<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Submit Your Top Web Hacking Techniques for 2008</title>
	<atom:link href="http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: a tale of a fateful trip &#171; fields of serenity</title>
		<link>http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/comment-page-1/#comment-126005</link>
		<dc:creator>a tale of a fateful trip &#171; fields of serenity</dc:creator>
		<pubDate>Wed, 18 Feb 2009 06:35:21 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2405#comment-126005</guid>
		<description>[...] Submit Your Top Web Hacking Techniques for 2008//GNUcitizen [...]</description>
		<content:encoded><![CDATA[<p>[...] Submit Your Top Web Hacking Techniques for 2008//GNUcitizen [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LonerVamp</title>
		<link>http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/comment-page-1/#comment-125958</link>
		<dc:creator>LonerVamp</dc:creator>
		<pubDate>Fri, 13 Feb 2009 17:10:58 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2405#comment-125958</guid>
		<description>Kinda like asking one person or even a team of people to secure everything in a company, you can&#039;t ask one person, team, group of judges, or even a general representation of your traffic/hits to poop out a list of the best things.

There will always be some person or group of another pdp who feels slighted or does not agree with the weighting or feels something was left out of wrongly included. Let alone getting respectful concensus inside the group itself! &quot;Bah, take my name off the list because I disagree!&quot;

I think that&#039;s going to be the nature of something like a list of top hacks or techniques or issues.

By the way, democracy does not always work. I would much rather have a good panel of judges rather than the dirty masses of the public...

The best I hope for in lists like this are as follows:
- eventual consistency (in scope and definitions)
- possible information that I didn&#039;t know before
- opinions from experts on what I should care about in my enterprise

That actual ordering or bragging rights on things like this are not important and will forever be open to debate by everyone.</description>
		<content:encoded><![CDATA[<p>Kinda like asking one person or even a team of people to secure everything in a company, you can&#8217;t ask one person, team, group of judges, or even a general representation of your traffic/hits to poop out a list of the best things.</p>
<p>There will always be some person or group of another pdp who feels slighted or does not agree with the weighting or feels something was left out of wrongly included. Let alone getting respectful concensus inside the group itself! &#8220;Bah, take my name off the list because I disagree!&#8221;</p>
<p>I think that&#8217;s going to be the nature of something like a list of top hacks or techniques or issues.</p>
<p>By the way, democracy does not always work. I would much rather have a good panel of judges rather than the dirty masses of the public&#8230;</p>
<p>The best I hope for in lists like this are as follows:<br />
- eventual consistency (in scope and definitions)<br />
- possible information that I didn&#8217;t know before<br />
- opinions from experts on what I should care about in my enterprise</p>
<p>That actual ordering or bragging rights on things like this are not important and will forever be open to debate by everyone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: XanthiX</title>
		<link>http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/comment-page-1/#comment-125858</link>
		<dc:creator>XanthiX</dc:creator>
		<pubDate>Sat, 07 Feb 2009 00:31:12 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2405#comment-125858</guid>
		<description>From my personal point of view the top web hacking technique for 2008 is XSS via Adobe Flash which is still active in current version of Adobe Flash pluggin. I have successfully tested XSS keylogger  via this attack vector and in my opinion this vector has potential to become very dangerous for the future, if not fixed.</description>
		<content:encoded><![CDATA[<p>From my personal point of view the top web hacking technique for 2008 is XSS via Adobe Flash which is still active in current version of Adobe Flash pluggin. I have successfully tested XSS keylogger  via this attack vector and in my opinion this vector has potential to become very dangerous for the future, if not fixed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/comment-page-1/#comment-125801</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 02 Feb 2009 15:18:24 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2405#comment-125801</guid>
		<description>haha :), ok, ok... I understand that it may look like that but this is definitely not the case :) just trying to improve the way these things are handled in the future. and there is alway room for improvements. I am interested what the judges will come with.</description>
		<content:encoded><![CDATA[<p>haha :), ok, ok&#8230; I understand that it may look like that but this is definitely not the case :) just trying to improve the way these things are handled in the future. and there is alway room for improvements. I am interested what the judges will come with.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremiah</title>
		<link>http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/comment-page-1/#comment-125788</link>
		<dc:creator>Jeremiah</dc:creator>
		<pubDate>Mon, 02 Feb 2009 01:29:51 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2405#comment-125788</guid>
		<description>Is that a subtle way of saying you want on the judges panel? ;) I would have asked you actually, but you were in the running for the top ten. Needed to limit bias. Would have also been the case for the &quot;30-50&quot; others likely. That&#039;s why no RSnake and a bunch of other researchers. 

