<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Secure By Default &#187; Uncategorized</title>
	<atom:link href="http://www.securebydefault.info/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securebydefault.info</link>
	<description>Designing, building and testing software for better security</description>
	<lastBuildDate>Mon, 09 Jan 2012 16:34:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>ORM validation</title>
		<link>http://www.securebydefault.info/2012/01/07/orm-validation/</link>
		<comments>http://www.securebydefault.info/2012/01/07/orm-validation/#comments</comments>
		<pubDate>Sat, 07 Jan 2012 18:45:20 +0000</pubDate>
		<dc:creator>stephendv</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.securebydefault.info/?p=16</guid>
		<description><![CDATA[@EoinKeary got me thinking about data validation again, in particular the security implications of relying on data val in the ORM tier when numerous attacks can be performed on the presentation and middle tiers before hitting ORM. I still prefer the approach of only defining data validation rules in one place, and that place should [...]]]></description>
		<wfw:commentRss>http://www.securebydefault.info/2012/01/07/orm-validation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HTTP Fingerprinting tool</title>
		<link>http://www.securebydefault.info/2009/11/10/http-fingerprinting-tool/</link>
		<comments>http://www.securebydefault.info/2009/11/10/http-fingerprinting-tool/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 12:23:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[http fingerprinting]]></category>

		<guid isPermaLink="false">http://www.securebydefault.info/2009/11/10/http-fingerprinting-tool/</guid>
		<description><![CDATA[A promising HTTP fingerprinting tool: http://useofwords.blogspot.com/2009/11/introducing-htrosbif.html]]></description>
		<wfw:commentRss>http://www.securebydefault.info/2009/11/10/http-fingerprinting-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI scoring contradiction</title>
		<link>http://www.securebydefault.info/2009/04/20/pci-scoring-contradiction/</link>
		<comments>http://www.securebydefault.info/2009/04/20/pci-scoring-contradiction/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 08:31:15 +0000</pubDate>
		<dc:creator>stephendv</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[CVSSv2]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.securebydefault.info/2009/04/20/pci-scoring-contradiction/</guid>
		<description><![CDATA[Risk ratings in a PCI security assessment are directly based on CVSS v2 scores, here&#8217;s an extract from CVSS v2 scoring guide: SCORING TIP #2: When scoring a vulnerability, consider the direct impact to the target host only. For example, consider a cross-site scripting vulnerability: the impact to a user&#8217;s system could be much greater [...]]]></description>
		<wfw:commentRss>http://www.securebydefault.info/2009/04/20/pci-scoring-contradiction/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

