<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0" xmlns:s="http://updates.zdnet.com/">
<channel>
	<title><![CDATA[xss Resources | ZDNet]]></title>
	<link><![CDATA[http://updates.zdnet.com/tags/xss.html]]></link>
	<description><![CDATA[White papers, case studies, technical articles, and blog posts relating to xss]]></description>
	<s:counts start="0" returned="20" found="88" />
	<language>en-us</language>
	<item>
		<title><![CDATA[phpMyAdmin Plugs SQL Injection, XSS Flaws]]></title>
		<link><![CDATA[http://talkback.zdnet.com/5208-12691-0.html?forumID=1&threadID=70481&messageID=1352730&start=0]]></link>
		<description><![CDATA[More secure than Windows solutions...You can put a Linux distro facing the public Internet however you cannot put a WindowsServer on the public Internet...]]></description>
		<s:doctype><![CDATA[Discussion threads]]></s:doctype>
		<pubDate>Fri, 16 Oct 2009 11:04:00 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/microsoft+windows.html"><![CDATA[Microsoft Windows]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[SECURITY]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/sql+injection.html"><![CDATA[SQL injection]]></category>
		<category domain="http://updates.zdnet.com/tags/sql.html"><![CDATA[SQL]]></category>
	</item>
	<item>
		<title><![CDATA[phpMyAdmin Plugs SQL Injection, XSS Flaws]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=4616]]></link>
		<description><![CDATA[A new version of phpMyAdmin has been released to plug two serious security holes that could lead to SQL injection and cross-site scripting attacks. by Ryan Naraine]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Fri, 16 Oct 2009 08:47:53 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/flaw.html"><![CDATA[Flaw]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/sql.html"><![CDATA[SQL]]></category>
		<category domain="http://updates.zdnet.com/tags/sql+injection.html"><![CDATA[SQL Injection]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
	</item>
	<item>
		<title><![CDATA[Adobe plugs critical ColdFusion, JRun vulnerabilities]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=4066]]></link>
		<description><![CDATA[Adobe's never-ending run on the security treadmill hit a new gear this week with the release of patches to cover serious vulnerabilities in the ColdFusion and JRun web design and development platforms.    The patches, rated critical, cover a total of 7 vulnerabilities, some of which "could lead...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Tue, 18 Aug 2009 12:11:50 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/adobe+systems+inc..html"><![CDATA[Adobe Systems Inc.]]></category>
		<category domain="http://updates.zdnet.com/tags/macromedia+jrun.html"><![CDATA[Macromedia JRun]]></category>
		<category domain="http://updates.zdnet.com/tags/allaire+coldfusion.html"><![CDATA[Allaire ColdFusion]]></category>
		<category domain="http://updates.zdnet.com/tags/vulnerability.html"><![CDATA[Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/cross-site+scripting+vulnerability.html"><![CDATA[Cross-site Scripting Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/development+tools.html"><![CDATA[Development Tools]]></category>
		<category domain="http://updates.zdnet.com/tags/software+development.html"><![CDATA[Software Development]]></category>
		<category domain="http://updates.zdnet.com/tags/software%252fweb+development.html"><![CDATA[Software/Web Development]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
		<category domain="http://rss.financialcontent.com/stocksymbol">ADBE</category>
		<category domain="tickers">ADBE</category>
	</item>
	<item>
		<title><![CDATA[Safari 4.0.2 patches two security vulnerabilities]]></title>
		<link><![CDATA[http://blogs.zdnet.com/Apple/?p=4362]]></link>
		<description><![CDATA[Apple yesterday released Safari 4.0.2 via Software Update and recommends the update for users on all platforms.    According to Apple's typically vague "release notes" the 40.2MB update improves the stability of the Nitro JavaScript engine and includes the latest compatibility and security fixes.    According...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Wed, 08 Jul 2009 21:53:11 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/web.html"><![CDATA[Web]]></category>
