<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for matthewhughes.co.uk</title>
	<atom:link href="http://matthewhughes.co.uk/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://matthewhughes.co.uk</link>
	<description></description>
	<lastBuildDate>Thu, 02 Sep 2010 15:52:07 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Announcing Security BSD 0.02 – Codename: Banal by Averroes</title>
		<link>http://matthewhughes.co.uk/2010/05/announcing-security-bsd-0-02-%e2%80%93-codename-banal/comment-page-1/#comment-1243</link>
		<dc:creator>Averroes</dc:creator>
		<pubDate>Thu, 02 Sep 2010 15:52:07 +0000</pubDate>
		<guid isPermaLink="false">http://matthewhughes.co.uk/?p=743#comment-1243</guid>
		<description>eagerly awaiting the elaboration!</description>
		<content:encoded><![CDATA[<p>eagerly awaiting the elaboration!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Please Spam Me &#8211; A study into the language of 419 scams, spam and phishing. by Matthew Hughes</title>
		<link>http://matthewhughes.co.uk/2010/09/please-spam-me-a-study-into-the-language-of-419-scams-spam-and-phishing/comment-page-1/#comment-1241</link>
		<dc:creator>Matthew Hughes</dc:creator>
		<pubDate>Thu, 02 Sep 2010 14:40:44 +0000</pubDate>
		<guid isPermaLink="false">http://matthewhughes.co.uk/?p=804#comment-1241</guid>
		<description>Goddammit, so you heard of my grudge with bliddle58 too?</description>
		<content:encoded><![CDATA[<p>Goddammit, so you heard of my grudge with bliddle58 too?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Please Spam Me &#8211; A study into the language of 419 scams, spam and phishing. by thomas mackenzie</title>
		<link>http://matthewhughes.co.uk/2010/09/please-spam-me-a-study-into-the-language-of-419-scams-spam-and-phishing/comment-page-1/#comment-1240</link>
		<dc:creator>thomas mackenzie</dc:creator>
		<pubDate>Thu, 02 Sep 2010 14:14:36 +0000</pubDate>
		<guid isPermaLink="false">http://matthewhughes.co.uk/?p=804#comment-1240</guid>
		<description>this is a lie and your just trying to spam someone aren&#039;t you!</description>
		<content:encoded><![CDATA[<p>this is a lie and your just trying to spam someone aren&#8217;t you!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on University of Reddit: Web Application Hacking with DVWA: Lesson 1 &#8211; Getting Started and reflected XSS by rich</title>
		<link>http://matthewhughes.co.uk/2010/07/university-of-reddit-web-application-hacking-with-dvwa-lesson-1-getting-started-and-reflected-xss/comment-page-1/#comment-880</link>
		<dc:creator>rich</dc:creator>
		<pubDate>Tue, 20 Jul 2010 05:21:26 +0000</pubDate>
		<guid isPermaLink="false">http://matthewhughes.co.uk/?p=794#comment-880</guid>
		<description>It says &quot;Log in to DVWA with the username ‘admin’ and password ‘Password’&quot; but it&#039;s actually &#039;password&#039; all lowercase.</description>
		<content:encoded><![CDATA[<p>It says &#8220;Log in to DVWA with the username ‘admin’ and password ‘Password’&#8221; but it&#8217;s actually &#8216;password&#8217; all lowercase.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on University of Reddit: Web Application Hacking with DVWA: Lesson 1 &#8211; Getting Started and reflected XSS by lenards</title>
		<link>http://matthewhughes.co.uk/2010/07/university-of-reddit-web-application-hacking-with-dvwa-lesson-1-getting-started-and-reflected-xss/comment-page-1/#comment-869</link>
		<dc:creator>lenards</dc:creator>
		<pubDate>Sun, 18 Jul 2010 19:48:28 +0000</pubDate>
		<guid isPermaLink="false">http://matthewhughes.co.uk/?p=794#comment-869</guid>
		<description>Along the boat maker analogy, one of the biggest failures in history re shipwrights or boat construction was the Vasa: 

