<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>Rant and Finding Vulnerabilities in Public Websites - Yorumlar</title>
  <description>Ferruh Mavituna - Me, Myself and My Alter Ego...</description>
  <copyright>Ferruh Mavituna</copyright>
  <link>http://ferruh.mavituna.com</link>
  <lastBuildDate>Paz, 12 Şub 2012 20:19:27 +0200</lastBuildDate>
  <image>
    <title>Ferruh Mavituna</title>
    <link>http://ferruh.mavituna.com</link>
    <url>http://ferruh.mavituna.com/rss/rss.gif</url>
  </image>
  <item>
  <title>Aspirin Osman</title>
  <link>http://ferruh.mavituna.com/rant-and-finding-vulnerabilities-in-public-websites-oku/</link>
  <author>Aspirin Osman</author>
  <pubDate>Çar, 01 Ağu 2007 22:52:40 +0200</pubDate>
  <description>           Hay Man Ferruh&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt; Ingilizcem bu kadar oldugu i&amp;#231;in makaleyi okuyamiyorum. T&amp;#252;rk&amp;#231;e kaynak sikintisindan dolayi pek bir ilerleme kaydedemiyoruz. Ingilizce bilen biri bunun gibi yazilari rahatlikla bulabilir ama T&amp;#252;r&amp;#231;e kaynak yok denecek kadar az belkide yok.&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt; Saygilar.</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/rant-and-finding-vulnerabilities-in-public-websites-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Pzt, 30 Tem 2007 22:58:19 +0200</pubDate>
  <description>           Today lots of other things happened appereantly, Quite funny and sad.&lt;br /&gt;&lt;br /&gt;http://sla.ckers.org/forum/read.php?3,14208&lt;br /&gt;http://blog.php-security.org/archives/90-More-CSRF-Redirectors.html&lt;br /&gt;http://www.0x000000.com/index.php?i=410&lt;br /&gt;</description>
</item>
<item>
  <title>daddyguy</title>
  <link>http://ferruh.mavituna.com/rant-and-finding-vulnerabilities-in-public-websites-oku/</link>
  <author>daddyguy</author>
  <pubDate>Cmt, 28 Tem 2007 21:37:35 +0200</pubDate>
  <description>           &lt;blockquote&gt;&lt;strong&gt;hi,&lt;br /&gt;http://sqlinject.blogspot.com/ &lt;br /&gt;This is my blog.   I am new at sql injection. I  found a lot of basic errors much too.&lt;/strong&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Merhaba, bu blog benim blogum. Yaptigimin fazla iyi olamdigni anlayip ticari siteleri yazmaktan vazge&amp;#231;tim hatta en son &amp;#252;&amp;#231; tane firmya eposta yolladim fakat adamlardan tik yok. Sonu&amp;#231;ta ben onalra yardim etmek istedim. Ayni zamanda sitede bir mssql vs. hatasi g&amp;#246;r&amp;#252;nce tatmin oluyor insan. Bir de su var kendi bilgisayarimda sunucuda bir seyler denemektense piyasada ugrasmak daha iyi geliyor bana. &amp;#199;&amp;#252;nk&amp;#252; herkesin kullandigi kod farkli, sabit degil. &lt;br /&gt;&lt;br /&gt;Ama ticari siteleri vs. vermek hatali. Yaptigim nelki sa&amp;#231;ma belki degil. Ama google'da arayip bulmak &amp;#231;ok zevkli. Simdi sql injection(sizma/sizdirma/g&amp;#246;mme) ile bir seyler yapmak, zarar vermek lamerlik diyen &amp;#231;ok olacak. Dogru basit bir sey ve marifet degil ama bug&amp;#252;nlerde bile hala bu a&amp;#231;igi kimse kapatma ihtiyaci duymamis veya haberdar degil. &lt;br /&gt;&lt;br /&gt;Bu arada sizin sql-injection makalesi &amp;#231;ok isime yaradi. Benim yaptigim site sahipleri uyarmaktan &amp;#246;te degil artik.&lt;br /&gt;Saygilarimla,&lt;br /&gt;Aykut</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/rant-and-finding-vulnerabilities-in-public-websites-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Cmt, 28 Tem 2007 19:04:21 +0200</pubDate>
  <description>           I know what you mean and I read the comments in your website. I can see your point too or exceptional full disclosure in here. Sorry about showing you as an example&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt; but I'm glad also you see my point.&lt;br /&gt;&lt;br /&gt;Thanks,</description>
</item>
<item>
  <title>Gareth Heyes</title>
  <link>http://ferruh.mavituna.com/rant-and-finding-vulnerabilities-in-public-websites-oku/</link>
  <author>Gareth Heyes</author>
  <pubDate>Cmt, 28 Tem 2007 17:42:05 +0200</pubDate>
  <description>           Hi&lt;br /&gt;&lt;br /&gt;That's just my personality, if someone posts a security tool to a list of security experts and it contains a hole, then what do you expect? And such an obvious one at that, maybe Chris should have been more professional and tested the tool before releasing it to the public.&lt;br /&gt;&lt;br /&gt;I enjoy finding holes in software because I enjoy the technical challenge, I don't just go and find XSS holes on web sites that's boring! I try to find unique creative ways of exploiting things.&lt;br /&gt;&lt;br /&gt;I can see your point and normally I would have reported it directly to the person but I just found the whole thing so ironic. What did annoy me though was the comments by Chris on my blog, he basically said that a XSS hole was a slight risk on his site, c'mon? From a security guy?</description>
</item>

</channel>
</rss>
