<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Web App Security</title>
	<atom:link href="http://www.idontplaydarts.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.idontplaydarts.com</link>
	<description>PHP &#38; LAMP Stack Security</description>
	<lastBuildDate>Tue, 31 Jan 2012 14:07:48 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>Comment on Extending Burp Suite to solve reCAPTCHA by travis</title>
		<link>http://www.idontplaydarts.com/2012/01/extending-burp-suite-to-solve-recaptcha/#comment-1379</link>
		<dc:creator>travis</dc:creator>
		<pubDate>Tue, 31 Jan 2012 14:07:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.idontplaydarts.com/?p=717#comment-1379</guid>
		<description>This looks awesome.  In my testing I haven&#039;t come across any applications using captcha as of late but when I do encounter one I&#039;ll make sure to try this technique.  Thanks for putting this together.  You just got a new follower.</description>
		<content:encoded><![CDATA[<p>This looks awesome.  In my testing I haven&#8217;t come across any applications using captcha as of late but when I do encounter one I&#8217;ll make sure to try this technique.  Thanks for putting this together.  You just got a new follower.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Decrypting suhosin sessions and cookies. by Phil</title>
		<link>http://www.idontplaydarts.com/2011/11/decrypting-suhosin-sessions-and-cookies/#comment-1372</link>
		<dc:creator>Phil</dc:creator>
		<pubDate>Thu, 26 Jan 2012 21:22:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.idontplaydarts.com/?p=650#comment-1372</guid>
		<description>As you say, chmod the ini file with the suhosin secret key in so it is only readable as root  and ensure that Suhosin is set to use the user agent as part of the encryption string. For defence in depth you can use open_basedir to prevent PHP from directly accessing the sessions directory :)</description>
		<content:encoded><![CDATA[<p>As you say, chmod the ini file with the suhosin secret key in so it is only readable as root  and ensure that Suhosin is set to use the user agent as part of the encryption string. For defence in depth you can use open_basedir to prevent PHP from directly accessing the sessions directory :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Decrypting suhosin sessions and cookies. by Steffen Müller</title>
		<link>http://www.idontplaydarts.com/2011/11/decrypting-suhosin-sessions-and-cookies/#comment-1370</link>
		<dc:creator>Steffen Müller</dc:creator>
		<pubDate>Thu, 26 Jan 2012 13:41:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.idontplaydarts.com/?p=650#comment-1370</guid>
		<description>Awesome article. Thanks for explaining this topic and for providing a  decrypter tool.

However, what&#039;s your conclusion to make encryption more safe? Do you think this is possible at all? 
At least the .ini-file containing the cryptkey should be readable by root only (chmod 400) otherwise the cryptkey can be read when bad guys gain access to filesystem.</description>
		<content:encoded><![CDATA[<p>Awesome article. Thanks for explaining this topic and for providing a  decrypter tool.</p>
<p>However, what&#8217;s your conclusion to make encryption more safe? Do you think this is possible at all?<br />
At least the .ini-file containing the cryptkey should be readable by root only (chmod 400) otherwise the cryptkey can be read when bad guys gain access to filesystem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scanning the internal network using SimpleXML by am</title>
		<link>http://www.idontplaydarts.com/2011/02/scanning-the-internal-network-using-simplexml/#comment-1335</link>
		<dc:creator>am</dc:creator>
		<pubDate>Mon, 23 Jan 2012 17:49:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.idontplaydarts.com/?p=72#comment-1335</guid>
		<description>ps: you should add an option to subscribe to comments via email. would be really useful!</description>
		<content:encoded><![CDATA[<p>ps: you should add an option to subscribe to comments via email. would be really useful!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scanning the internal network using SimpleXML by am</title>
		<link>http://www.idontplaydarts.com/2011/02/scanning-the-internal-network-using-simplexml/#comment-1334</link>
		<dc:creator>am</dc:creator>
		<pubDate>Mon, 23 Jan 2012 17:48:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.idontplaydarts.com/?p=72#comment-1334</guid>
		<description>that&#039;s even more interesting:))</description>
		<content:encoded><![CDATA[<p>that&#8217;s even more interesting:))</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scanning the internal network using SimpleXML by Phil</title>
		<link>http://www.idontplaydarts.com/2011/02/scanning-the-internal-network-using-simplexml/#comment-1330</link>
		<dc:creator>Phil</dc:creator>
		<pubDate>Mon, 23 Jan 2012 09:55:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.idontplaydarts.com/?p=72#comment-1330</guid>
		<description>Nice spot - post updated now, looks like you can use php filters to read binary files as well :)</description>
		<content:encoded><![CDATA[<p>Nice spot &#8211; post updated now, looks like you can use php filters to read binary files as well :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scanning the internal network using SimpleXML by am</title>
		<link>http://www.idontplaydarts.com/2011/02/scanning-the-internal-network-using-simplexml/#comment-1328</link>
		<dc:creator>am</dc:creator>
		<pubDate>Mon, 23 Jan 2012 06:57:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.idontplaydarts.com/?p=72#comment-1328</guid>
		<description>what have you updated i don&#039;t see.... On php you have to use file:////etc/passwd.</description>
		<content:encoded><![CDATA[<p>what have you updated i don&#8217;t see&#8230;. On php you have to use file:////etc/passwd.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scanning the internal network using SimpleXML by am</title>
		<link>http://www.idontplaydarts.com/2011/02/scanning-the-internal-network-using-simplexml/#comment-1327</link>
		<dc:creator>am</dc:creator>
		<pubDate>Mon, 23 Jan 2012 06:55:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.idontplaydarts.com/?p=72#comment-1327</guid>
		<description>i&#039;ve managed to read files using php:)</description>
		<content:encoded><![CDATA[<p>i&#8217;ve managed to read files using php:)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scanning the internal network using SimpleXML by Phil</title>
		<link>http://www.idontplaydarts.com/2011/02/scanning-the-internal-network-using-simplexml/#comment-1321</link>
		<dc:creator>Phil</dc:creator>
		<pubDate>Sun, 22 Jan 2012 21:03:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.idontplaydarts.com/?p=72#comment-1321</guid>
		<description>Good spot, I&#039;ve updated the post. If the parser supports it then its a good idea to try LFI - I found file://etc/passwd works on most Java implementations but the file syntax doesn&#039;t appear to work with ASP.NET / PHP.</description>
		<content:encoded><![CDATA[<p>Good spot, I&#8217;ve updated the post. If the parser supports it then its a good idea to try LFI &#8211; I found file://etc/passwd works on most Java implementations but the file syntax doesn&#8217;t appear to work with ASP.NET / PHP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scanning the internal network using SimpleXML by am</title>
		<link>http://www.idontplaydarts.com/2011/02/scanning-the-internal-network-using-simplexml/#comment-1316</link>
		<dc:creator>am</dc:creator>
		<pubDate>Sun, 22 Jan 2012 12:26:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.idontplaydarts.com/?p=72#comment-1316</guid>
		<description>this is an interesting topic.
are you sure the first 2 errors are because of invalid xml synthax? It looks 2 me that those 2 remote files are non-existent....one redirects, the other is a 404.

Also, it should be tested if local files could be read.</description>
		<content:encoded><![CDATA[<p>this is an interesting topic.<br />
are you sure the first 2 errors are because of invalid xml synthax? It looks 2 me that those 2 remote files are non-existent&#8230;.one redirects, the other is a 404.</p>
<p>Also, it should be tested if local files could be read.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

