<?xml version="1.0" encoding="ISO-8859-1"?>
<!-- generator="wordpress/2.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Mighty Seek &#187; Podcasts</title>
	<link>http://www.mightyseek.com</link>
	<description>A podcast about web application security, as well as general web application development issues. The primary focus is on security and tries to explain things so that anyone can understand them since security issues affect everyone across an organization. Hopefully this show will be a resource for everyone involved in a software development project.</description>
	<pubDate>Tue, 04 Mar 2008 07:04:07 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2</generator>
	<language>en</language>
		<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;Dan Kuykendall </copyright>
		<managingEditor>dan@kuykendall.org (Dan Kuykendall)</managingEditor>
		<webMaster>dan@kuykendall.org(Dan Kuykendall)</webMaster>
		<category>Technolgy</category>
		<ttl>1440</ttl>
		<itunes:keywords>web application security development</itunes:keywords>
		<itunes:subtitle>A podcast about web application security, as well as general web application development issues. The primary focus is on security and tries to explain things so that anyone can understand them since security issues affect everyone across an organizatio...</itunes:subtitle>
		<itunes:summary>A podcast about web application security, as well as general web application development issues. The primary focus is on security and tries to explain things so that anyone can understand them since security issues affect everyone across an organization. Hopefully this show will be a resource for everyone involved in a software development project.</itunes:summary>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:category text="Technology"/>
<itunes:category text="Technology">
  <itunes:category text="Software How-To"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="Training"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>Dan Kuykendall</itunes:name>
			<itunes:email>dan@kuykendall.org</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://www.mightyseek.com/images/itunescover.jpg" />
		<image>
			<url>http://www.mightyseek.com/images/itunescover.jpg</url>
			<title>Mighty Seek</title>
			<link>http://www.mightyseek.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>SQL Injection mention on hype-free</title>
		<link>http://www.mightyseek.com/web-application-security/sql-injection-mention-on-hype-free</link>
		<comments>http://www.mightyseek.com/web-application-security/sql-injection-mention-on-hype-free#comments</comments>
		<pubDate>Fri, 27 Apr 2007 07:35:42 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Hands On Series]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podcasts/sql-injection-mention-on-hype-free</guid>
		<description><![CDATA[Every once in awhile I try and find out if anyone is noticing my podcast. Well I stumbled on a mention of the SQL Injection hands on episode on hype-free.
]]></description>
			<content:encoded><![CDATA[<p>Every once in awhile I try and find out if anyone is noticing my podcast. Well I stumbled on a <a href="http://hype-free.blogspot.com/2007/04/sql-injections-what-they-are-and-how-to.html">mention of the SQL Injection hands on</a> episode on hype-free.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/sql-injection-mention-on-hype-free/feed</wfw:commentRss>
		</item>
		<item>
		<title>MightySeek Interviews rsnake</title>
		<link>http://www.mightyseek.com/web-application-security/mightyseek-interviews-rsnake</link>
		<comments>http://www.mightyseek.com/web-application-security/mightyseek-interviews-rsnake#comments</comments>
		<pubDate>Thu, 19 Apr 2007 07:45:27 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podcasts/mightyseek-interviews-rsnake</guid>
		<description><![CDATA[Today I had the pleasure of meeting up with a celeb of the web app sec world&#8230;. rsnake of the ha.ckers.org website. I hope you enjoy the interview, but I made a huge mistake with the recording. Here I was with my first interview, I hook up my mic and load up the recording software [...]]]></description>
			<content:encoded><![CDATA[<p>Today I had the pleasure of meeting up with a celeb of the web app sec world&#8230;. rsnake of the <a href="http://ha.ckers.org/" target="_blank">ha.ckers.org</a> website. I hope you enjoy the interview, but I made a huge mistake with the recording. Here I was with my first interview, I hook up my mic and load up the recording software and then completely forget to switch to the mic input to my good mic, and end up doing the recording on the lame mic thats built into my laptop.</p>
<p>In any case, here ya go.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/mightyseek-interviews-rsnake/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/56/0/MightySeek-18-2007-04-18-rsnakeInterview.mp3" length="30225059" type="audio/mpeg"/>
<itunes:duration>41:57</itunes:duration>
		<itunes:subtitle>Today I had the pleasure of meeting up with a celeb of the web app sec world.... rsnake of the ha.ckers.org website. I hope you ...</itunes:subtitle>
		<itunes:summary>Today I had the pleasure of meeting up with a celeb of the web app sec world.... rsnake of the ha.ckers.org website. I hope you enjoy the interview, but I made a huge mistake with the recording. Here I was with my first interview, I hook up my mic and load up the recording software and then completely forget to switch to the mic input to my good mic, and end up doing the recording on the lame mic thats built into my laptop.

