<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-31040560</id><updated>2011-04-21T11:02:23.928-07:00</updated><title type='text'>PHP Security Project - SbanWart</title><subtitle type='html'>PHP Security Project</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://sbanwart.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31040560/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://sbanwart.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Sbanwart</name><uri>http://www.blogger.com/profile/05321317057567654223</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-31040560.post-115274450957904923</id><published>2006-07-12T15:48:00.000-07:00</published><updated>2006-07-12T15:48:29.580-07:00</updated><title type='text'>PHP Security by Example</title><content type='html'>Almost an entire month has passed since my last blog entry, and a lot has happened. I'll try to catch up over the next week or two.&lt;br /&gt;&lt;br /&gt;About a week ago, the Flash version of PHP Security by Example was Dugg.&lt;br /&gt;&lt;br /&gt;I'm always disappointed to see trolls (Digg seems to have a bigger problem with this than Slashdot), but a few of the comments raise some valid questions. I'll try to summarize and answer those here.&lt;br /&gt;&lt;br /&gt;It's true that slides are never a substitute for a talk, and this is especially true for this one, because it's a hands-on workshop. It's something Marco calls a BYOL (bring your own laptop), and it involves a lot of one-on-one attention and hand-holding.&lt;br /&gt;&lt;br /&gt;The reason it's in Flash is because the person submitting the story linked to the Flash version. :-) To be fair, the only other format available for this talk is PDF. I've been wanting to create a nice web application for viewing Keynote slides. I think the best approach might be to export the slides as images, and create a simple slide navigator. I can always continue to also offer PDF, Quicktime, and Flash formats.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31040560-115274450957904923?l=sbanwart.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sbanwart.blogspot.com/feeds/115274450957904923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31040560&amp;postID=115274450957904923' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31040560/posts/default/115274450957904923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31040560/posts/default/115274450957904923'/><link rel='alternate' type='text/html' href='http://sbanwart.blogspot.com/2006/07/php-security-by-example.html' title='PHP Security by Example'/><author><name>Sbanwart</name><uri>http://www.blogger.com/profile/05321317057567654223</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31040560.post-115274444374976360</id><published>2006-07-12T15:46:00.000-07:00</published><updated>2006-07-12T15:48:47.270-07:00</updated><title type='text'>OWASP, the Open Web Application Security Project</title><content type='html'>OWASP, the Open Web Application Security Project, is famous for its Top Ten list of security vulnerabilities. David ported the list to PHP (PHP and the OWASP Top Ten), and now OWASP has released its own PHP-specific list, the PHP Top 5: &lt;br /&gt;The PHP Top 5 is based upon attack frequency in 2005 as reported to Bugtraq. This information is a valuable insight into the most devastating attacks against the world's most popular web application framework.In 2005, OWASP collaborated with SANS to research and write a completely new PHP section to their successful Top 20 2005. The OWASP PHP Top 5 is the full unabridged text, updated to reflect recent XSS attacks and SQL injection vectors.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31040560-115274444374976360?l=sbanwart.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sbanwart.blogspot.com/feeds/115274444374976360/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31040560&amp;postID=115274444374976360' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31040560/posts/default/115274444374976360'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31040560/posts/default/115274444374976360'/><link rel='alternate' type='text/html' href='http://sbanwart.blogspot.com/2006/07/owasp-open-web-application-security.html' title='OWASP, the Open Web Application Security Project'/><author><name>Sbanwart</name><uri>http://www.blogger.com/profile/05321317057567654223</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31040560.post-115274434870143320</id><published>2006-07-12T15:45:00.000-07:00</published><updated>2006-07-12T15:45:48.710-07:00</updated><title type='text'>Home User's Security Checklist</title><content type='html'>SecurityFocus has a &lt;a href="http://www.securityfocus.com/columnists/220"&gt;nice checkbox system&lt;/a&gt; to let you score your own PC security level. Each checkbox item has a link to get more information. Using this sytem, you can check the boxes you know are 'ok' and follow-up by reading more information about the items which you are unsure.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31040560-115274434870143320?l=sbanwart.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sbanwart.blogspot.com/feeds/115274434870143320/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31040560&amp;postID=115274434870143320' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31040560/posts/default/115274434870143320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31040560/posts/default/115274434870143320'/><link rel='alternate' type='text/html' href='http://sbanwart.blogspot.com/2006/07/home-users-security-checklist.html' title='Home User&apos;s Security Checklist'/><author><name>Sbanwart</name><uri>http://www.blogger.com/profile/05321317057567654223</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31040560.post-115274061233224090</id><published>2006-07-12T14:42:00.000-07:00</published><updated>2006-07-12T15:52:37.760-07:00</updated><title type='text'>About me and PHP</title><content type='html'>Hello World&lt;br /&gt;&lt;br /&gt;My name is Sco Sban Wart :) It is my blog :) I will write about php security and put some interesting information from the net.&lt;br /&gt;&lt;br /&gt; PHP is a very popular language. Every PHP developer and hoster should understand the primary attack vectors being used by attackers against PHP applications. &lt;br /&gt;&lt;br /&gt;This article is the underlying research behind the SANS Top 20 2005's PHP section. The methodology used in the preparation of this article is to review all Bugtraq postings containing the word "PHP" and categorize each unique flaw. The author analyzed the most popular flaws / attacks, and researched prevention techniques, resulting in this article.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31040560-115274061233224090?l=sbanwart.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sbanwart.blogspot.com/feeds/115274061233224090/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31040560&amp;postID=115274061233224090' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31040560/posts/default/115274061233224090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31040560/posts/default/115274061233224090'/><link rel='alternate' type='text/html' href='http://sbanwart.blogspot.com/2006/07/about-me-and-php.html' title='About me and PHP'/><author><name>Sbanwart</name><uri>http://www.blogger.com/profile/05321317057567654223</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
