<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 6th OWASP Conference</title>
	<atom:link href="http://www.gnucitizen.org/blog/6th-owasp-conference/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/6th-owasp-conference/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Attacking Password Recovery Facilities &#124; ::: Dz Geniuses Team :::</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-125987</link>
		<dc:creator>Attacking Password Recovery Facilities &#124; ::: Dz Geniuses Team :::</dc:creator>
		<pubDate>Mon, 16 Feb 2009 09:30:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-125987</guid>
		<description>[...] services to facilitate the process of extracting information even more. I recommend checking out pdp’s research on this [...]</description>
		<content:encoded><![CDATA[<p>[...] services to facilitate the process of extracting information even more. I recommend checking out pdp’s research on this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yahoo Site Explorer Spider &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-125660</link>
		<dc:creator>Yahoo Site Explorer Spider &#124; GNUCITIZEN</dc:creator>
		<pubDate>Wed, 28 Jan 2009 13:45:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-125660</guid>
		<description>[...] I&#8217;ve being talking about client-side spiders for quite some time now over here and here and I even came up with POC based on Yahoo Pipes for my OWASP presentation on Advanced Web Hacking Reveled, which you can find over there. [...]</description>
		<content:encoded><![CDATA[<p>[...] I&#8217;ve being talking about client-side spiders for quite some time now over here and here and I even came up with POC based on Yahoo Pipes for my OWASP presentation on Advanced Web Hacking Reveled, which you can find over there. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yahoo Pipes becomes Mage Powerful &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-40495</link>
		<dc:creator>Yahoo Pipes becomes Mage Powerful &#124; GNUCITIZEN</dc:creator>
		<pubDate>Mon, 13 Aug 2007 22:48:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-40495</guid>
		<description>[...] and can enable JavaScript to do things that where hardly imaginable a couple of year ago. I discussed most of these security aspects in my talk at this year OWASP in Italy and also come up with several [...]</description>
		<content:encoded><![CDATA[<p>[...] and can enable JavaScript to do things that where hardly imaginable a couple of year ago. I discussed most of these security aspects in my talk at this year OWASP in Italy and also come up with several [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-35579</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sun, 15 Jul 2007 20:03:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-35579</guid>
		<description>&lt;div class=&quot;message&quot;&gt;Due to the fact that Yahoo is constantly changing their services, you might not be able to successfully execute this POC. At the time of publishing, the POC was working successfully.&lt;/div&gt;</description>
		<content:encoded><![CDATA[<div class="message">Due to the fact that Yahoo is constantly changing their services, you might not be able to successfully execute this POC. At the time of publishing, the POC was working successfully.</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: XSSDB Elite &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-34615</link>
		<dc:creator>XSSDB Elite &#124; GNUCITIZEN</dc:creator>
		<pubDate>Sun, 08 Jul 2007 19:22:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-34615</guid>
		<description>[...] why I targeted this website in particular in my research on hacking Web2.0 services/applications (Advanced Web Hacking Revealed), presented at OWASP, Italy 2007. During the conference, I discussed how attackers can use Dapper [...]</description>
		<content:encoded><![CDATA[<p>[...] why I targeted this website in particular in my research on hacking Web2.0 services/applications (Advanced Web Hacking Revealed), presented at OWASP, Italy 2007. During the conference, I discussed how attackers can use Dapper [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Attacking Password Recovery Facilities &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-34157</link>
		<dc:creator>Attacking Password Recovery Facilities &#124; GNUCITIZEN</dc:creator>
		<pubDate>Fri, 06 Jul 2007 08:58:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-34157</guid>
		<description>[...] services to facilitate the process of extracting information even more. I recommend checking out pdp&#8217;s research on this [...]</description>
		<content:encoded><![CDATA[<p>[...] services to facilitate the process of extracting information even more. I recommend checking out pdp&#8217;s research on this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; Google Hacking Database</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-22966</link>
		<dc:creator>GNUCITIZEN &#187; Google Hacking Database</dc:creator>
		<pubDate>Mon, 21 May 2007 13:24:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-22966</guid>
