]]></category>

		<category><![CDATA[loosely-joined]]></category>

		<category><![CDATA[minnesota]]></category>

		<category><![CDATA[nintendo]]></category>

		<category><![CDATA[photography]]></category>

		<category><![CDATA[presenter-class]]></category>

		<category><![CDATA[random]]></category>

		<category><![CDATA[ruby]]></category>

		<category><![CDATA[ruby-on-rails]]></category>

		<category><![CDATA[small-things]]></category>

		<category><![CDATA[video-games]]></category>

		<category><![CDATA[web]]></category>

		<category><![CDATA[written-fast]]></category>

		<guid isPermaLink="false">http://inputfiltering.com/input_filtering/railsconf-2008-recap/</guid>
		<description><![CDATA[Take advantage of the quote() function to sanitize user input (for SQL). Cross Site Scripting preventive measures: SafeERb, XSS Shield, Manual Escaping with h(). Tarantula plugin crawls everything and performs form fuzzing. &#8230;
]]></description>
			<content:encoded><![CDATA[<p>Take advantage of the quote() function to sanitize user <b>input</b> (for SQL). Cross Site Scripting preventive measures: SafeERb, XSS Shield, Manual <b>Escaping</b> with h(). Tarantula plugin crawls everything and performs form fuzzing. <b>&#8230;</b></p>
]]></content:encoded>
			<wfw:commentRss>http://inputfiltering.com/programming/railsconf-2008-recap/feed/</wfw:commentRss>
		</item>
		<item>
		<title>[WEB SECURITY] question about anti-xss applicability of PHP&#39;s &#8230;</title>
		<link>http://inputfiltering.com/security/web-security-question-about-anti-xss-applicability-of-phps/</link>
		<comments>http://inputfiltering.com/security/web-security-question-about-anti-xss-applicability-of-phps/#comments</comments>
		<pubDate>Mon, 02 Jun 2008 22:37:00 +0000</pubDate>
		<dc:creator>xadmin</dc:creator>
		
		<category><![CDATA[security]]></category>

		<category><![CDATA[basil-brush]]></category>

		<category><![CDATA[black]]></category>

		<category><![CDATA[comics]]></category>

		<category><![CDATA[corgi-comics]]></category>

		<category><![CDATA[corgi-toys]]></category>

		<category><![CDATA[data-recovery]]></category>

		<category><![CDATA[forbidden-sneak]]></category>

		<category><![CDATA[include-name]]></category>

		<category><![CDATA[input filtering]]></category>

		<category><![CDATA[instant-support]]></category>

		<category><![CDATA[loop-values]]></category>

		<category><![CDATA[magic-roundabout]]></category>

		<category><![CDATA[model]]></category>

		<category><![CDATA[roundabout]]></category>

		<category><![CDATA[rumble]]></category>

		<category><![CDATA[secure]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<category><![CDATA[web]]></category>

		<category><![CDATA[yellow]]></category>

		<guid isPermaLink="false">http://inputfiltering.com/input_filtering/web-security-question-about-anti-xss-applicability-of-phps/</guid>
		<description><![CDATA[Hi all,I&#8217;ve been trusting PHP&#8217;s htmlentities() to escape to HTML for a long time now on several customer site and I want to be sure that it&#8217;s secure. I am specifying UTF-8 as my charset in XHTML headers, so I don&#8217;t think alternative &#8230;
]]></description>
			<content:encoded><![CDATA[<p>Hi all,I&#8217;ve been trusting PHP&#8217;s htmlentities() to <b>escape</b> to HTML for a long time now on several customer site and I want to be sure that it&#8217;s secure. I am specifying UTF-8 as my charset in XHTML headers, so I don&#8217;t think alternative <b>&#8230;</b></p>
]]></content:encoded>
			<wfw:commentRss>http://inputfiltering.com/security/web-security-question-about-anti-xss-applicability-of-phps/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
