<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: OWASP (Open Web Application Security Project) Testing Guide v3 Released</title>
	<atom:link href="http://www.darknet.org.uk/2009/01/owasp-open-web-application-security-project-testing-guide-v3-released/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2009/01/owasp-open-web-application-security-project-testing-guide-v3-released/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sun, 08 Nov 2009 07:15:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bogwitch</title>
		<link>http://www.darknet.org.uk/2009/01/owasp-open-web-application-security-project-testing-guide-v3-released/#comment-125371</link>
		<dc:creator>Bogwitch</dc:creator>
		<pubDate>Mon, 12 Jan 2009 17:55:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1375#comment-125371</guid>
		<description>The security assessments I have performed indicates that website developers and application developers have never heard of OWASP. When pointed to OWASP the remarks are often &quot;But that&#039;s about security, not web design&quot; - and I think the problem stems from there. Web designers are all-to-often graphic artists, and have cut their teeth in environments where the application software they need to run, runs with elevated privileges, they have access to large portions of systems to aid in publication of content and therefore believe they are above security or that it doesn&#039;t apply to them.</description>
		<content:encoded><![CDATA[<p>The security assessments I have performed indicates that website developers and application developers have never heard of OWASP. When pointed to OWASP the remarks are often &#8220;But that&#8217;s about security, not web design&#8221; &#8211; and I think the problem stems from there. Web designers are all-to-often graphic artists, and have cut their teeth in environments where the application software they need to run, runs with elevated privileges, they have access to large portions of systems to aid in publication of content and therefore believe they are above security or that it doesn&#8217;t apply to them.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