In any case, here ya go.</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>PHP Security and the Month of PHP Bugs</title>
		<link>http://www.mightyseek.com/web-application-security/php-security-and-the-month-of-php-bugs</link>
		<comments>http://www.mightyseek.com/web-application-security/php-security-and-the-month-of-php-bugs#comments</comments>
		<pubDate>Sat, 10 Mar 2007 01:20:01 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podcasts/php-security-and-the-month-of-php-bugs</guid>
		<description><![CDATA[In this episode is discuss PHP security. Up till this point I have talked about web app sec in general, but I break from this in honor of the Month Of PHP Bugs that is going on through March.
PHP has frequently been blamed for security problems in applications written in PHP which really is no [...]]]></description>
			<content:encoded><![CDATA[<p>In this episode is discuss PHP security. Up till this point I have talked about web app sec in general, but I break from this in honor of the <a href="http://www.php-security.org/" target="_blank">Month Of PHP Bugs</a> that is going on through March.</p>
<p>PHP has frequently been blamed for security problems in applications written in PHP which really is no fault of the language and engine itself.  It would be like everyone blaming C and C++ as being insecure, and the cause of tons of security problems. Most of the time the problem is the developers who use the languages, not the languages themselves. However, there are security problems in the PHP codebase which need to be fixed and is what is being highlighted by the <a href="http://www.php-security.org/" target="_blank">Month Of PHP Bugs</a>.</p>
<p>So in this episode I discuss these issues, some of my past projects and some various other issues in PHP&#8230;  Its so good to be back at the mic, even tho I am still recovering from the flu and had my voice start failing me at the end.<br />
Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/php-security-and-the-month-of-php-bugs/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/53/0/MightySeek-17-2007-03-09-MonthOfPHPBugs.mp3" length="47224361" type="audio/mpeg"/>
<itunes:duration>65:34</itunes:duration>
		<itunes:subtitle>In this episode is discuss PHP security. Up till this point I have talked about web app sec in general, but I break from this ...</itunes:subtitle>
		<itunes:summary>In this episode is discuss PHP security. Up till this point I have talked about web app sec in general, but I break from this in honor of the Month Of PHP Bugs that is going on through March.
PHP has frequently been blamed for security problems in applications written in PHP which really is no fault of the language and engine itself.  It would be like everyone blaming C and C++ as being insecure, and the cause of tons of security problems. Most of the time the problem is the developers who use the languages, not the languages themselves. However, there are security problems in the PHP codebase which need to be fixed and is what is being highlighted by the Month Of PHP Bugs.
So in this episode I discuss these issues, some of my past projects and some various other issues in PHP...  Its so good to be back at the mic, even tho I am still recovering from the flu and had my voice start failing me at the end.
Enjoy!
</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Hands On Series - Cross Site Scripting (XSS) Part 1</title>
		<link>http://www.mightyseek.com/web-application-security/hands-on-series-cross-site-scripting-xss-part-1</link>
		<comments>http://www.mightyseek.com/web-application-security/hands-on-series-cross-site-scripting-xss-part-1#comments</comments>
		<pubDate>Mon, 28 Aug 2006 03:57:40 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Hands On Series]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podcasts/hands-on-series-cross-site-scripting-xss-part-1</guid>
		<description><![CDATA[The &#8220;Hands on Series&#8221; continues!

