<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: A Lesson in Web Application Security Part 1</title>
	<atom:link href="http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/</link>
	<description>http://blog.thewheatfield.org</description>
	<lastBuildDate>Wed, 15 Feb 2012 02:46:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: A Lesson in Web Application Security Part 2 &#171; TheWheat Field</title>
		<link>http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/#comment-1989</link>
		<dc:creator><![CDATA[A Lesson in Web Application Security Part 2 &#171; TheWheat Field]]></dc:creator>
		<pubDate>Wed, 25 Mar 2009 17:01:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/#comment-1989</guid>
		<description><![CDATA[[...] , Security , Technology Tags: a level, as, Brunei, exploit, o level, results, sms      **Read Part 1 to get the full picture of [...]]]></description>
		<content:encoded><![CDATA[<p>[...] , Security , Technology Tags: a level, as, Brunei, exploit, o level, results, sms      **Read Part 1 to get the full picture of [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NTT</title>
		<link>http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/#comment-1945</link>
		<dc:creator><![CDATA[NTT]]></dc:creator>
		<pubDate>Fri, 30 Jan 2009 11:02:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/#comment-1945</guid>
		<description><![CDATA[So you&#039;re saying the issue is that anyone can access the results of any candidate as long as they know the Candidate Code?? But that&#039;s gonna be hard no??

But one can use this just to do a DOS attack on the telecom company, or an individual.. Just write a script to &quot;attach&quot; a cellphone no. on ALL results.. Hehehehe.. Ooops.. Am I not supposed to say that??]]></description>
		<content:encoded><![CDATA[<p>So you&#8217;re saying the issue is that anyone can access the results of any candidate as long as they know the Candidate Code?? But that&#8217;s gonna be hard no??</p>
<p>But one can use this just to do a DOS attack on the telecom company, or an individual.. Just write a script to &#8220;attach&#8221; a cellphone no. on ALL results.. Hehehehe.. Ooops.. Am I not supposed to say that??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TheWheat</title>
		<link>http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/#comment-1944</link>
		<dc:creator><![CDATA[TheWheat]]></dc:creator>
		<pubDate>Fri, 30 Jan 2009 04:33:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/#comment-1944</guid>
		<description><![CDATA[It&#039;s not meant to be seen... yet as I don&#039;t want it to be exploited. Though, you are always free to investigate on your own. Trying to do responsible disclosure.]]></description>
		<content:encoded><![CDATA[<p>It&#8217;s not meant to be seen&#8230; yet as I don&#8217;t want it to be exploited. Though, you are always free to investigate on your own. Trying to do responsible disclosure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LSM</title>
		<link>http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/#comment-1943</link>
		<dc:creator><![CDATA[LSM]]></dc:creator>
		<pubDate>Fri, 30 Jan 2009 04:20:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/#comment-1943</guid>
		<description><![CDATA[So then what is the issue? I&#039;m not seeing it.]]></description>
		<content:encoded><![CDATA[<p>So then what is the issue? I&#8217;m not seeing it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TheWheat</title>
		<link>http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/#comment-1942</link>
		<dc:creator><![CDATA[TheWheat]]></dc:creator>
		<pubDate>Fri, 30 Jan 2009 03:01:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/#comment-1942</guid>
		<description><![CDATA[Ok it&#039;s fixed. ScribeFire issue not working well with Wordpress. Well the actual names and results are changed to protect the identity and results of the person whose results I did get]]></description>
		<content:encoded><![CDATA[<p>Ok it&#8217;s fixed. ScribeFire issue not working well with WordPress. Well the actual names and results are changed to protect the identity and results of the person whose results I did get</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LSM</title>
		<link>http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/#comment-1940</link>
		<dc:creator><![CDATA[LSM]]></dc:creator>
		<pubDate>Fri, 30 Jan 2009 02:49:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.thewheatfield.org/2009/01/30/a-lesson-in-web-application-security-part-1/#comment-1940</guid>
		<description><![CDATA[I think you need to reflow Steps 4 and 5. They&#039;re hidden cos they&#039;re too long. You can copy &amp; paste the text into notepad but that&#039;s a pain.

If you mean the design flaw is defaulting everything to A&#039;s I can imagine a lot of people called CANDIDATE NAME will be celebrating prematurely.]]></description>
		<content:encoded><![CDATA[<p>I think you need to reflow Steps 4 and 5. They&#8217;re hidden cos they&#8217;re too long. You can copy &amp; paste the text into notepad but that&#8217;s a pain.</p>
<p>If you mean the design flaw is defaulting everything to A&#8217;s I can imagine a lot of people called CANDIDATE NAME will be celebrating prematurely.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

