<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>rednael - Security</title>
    <link>http://blog.rednael.com/</link>
    <description>random thoughts, formed in the twisted mind of a coder...</description>
    <language>en-us</language>
    <copyright>Martijn Thie</copyright>
    <lastBuildDate>Tue, 04 Aug 2009 13:49:23 GMT</lastBuildDate>
    <generator>newtelligence dasBlog 2.3.9074.18820</generator>
    <managingEditor>blog@rednael.com</managingEditor>
    <webMaster>blog@rednael.com</webMaster>
    <item>
      <trackback:ping>http://blog.rednael.com/Trackback.aspx?guid=4a18a728-9957-4af8-aa42-a64e69c2cb30</trackback:ping>
      <pingback:server>http://blog.rednael.com/pingback.aspx</pingback:server>
      <pingback:target>http://blog.rednael.com/PermaLink,guid,4a18a728-9957-4af8-aa42-a64e69c2cb30.aspx</pingback:target>
      <dc:creator>Martijn Thie</dc:creator>
      <wfw:comment>http://blog.rednael.com/CommentView,guid,4a18a728-9957-4af8-aa42-a64e69c2cb30.aspx</wfw:comment>
      <wfw:commentRss>http://blog.rednael.com/SyndicationService.asmx/GetEntryCommentsRss?guid=4a18a728-9957-4af8-aa42-a64e69c2cb30</wfw:commentRss>
      <title>Securing webpages with the Locked element</title>
      <guid isPermaLink="false">http://blog.rednael.com/PermaLink,guid,4a18a728-9957-4af8-aa42-a64e69c2cb30.aspx</guid>
      <link>http://blog.rednael.com/2009/08/04/SecuringWebpagesWithTheLockedElement.aspx</link>
      <pubDate>Tue, 04 Aug 2009 13:49:23 GMT</pubDate>
      <description>Is there a way to fight JavaScript injections and cross-side scripting? Not in a very effective way. Not in a standards compliant way. Time to change the standards!&lt;img width="0" height="0" src="http://blog.rednael.com/aggbug.ashx?id=4a18a728-9957-4af8-aa42-a64e69c2cb30"/&gt;&lt;br/&gt;&lt;hr/&gt;visit my blog at &lt;a href="http://blog.rednael.com"&gt;blog.rednael.com&lt;/a&gt;. &lt;br /&gt;Rednael</description>
      <comments>http://blog.rednael.com/CommentView,guid,4a18a728-9957-4af8-aa42-a64e69c2cb30.aspx</comments>
      <category>Script and HTML</category>
      <category>Security</category>
    </item>
    <item>
      <trackback:ping>http://blog.rednael.com/Trackback.aspx?guid=2be3eb86-f166-4e2f-a74b-c77136c73de5</trackback:ping>
      <pingback:server>http://blog.rednael.com/pingback.aspx</pingback:server>
      <pingback:target>http://blog.rednael.com/PermaLink,guid,2be3eb86-f166-4e2f-a74b-c77136c73de5.aspx</pingback:target>
      <dc:creator>Martijn Thie</dc:creator>
      <wfw:comment>http://blog.rednael.com/CommentView,guid,2be3eb86-f166-4e2f-a74b-c77136c73de5.aspx</wfw:comment>
      <wfw:commentRss>http://blog.rednael.com/SyndicationService.asmx/GetEntryCommentsRss?guid=2be3eb86-f166-4e2f-a74b-c77136c73de5</wfw:commentRss>
      <title>Javascript Injection</title>
      <guid isPermaLink="false">http://blog.rednael.com/PermaLink,guid,2be3eb86-f166-4e2f-a74b-c77136c73de5.aspx</guid>
      <link>http://blog.rednael.com/2009/08/04/JavascriptInjection.aspx</link>
      <pubDate>Tue, 04 Aug 2009 11:52:00 GMT</pubDate>
      <description>Injecting remote scripts into any webpage using the addressbar. How it's done and what could happen. A serious serious security issue.&lt;img width="0" height="0" src="http://blog.rednael.com/aggbug.ashx?id=2be3eb86-f166-4e2f-a74b-c77136c73de5"/&gt;&lt;br/&gt;&lt;hr/&gt;visit my blog at &lt;a href="http://blog.rednael.com"&gt;blog.rednael.com&lt;/a&gt;. &lt;br /&gt;Rednael</description>
      <comments>http://blog.rednael.com/CommentView,guid,2be3eb86-f166-4e2f-a74b-c77136c73de5.aspx</comments>
      <category>Script and HTML</category>