In this episode we start dealing with Cross Site Scripting (XSS) attacks. 
CSS = Cascading Style Sheets
XSS = Cross Site Scripting
Cross Site Scripting is a technique used to add script to a trusted site that will be executed on other users browsers.
A key element to XSS is that one user can [...]]]></description>
			<content:encoded><![CDATA[<p>The &#8220;Hands on Series&#8221; continues!<br />
<br />
In this episode we start dealing with Cross Site Scripting (XSS) attacks. </p>
<p>CSS = Cascading Style Sheets<br />
XSS = Cross Site Scripting</p>
<p>Cross Site Scripting is a technique used to add script to a trusted site that will be executed on other users browsers.<br />
A key element to XSS is that one user can submit data to a website that will later be displayed for other users.<br />
It is nessesary that the bad guy NOT mess up the HTML structure, otherwise the result will be web defacement rather then attacking other users.</p>
<p>The <a href="http://hackme.ntobjectives.com/" target="_new"><b>hackme site</b></a> has been updated and improved (more about that in a moment)</p>
<p>and now includes a section for XSS which we will be using in this episode.<br />
<a id="more-59"></a><br /> <a href="http://www.mightyseek.com/web-application-security/hands-on-series-cross-site-scripting-xss-part-1#more-14" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/hands-on-series-cross-site-scripting-xss-part-1/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/14/0/MightySeek-16-2006-07-28-HandOnSeriesXSS.mp3" length="27508399" type="audio/mpeg"/>
<itunes:duration>38:10</itunes:duration>
		<itunes:subtitle>The #8220;Hands on Series#8221; continues!

In this episode we start dealing with Cross Site Scripting (XSS) attacks. 
CSS = Cascading Style Sheets
XSS = Cross Site Scripting
Cross ...</itunes:subtitle>
		<itunes:summary>The #8220;Hands on Series#8221; continues!

In this episode we start dealing with Cross Site Scripting (XSS) attacks. 
CSS = Cascading Style Sheets
XSS = Cross Site Scripting
Cross Site Scripting is a technique used to add script to a trusted site that will be executed on other users browsers.
A key element to XSS is that one user can submit data to a website that will later be displayed for other users.
It is nessesary that the bad guy NOT mess up the HTML structure, otherwise the result will be web defacement rather then attacking other users.
The hackme site has been updated and improved (more about that in a moment)

and now includes a section for XSS which we will be using in this episode.
</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Hands,On,Series,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Mighty Seek Podcast #15 - News and Misc Topics</title>
		<link>http://www.mightyseek.com/web-application-security/mighty-seek-podcast-15-news-and-misc-topics</link>
		<comments>http://www.mightyseek.com/web-application-security/mighty-seek-podcast-15-news-and-misc-topics#comments</comments>
		<pubDate>Fri, 26 May 2006 22:41:15 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/05/26/mighty-seek-podcast-15-news-and-misc-topics/</guid>
		<description><![CDATA[A quick in between to the Hands On Series, I chat about some news and issues of the day.
Turkish Hacker defaces 38,000 websites hosted on GoDaddy
Flawed USC admissions site allowed access to applicant data
Breach case could curtail Web flaw finders
Man charged with accessing USC student data
Tsunami appeal site &#8216;hacker&#8217; found guilty
]]></description>
			<content:encoded><![CDATA[<p>A quick in between to the Hands On Series, I chat about some news and issues of the day.</p>
<p><a href="http://www.zone-h.org/en/news/read/id=206009/">Turkish Hacker defaces 38,000 websites hosted on GoDaddy</a></p>
<p><a href="http://www.securityfocus.com/news/11239">Flawed USC admissions site allowed access to applicant data</a></p>
<p><a href="http://www.securityfocus.com/news/11389/1">Breach case could curtail Web flaw finders</a></p>
<p><a href="http://www.securityfocus.com/brief/191">Man charged with accessing USC student data</a></p>
<p><a href="http://news.zdnet.co.uk/0,39020330,39226548,00.htm">Tsunami appeal site &#8216;hacker&#8217; found guilty</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/mighty-seek-podcast-15-news-and-misc-topics/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/9/0/MightySeek-15-2006-05-23-NewsAndMiscTopics.mp3" length="24381600" type="audio/mpeg"/>
<itunes:duration>33:50</itunes:duration>
		<itunes:subtitle>A quick in between to the Hands On Series, I chat about some news and issues of the day.

Turkish Hacker defaces 38,000 websites hosted on ...</itunes:subtitle>
		<itunes:summary>A quick in between to the Hands On Series, I chat about some news and issues of the day.

