<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://keepitlocked.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>KeepItLocked.net - All Comments</title><link>http://keepitlocked.net/default.aspx</link><description /><dc:language>en</dc:language><generator>CommunityServer 2007 SP2 (Build: 20611.960)</generator><item><title>Microsoft Anti-Cross Site Scripting Library V3.1发布</title><link>http://keepitlocked.net/archive/2009/07/29/owasp-net-esapi-0-2-released.aspx#52290</link><pubDate>Fri, 18 Sep 2009 09:07:20 GMT</pubDate><guid isPermaLink="false">a3f75fb5-0505-4d35-9795-aaa2ed659a71:52290</guid><dc:creator>Web应用安全观察站</dc:creator><description>&lt;p&gt;MSAnti-XSSLib实在是一个非常好的工具库，从3.0版本开始就内含了一个SRE(SecurityRuntimeEngine)，SRE实现为一个HttpModule。现在3.1版本也...&lt;/p&gt;
&lt;img src="http://keepitlocked.net/aggbug.aspx?PostID=52290" width="1" height="1"&gt;</description></item><item><title>re: SSL Warning Messages – Expired Certificates and Mismatched Sub-Domains</title><link>http://keepitlocked.net/archive/2009/07/07/ssl-warning-messages-expired-certificates-and-mismatched-sub-domains.aspx#52288</link><pubDate>Wed, 08 Jul 2009 18:50:07 GMT</pubDate><guid isPermaLink="false">a3f75fb5-0505-4d35-9795-aaa2ed659a71:52288</guid><dc:creator>jcrawfordor</dc:creator><description>&lt;p&gt;I've always had an issue with the extremely dire warnings on self-signed SSL certs. With companies like Verisign running the show, CA-signed certificates can be prohibitively expensive, particularly for temporary situations. When a CA-signed cert is not available, it's still preferably to at least have confidentiality and integrity, without authentication, rather than having none of the three. But browser warnings make people tend to immediately distrust servers with self-signed certificates, when browsers don't throw any warning about servers that are not encrypting at all.&lt;/p&gt;
&lt;p&gt;I once heard an anecdote about a server at DEFCON (or some other security event, I forget which) which was operating an e-commerce deal selling memorabilia. Because it was a temporary setup it was using a self-signed SSL cert to protect payment info. However, the SSL warnings led many non-security-professionals (reporters etc...) to instead use a completely unencrypted connection!&lt;/p&gt;
&lt;p&gt;I've seen this happen in my workplace as well - users see the dire warnings about self-signed certs and think that it is safer to use an unencrypted connection. Particularly in FF and IE where the warnings are particularly frightening, and in the case of FF, difficult to get past.&lt;/p&gt;
&lt;img src="http://keepitlocked.net/aggbug.aspx?PostID=52288" width="1" height="1"&gt;</description></item><item><title>re: Command Injection Impossible in Java and .NET?</title><link>http://keepitlocked.net/archive/2009/04/29/command-injection-impossible-in-java-and-net.aspx#33214</link><pubDate>Fri, 08 May 2009 00:49:51 GMT</pubDate><guid isPermaLink="false">a3f75fb5-0505-4d35-9795-aaa2ed659a71:33214</guid><dc:creator>Dan Cornell</dc:creator><description>&lt;p&gt;Yet another follow-up. &amp;nbsp;I was uneasy with my previous test results because I remembered that WebGoat had an example of command injection in Java. &amp;nbsp;So I looked at some code and updated my test program to run the Java tests on Windows. &amp;nbsp;Blog post with the results is here:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://denimgroup.typepad.com/denim_group/2009/05/command-injection-in-java-on-windows-100-proven-that-it-is-100-possible.html"&gt;denimgroup.typepad.com/.../command-injection-in-java-on-windows-100-proven-that-it-is-100-possible.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;--Dan&lt;/p&gt;
&lt;img src="http://keepitlocked.net/aggbug.aspx?PostID=33214" width="1" height="1"&gt;</description></item><item><title>re: Command Injection Impossible in Java and .NET?</title><link>http://keepitlocked.net/archive/2009/04/29/command-injection-impossible-in-java-and-net.aspx#32783</link><pubDate>Wed, 06 May 2009 13:11:00 GMT</pubDate><guid isPermaLink="false">a3f75fb5-0505-4d35-9795-aaa2ed659a71:32783</guid><dc:creator>Dan Cornell</dc:creator><description>&lt;p&gt;I did the same thing for .NET with similar results. &amp;nbsp;Looks like .NET is reasonably safe, too. &amp;nbsp;Blog post is online here:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://denimgroup.typepad.com/denim_group/2009/05/command-injection-in-net-82-proven-that-is-98-impossible.html"&gt;denimgroup.typepad.com/.../command-injection-in-net-82-proven-that-is-98-impossible.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;--Dan&lt;/p&gt;
&lt;img src="http://keepitlocked.net/aggbug.aspx?PostID=32783" width="1" height="1"&gt;</description></item><item><title>re: Command Injection Impossible in Java and .NET?</title><link>http://keepitlocked.net/archive/2009/04/29/command-injection-impossible-in-java-and-net.aspx#32622</link><pubDate>Wed, 06 May 2009 01:32:22 GMT</pubDate><guid isPermaLink="false">a3f75fb5-0505-4d35-9795-aaa2ed659a71:32622</guid><dc:creator>Dan Cornell</dc:creator><description>&lt;p&gt;Yeah that link should have been:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://denimgroup.typepad.com/denim_group/2009/05/command-injection-in-java-80-proven-that-it-is-100-impossible.html"&gt;denimgroup.typepad.com/.../command-injection-in-java-80-proven-that-it-is-100-impossible.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;My attempt to make it more clickable added a &amp;gt; at the end. &amp;nbsp;D'Oh!&lt;/p&gt;
&lt;p&gt;--Dan&lt;/p&gt;
&lt;p&gt;dan _at_ denimgroup.om&lt;/p&gt;
&lt;img src="http://keepitlocked.net/aggbug.aspx?PostID=32622" width="1" height="1"&gt;</description></item></channel></rss>