		<category domain="http://updates.zdnet.com/tags/apple+safari.html"><![CDATA[Apple Safari]]></category>
		<category domain="http://updates.zdnet.com/tags/knowledgebase.html"><![CDATA[Knowledgebase]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/patch+management.html"><![CDATA[Patch Management]]></category>
		<category domain="http://updates.zdnet.com/tags/web+site.html"><![CDATA[Web Site]]></category>
		<category domain="http://updates.zdnet.com/tags/security+fix.html"><![CDATA[Security Fix]]></category>
		<category domain="http://updates.zdnet.com/tags/web+site+development.html"><![CDATA[Web Site Development]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/internet.html"><![CDATA[Internet]]></category>
		<category domain="http://updates.zdnet.com/tags/jason+d.+o%2527grady.html"><![CDATA[Jason D. O'Grady]]></category>
	</item>
	<item>
		<title><![CDATA[Apple plugs dangerous Safari security holes]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=3720]]></link>
		<description><![CDATA[Apple has released Safari 4.0.2 to fix a pair of security flaws that could lead to cross-site scripting or remote code execution attacks.    The vulnerabilities affect Safari for Windows XP and Vista and Mac OS X.    Here are the raw details:   ...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Wed, 08 Jul 2009 18:05:29 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/apple+safari.html"><![CDATA[Apple Safari]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/apple+inc..html"><![CDATA[Apple Inc.]]></category>
		<category domain="http://updates.zdnet.com/tags/safari+4.0.2.html"><![CDATA[Safari 4.0.2]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
		<category domain="http://rss.financialcontent.com/stocksymbol">AAPL</category>
		<category domain="tickers">AAPL</category>
	</item>
	<item>
		<title><![CDATA[Mozilla tackles XSS vulnerabilities with new technology]]></title>
		<link><![CDATA[http://talkback.zdnet.com/5208-12691-0.html?forumID=1&threadID=65968&messageID=1238393&start=0]]></link>
		<description><![CDATA[Mozilla tackles XSS vulnerabilities with new technologysounds kinda like SPF, but for JavaScriptVery cool!On another note, any idea's why Firefox doesn't take advantage of the Sandbox framework provided by Vista?Is it because of Vista's market share, to ease cross platform porting, or something else?It's JavaScript not Java ScriptSome purists might...]]></description>
		<s:doctype><![CDATA[Discussion threads]]></s:doctype>
		<pubDate>Mon, 22 Jun 2009 14:38:00 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/scripting+languages.html"><![CDATA[Scripting languages]]></category>
		<category domain="http://updates.zdnet.com/tags/web+browsers.html"><![CDATA[Web browsers]]></category>
		<category domain="http://updates.zdnet.com/tags/javascript.html"><![CDATA[JavaScript]]></category>
		<category domain="http://updates.zdnet.com/tags/xss+vulnerability.html"><![CDATA[XSS Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/mozilla+corp..html"><![CDATA[Mozilla Corp.]]></category>
	</item>
	<item>
		<title><![CDATA[Mozilla tackles XSS vulnerabilities with new technology]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=3654]]></link>
		<description><![CDATA[Mozilla's security engineers are working on new technology that promises to mitigate a large class of Web application vulnerabilities, especially the cross-site scripting XSS plague against modern Web browsers.    The project, called Content Security Policy, is designed to shut down XSS attacks by providing a mechanism for...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Mon, 22 Jun 2009 13:39:30 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/vulnerability.html"><![CDATA[Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/web+browser.html"><![CDATA[Web Browser]]></category>
		<category domain="http://updates.zdnet.com/tags/mozilla+corp..html"><![CDATA[Mozilla Corp.]]></category>
		<category domain="http://updates.zdnet.com/tags/web+browsers.html"><![CDATA[Web Browsers]]></category>
		<category domain="http://updates.zdnet.com/tags/internet.html"><![CDATA[Internet]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
	</item>
	<item>
		<title><![CDATA[StrongWebmail CEO's mail account hacked via XSS]]></title>
		<link><![CDATA[http://talkback.zdnet.com/5208-12691-0.html?forumID=1&threadID=65301&messageID=1219747&start=0]]></link>
