<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Erata.NET &#187; Security</title>
	<atom:link href="http://www.erata.net/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.erata.net</link>
	<description>If we don't have the solution you have the wrong problem</description>
	<lastBuildDate>Thu, 17 Nov 2011 11:12:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>WordPress Exploit Scanner Plugin</title>
		<link>http://www.erata.net/security/wordpress-exploit-scanner-plugin/</link>
		<comments>http://www.erata.net/security/wordpress-exploit-scanner-plugin/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 08:45:30 +0000</pubDate>
		<dc:creator>Iulian Margarintescu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[API]]></category>
		<category><![CDATA[core files]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploits/throjans/malware web scripts]]></category>
		<category><![CDATA[installation folder]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[scanner]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[secure]]></category>
		<category><![CDATA[security tool]]></category>
		<category><![CDATA[suspicious files]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[way]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web scripts]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.erata.net/?p=65</guid>
		<description><![CDATA[I've found a few days ago <a title="Exploit Scanner" href="http://ocaoimh.ie/exploit-scanner/">this plugin</a> and i would like to share with everybody since it may help secure the web. This plugin scans the wordpress installation folder for paterns usualy found in exploits/throjans/malware web scripts. The plugin produces quite a few false positive alerts but also it's very easy to spot suspicious code in suspicious files. 
 
It would be nice if <a href="http://www.erata.net/security/wordpress-exploit-scanner-plugin/">read full article</a>]]></description>
		<wfw:commentRss>http://www.erata.net/security/wordpress-exploit-scanner-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I gave up on Coppermine Gallery</title>
		<link>http://www.erata.net/security/i-gave-up-on-coppermine-gallery/</link>
		<comments>http://www.erata.net/security/i-gave-up-on-coppermine-gallery/#comments</comments>
		<pubDate>Fri, 27 Feb 2009 16:14:33 +0000</pubDate>
		<dc:creator>Iulian Margarintescu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[coppermine]]></category>
		<category><![CDATA[Coppermine Photo Gallery]]></category>
		<category><![CDATA[desktop application]]></category>
		<category><![CDATA[gallery]]></category>
		<category><![CDATA[number]]></category>
		<category><![CDATA[peer reviews]]></category>
		<category><![CDATA[pice]]></category>
		<category><![CDATA[safe alternatives]]></category>
		<category><![CDATA[stone]]></category>
		<category><![CDATA[today]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web gallery]]></category>
		<category><![CDATA[web gallery needs]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.erata.net/?p=60</guid>
		<description><![CDATA[I used to use <a title="Coppermine Gallery" href="http://coppermine-gallery.net/">Coppermine Photo Gallery</a> for <a title="Erata.NET Photo Gallery " href="http://gallery.erata.net">http://gallery.erata.net</a> but today i've decided to close it down. The number of vulnerabilities ( most of them critical ) discovered over the years got me thinking. You can see what i mean here <a title="Exploits List" href="http://www.milw0rm.com/search.php?dong=coppermine">http://www.milw0rm.com/search.php?dong=coppermine</a>. 3 vulnerabilities found in the first two months of 2009.  4 in 2008. This remembers me of <a href="http://www.erata.net/security/i-gave-up-on-coppermine-gallery/">read full article</a>]]></description>
		<wfw:commentRss>http://www.erata.net/security/i-gave-up-on-coppermine-gallery/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Web application security flows</title>
		<link>http://www.erata.net/security/web-application-security-flows/</link>
		<comments>http://www.erata.net/security/web-application-security-flows/#comments</comments>
		<pubDate>Thu, 12 Oct 2006 12:07:06 +0000</pubDate>
		<dc:creator>Iulian Margarintescu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[application]]></category>
		<category><![CDATA[author]]></category>
		<category><![CDATA[database server]]></category>
		<category><![CDATA[error]]></category>
		<category><![CDATA[first security]]></category>
		<category><![CDATA[http]]></category>
		<category><![CDATA[member]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[query]]></category>
		<category><![CDATA[safe]]></category>
		<category><![CDATA[server side programming]]></category>
		<category><![CDATA[server side programming language]]></category>
		<category><![CDATA[side programming language]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[way]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web application]]></category>
		<category><![CDATA[Web application security]]></category>
		<category><![CDATA[web applications]]></category>
		<category><![CDATA[WHERE]]></category>

		<guid isPermaLink="false">http://www.erata.net/weblog/projects/2006/10/12/web-application-security-flows/</guid>
		<description><![CDATA[Here goes... my first security related post :)
<h3>Intro</h3>
First i must say that this will not be a way to prove that your application is secure, it will only be a quick &#38; dirty way of finding common bugs in web applications. The following will be a few techniques that i tend to use the first time i see an web application ( and generally a database application ). I will use PHP for the few code examples but the vulnerabilities presented are not limited to PHP, in fact are independent of the server-side programming language used.

 <a href="http://www.erata.net/security/web-application-security-flows/">read full article</a>]]></description>
		<wfw:commentRss>http://www.erata.net/security/web-application-security-flows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

