<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: MIT/Stanford/Syracuse Team Develop New PHP Intepreter-Based XSS and SQL Security Tester</title>
	<atom:link href="http://www.rkrishardy.com/2009/06/new-php-interpreter-based-xss-and-sql-security-tester/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rkrishardy.com/2009/06/new-php-interpreter-based-xss-and-sql-security-tester/</link>
	<description>Software Development, Web Applications and Business Analytics</description>
	<lastBuildDate>Wed, 10 Mar 2010 14:03:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Kris</title>
		<link>http://www.rkrishardy.com/2009/06/new-php-interpreter-based-xss-and-sql-security-tester/comment-page-1/#comment-1400</link>
		<dc:creator>Kris</dc:creator>
		<pubDate>Mon, 16 Nov 2009 18:54:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.rkrishardy.com/?p=181#comment-1400</guid>
		<description>A quick update...  Acunetix WVS can do this, so it doesn&#039;t look like Ardilla is the only way.  However, Acunetix is very expensive (close to $10,000 a license, last time I checked).  This may be a project for my Java Certified Developer certification.  ;)

I talked to the guys at Acunetix about how their query taint tracking works, and they were a little tight lipped.  I haven&#039;t had a chance to look at the code, although a reputable source tells me that it needs some work...

I found this link to a list of web vulnerability scanners.  I&#039;m working through them when I get the time.

http://sectools.org/web-scanners.html</description>
		<content:encoded><![CDATA[<p>A quick update&#8230;  Acunetix WVS can do this, so it doesn&#8217;t look like Ardilla is the only way.  However, Acunetix is very expensive (close to $10,000 a license, last time I checked).  This may be a project for my Java Certified Developer certification.  <img src='http://www.rkrishardy.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>I talked to the guys at Acunetix about how their query taint tracking works, and they were a little tight lipped.  I haven&#8217;t had a chance to look at the code, although a reputable source tells me that it needs some work&#8230;</p>
<p>I found this link to a list of web vulnerability scanners.  I&#8217;m working through them when I get the time.</p>
<p><a href="http://sectools.org/web-scanners.html" rel="nofollow">http://sectools.org/web-scanners.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nicolae Nmaolovan</title>
		<link>http://www.rkrishardy.com/2009/06/new-php-interpreter-based-xss-and-sql-security-tester/comment-page-1/#comment-991</link>
		<dc:creator>Nicolae Nmaolovan</dc:creator>
		<pubDate>Mon, 28 Sep 2009 18:29:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.rkrishardy.com/?p=181#comment-991</guid>
		<description>Hi, I&#039;m interested too, is there any know alternatives ? This would be very useful..</description>
		<content:encoded><![CDATA[<p>Hi, I&#8217;m interested too, is there any know alternatives ? This would be very useful..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kris</title>
		<link>http://www.rkrishardy.com/2009/06/new-php-interpreter-based-xss-and-sql-security-tester/comment-page-1/#comment-512</link>
		<dc:creator>Kris</dc:creator>
		<pubDate>Tue, 18 Aug 2009 16:29:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.rkrishardy.com/?p=181#comment-512</guid>
		<description>I&#039;ve talked with the guys at Washington about this, and they are interested in making it Open Source, but it doesn&#039;t look like it has moved forward yet.  I&#039;m keeping an eye on this, and may have a go on my own, because I would love to use it too.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve talked with the guys at Washington about this, and they are interested in making it Open Source, but it doesn&#8217;t look like it has moved forward yet.  I&#8217;m keeping an eye on this, and may have a go on my own, because I would love to use it too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Breck</title>
		<link>http://www.rkrishardy.com/2009/06/new-php-interpreter-based-xss-and-sql-security-tester/comment-page-1/#comment-491</link>
		<dc:creator>Breck</dc:creator>
		<pubDate>Mon, 17 Aug 2009 23:13:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.rkrishardy.com/?p=181#comment-491</guid>
		<description>Wow, really smart idea.

Any updates on whether this will be released? I&#039;ve got some large codebases that I would love to try it on.</description>
		<content:encoded><![CDATA[<p>Wow, really smart idea.</p>
<p>Any updates on whether this will be released? I&#8217;ve got some large codebases that I would love to try it on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How I Make $5000 a Month Posting Links on Google</title>
		<link>http://www.rkrishardy.com/2009/06/new-php-interpreter-based-xss-and-sql-security-tester/comment-page-1/#comment-191</link>
		<dc:creator>How I Make $5000 a Month Posting Links on Google</dc:creator>
		<pubDate>Fri, 26 Jun 2009 00:43:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.rkrishardy.com/?p=181#comment-191</guid>
		<description>Loved your latest post, by the way.</description>
		<content:encoded><![CDATA[<p>Loved your latest post, by the way.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Katy</title>
		<link>http://www.rkrishardy.com/2009/06/new-php-interpreter-based-xss-and-sql-security-tester/comment-page-1/#comment-187</link>
		<dc:creator>Katy</dc:creator>
		<pubDate>Wed, 24 Jun 2009 03:43:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.rkrishardy.com/?p=181#comment-187</guid>
		<description>Pretty nice post. I just found your blog and wanted to say 
that I have really liked reading your blog posts. Anyway 
I&#039;ll be subscribing to your feed and I hope you write again soon!</description>
		<content:encoded><![CDATA[<p>Pretty nice post. I just found your blog and wanted to say<br />
that I have really liked reading your blog posts. Anyway<br />
I&#8217;ll be subscribing to your feed and I hope you write again soon!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wayne State Web Communications Blog &#187; Blog Archive &#187; [Friday Links] The Summer Edition</title>
		<link>http://www.rkrishardy.com/2009/06/new-php-interpreter-based-xss-and-sql-security-tester/comment-page-1/#comment-183</link>
		<dc:creator>Wayne State Web Communications Blog &#187; Blog Archive &#187; [Friday Links] The Summer Edition</dc:creator>
		<pubDate>Sun, 21 Jun 2009 13:15:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.rkrishardy.com/?p=181#comment-183</guid>
		<description>[...] MIT/Stanford/Syracuse Team Develop New PHP Intepreter-Based XSS and SQL Security Tester [...]</description>
		<content:encoded><![CDATA[<p>[...] MIT/Stanford/Syracuse Team Develop New PHP Intepreter-Based XSS and SQL Security Tester [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Digital Media Minute</title>
		<link>http://www.rkrishardy.com/2009/06/new-php-interpreter-based-xss-and-sql-security-tester/comment-page-1/#comment-178</link>
		<dc:creator>Digital Media Minute</dc:creator>
		<pubDate>Sat, 20 Jun 2009 07:04:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.rkrishardy.com/?p=181#comment-178</guid>
		<description>&lt;strong&gt;PHP Security&#160;Checker...&lt;/strong&gt;

We did a post on ten security checks for PHP, and pointed to a PHP security guide as well. On a more recent, related note, you might want to take a look at Rkrishardy.com regarding researchers from MIT, Stanford and Syracuse having developed “Ardilla...</description>
		<content:encoded><![CDATA[<p><strong>PHP Security&nbsp;Checker&#8230;</strong></p>
<p>We did a post on ten security checks for PHP, and pointed to a PHP security guide as well. On a more recent, related note, you might want to take a look at Rkrishardy.com regarding researchers from MIT, Stanford and Syracuse having developed “Ardilla&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
