<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments for php security blog</title>
	<atom:link href="http://phpsecurity.wordpress.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://phpsecurity.wordpress.com</link>
	<description>security threads for web developers from bernd essl</description>
	<pubDate>Thu, 16 Oct 2008 06:55:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on (evil) Register Globals (on) by b23</title>
		<link>http://phpsecurity.wordpress.com/2007/11/07/evil-register-globals-on/#comment-71</link>
		<dc:creator>b23</dc:creator>
		<pubDate>Wed, 30 Jul 2008 21:24:21 +0000</pubDate>
		<guid isPermaLink="false">http://phpsecurity.wordpress.com/2007/11/07/evil-register-globals-on/#comment-71</guid>
		<description>Thank you Bijay Rungta!</description>
		<content:encoded><![CDATA[<p>Thank you Bijay Rungta!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on (evil) Register Globals (on) by Bijay Rungta</title>
		<link>http://phpsecurity.wordpress.com/2007/11/07/evil-register-globals-on/#comment-70</link>
		<dc:creator>Bijay Rungta</dc:creator>
		<pubDate>Wed, 30 Jul 2008 18:06:17 +0000</pubDate>
		<guid isPermaLink="false">http://phpsecurity.wordpress.com/2007/11/07/evil-register-globals-on/#comment-70</guid>
		<description>The register_globals directive is disabled (register_globals = Off) by default in PHP versions 4.2.0 and greater in the php config (php.ini). While it doesn’t represent a security vulnerability, it’s a security risk.

The text is a little misleading....
The last para should have read as
While leaving [emphasize]register_globals [emphasizeEvenMore]On[/emphasizeEvenMore][/emphasize] doesn’t represent a security vulnerability, it’s a security risk.

I had come here to confirm what is good and what's bad.....

Thanks a lot..

Bijay Rungta</description>
		<content:encoded><![CDATA[<p>The register_globals directive is disabled (register_globals = Off) by default in PHP versions 4.2.0 and greater in the php config (php.ini). While it doesn’t represent a security vulnerability, it’s a security risk.</p>
<p>The text is a little misleading&#8230;.<br />
The last para should have read as<br />
While leaving [emphasize]register_globals [emphasizeEvenMore]On[/emphasizeEvenMore][/emphasize] doesn’t represent a security vulnerability, it’s a security risk.</p>
<p>I had come here to confirm what is good and what&#8217;s bad&#8230;..</p>
<p>Thanks a lot..</p>
<p>Bijay Rungta</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hide your php source code (expired) by b23</title>
		<link>http://phpsecurity.wordpress.com/2008/01/02/hide-your-php-source-code/#comment-69</link>
		<dc:creator>b23</dc:creator>
		<pubDate>Sun, 27 Jul 2008 10:57:23 +0000</pubDate>
		<guid isPermaLink="false">http://phpsecurity.wordpress.com/2008/01/02/hide-your-php-source-code/#comment-69</guid>
		<description>This post has expired, I think. I was not able to install the bcompiler again quickly. 
Maybe you can ask any of the maintainers for help: http://pecl.php.net/package/bcompiler.

good luck.</description>
		<content:encoded><![CDATA[<p>This post has expired, I think. I was not able to install the bcompiler again quickly.<br />
Maybe you can ask any of the maintainers for help: <a href="http://pecl.php.net/package/bcompiler" rel="nofollow">http://pecl.php.net/package/bcompiler</a>.</p>
<p>good luck.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hide your php source code (expired) by S.V. Sureshkumar</title>
		<link>http://phpsecurity.wordpress.com/2008/01/02/hide-your-php-source-code/#comment-67</link>
		<dc:creator>S.V. Sureshkumar</dc:creator>
		<pubDate>Thu, 24 Jul 2008 04:39:41 +0000</pubDate>
		<guid isPermaLink="false">http://phpsecurity.wordpress.com/2008/01/02/hide-your-php-source-code/#comment-67</guid>
		<description>bcompiled code is not working in firefox 2 in ubundu 5 &#38; Debian. Please give me the tips to run bcompiled code</description>
		<content:encoded><![CDATA[<p>bcompiled code is not working in firefox 2 in ubundu 5 &amp; Debian. Please give me the tips to run bcompiled code</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hide your php source code (expired) by S.V. Sureshkumar</title>
		<link>http://phpsecurity.wordpress.com/2008/01/02/hide-your-php-source-code/#comment-66</link>
		<dc:creator>S.V. Sureshkumar</dc:creator>
		<pubDate>Tue, 15 Jul 2008 05:11:20 +0000</pubDate>
		<guid isPermaLink="false">http://phpsecurity.wordpress.com/2008/01/02/hide-your-php-source-code/#comment-66</guid>
		<description>Bcompiled code (php5 ) not working for postgress database operation in Debaian/ubuntu environment. Please give me a replay to work the bcompiled code for database operation
SVS</description>
		<content:encoded><![CDATA[<p>Bcompiled code (php5 ) not working for postgress database operation in Debaian/ubuntu environment. Please give me a replay to work the bcompiled code for database operation<br />
SVS</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Automated testing with Selenium IDE by Johny</title>
		<link>http://phpsecurity.wordpress.com/2007/11/24/automated-testing-with-selenium-ide/#comment-65</link>
		<dc:creator>Johny</dc:creator>
		<pubDate>Mon, 23 Jun 2008 13:07:56 +0000</pubDate>
		<guid isPermaLink="false">http://phpsecurity.wordpress.com/2007/11/24/automated-testing-with-selenium-ide/#comment-65</guid>
		<description>It s nice for frontend Testing where you watch but for real automated one it seems to be not usable yet</description>
		<content:encoded><![CDATA[<p>It s nice for frontend Testing where you watch but for real automated one it seems to be not usable yet</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Protect your application against SQL injections part 1 by Phill Brown</title>
		<link>http://phpsecurity.wordpress.com/2007/12/05/protect-your-application-against-sql-injections-part-1/#comment-64</link>
		<dc:creator>Phill Brown</dc:creator>
		<pubDate>Sun, 15 Jun 2008 02:10:43 +0000</pubDate>
		<guid isPermaLink="false">http://phpsecurity.wordpress.com/2007/12/05/protect-your-application-against-sql-injections-part-1/#comment-64</guid>
		<description>Thanks for the article.  It is great to come across different methods of prevention.  I had previously simply escaped strings and not thought about integers.

