<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Erata.NET &#187; Security</title>
	<atom:link href="http://www.erata.net/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.erata.net</link>
	<description>If we don't have the solution you have the wrong problem</description>
	<lastBuildDate>Thu, 17 Nov 2011 11:12:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Hardware-based brute force attacks</title>
		<link>http://www.erata.net/jokes/hardware-based-brute-force-attacks/</link>
		<comments>http://www.erata.net/jokes/hardware-based-brute-force-attacks/#comments</comments>
		<pubDate>Wed, 09 Feb 2011 14:52:44 +0000</pubDate>
		<dc:creator>Iulian Margarintescu</dc:creator>
				<category><![CDATA[Jokes]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[colin percival]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[document]]></category>
		<category><![CDATA[funny]]></category>
		<category><![CDATA[Hardware-based]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[pdf presentation]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[presentation document]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[slides]]></category>
		<category><![CDATA[Source]]></category>

		<guid isPermaLink="false">http://www.erata.net/?p=201</guid>
		<description><![CDATA[I've found this image in a <a title="scrypt: A new key derivation function" href="http://www.tarsnap.com/scrypt/scrypt-slides.pdf">PDF presentation document</a> and i feel like sharing: 
 
<div id="attachment_202" class="wp-caption aligncenter" style="width: 458px"><a href="http://www.erata.net/wp-content/uploads/2011/02/hardware-crypto.png"><img class="size-full wp-image-202" title="Hardware Brute Force" src="http://www.erata.net/wp-content/uploads/2011/02/hardware-crypto.png" alt="Hardware Brute Force Attacks" width="448" height="274" /></a><p class="wp-caption-text">Hardware-based brute force attacks</p></div> 
 
Source: <a href="http://www.tarsnap.com/scrypt/scrypt-slides.pdf">http://www.tarsnap.com/scrypt/scrypt-slides.pdf</a> by Colin Percival <a href="http://www.erata.net/jokes/hardware-based-brute-force-attacks/">read full article</a>]]></description>
		<wfw:commentRss>http://www.erata.net/jokes/hardware-based-brute-force-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress Exploit Scanner Plugin</title>
		<link>http://www.erata.net/security/wordpress-exploit-scanner-plugin/</link>
		<comments>http://www.erata.net/security/wordpress-exploit-scanner-plugin/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 08:45:30 +0000</pubDate>
		<dc:creator>Iulian Margarintescu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[API]]></category>
		<category><![CDATA[core files]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploits/throjans/malware web scripts]]></category>
		<category><![CDATA[installation folder]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[scanner]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[secure]]></category>
		<category><![CDATA[security tool]]></category>
		<category><![CDATA[suspicious files]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[way]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web scripts]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.erata.net/?p=65</guid>
		<description><![CDATA[I've found a few days ago <a title="Exploit Scanner" href="http://ocaoimh.ie/exploit-scanner/">this plugin</a> and i would like to share with everybody since it may help secure the web. This plugin scans the wordpress installation folder for paterns usualy found in exploits/throjans/malware web scripts. The plugin produces quite a few false positive alerts but also it's very easy to spot suspicious code in suspicious files. 
 
It would be nice if <a href="http://www.erata.net/security/wordpress-exploit-scanner-plugin/">read full article</a>]]></description>
		<wfw:commentRss>http://www.erata.net/security/wordpress-exploit-scanner-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I gave up on Coppermine Gallery</title>
		<link>http://www.erata.net/security/i-gave-up-on-coppermine-gallery/</link>
		<comments>http://www.erata.net/security/i-gave-up-on-coppermine-gallery/#comments</comments>
		<pubDate>Fri, 27 Feb 2009 16:14:33 +0000</pubDate>
		<dc:creator>Iulian Margarintescu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[coppermine]]></category>
		<category><![CDATA[Coppermine Photo Gallery]]></category>
		<category><![CDATA[desktop application]]></category>
		<category><![CDATA[gallery]]></category>
		<category><![CDATA[number]]></category>
		<category><![CDATA[peer reviews]]></category>
		<category><![CDATA[pice]]></category>
		<category><![CDATA[safe alternatives]]></category>
		<category><![CDATA[stone]]></category>
		<category><![CDATA[today]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web gallery]]></category>
		<category><![CDATA[web gallery needs]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.erata.net/?p=60</guid>
		<description><![CDATA[I used to use <a title="Coppermine Gallery" href="http://coppermine-gallery.net/">Coppermine Photo Gallery</a> for <a title="Erata.NET Photo Gallery " href="http://gallery.erata.net">http://gallery.erata.net</a> but today i've decided to close it down. The number of vulnerabilities ( most of them critical ) discovered over the years got me thinking. You can see what i mean here <a title="Exploits List" href="http://www.milw0rm.com/search.php?dong=coppermine">http://www.milw0rm.com/search.php?dong=coppermine</a>. 3 vulnerabilities found in the first two months of 2009.  4 in 2008. This remembers me of <a href="http://www.erata.net/security/i-gave-up-on-coppermine-gallery/">read full article</a>]]></description>
		<wfw:commentRss>http://www.erata.net/security/i-gave-up-on-coppermine-gallery/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Web application security flows</title>
		<link>http://www.erata.net/security/web-application-security-flows/</link>
		<comments>http://www.erata.net/security/web-application-security-flows/#comments</comments>
		<pubDate>Thu, 12 Oct 2006 12:07:06 +0000</pubDate>
		<dc:creator>Iulian Margarintescu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[application]]></category>
		<category><![CDATA[author]]></category>
		<category><![CDATA[database server]]></category>
		<category><![CDATA[error]]></category>
		<category><![CDATA[first security]]></category>
		<category><![CDATA[http]]></category>
		<category><![CDATA[member]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[query]]></category>
		<category><![CDATA[safe]]></category>
		<category><![CDATA[server side programming]]></category>
		<category><![CDATA[server side programming language]]></category>
		<category><![CDATA[side programming language]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[way]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[web application]]></category>
		<category><![CDATA[Web application security]]></category>
		<category><![CDATA[web applications]]></category>
		<category><![CDATA[WHERE]]></category>

		<guid isPermaLink="false">http://www.erata.net/weblog/projects/2006/10/12/web-application-security-flows/</guid>
		<description><![CDATA[Here goes... my first security related post :)
<h3>Intro</h3>
First i must say that this will not be a way to prove that your application is secure, it will only be a quick &#38; dirty way of finding common bugs in web applications. The following will be a few techniques that i tend to use the first time i see an web application ( and generally a database application ). I will use PHP for the few code examples but the vulnerabilities presented are not limited to PHP, in fact are independent of the server-side programming language used.

 <a href="http://www.erata.net/security/web-application-security-flows/">read full article</a>]]></description>
		<wfw:commentRss>http://www.erata.net/security/web-application-security-flows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