Turkish Hacker defaces 38,000 websites hosted on GoDaddy
Flawed USC admissions site allowed access to applicant data
Breach case could curtail Web flaw finders
Man charged with accessing USC student data
Tsunami appeal site #8216;hacker#8217; found guilty</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Network Security Blog: Network Security Podcast, Episode 28</title>
		<link>http://www.mightyseek.com/podcasts/network-security-blog-network-security-podcast-episode-28</link>
		<comments>http://www.mightyseek.com/podcasts/network-security-blog-network-security-podcast-episode-28#comments</comments>
		<pubDate>Wed, 24 May 2006 22:35:32 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/05/24/network-security-blog-network-security-podcast-episode-28/</guid>
		<description><![CDATA[Network Security Blog: Network Security Podcast, Episode 28
Tonight I appear as co-host/guest of the Network Security Podcast with Martin McKeay. This podcast is a fellow Security Round Table podcast, and I had alot of fun being able to discuss more general security issues.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.mckeay.net/secure/2006/05/network_security_podcast_episo_25.html">Network Security Blog: Network Security Podcast, Episode 28</a></p>
<p>Tonight I appear as co-host/guest of the <a href="http://www.mckeay.net">Network Security Podcast</a> with Martin McKeay. This podcast is a fellow <a href="http://www.securityroundtable.com/">Security Round Table</a> podcast, and I had alot of fun being able to discuss more general security issues.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasts/network-security-blog-network-security-podcast-episode-28/feed</wfw:commentRss>
		</item>
		<item>
		<title>Questions for podcast with Dan (PodPress developer)</title>
		<link>http://www.mightyseek.com/podcasts/questions-for-podcast-with-dan-podpress-developer</link>
		<comments>http://www.mightyseek.com/podcasts/questions-for-podcast-with-dan-podpress-developer#comments</comments>
		<pubDate>Thu, 18 May 2006 22:31:14 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasts]]></category>

		<category><![CDATA[PodPress]]></category>

		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/05/18/questions-for-podcast-with-dan-podpress-developer/</guid>
		<description><![CDATA[James Woodcock will be interviewing me in the coming days, and so posted this on the forums.
Click here to get to the forum topic
Dan (Mighty Seek) developer of the PodPress plugin for Wordpress, will be interviewed in one of my future blogcasts on my website.
If you have any questions you would like him to answer [...]]]></description>
			<content:encoded><![CDATA[<p>James Woodcock will be interviewing me in the coming days, and so posted this on the forums.</p>
<p><a href="http://www.mightyseek.com/forum/showthread.php?t=251">Click here to get to the forum topic</a></p>
<p>Dan (Mighty Seek) developer of the PodPress plugin for Wordpress, will be interviewed in one of my future blogcasts on my website.</p>
<p>If you have any questions you would like him to answer about either his PodPress plugin or security, please ring my automated (non-premium) voicemail on UK: 0207 193 3092 or Worldwide: +44 207 193 3092 or for free on skype id: glidem</p>
<p>The best questions will be included in the show&#8230;..<br />
__________________<br />
>> <a href="http://www.jameswoodcock.co.uk/?p=252">Hear more about PodPress, in my audio interview with Dan Kuykendall</a> <<</p>
<p><a href="http://www.jameswoodcock.co.uk">http://www.jameswoodcock.co.uk</a> - My personal online diary covering the internet that I find of interest including audio interviews, music, gaming, technology, gadgets, websites, free downloads and general articles.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasts/questions-for-podcast-with-dan-podpress-developer/feed</wfw:commentRss>
		</item>
		<item>
		<title>Hands On Series - SQL Injection Part 1</title>
		<link>http://www.mightyseek.com/web-application-security/hands-on-series-sql-injection</link>
		<comments>http://www.mightyseek.com/web-application-security/hands-on-series-sql-injection#comments</comments>
		<pubDate>Fri, 28 Apr 2006 21:56:15 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Hands On Series]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podcasts/hands-on-series-sql-injection</guid>
		<description><![CDATA[The start of the “Hands on Series”, which means that there are actual
hands on excersises to go along with these shows.

