<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: AJAX: Is your application secure enough?</title>
	<atom:link href="http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Fri, 08 Aug 2008 21:36:11 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: eM3rC</title>
		<link>http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-113322</link>
		<dc:creator>eM3rC</dc:creator>
		<pubDate>Fri, 22 Feb 2008 02:33:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-113322</guid>
		<description>Thanks Mike for the post!

I hadn't heard of that program before but from what you been saying it sounds like a good piece of software to add for a network security person's arsenal.</description>
		<content:encoded><![CDATA[<p>Thanks Mike for the post!</p>
<p>I hadn&#8217;t heard of that program before but from what you been saying it sounds like a good piece of software to add for a network security person&#8217;s arsenal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-113294</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Thu, 21 Feb 2008 23:57:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-113294</guid>
		<description>"Analysing HTTP traffic analysis with tools like ethereal (yeh I like GUIs so sue me) surely comes in handy to figure out whether applications you use are actually safe from exploitation. This application allows one to easily filter and follow TCP streams so one can properly analyse what is happening there."

I couldn't agree more.  My company uses Network Instruments Observer (&lt;a href="http://www.networkinstruments.com" rel="nofollow"&gt;http://www.networkinstruments.com&lt;/a&gt;) and it works like a charm.

Cheers,
Mike</description>
		<content:encoded><![CDATA[<p>&#8220;Analysing HTTP traffic analysis with tools like ethereal (yeh I like GUIs so sue me) surely comes in handy to figure out whether applications you use are actually safe from exploitation. This application allows one to easily filter and follow TCP streams so one can properly analyse what is happening there.&#8221;</p>
<p>I couldn&#8217;t agree more.  My company uses Network Instruments Observer (<a href="http://www.networkinstruments.com" rel="nofollow">http://www.networkinstruments.com</a>) and it works like a charm.</p>
<p>Cheers,<br />
Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eM3rC</title>
		<link>http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-110475</link>
		<dc:creator>eM3rC</dc:creator>
		<pubDate>Wed, 13 Feb 2008 02:33:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-110475</guid>
		<description>I can personally vouch for Acunetix and say it is an awesome vulnerability scanner. Only downside is it costs money, but if you do it for a profession I think it is worth every cent.</description>
		<content:encoded><![CDATA[<p>I can personally vouch for Acunetix and say it is an awesome vulnerability scanner. Only downside is it costs money, but if you do it for a profession I think it is worth every cent.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pantagruel</title>
		<link>http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-110272</link>
		<dc:creator>Pantagruel</dc:creator>
		<pubDate>Tue, 12 Feb 2008 18:24:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-110272</guid>
		<description>Read here for some info:

&lt;a href="http://www.jeremiahgrossman.blogspot.com/2007/10/best-web-application-vulnerability.html" rel="nofollow"&gt;http://www.jeremiahgrossman.blogspot.com/2007/10/best-web-application-vulnerability.html&lt;/a&gt;

or try acunetix

www.acunetix.com/vulnerability-scanner/</description>
		<content:encoded><![CDATA[<p>Read here for some info:</p>
<p><a href="http://www.jeremiahgrossman.blogspot.com/2007/10/best-web-application-vulnerability.html" rel="nofollow">http://www.jeremiahgrossman.blogspot.com/2007/10/best-web-application-vulnerability.html</a></p>
<p>or try acunetix</p>
<p><a href="http://www.acunetix.com/vulnerability-scanner/" rel="nofollow">http://www.acunetix.com/vulnerability-scanner/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J. Lion</title>
		<link>http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-110268</link>
		<dc:creator>J. Lion</dc:creator>
		<pubDate>Tue, 12 Feb 2008 18:12:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-110268</guid>
		<description>Is there a vulnerability scanner that can check for AJAX vulnerabilities that we can use during development (coding)?</description>
		<content:encoded><![CDATA[<p>Is there a vulnerability scanner that can check for AJAX vulnerabilities that we can use during development (coding)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-104477</link>
		<dc:creator>John</dc:creator>
		<pubDate>Tue, 29 Jan 2008 19:24:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-104477</guid>
		<description>Nice article</description>
		<content:encoded><![CDATA[<p>Nice article</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adeeb Rantawi</title>
		<link>http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-72793</link>
		<dc:creator>Adeeb Rantawi</dc:creator>
		<pubDate>Tue, 13 Nov 2007 23:09:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-72793</guid>
		<description>Please Dennis, would you guide me how to use AJAX properly? I want to learn from you and other gurus..

Please post your ways in a practical and real life example, and I will be thankful.</description>
		<content:encoded><![CDATA[<p>Please Dennis, would you guide me how to use AJAX properly? I want to learn from you and other gurus..</p>
<p>Please post your ways in a practical and real life example, and I will be thankful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dennis</title>
		<link>http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-72787</link>
		<dc:creator>Dennis</dc:creator>
		<pubDate>Tue, 13 Nov 2007 22:25:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-72787</guid>
		<description>The main problem is always bad programming style and not the language or in this case Ajax.

If u use it proberly it won't be a problem...

anyway, nice and detailed article... thx</description>
		<content:encoded><![CDATA[<p>The main problem is always bad programming style and not the language or in this case Ajax.</p>
<p>If u use it proberly it won&#8217;t be a problem&#8230;</p>
<p>anyway, nice and detailed article&#8230; thx</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AJAX Security Considerations&#8230; at M and L Adventures</title>
		<link>http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-62338</link>
		<dc:creator>AJAX Security Considerations&#8230; at M and L Adventures</dc:creator>
		<pubDate>Fri, 10 Aug 2007 12:34:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-62338</guid>
		<description>[...] so you know where to start more about AJAX security, Darknet offers some good insight on securing AJAX by explaining some of the common ways to attack AJAX [...]</description>
		<content:encoded><![CDATA[<p>[...] so you know where to start more about AJAX security, Darknet offers some good insight on securing AJAX by explaining some of the common ways to attack AJAX [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adeeb Rantawi</title>
		<link>http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-57764</link>
		<dc:creator>Adeeb Rantawi</dc:creator>
		<pubDate>Wed, 25 Apr 2007 12:38:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/#comment-57764</guid>
		<description>Unfortunately you are completely right Guy.. I wish that FireFox will support HTTP_REFERER in their XMLHttpRequest() object in near future so that AJAX scripts can be tied to running server, noting that all browsers does support it except FireFox. I will go to mozilla.org and post a wish with explanation.

For now, all I can do is to include an HTML copyright comment inside results and to append add-on links to it such as "Suggest Something", "Tell a Friend", etc., so that when user clicks it s/he will go to my web site in case results are displayed somewhere else!</description>
		<content:encoded><![CDATA[<p>Unfortunately you are completely right Guy.. I wish that FireFox will support HTTP_REFERER in their XMLHttpRequest() object in near future so that AJAX scripts can be tied to running server, noting that all browsers does support it except FireFox. I will go to mozilla.org and post a wish with explanation.</p>
<p>For now, all I can do is to include an HTML copyright comment inside results and to append add-on links to it such as &#8220;Suggest Something&#8221;, &#8220;Tell a Friend&#8221;, etc., so that when user clicks it s/he will go to my web site in case results are displayed somewhere else!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
