<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Xato : Application Security</title><link>http://msmvps.com/blogs/xato/archive/tags/Application+Security/default.aspx</link><description>Tags: Application Security</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Lesson two on what not to do with a CAPTCHA</title><link>http://msmvps.com/blogs/xato/archive/2007/08/22/lesson-two-on-what-not-to-do-with-a-captcha.aspx</link><pubDate>Wed, 22 Aug 2007 18:02:54 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1131446</guid><dc:creator>MB's Windows Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1131446</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2007/08/22/lesson-two-on-what-not-to-do-with-a-captcha.aspx#comments</comments><description>In my previous post on CAPTCHAs I mentioned that &amp;#8220;&amp;#8230;you need to make sure the end user can’t do anything to influence what code you pick.&amp;#8221; For this example, I will pick on captchas.net, which provides a free CAPTCHA service for anyone...(&lt;a href="http://msmvps.com/blogs/xato/archive/2007/08/22/lesson-two-on-what-not-to-do-with-a-captcha.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1131446" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Windows+Security/default.aspx">Windows Security</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://msmvps.com/blogs/xato/archive/tags/CAPTCHA/default.aspx">CAPTCHA</category></item><item><title>These CAPTCHAs are just not working out</title><link>http://msmvps.com/blogs/xato/archive/2007/08/21/these-captchas-are-just-not-working-out.aspx</link><pubDate>Wed, 22 Aug 2007 01:47:17 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1129268</guid><dc:creator>MB's Windows Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1129268</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2007/08/21/these-captchas-are-just-not-working-out.aspx#comments</comments><description>Filling out a web form without also having to pass a CAPTCHA test nowadays is pretty rare. CAPTCHAs weren&amp;#8217;t really that annoying to me when they were more of a rare occurrence but I have been finding myself more and more bothered with them lately...(&lt;a href="http://msmvps.com/blogs/xato/archive/2007/08/21/these-captchas-are-just-not-working-out.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1129268" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Windows+Security/default.aspx">Windows Security</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Cryptography/default.aspx">Cryptography</category><category domain="http://msmvps.com/blogs/xato/archive/tags/exploits/default.aspx">exploits</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://msmvps.com/blogs/xato/archive/tags/CAPTCHA/default.aspx">CAPTCHA</category></item><item><title>The Program.exe Problem</title><link>http://msmvps.com/blogs/xato/archive/2007/02/17/the-program-exe-problem.aspx</link><pubDate>Sat, 17 Feb 2007 19:30:07 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1564342</guid><dc:creator>MBs Windows Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1564342</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2007/02/17/the-program-exe-problem.aspx#comments</comments><description>A couple years ago I mentioned in a SecurityFocus column that Windows has a problem when you put a file named &amp;#8220;program.exe&amp;#8221; in the system root directory. The problem is basically in how it deals with spaces in paths that don&amp;#8217;t have quotes...(&lt;a href="http://msmvps.com/blogs/xato/archive/2007/02/17/the-program-exe-problem.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1564342" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Hardening/default.aspx">Hardening</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Malware/default.aspx">Malware</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Tools/default.aspx">Tools</category></item><item><title>Be Smarter with Account Names</title><link>http://msmvps.com/blogs/xato/archive/2007/02/15/be-smarter-with-account-names.aspx</link><pubDate>Fri, 16 Feb 2007 01:28:50 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1564343</guid><dc:creator>MBs Windows Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1564343</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2007/02/15/be-smarter-with-account-names.aspx#comments</comments><description>One thing that bothers me about many web sites out there is how I get to (or don&amp;#8217;t get to) choose my account name. Sure, many web sites let you have any account name you want, but some web sites just want to use your e-mail address. While this is...(&lt;a href="http://msmvps.com/blogs/xato/archive/2007/02/15/be-smarter-with-account-names.