<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>CSRF, XSS, SQL Injection den Korunma ve Diger Korunma Geyikleri - Yorumlar</title>
  <description>Ferruh Mavituna - Me, Myself and My Alter Ego...</description>
  <copyright>Ferruh Mavituna</copyright>
  <link>http://ferruh.mavituna.com</link>
  <lastBuildDate>Paz, 12 Şub 2012 20:46:26 +0200</lastBuildDate>
  <image>
    <title>Ferruh Mavituna</title>
    <link>http://ferruh.mavituna.com</link>
    <url>http://ferruh.mavituna.com/rss/rss.gif</url>
  </image>
  <item>
  <title>ZeberuS</title>
  <link>http://ferruh.mavituna.com/csrf-xss-sql-injection-den-korunma-ve-diger-korunma-geyikleri-oku/</link>
  <author>ZeberuS</author>
  <pubDate>Pzt, 03 Ara 2007 23:48:50 +0200</pubDate>
  <description>           .htaccess Ile bunlari  XSS,XSRF Kapatmanizda M&amp;#252;mk&amp;#252;n Olabilir ,</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/csrf-xss-sql-injection-den-korunma-ve-diger-korunma-geyikleri-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Pzt, 16 Nis 2007 22:20:12 +0200</pubDate>
  <description>           SQL icin prepared statementlar kullanin mumukun degilse,&lt;br /&gt;&lt;br /&gt;integer' in integer oldugundan emin olur &lt;strong&gt;isnumeric()&lt;/strong&gt; ve stringlerde de tek tirnakin iki tek tirnak ile replace edildiginden &lt;strong&gt;Replace(param,&amp;quot;'&amp;quot;,&amp;quot;''&amp;quot;)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;XSS icinde &lt;strong&gt;Server.HTMLEncode()&lt;/strong&gt; kullanidiginizdan emin olun.</description>
</item>
<item>
  <title>Oguzhan Eren</title>
  <link>http://ferruh.mavituna.com/csrf-xss-sql-injection-den-korunma-ve-diger-korunma-geyikleri-oku/</link>
  <author>Oguzhan Eren</author>
  <pubDate>Pzt, 16 Nis 2007 20:12:03 +0200</pubDate>
  <description>           tesekk&amp;#252;r ederim cevabini i&amp;#231;in ama ben ASP i&amp;#231;in demistim </description>
</item>
<item>
  <title>koray</title>
  <link>http://ferruh.mavituna.com/csrf-xss-sql-injection-den-korunma-ve-diger-korunma-geyikleri-oku/</link>
  <author>koray</author>
  <pubDate>Paz, 15 Nis 2007 14:05:32 +0200</pubDate>
  <description>           Oguzhan Eren,&lt;br /&gt;&lt;br /&gt;Ferruh Mavituna diyor ki;&lt;br /&gt;eger bunlari bloklarsaniz hatali bir is yapiyorsunuz demektir diyor.&lt;br /&gt;www.phpguvenligi.org'dan sql injection,xss ve digerlerinden korunmak i&amp;#231;in ne yapabiliriz,bir &amp;#231;ok d&amp;#246;k&amp;#252;man mevcut.&lt;br /&gt;&lt;br /&gt;iyi g&amp;#252;nler</description>
</item>
<item>
  <title>Oguzhan Eren</title>
  <link>http://ferruh.mavituna.com/csrf-xss-sql-injection-den-korunma-ve-diger-korunma-geyikleri-oku/</link>
  <author>Oguzhan Eren</author>
  <pubDate>Cum, 13 Nis 2007 23:21:04 +0200</pubDate>
  <description>           G&amp;#252;zel bir d&amp;#246;k&amp;#252;man olmus&lt;br /&gt;&lt;br /&gt;union bloklarsaniz sonsuz bir d&amp;#246;ng&amp;#252; olur demissiniz pek anlamadim&lt;img src=&quot;/mg/smilies/sad.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:(&quot; /&gt;&lt;br /&gt;&lt;br /&gt;ASP de saglam bir SQL Injection koruma ve XSS koruma i&amp;#231;in kod vermeniz m&amp;#252;mk&amp;#252;nm&amp;#252;d&amp;#252;r&lt;br /&gt;kisa bir sey olsa bile ondan uyarliyarak yazabilirim</description>
</item>
<item>
  <title></title>
  <link>http://ferruh.mavituna.com/csrf-xss-sql-injection-den-korunma-ve-diger-korunma-geyikleri-oku/</link>
  <author></author>
  <pubDate>Çar, 11 Nis 2007 00:03:30 +0200</pubDate>
  <description>           guzel yazi da senin rightbase kaymis sanki</description>
</item>
<item>
  <title>koray</title>
  <link>http://ferruh.mavituna.com/csrf-xss-sql-injection-den-korunma-ve-diger-korunma-geyikleri-oku/</link>
  <author>koray</author>
  <pubDate>Sal, 10 Nis 2007 20:18:57 +0200</pubDate>
  <description>           Himm,anladim yorumun i&amp;#231;in tesekk&amp;#252;r ederim.</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/csrf-xss-sql-injection-den-korunma-ve-diger-korunma-geyikleri-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Sal, 10 Nis 2007 18:19:30 +0200</pubDate>
  <description>           Genel olarak filtreleme whitelisting olmali yani sadece gereken karakterleri kabul etmeli ve dogerlerini almamali.&lt;br /&gt;&lt;br /&gt;Dedigim gibi XSS icin kullanidginiz web dili HTML Encode u ne ile yapiyorsa o, SQL icinse prepared statement. Eger union vs. bloklama kalkarsaniz sonu gelmez bir dongu, hataya cok megilli bir is yapiyor olacaksiniz.</description>
</item>
<item>
  <title>koray</title>
  <link>http://ferruh.mavituna.com/csrf-xss-sql-injection-den-korunma-ve-diger-korunma-geyikleri-oku/</link>
  <author>koray</author>
  <pubDate>Sal, 10 Nis 2007 18:14:44 +0200</pubDate>
  <description>           Peki,karakterleri filtrelersek */&amp;lt;UNION% gibi bir ise yarar mi ,karakterleri hex'e &amp;#231;evirerek filtreden ge&amp;#231;mek isteyenler bu karakterleri filtrelersem xss,sql vs..'den korunabilir miyim?Zaten tam g&amp;#252;venlik yoktur  bunun yaninda hostta da g&amp;#252;venlik saglanmali ama benim sorum sadece belirli karakterleri filtrelersen yukaridaki gibi bir nevi korunmus olur muyum?&lt;br /&gt;&lt;br /&gt;Tesekk&amp;#252;rler.</description>
</item>

</channel>
</rss>