		<description><![CDATA[StrongWebmail CEO's mail account hacked via XSSXSS is one way to do it.. But the telephone authentication is still a flawed 2-factor authentication method.Well, I was really hoping I'd get to it before Lance did, my hat's off to you brother. I would have just attacked it form the phone...]]></description>
		<s:doctype><![CDATA[Discussion threads]]></s:doctype>
		<pubDate>Thu, 04 Jun 2009 16:05:00 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/telecom+%2526+utilities.html"><![CDATA[Telecom & Utilities]]></category>
		<category domain="http://updates.zdnet.com/tags/phone.html"><![CDATA[phone]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/strongwebmail.html"><![CDATA[StrongWebMail]]></category>
	</item>
	<item>
		<title><![CDATA[StrongWebmail CEO's mail account hacked via XSS]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=3514]]></link>
		<description><![CDATA[A Webmail service that touts itself as hack-proof and offered $10,000 to anyone who could break into the CEO's e-mail has lost the challenge.    A trio of hackers successfully compromised the e-mail using persistent cross-site scripting XSS vulnerability and are now claiming the bounty.   ...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Thu, 04 Jun 2009 14:16:32 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/ceo.html"><![CDATA[CEO]]></category>
		<category domain="http://updates.zdnet.com/tags/e-mail.html"><![CDATA[E-mail]]></category>
		<category domain="http://updates.zdnet.com/tags/online+communications.html"><![CDATA[Online Communications]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
	</item>
	<item>
		<title><![CDATA[SWAP: Mitigating XSS Attacks Using a Reverse Proxy]]></title>
		<link><![CDATA[http://whitepapers.zdnet.com/abstract.aspx?docid=1174659]]></link>
		<description><![CDATA[Due to the increasing amount of Web sites offering features to contribute rich content, and the frequent failure of Web developers to properly sanitize user input, cross-site scripting prevails as the most significant security threat to Web applications. Using cross-site scripting techniques, miscreants can hijack Web sessions, and craft credible...]]></description>
		<s:doctype><![CDATA[White papers]]></s:doctype>
		<pubDate>Wed, 13 May 2009 00:00:00 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/attack.html"><![CDATA[Attack]]></category>
	</item>
	<item>
		<title><![CDATA[Five 'must-secure' Web app vulnerabilities]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=3268]]></link>
		<description><![CDATA[Security holes in the Apache Geronimo Application Server and SAP cFolders headline a list of five serious Web app vulnerabilities that demand immediate attention.    According to Mark Painter from the HP Security Laboratory, the Geronimo flaws expose users to a variety of attack vectors that could lead...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Wed, 29 Apr 2009 11:30:21 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/novell+inc..html"><![CDATA[Novell Inc.]]></category>
		<category domain="http://updates.zdnet.com/tags/apache+geronimo.html"><![CDATA[Apache Geronimo]]></category>
		<category domain="http://updates.zdnet.com/tags/attacker.html"><![CDATA[Attacker]]></category>
		<category domain="http://updates.zdnet.com/tags/vulnerability.html"><![CDATA[Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/web+application.html"><![CDATA[Web Application]]></category>
		<category domain="http://updates.zdnet.com/tags/sap+ag.html"><![CDATA[SAP AG]]></category>
		<category domain="http://updates.zdnet.com/tags/attack.html"><![CDATA[Attack]]></category>
		<category domain="http://updates.zdnet.com/tags/authentication+credential.html"><![CDATA[Authentication Credential]]></category>
		<category domain="http://updates.zdnet.com/tags/sap+cfolders+sap+cfolders.html"><![CDATA[SAP cFolders SAP cFolders]]></category>
		<category domain="http://updates.zdnet.com/tags/cs+whois+lookup+cs+whois+lookup.html"><![CDATA[CS Whois Lookup CS Whois Lookup]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
		<category domain="http://rss.financialcontent.com/stocksymbol">NOVL</category>
		<category domain="http://rss.financialcontent.com/stocksymbol">SAP</category>
		<category domain="tickers">NOVL,SAP</category>
	</item>