      <category>Security</category>
    </item>
    <item>
      <trackback:ping>http://blog.rednael.com/Trackback.aspx?guid=f5bb912e-c7e8-4bf6-bf29-8c653e0debeb</trackback:ping>
      <pingback:server>http://blog.rednael.com/pingback.aspx</pingback:server>
      <pingback:target>http://blog.rednael.com/PermaLink,guid,f5bb912e-c7e8-4bf6-bf29-8c653e0debeb.aspx</pingback:target>
      <dc:creator>Martijn Thie</dc:creator>
      <wfw:comment>http://blog.rednael.com/CommentView,guid,f5bb912e-c7e8-4bf6-bf29-8c653e0debeb.aspx</wfw:comment>
      <wfw:commentRss>http://blog.rednael.com/SyndicationService.asmx/GetEntryCommentsRss?guid=f5bb912e-c7e8-4bf6-bf29-8c653e0debeb</wfw:commentRss>
      <title>SMTP Sinks: Using AsyncCompletion for Tarpitting</title>
      <guid isPermaLink="false">http://blog.rednael.com/PermaLink,guid,f5bb912e-c7e8-4bf6-bf29-8c653e0debeb.aspx</guid>
      <link>http://blog.rednael.com/2009/01/28/SMTPSinksUsingAsyncCompletionForTarpitting.aspx</link>
      <pubDate>Wed, 28 Jan 2009 09:12:23 GMT</pubDate>
      <description>How to enable tarpitting on your SMTP server for specific commands? This article describes how you can customize tarpitting using the AsyncCallback functionality provided by the sink interface.&lt;img width="0" height="0" src="http://blog.rednael.com/aggbug.ashx?id=f5bb912e-c7e8-4bf6-bf29-8c653e0debeb"/&gt;&lt;br/&gt;&lt;hr/&gt;visit my blog at &lt;a href="http://blog.rednael.com"&gt;blog.rednael.com&lt;/a&gt;. &lt;br /&gt;Rednael</description>
      <comments>http://blog.rednael.com/CommentView,guid,f5bb912e-c7e8-4bf6-bf29-8c653e0debeb.aspx</comments>
      <category>.Net</category>
      <category>Microsoft SMTP</category>
      <category>Security</category>
    </item>
    <item>
      <trackback:ping>http://blog.rednael.com/Trackback.aspx?guid=de3bf162-a075-47ee-b53f-c306e225d11c</trackback:ping>
      <pingback:server>http://blog.rednael.com/pingback.aspx</pingback:server>
      <pingback:target>http://blog.rednael.com/PermaLink,guid,de3bf162-a075-47ee-b53f-c306e225d11c.aspx</pingback:target>
      <dc:creator>Martijn Thie</dc:creator>
      <wfw:comment>http://blog.rednael.com/CommentView,guid,de3bf162-a075-47ee-b53f-c306e225d11c.aspx</wfw:comment>
      <wfw:commentRss>http://blog.rednael.com/SyndicationService.asmx/GetEntryCommentsRss?guid=de3bf162-a075-47ee-b53f-c306e225d11c</wfw:commentRss>
      <slash:comments>3</slash:comments>
      <title>Securing your password transfers with Keyed-Hashing (HMAC/Cram-MD5)</title>
      <guid isPermaLink="false">http://blog.rednael.com/PermaLink,guid,de3bf162-a075-47ee-b53f-c306e225d11c.aspx</guid>
      <link>http://blog.rednael.com/2008/09/30/SecuringYourPasswordTransfersWithKeyedHashingHMACCramMD5.aspx</link>
      <pubDate>Tue, 30 Sep 2008 14:49:26 GMT</pubDate>
      <description>Checking passwords the secure way. This post explains how you can implement a secure password system. A system where you don't have to send your password over the internet to be validated. It explains about HMAC and Cram-MD5. Some examples (in C#.Net) are included to demonstrate implementation of the system.&lt;img width="0" height="0" src="http://blog.rednael.com/aggbug.ashx?id=de3bf162-a075-47ee-b53f-c306e225d11c"/&gt;&lt;br/&gt;&lt;hr/&gt;visit my blog at &lt;a href="http://blog.rednael.com"&gt;blog.rednael.com&lt;/a&gt;. &lt;br /&gt;Rednael</description>
      <comments>http://blog.rednael.com/CommentView,guid,de3bf162-a075-47ee-b53f-c306e225d11c.aspx</comments>
      <category>Script and HTML</category>
      <category>Security</category>
    </item>
  </channel>
</rss>