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1564343" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Application+Security/default.aspx">Application Security</category></item><item><title>Patterns &amp; Practices Security Wiki</title><link>http://msmvps.com/blogs/xato/archive/2007/02/15/patterns-amp-practices-security-wiki.aspx</link><pubDate>Thu, 15 Feb 2007 23:36:14 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1564344</guid><dc:creator>MBs Windows Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1564344</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2007/02/15/patterns-amp-practices-security-wiki.aspx#comments</comments><description>If you do any kind of .NET web development, it would be well worth your time to dig through Microsoft&amp;#8217;s Patterns &amp;#038; Practices Security Wiki The Wiki is a good index of old articles and a launching point for new articles on secure web development...(&lt;a href="http://msmvps.com/blogs/xato/archive/2007/02/15/patterns-amp-practices-security-wiki.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1564344" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Application+Security/default.aspx">Application Security</category></item><item><title>My SSN is showing?</title><link>http://msmvps.com/blogs/xato/archive/2007/02/06/my-ssn-is-showing.aspx</link><pubDate>Wed, 07 Feb 2007 00:34:46 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1564350</guid><dc:creator>MBs Windows Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1564350</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2007/02/06/my-ssn-is-showing.aspx#comments</comments><description>I got an e-mail earlier this week from a financial web site. The e-mail displayed the last 4 digits of my U.S. social security number. Presumably, they didn&amp;#8217;t show the entire number for security reasons, but I wondered how secure that really is...(&lt;a href="http://msmvps.com/blogs/xato/archive/2007/02/06/my-ssn-is-showing.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1564350" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Application+Security/default.aspx">Application Security</category></item><item><title>Yet another failed CAPTCHA?</title><link>http://msmvps.com/blogs/xato/archive/2007/02/02/yet-another-failed-captcha.aspx</link><pubDate>Sat, 03 Feb 2007 00:02:13 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1564353</guid><dc:creator>MBs Windows Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1564353</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2007/02/02/yet-another-failed-captcha.aspx#comments</comments><description>Today I ran across a Firefox add-on that automatically fills out the CAPTCHA form when you log in: https://addons.mozilla.org/firefox/4381/ Although some might think this is convenient, it obviously shows that eBay&amp;#8217;s CAPTCHA, like so many others...(&lt;a href="http://msmvps.com/blogs/xato/archive/2007/02/02/yet-another-failed-captcha.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1564353" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Application+Security/default.aspx">Application Security</category></item><item><title>Pafwert: Smarter Passwords</title><link>http://msmvps.com/blogs/xato/archive/2007/01/30/pafwert-smarter-passwords.aspx</link><pubDate>Wed, 31 Jan 2007 04:30:35 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1564356</guid><dc:creator>MBs Windows Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1564356</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2007/01/30/pafwert-smarter-passwords.aspx#comments</comments><description>Pafwert is an unique free tool to help you to select strong passwords that are easy to remember. Read More......(&lt;a href="http://msmvps.com/blogs/xato/archive/2007/01/30/pafwert-smarter-passwords.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1564356" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Windows+Security/default.aspx">Windows Security</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Tools/default.aspx">Tools</category></item><item><title>Anti-phishing system can make phishing worse</title><link>http://msmvps.com/blogs/xato/archive/2006/12/10/anti-phishing-system-can-make-phishing-worse.aspx</link><pubDate>Mon, 11 Dec 2006 04:28:50 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1564368</guid><dc:creator>MBs Windows Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1564368</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2006/12/10/anti-phishing-system-can-make-phishing-worse.aspx#comments</comments><description>I am constantly frustrated with poor security implementations I see all around the web. Often, these mistakes could be avoided by never breaking the simple security rules. One of these rules wrote about in my book Hacking the Code is that you should always...(&lt;a href="http://msmvps.com/blogs/xato/archive/2006/12/10/anti-phishing-system-can-make-phishing-worse.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1564368" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Application+Security/default.aspx">Application Security</category></item></channel></rss>