	<item>
		<title><![CDATA[Twitter worm author gets a job at exqSoft Solutions]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=3170]]></link>
		<description><![CDATA[UPDATE: Mikeyy Mooney of Stalk Daily gets Hacked. Here's more info.    Now that was so fast that even Owen Thor Walker AKILL and Michael Calce Mafiaboy should envy the short cybercrime-to-job offer cycle here. 17 years old Mikeyy Mooney, the author/spreader of StalkDaily/Mickeyy XSS worm that exploited...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Fri, 17 Apr 2009 11:11:53 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/job.html"><![CDATA[Job]]></category>
		<category domain="http://updates.zdnet.com/tags/web.html"><![CDATA[Web]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/web+application.html"><![CDATA[Web Application]]></category>
		<category domain="http://updates.zdnet.com/tags/worm.html"><![CDATA[Worm]]></category>
		<category domain="http://updates.zdnet.com/tags/twitter.html"><![CDATA[Twitter]]></category>
		<category domain="http://updates.zdnet.com/tags/cloud+computing.html"><![CDATA[Cloud Computing]]></category>
		<category domain="http://updates.zdnet.com/tags/cyberthreats.html"><![CDATA[Cyberthreats]]></category>
		<category domain="http://updates.zdnet.com/tags/channel+management.html"><![CDATA[Channel Management]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/viruses+and+worms.html"><![CDATA[Viruses And Worms]]></category>
		<category domain="http://updates.zdnet.com/tags/marketing.html"><![CDATA[Marketing]]></category>
		<category domain="http://updates.zdnet.com/tags/dancho+danchev.html"><![CDATA[Dancho Danchev]]></category>
	</item>
	<item>
		<title><![CDATA[Twitter hit by multiple variants of XSS worm]]></title>
		<link><![CDATA[http://talkback.zdnet.com/5208-12691-0.html?forumID=1&threadID=63260&messageID=1170063&start=0]]></link>
		<description><![CDATA[Twitter hit by multiple variants of XSS wormYou're behind the times...This has already hit the /. community two days ago and most of the talk has been the usual "tar & feather" kind for the 17 year old that had created this particular worm.  Especially given that at least...]]></description>
		<s:doctype><![CDATA[Discussion threads]]></s:doctype>
		<pubDate>Tue, 14 Apr 2009 06:41:00 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/cyberthreats.html"><![CDATA[Cyberthreats]]></category>
		<category domain="http://updates.zdnet.com/tags/viruses+and+worms.html"><![CDATA[Viruses and worms]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[SECURITY]]></category>
		<category domain="http://updates.zdnet.com/tags/worm.html"><![CDATA[worm]]></category>
		<category domain="http://updates.zdnet.com/tags/xss+worm.html"><![CDATA[XSS worm]]></category>
		<category domain="http://updates.zdnet.com/tags/multiple+variant.html"><![CDATA[multiple variant]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/twitter.html"><![CDATA[Twitter]]></category>
	</item>
	<item>
		<title><![CDATA[Twitter hit by multiple variants of XSS worm]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=3125]]></link>
		<description><![CDATA[During the weekend and early Monday, at least four separate variants of the original StalkDaily.com XSS worm hit the popular micro-blogging site Twitter,Â  automatically hijacking accounts and advertising the author's web site by posting tweets on behalf of the account holders, by exploiting cross site scripting flaws at the site....]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Tue, 14 Apr 2009 02:19:13 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/flaw.html"><![CDATA[Flaw]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/worm.html"><![CDATA[Worm]]></category>
		<category domain="http://updates.zdnet.com/tags/twitter.html"><![CDATA[Twitter]]></category>
		<category domain="http://updates.zdnet.com/tags/www.stalkdaily.com.html"><![CDATA[www.StalkDaily.com]]></category>
		<category domain="http://updates.zdnet.com/tags/mikeyy+xss.html"><![CDATA[Mikeyy XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/cyberthreats.html"><![CDATA[Cyberthreats]]></category>
		<category domain="http://updates.zdnet.com/tags/viruses+and+worms.html"><![CDATA[Viruses And Worms]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/dancho+danchev.html"><![CDATA[Dancho Danchev]]></category>
	</item>