Thanks</description>
		<content:encoded><![CDATA[<p>Thanks for the article.  It is great to come across different methods of prevention.  I had previously simply escaped strings and not thought about integers.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The null byte to hack includes by pitagora</title>
		<link>http://phpsecurity.wordpress.com/2007/12/09/the-null-byte-to-hack-includes/#comment-61</link>
		<dc:creator>pitagora</dc:creator>
		<pubDate>Mon, 02 Jun 2008 20:56:28 +0000</pubDate>
		<guid isPermaLink="false">http://phpsecurity.wordpress.com/2007/12/09/the-null-byte-to-hack-includes/#comment-61</guid>
		<description>

Who said that is bullet proof even if you don't use null byte injection? What's stopping me from referencing a php on my site? You if think it's the fact that it will get executed on my server rather then you are double wrong. What's stopping me to mess with my server to see php files just like txt files? Hell I don't need to mess with anything...just install a default IIS that doesn't know about php. Either that or I put one line of code in my .htaccess to redirect the php to a txt file.

Including files given by a variable is plain dumb...no matter how you look at it.</description>
		<content:encoded><![CDATA[<p>Who said that is bullet proof even if you don&#8217;t use null byte injection? What&#8217;s stopping me from referencing a php on my site? You if think it&#8217;s the fact that it will get executed on my server rather then you are double wrong. What&#8217;s stopping me to mess with my server to see php files just like txt files? Hell I don&#8217;t need to mess with anything&#8230;just install a default IIS that doesn&#8217;t know about php. Either that or I put one line of code in my .htaccess to redirect the php to a txt file.</p>
<p>Including files given by a variable is plain dumb&#8230;no matter how you look at it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Books by Tobias Wassermann</title>
		<link>http://phpsecurity.wordpress.com/books/#comment-59</link>
		<dc:creator>Tobias Wassermann</dc:creator>
		<pubDate>Tue, 27 May 2008 21:54:18 +0000</pubDate>
		<guid isPermaLink="false">http://phpsecurity.wordpress.com/books/#comment-59</guid>
		<description>Hi,

ich wollte eigentlich schon länger einmal Danke für die Rezension meines "Sichere Webanwendungen mit PHP"-Buchs sagen, jetzt schaffe ich es endlich einmal.

Gruß

Tobias</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>ich wollte eigentlich schon länger einmal Danke für die Rezension meines &#8220;Sichere Webanwendungen mit PHP&#8221;-Buchs sagen, jetzt schaffe ich es endlich einmal.</p>
<p>Gruß</p>
<p>Tobias</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hide your php source code (expired) by me</title>
		<link>http://phpsecurity.wordpress.com/2008/01/02/hide-your-php-source-code/#comment-57</link>
		<dc:creator>me</dc:creator>
		<pubDate>Fri, 11 Apr 2008 04:52:45 +0000</pubDate>
		<guid isPermaLink="false">http://phpsecurity.wordpress.com/2008/01/02/hide-your-php-source-code/#comment-57</guid>
		<description>is the protection of php source code only recommended on distributed php scripts or even in the web? 

i mean, the index.php on the website, is there a possibility the php codes will be shown as well??</description>
		<content:encoded><![CDATA[<p>is the protection of php source code only recommended on distributed php scripts or even in the web? </p>
<p>i mean, the index.php on the website, is there a possibility the php codes will be shown as well??</p>
]]></content:encoded>
	</item>
</channel>
</rss>
