<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Top Ten Security Vulnerabilities in PHP Code !</title>
	<atom:link href="http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/feed/" rel="self" type="application/rss+xml" />
	<link>http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/</link>
	<description>Know your limits, but never stop trying to exceed them.</description>
	<lastBuildDate>Tue, 09 Mar 2010 01:38:57 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Lakshmikanth</title>
		<link>http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/comment-page-1/#comment-1234</link>
		<dc:creator>Lakshmikanth</dc:creator>
		<pubDate>Wed, 29 Jul 2009 10:23:37 +0000</pubDate>
		<guid isPermaLink="false">http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/#comment-1234</guid>
		<description>pls include the vulnerabilities of remote file inclusion</description>
		<content:encoded><![CDATA[<p>pls include the vulnerabilities of remote file inclusion</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe</title>
		<link>http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/comment-page-1/#comment-1188</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Wed, 20 May 2009 09:00:53 +0000</pubDate>
		<guid isPermaLink="false">http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/#comment-1188</guid>
		<description>You can also try using automated blackbox approach using fuzzing to find vulnerabilities in your code. I had very good results with mine PHP applications. &#039;Securing PHP Web Applications&#039; by Tricia Ballad; William Ballad mentions some good fuzzers. I recommend Powerfuzzer.</description>
		<content:encoded><![CDATA[<p>You can also try using automated blackbox approach using fuzzing to find vulnerabilities in your code. I had very good results with mine PHP applications. &#8216;Securing PHP Web Applications&#8217; by Tricia Ballad; William Ballad mentions some good fuzzers. I recommend Powerfuzzer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rochakchauhan</title>
		<link>http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/comment-page-1/#comment-747</link>
		<dc:creator>rochakchauhan</dc:creator>
		<pubDate>Wed, 03 Sep 2008 07:24:01 +0000</pubDate>
		<guid isPermaLink="false">http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/#comment-747</guid>
		<description>Sorry for the confusion, no offense to David Sklar. I have explained him the situation personally. The idea was to share and spread the word. But I guess I owe an apology for NOT including the credits.

I have added the credits in the post now. You all are requested to make use of the information and thank David (http://www.sklar.com)</description>
		<content:encoded><![CDATA[<p>Sorry for the confusion, no offense to David Sklar. I have explained him the situation personally. The idea was to share and spread the word. But I guess I owe an apology for NOT including the credits.</p>
<p>I have added the credits in the post now. You all are requested to make use of the information and thank David (<a href="http://www.sklar.com" rel="nofollow">http://www.sklar.com</a>)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff Carouth</title>
		<link>http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/comment-page-1/#comment-746</link>
		<dc:creator>Jeff Carouth</dc:creator>
		<pubDate>Mon, 01 Sep 2008 16:34:16 +0000</pubDate>
		<guid isPermaLink="false">http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/#comment-746</guid>
		<description>Seriously, have some integrity and give credit where it is due. While some people may praise you for this, it is despicable practice and reflects poorly on yourself as an individual and your company. Do the right thing.

(See post by Chris Shiflett for a link to the original copy by the _real_ author of this post)</description>
		<content:encoded><![CDATA[<p>Seriously, have some integrity and give credit where it is due. While some people may praise you for this, it is despicable practice and reflects poorly on yourself as an individual and your company. Do the right thing.</p>
<p>(See post by Chris Shiflett for a link to the original copy by the _real_ author of this post)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ivan Jovanovic</title>
		<link>http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/comment-page-1/#comment-745</link>
		<dc:creator>Ivan Jovanovic</dc:creator>
		<pubDate>Mon, 01 Sep 2008 15:02:19 +0000</pubDate>
		<guid isPermaLink="false">http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/#comment-745</guid>
		<description>Stealing just shouldn&#039;t be done :) Someone spent lot of time getting to know these things and even was kind to share them with use that know less than him. Plagiarism of this kind is just the worst.</description>
		<content:encoded><![CDATA[<p>Stealing just shouldn&#8217;t be done <img src='http://rochakchauhan.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Someone spent lot of time getting to know these things and even was kind to share them with use that know less than him. Plagiarism of this kind is just the worst.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joseph Crawford</title>
		<link>http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/comment-page-1/#comment-744</link>
		<dc:creator>Joseph Crawford</dc:creator>
		<pubDate>Mon, 01 Sep 2008 14:53:17 +0000</pubDate>
		<guid isPermaLink="false">http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/#comment-744</guid>
		<description>Wow why would you steal something like this then not give credit where credit is due.  This was a great article David!!!  Cannot believe people still plagiarize work like this.</description>
		<content:encoded><![CDATA[<p>Wow why would you steal something like this then not give credit where credit is due.  This was a great article David!!!  Cannot believe people still plagiarize work like this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Shiflett</title>
		<link>http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/comment-page-1/#comment-743</link>
		<dc:creator>Chris Shiflett</dc:creator>
		<pubDate>Mon, 01 Sep 2008 14:41:05 +0000</pubDate>
		<guid isPermaLink="false">http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/#comment-743</guid>
		<description>Stealing other people&#039;s work without providing attribution is the worst form of plagiarism.

http://www.sklar.com/page/article/owasp-top-ten</description>
		<content:encoded><![CDATA[<p>Stealing other people&#8217;s work without providing attribution is the worst form of plagiarism.</p>
<p><a href="http://www.sklar.com/page/article/owasp-top-ten" rel="nofollow">http://www.sklar.com/page/article/owasp-top-ten</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: frank</title>
		<link>http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/comment-page-1/#comment-742</link>
		<dc:creator>frank</dc:creator>
		<pubDate>Sun, 31 Aug 2008 06:41:45 +0000</pubDate>
		<guid isPermaLink="false">http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/#comment-742</guid>
		<description>with regards to xss; you might also consider looking into http://htmlpurifier.org/, a great whitelist-filtering component which can be used if you want to allow your users to use some code (html) in what they submit.</description>
		<content:encoded><![CDATA[<p>with regards to xss; you might also consider looking into <a href="http://htmlpurifier.org/" rel="nofollow">http://htmlpurifier.org/</a>, a great whitelist-filtering component which can be used if you want to allow your users to use some code (html) in what they submit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Hendrickx</title>
		<link>http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/comment-page-1/#comment-736</link>
		<dc:creator>Michael Hendrickx</dc:creator>
		<pubDate>Fri, 01 Aug 2008 16:48:14 +0000</pubDate>
		<guid isPermaLink="false">http://rochakchauhan.com/blog/2008/07/13/top-ten-security-vulnerabilities-in-php-code/#comment-736</guid>
		<description>Most of these are not application in PHP6 anymore, but still.. nice post!</description>
		<content:encoded><![CDATA[<p>Most of these are not application in PHP6 anymore, but still.. nice post!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