	<item>
		<title><![CDATA[Google downplays severity of Gmail CSRF flaw]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=2773]]></link>
		<description><![CDATA[Yesterday, Vicente Aguilera Diaz from Internet Security Auditors released proof of concept of a CSRF (Cross-Site Request Forgery) vulnerability in Google's Gmail, which he originally communicated to Google two years ago. The CSRF flaw affects Gmail's "Change Password" function, since according to Diaz the session cookie is automatically sent by...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Wed, 04 Mar 2009 14:44:05 -0800</pubDate>
		<category domain="http://updates.zdnet.com/tags/google+inc..html"><![CDATA[Google Inc.]]></category>
		<category domain="http://updates.zdnet.com/tags/google+gmail.html"><![CDATA[Google Gmail]]></category>
		<category domain="http://updates.zdnet.com/tags/password.html"><![CDATA[Password]]></category>
		<category domain="http://updates.zdnet.com/tags/flaw.html"><![CDATA[Flaw]]></category>
		<category domain="http://updates.zdnet.com/tags/vulnerability.html"><![CDATA[Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/csrf+flaw.html"><![CDATA[CSRF Flaw]]></category>
		<category domain="http://updates.zdnet.com/tags/e-mail+providers.html"><![CDATA[E-mail Providers]]></category>
		<category domain="http://updates.zdnet.com/tags/cloud+computing.html"><![CDATA[Cloud Computing]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/internet.html"><![CDATA[Internet]]></category>
		<category domain="http://updates.zdnet.com/tags/dancho+danchev.html"><![CDATA[Dancho Danchev]]></category>
		<category domain="http://updates.zdnet.com/tags/dancho+danchev.html"><![CDATA[Dancho Danchev]]></category>
		<category domain="http://rss.financialcontent.com/stocksymbol">GOOG</category>
		<category domain="tickers">GOOG</category>
	</item>
	<item>
		<title><![CDATA[URL rewriting can help thwart Web app attacks]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=2728]]></link>
		<description><![CDATA[A Microsoft Web application security specialist is suggesting an offbeat defense-in-depth strategy to protect Web sites and applications from cross-site scripting XSS and cross-site request forgery XSRF attacks.    According to Bryan Sullivan, security program manager for Redmond's Security Development Lifecycle team, Web developers should consider URL Rewriting...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Fri, 27 Feb 2009 08:28:48 -0800</pubDate>
		<category domain="http://updates.zdnet.com/tags/hyperlink.html"><![CDATA[Hyperlink]]></category>
		<category domain="http://updates.zdnet.com/tags/attacker.html"><![CDATA[Attacker]]></category>
		<category domain="http://updates.zdnet.com/tags/vulnerability.html"><![CDATA[Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/web+application.html"><![CDATA[Web Application]]></category>
		<category domain="http://updates.zdnet.com/tags/attack.html"><![CDATA[Attack]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+web+application+security+specialist.html"><![CDATA[Microsoft Web Application Security Specialist]]></category>
		<category domain="http://updates.zdnet.com/tags/bryan+sullivan.html"><![CDATA[Bryan Sullivan]]></category>
		<category domain="http://updates.zdnet.com/tags/e-mail.html"><![CDATA[E-mail]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/online+communications.html"><![CDATA[Online Communications]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
	</item>
	<item>
		<title><![CDATA[Flaw exposes Chrome, Firefox to clickjacking]]></title>
		<link><![CDATA[http://talkback.zdnet.com/5208-9595-0.html?forumID=1&threadID=60181&messageID=1104566&start=0]]></link>
		<description><![CDATA[Flaw exposes Chrome, Firefox to clickjackingStonewalling over IE???How about the flaw in IE 6?  IE 7??  After all, most users would be on one of those...not IE 8.  LOVE how the headline leaves IE out and focuses on Chrome and Firefox.Whoa!Microsoft actually on top of security issues...]]></description>
		<s:doctype><![CDATA[Discussion threads]]></s:doctype>
		<pubDate>Thu, 29 Jan 2009 07:13:00 -0800</pubDate>
		<category domain="http://updates.zdnet.com/tags/web+browsers.html"><![CDATA[Web browsers]]></category>
		<category domain="http://updates.zdnet.com/tags/spyware%252c+adware+%2526+malware.html"><![CDATA[Spyware, adware & malware]]></category>