http://en.wikipedia.org/wiki/Vasa_%28ship%29

Neal Ford often talks about it as a meme that should be spread in the software development as a beautiful cautionary tale of the need to test, speak up, and not allow &quot;The King&quot; to force a project&#039;s failure.</description>
		<content:encoded><![CDATA[<p>Along the boat maker analogy, one of the biggest failures in history re shipwrights or boat construction was the Vasa: </p>
<p><a href="http://en.wikipedia.org/wiki/Vasa_%28ship%29" rel="nofollow">http://en.wikipedia.org/wiki/Vasa_%28ship%29</a></p>
<p>Neal Ford often talks about it as a meme that should be spread in the software development as a beautiful cautionary tale of the need to test, speak up, and not allow &#8220;The King&#8221; to force a project&#8217;s failure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on University of Reddit: Web Application Hacking with DVWA: Lesson 1 &#8211; Getting Started and reflected XSS by lenards</title>
		<link>http://matthewhughes.co.uk/2010/07/university-of-reddit-web-application-hacking-with-dvwa-lesson-1-getting-started-and-reflected-xss/comment-page-1/#comment-868</link>
		<dc:creator>lenards</dc:creator>
		<pubDate>Sun, 18 Jul 2010 19:46:11 +0000</pubDate>
		<guid isPermaLink="false">http://matthewhughes.co.uk/?p=794#comment-868</guid>
		<description>Isn&#039;t one choice to use the DVWA LiveCD and install it in VMWare/VirtualBox/etc?  Or would the DVWA LiveCD also need XAMPP?</description>
		<content:encoded><![CDATA[<p>Isn&#8217;t one choice to use the DVWA LiveCD and install it in VMWare/VirtualBox/etc?  Or would the DVWA LiveCD also need XAMPP?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on University of Reddit: Web Application Hacking with DVWA: Lesson 1 &#8211; Getting Started and reflected XSS by ethicalhack3r</title>
		<link>http://matthewhughes.co.uk/2010/07/university-of-reddit-web-application-hacking-with-dvwa-lesson-1-getting-started-and-reflected-xss/comment-page-1/#comment-860</link>
		<dc:creator>ethicalhack3r</dc:creator>
		<pubDate>Sat, 17 Jul 2010 11:25:06 +0000</pubDate>
		<guid isPermaLink="false">http://matthewhughes.co.uk/?p=794#comment-860</guid>
		<description>@Jigme Datse Rasku
Maybe you forgot to set the security level to low?

1) What is XSS?
XSS is better understood when called HTML injection. As the name XSS (Cross Site Scripting) implies that client side scripting code or Javascript more specifically is needed for successful exploitation. When in fact XSS can be exploited with just pure HTML. The name XSS can be confusing however if you think of it as simply injecting your own HTML into a web application then you can begin to understand its implications.

2) Why is this considered XSS?
Cross Site Scripting is when you inject code which is not from the same origin (web application). Meaning you bypass same origin policies. 

3) How do we fix this?
On a non technical level it is down to the software development culture. Developers are pushed to meet deadlines, as long as the code does what was set out in the original spec, the boss is happy. Implementing a Secure Development Life Cycle (SDLC) costs software vendors time and money. What needs to happen is that software vendors be legally accountable for the quality of their code. The cost for bad coding is very much pushed on to the consumer. Until the vendors have an incentive to write good secure code, why bother, it will only cost them more money.

On a technical level, good input and output sanitation on all user supplied input, regular source code or black box assessments by some one other than the development team. As a user there is the NoScript Firefox plugin and IE8&#039;s XSS filter. Both cannot 100% protect you however are a good start.</description>
		<content:encoded><![CDATA[<p>@Jigme Datse Rasku<br />
Maybe you forgot to set the security level to low?</p>
<p>1) What is XSS?<br />
XSS is better understood when called HTML injection. As the name XSS (Cross Site Scripting) implies that client side scripting code or Javascript more specifically is needed for successful exploitation. When in fact XSS can be exploited with just pure HTML. The name XSS can be confusing however if you think of it as simply injecting your own HTML into a web application then you can begin to understand its implications.</p>
<p>2) Why is this considered XSS?<br />
Cross Site Scripting is when you inject code which is not from the same origin (web application). Meaning you bypass same origin policies. </p>
<p>3) How do we fix this?<br />
On a non technical level it is down to the software development culture. Developers are pushed to meet deadlines, as long as the code does what was set out in the original spec, the boss is happy. Implementing a Secure Development Life Cycle (SDLC) costs software vendors time and money. What needs to happen is that software vendors be legally accountable for the quality of their code. The cost for bad coding is very much pushed on to the consumer. Until the vendors have an incentive to write good secure code, why bother, it will only cost them more money.</p>
<p>On a technical level, good input and output sanitation on all user supplied input, regular source code or black box assessments by some one other than the development team. As a user there is the NoScript Firefox plugin and IE8&#8217;s XSS filter. Both cannot 100% protect you however are a good start.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on University of Reddit: Web Application Hacking with DVWA: Lesson 1 &#8211; Getting Started and reflected XSS by Matthew Hughes</title>
		<link>http://matthewhughes.co.uk/2010/07/university-of-reddit-web-application-hacking-with-dvwa-lesson-1-getting-started-and-reflected-xss/comment-page-1/#comment-855</link>
		<dc:creator>Matthew Hughes</dc:creator>
		<pubDate>Fri, 16 Jul 2010 23:32:37 +0000</pubDate>
		<guid isPermaLink="false">http://matthewhughes.co.uk/?p=794#comment-855</guid>
		<description>1.) That was a typo that was corrected a few minutes after publication. Admin and Password is the correct login. 
2.) I just tried it on my own computer, and it worked fine. Are you sure you&#039;re doing it right? &lt; s c r i p t &gt; a l e r t ( &#039; x s s &#039; ) ; &lt; / s c r i p t &gt; is what you need to type in, minus the spaces. I just tried it at home on both Chrome and Firefox and it worked perfectly. 