		<description>[...] demonstration materials from my OWASP talk or read the follow up post over here. &#187; launch &#124; &#187; trackback &#124; &#187; digg it &#124; bookmark it with &#187; del.icio.us &#124; written by &#187;pdp [...]</description>
		<content:encoded><![CDATA[<p>[...] demonstration materials from my OWASP talk or read the follow up post over here. &raquo; launch | &raquo; trackback | &raquo; digg it | bookmark it with &raquo; del.icio.us | written by &raquo;pdp [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-22765</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sun, 20 May 2007 07:55:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-22765</guid>
		<description>yes, it is possible and very probable that it will happen!</description>
		<content:encoded><![CDATA[<p>yes, it is possible and very probable that it will happen!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MacGyveR</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-22682</link>
		<dc:creator>MacGyveR</dc:creator>
		<pubDate>Sat, 19 May 2007 13:51:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-22682</guid>
		<description>Have you thought of implementing redundancy on the tinyFS by using other such services in a type of software raid manner. striping or mirroring could be done here, giving potenial worms etc. a fallback if one service blocks them.</description>
		<content:encoded><![CDATA[<p>Have you thought of implementing redundancy on the tinyFS by using other such services in a type of software raid manner. striping or mirroring could be done here, giving potenial worms etc. a fallback if one service blocks them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-22340</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 18 May 2007 07:36:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-22340</guid>
		<description>&lt;div class=&quot;message&quot;&gt;Unfortunately, PIPEs is down again. I suspect Yahoo has some serious problems. I have never seen anything like that before.&lt;/div&gt;</description>
		<content:encoded><![CDATA[<div class="message">Unfortunately, PIPEs is down again. I suspect Yahoo has some serious problems. I have never seen anything like that before.</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-22187</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 17 May 2007 20:00:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-22187</guid>
		<description>To me, the Web is one gigantic operating system with hundreds of APIs and syscalls. The browser is our shell from where we can access the WebOS features. TinyURL, although just URL shrinking service, can be used as a storage mechanism as you pointed out long time ago. However, I seriously doubt that no one has thought that this functionality will be available to JavaScript as well. Similar types of setups can significantly increase the attack surface of web based malware written entirely in JavaScript.</description>
		<content:encoded><![CDATA[<p>To me, the Web is one gigantic operating system with hundreds of APIs and syscalls. The browser is our shell from where we can access the WebOS features. TinyURL, although just URL shrinking service, can be used as a storage mechanism as you pointed out long time ago. However, I seriously doubt that no one has thought that this functionality will be available to JavaScript as well. Similar types of setups can significantly increase the attack surface of web based malware written entirely in JavaScript.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Acidus</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-22183</link>
		<dc:creator>Acidus</dc:creator>
		<pubDate>Thu, 17 May 2007 19:49:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-22183</guid>
		<description>HAHA! That&#039;s awesome! I did some work against TinyURL a year or so back with TinyDisk (http://www.msblabs.org/tinydisk). Glad to see someone else using it as a data storage system!

Go pdp!</description>
		<content:encoded><![CDATA[<p>HAHA! That&#8217;s awesome! I did some work against TinyURL a year or so back with TinyDisk (<a href="http://www.msblabs.org/tinydisk" rel="nofollow">http://www.msblabs.org/tinydisk</a>). Glad to see someone else using it as a data storage system!</p>
<p>Go pdp!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-22178</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 17 May 2007 19:28:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-22178</guid>
		<description>&lt;div class=&quot;message&quot;&gt;Yahoo PIPEs is back. POCs work.&lt;/div&gt;</description>
		<content:encoded><![CDATA[<div class="message">Yahoo PIPEs is back. POCs work.</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/6th-owasp-conference/comment-page-1/#comment-22102</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 17 May 2007 12:41:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/6th-owasp-conference#comment-22102</guid>
		<description>&lt;div class=&quot;message&quot;&gt;Yahoo PIPEs is down for now. Give Yahoo some time to fix the mess, then try the POCs.&lt;/div&gt;</description>
		<content:encoded><![CDATA[<div class="message">Yahoo PIPEs is down for now. Give Yahoo some time to fix the mess, then try the POCs.</div>
]]></content:encoded>
	</item>
</channel>
</rss>