		<category domain="http://updates.zdnet.com/tags/cyberthreats.html"><![CDATA[Cyberthreats]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[SECURITY]]></category>
		<category domain="http://updates.zdnet.com/tags/viruses+and+worms.html"><![CDATA[Viruses and worms]]></category>
		<category domain="http://updates.zdnet.com/tags/anti-spyware+tool.html"><![CDATA[Anti-spyware tool]]></category>
		<category domain="http://updates.zdnet.com/tags/noscript.html"><![CDATA[NoScript]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+internet+explorer.html"><![CDATA[Microsoft Internet Explorer]]></category>
		<category domain="http://updates.zdnet.com/tags/malware.html"><![CDATA[malware]]></category>
		<category domain="http://updates.zdnet.com/tags/mozilla+firefox.html"><![CDATA[Mozilla Firefox]]></category>
		<category domain="http://updates.zdnet.com/tags/web+browser.html"><![CDATA[Web browser]]></category>
	</item>
	<item>
		<title><![CDATA[First look - Internet Explorer 8 RC1]]></title>
		<link><![CDATA[http://blogs.zdnet.com/hardware/?p=3380]]></link>
		<description><![CDATA[Yesterday Microsoft made available Internet Explorer 8 RC1 (release candidate 1), which means that as far as Microsoft is concerned, IE8 is cooked and that barring anything major, this will become the final release. So, what's the new browser like? by Adrian Kingsley-Hughes]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Tue, 27 Jan 2009 08:30:04 -0800</pubDate>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+internet+explorer.html"><![CDATA[Microsoft Internet Explorer]]></category>
		<category domain="http://updates.zdnet.com/tags/web+browser.html"><![CDATA[Web Browser]]></category>
		<category domain="http://updates.zdnet.com/tags/ie8.html"><![CDATA[IE8]]></category>
		<category domain="http://updates.zdnet.com/tags/web+browsers.html"><![CDATA[Web Browsers]]></category>
		<category domain="http://updates.zdnet.com/tags/internet.html"><![CDATA[Internet]]></category>
		<category domain="http://updates.zdnet.com/tags/adrian+kingsley-hughes.html"><![CDATA[Adrian Kingsley-Hughes]]></category>
		<category domain="http://updates.zdnet.com/tags/adrian+kingsley-hughes.html"><![CDATA[Adrian Kingsley-Hughes]]></category>
	</item>
	<item>
		<title><![CDATA[MSDN Webcast: Managing Cross-Site Scripting Using CAT.NET and AntiXSS (Level 200)]]></title>
		<link><![CDATA[http://whitepapers.zdnet.com/abstract.aspx?docid=912067]]></link>
		<description><![CDATA[Cross-site scripting attacks are one of the most common attack vectors that plague Web applications. This webcast provide an overview of the tools designed for discovery and mitigation of cross-site scripting vulnerabilities in Microsoft .NET applications. Specifically, it looks at CAT.NET, which is a static code analysis tool developed by...]]></description>
		<s:doctype><![CDATA[Webcasts]]></s:doctype>
		<pubDate>Fri, 09 Jan 2009 00:00:00 -0800</pubDate>
		<category domain="http://updates.zdnet.com/tags/microsoft+developer+network.html"><![CDATA[Microsoft Developer Network]]></category>
		<category domain="http://updates.zdnet.com/tags/webcast.html"><![CDATA[Webcast]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+corp..html"><![CDATA[Microsoft Corp.]]></category>
		<category domain="http://updates.zdnet.com/tags/cross-site+scripting+attack.html"><![CDATA[Cross-site Scripting Attack]]></category>
		<category domain="http://rss.financialcontent.com/stocksymbol">MSFT</category>
		<category domain="tickers">MSFT</category>
	</item>
	<item>
		<title><![CDATA[The Perils of Cross-Site Scripting (XSS)]]></title>
		<link><![CDATA[http://whitepapers.zdnet.com/abstract.aspx?docid=1151369]]></link>
		<description><![CDATA[Cross-site Scripting XSS attacks are universally seen as the #1 security vulnerability facing web applications. Don't wait another today to learn how protect the organization. The presenter of this webcast gives an overview on XSS (techniques, consequences and vulnerabilities and give real-world examples and offensive techniques aimed at short circuiting...]]></description>
		<s:doctype><![CDATA[Webcasts]]></s:doctype>
		<pubDate>Thu, 01 Jan 2009 00:00:00 -0800</pubDate>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/breach+security.html"><![CDATA[Breach Security]]></category>
	</item>
</channel>
</rss>