I answered your questions in the post, but with not that much depth. I&#039;ll make another post explaining XSS in more detail.</description>
		<content:encoded><![CDATA[<p>1.) That was a typo that was corrected a few minutes after publication. Admin and Password is the correct login.<br />
2.) I just tried it on my own computer, and it worked fine. Are you sure you&#8217;re doing it right? < s c r i p t > a l e r t ( &#8216; x s s &#8216; ) ; < / s c r i p t > is what you need to type in, minus the spaces. I just tried it at home on both Chrome and Firefox and it worked perfectly. </p>
<p>I answered your questions in the post, but with not that much depth. I&#8217;ll make another post explaining XSS in more detail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on University of Reddit: Web Application Hacking with DVWA: Lesson 1 &#8211; Getting Started and reflected XSS by Jigme Datse Rasku</title>
		<link>http://matthewhughes.co.uk/2010/07/university-of-reddit-web-application-hacking-with-dvwa-lesson-1-getting-started-and-reflected-xss/comment-page-1/#comment-854</link>
		<dc:creator>Jigme Datse Rasku</dc:creator>
		<pubDate>Fri, 16 Jul 2010 22:50:56 +0000</pubDate>
		<guid isPermaLink="false">http://matthewhughes.co.uk/?p=794#comment-854</guid>
		<description>A few issues:

1) there is no &#039;DVWA&#039; account created with my version of DVWA, there is an &#039;admin&#039; account with password &#039;password&#039;.
2) the &#039;alert(‘xss’);&#039; has no *visible* effect on Chrome, or Firefox.  Not sure why this is, I&#039;m not very familiar with Javascript so I&#039;m not sure what the issue might be.

A couple of questions:

1) What is XSS?
2) Why is this considered XSS?
3) How do we fix this?

Thanks,

Jigme</description>
		<content:encoded><![CDATA[<p>A few issues:</p>
<p>1) there is no &#8216;DVWA&#8217; account created with my version of DVWA, there is an &#8216;admin&#8217; account with password &#8216;password&#8217;.<br />
2) the &#8216;alert(‘xss’);&#8217; has no *visible* effect on Chrome, or Firefox.  Not sure why this is, I&#8217;m not very familiar with Javascript so I&#8217;m not sure what the issue might be.</p>
<p>A couple of questions:</p>
<p>1) What is XSS?<br />
2) Why is this considered XSS?<br />
3) How do we fix this?</p>
<p>Thanks,</p>
<p>Jigme</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on A Brief Guide To The LIGATT Saga by B_Real</title>
		<link>http://matthewhughes.co.uk/2010/06/a-brief-guide-to-the-ligatt-saga/comment-page-1/#comment-801</link>
		<dc:creator>B_Real</dc:creator>
		<pubDate>Wed, 07 Jul 2010 15:47:35 +0000</pubDate>
		<guid isPermaLink="false">http://matthewhughes.co.uk/?p=791#comment-801</guid>
		<description>This nonsense with Evan’s criminal record has gone on for too long. Who cares if he was a felon or not? Anybody in a free market system can create their own companies and make a living, even reformed criminals. Ligatt has like 5 offices and government contracts according to their website, so I guess the government forgave him.</description>
		<content:encoded><![CDATA[<p>This nonsense with Evan’s criminal record has gone on for too long. Who cares if he was a felon or not? Anybody in a free market system can create their own companies and make a living, even reformed criminals. Ligatt has like 5 offices and government contracts according to their website, so I guess the government forgave him.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