Had to choose some solid security people with some webappsec background.</description>
		<content:encoded><![CDATA[<p>Is that a subtle way of saying you want on the judges panel? ;) I would have asked you actually, but you were in the running for the top ten. Needed to limit bias. Would have also been the case for the &#8220;30-50&#8243; others likely. That&#8217;s why no RSnake and a bunch of other researchers. </p>
<p>Had to choose some solid security people with some webappsec background.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/comment-page-1/#comment-125785</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sun, 01 Feb 2009 22:34:27 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2405#comment-125785</guid>
		<description>J,

why didn&#039;t you form an internal group/mail list of experts, 30-50 people, to form the list of web hacking techniques and decide between each other which one is the best? that way, the whole thing will be consistent from start.</description>
		<content:encoded><![CDATA[<p>J,</p>
<p>why didn&#8217;t you form an internal group/mail list of experts, 30-50 people, to form the list of web hacking techniques and decide between each other which one is the best? that way, the whole thing will be consistent from start.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremiah</title>
		<link>http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/comment-page-1/#comment-125784</link>
		<dc:creator>Jeremiah</dc:creator>
		<pubDate>Sun, 01 Feb 2009 20:47:13 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2405#comment-125784</guid>
		<description>There were a couple of factors that went into my decision for this year. And remember, last year I did an open vote system via survey monkey.

1) Ballot stuffing last year was a real problem. My decision had nothing to do with the &quot;security&quot; of a site, but a lot more to do with the amount of workload involved.

2) While we got results last year I felt were representative of the communities vote, myself and several others did not feel it was accurate. At least a couple very powerful attacks were left off the list and should have easily overtaken others. 

So for this year I felt it would be better to leave it to a solid panel of experts that could fully investigate the merits of the attacks to come up with a better list. Will it be perfect? No, of course not, impossible to make everyone happy. Will it be better than last year? Yes, that is my hope.</description>
		<content:encoded><![CDATA[<p>There were a couple of factors that went into my decision for this year. And remember, last year I did an open vote system via survey monkey.</p>
<p>1) Ballot stuffing last year was a real problem. My decision had nothing to do with the &#8220;security&#8221; of a site, but a lot more to do with the amount of workload involved.</p>
<p>2) While we got results last year I felt were representative of the communities vote, myself and several others did not feel it was accurate. At least a couple very powerful attacks were left off the list and should have easily overtaken others. </p>
<p>So for this year I felt it would be better to leave it to a solid panel of experts that could fully investigate the merits of the attacks to come up with a better list. Will it be perfect? No, of course not, impossible to make everyone happy. Will it be better than last year? Yes, that is my hope.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/comment-page-1/#comment-125781</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sun, 01 Feb 2009 18:26:56 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2405#comment-125781</guid>
		<description>sometimes security experts are just keen on not taking the risk so that they can have clean names :) although we all know that people make mistakes, regardless how good they are. it is a proven fact.</description>
		<content:encoded><![CDATA[<p>sometimes security experts are just keen on not taking the risk so that they can have clean names :) although we all know that people make mistakes, regardless how good they are. it is a proven fact.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: torstein</title>
		<link>http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/comment-page-1/#comment-125772</link>
		<dc:creator>torstein</dc:creator>
		<pubDate>Sun, 01 Feb 2009 13:12:50 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2405#comment-125772</guid>
		<description>If you - of all people - can&#039;t secure a webapp, Jeremiah, how can you expect anyone else to?

(no offence)</description>
		<content:encoded><![CDATA[<p>If you &#8211; of all people &#8211; can&#8217;t secure a webapp, Jeremiah, how can you expect anyone else to?</p>
<p>(no offence)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/comment-page-1/#comment-125723</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 30 Jan 2009 09:32:03 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2405#comment-125723</guid>
		<description>I don&#039;t know J :) Saying this is like saying that there is no point of securing Web Application as they will get hacked eventually. I think that it can be done and it can be made secure too. Here is something that wont be easy to trick.

&lt;pre&gt;&lt;code&gt;Recaptcha + Email Verification = Vote you should be able to trust!&lt;/code&gt;&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<p>I don&#8217;t know J :) Saying this is like saying that there is no point of securing Web Application as they will get hacked eventually. I think that it can be done and it can be made secure too. Here is something that wont be easy to trick.</p>
<pre><code>Recaptcha + Email Verification = Vote you should be able to trust!</code></pre>
]]></content:encoded>
	</item>
	<item>
		<title>By: jeremiah</title>
		<link>http://www.gnucitizen.org/blog/submit-your-top-web-hacking-techniques-for-2008/comment-page-1/#comment-125700</link>
		<dc:creator>jeremiah</dc:creator>
		<pubDate>Fri, 30 Jan 2009 00:45:42 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2405#comment-125700</guid>
		<description>I&#039;d preferred to have an open voting system decide the eventual outcome, if fact, this is what I did the last time. However, when doing this in the midst of a bunch of Web hackers, its a bit easier said than done. :) What if we used a public voting system create a short list and let the judges order the final 10. Or, perhaps the other way around?</description>
		<content:encoded><![CDATA[<p>I&#8217;d preferred to have an open voting system decide the eventual outcome, if fact, this is what I did the last time. However, when doing this in the midst of a bunch of Web hackers, its a bit easier said than done. :) What if we used a public voting system create a short list and let the judges order the final 10. Or, perhaps the other way around?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