I feel that its time to go beyond the concepts, the chatter about what bad guys can do,
and actually show you directly. Let you see for yourself the saying goes.
I recommend that you listen to [...]]]></description>
			<content:encoded><![CDATA[<p>The start of the “Hands on Series”, which means that there are actual<br />
hands on excersises to go along with these shows.</p>
<p></p>
<p>I feel that its time to go beyond the concepts, the chatter about what bad guys can do,<br />
and actually show you directly. Let you see for yourself the saying goes.</p>
<p>I recommend that you listen to these episodes while viewing the hacking test site and<br />
have the show notes visible and ready to cut and paste from.</p>
<ul>
<li><a href="http://hackme.ntobjectives.com/">http://hackme.ntobjectives.com/</a> - The new site setup for you to practice web app hacking.
<p>Includes <a href="http://hackme.ntobjectives.com/sql_inject/SQLInjectionAttacks.txt">detailed notes</a> and samples that can be used to practice with.</li>
<li><a href="http://www.mightyseek.com/web-hacking-toolkit/">Web App Hacking Toolkit</a> - Collection of tools and links helpful for web security.</li>
<li><a href="http://jonathancoulton.com/">Jonathan Coulton’s Things a Week</a> - Where the Code Monkey song came from.</li>
</ul>
<p> <a href="http://www.mightyseek.com/web-application-security/hands-on-series-sql-injection#more-5" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/hands-on-series-sql-injection/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/5/0/MightySeek-14-2006-04-28-HandOnSeriesSQLInjection.mp3" length="41814674" type="audio/mpeg"/>
<itunes:duration>58:03</itunes:duration>
		<itunes:subtitle>The start of the ldquo;Hands on Seriesrdquo;, which means that there are actual
hands on excersises to go along with these shows.

I feel that its time ...</itunes:subtitle>
		<itunes:summary>The start of the ldquo;Hands on Seriesrdquo;, which means that there are actual
hands on excersises to go along with these shows.

I feel that its time to go beyond the concepts, the chatter about what bad guys can do,
and actually show you directly. Let you see for yourself the saying goes.
I recommend that you listen to these episodes while viewing the hacking test site and
have the show notes visible and ready to cut and paste from.

http://hackme.ntobjectives.com/ - The new site setup for you to practice web app hacking.

Includes detailed notes and samples that can be used to practice with.
Web App Hacking Toolkit - Collection of tools and links helpful for web security.
Jonathan Coultonrsquo;s Things a Week - Where the Code Monkey song came from.

</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Hands,On,Series,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Privilage Escalation Attacks</title>
		<link>http://www.mightyseek.com/web-application-security/privilage-escalation-attacks</link>
		<comments>http://www.mightyseek.com/web-application-security/privilage-escalation-attacks#comments</comments>
		<pubDate>Fri, 14 Apr 2006 17:10:39 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/04/14/privilage-escalation-attacks/</guid>
		<description><![CDATA[In this podcast I discuss a type of attack that allows users to basicly do things they are not supposed to do, without ever having to hack the admin type of accounts. So without having to figure out the admin password it is often possible to do administrative functions by simply attempting them.
The problem is [...]]]></description>
			<content:encoded><![CDATA[<p>In this podcast I discuss a type of attack that allows users to basicly do things they are not supposed to do, without ever having to hack the admin type of accounts. So without having to figure out the admin password it is often possible to do administrative functions by simply attempting them.</p>
<p>The problem is around validation against access controls at every point of execution. Too often the access controls are done to control the navigational structure, meaning that the menus do not have links to the admin functionality, but if you know what the URL is then you can just type it into your browser and get there. Thats bad design in the app, and it is VERY common.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/privilage-escalation-attacks/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/15/0/MightySeek-13-2006-04-14-PrivilegeEscalation.mp3" length="15073162" type="audio/mpeg"/>
<itunes:duration>20:55</itunes:duration>
		<itunes:subtitle>In this podcast I discuss a type of attack that allows users to basicly do things they are not supposed to do, without ever having ...</itunes:subtitle>
		<itunes:summary>In this podcast I discuss a type of attack that allows users to basicly do things they are not supposed to do, without ever having to hack the admin type of accounts. So without having to figure out the admin password it is often possible to do administrative functions by simply attempting them.

The problem is around validation against access controls at every point of execution. Too often the access controls are done to control the navigational structure, meaning that the menus do not have links to the admin functionality, but if you know what the URL is then you can just type it into your browser and get there. Thats bad design in the app, and it is VERY common. </itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Catching up and a preview of future shows</title>
		<link>http://www.mightyseek.com/web-application-security/catching-up-and-a-preview-of-future-shows</link>
		<comments>http://www.mightyseek.com/web-application-security/catching-up-and-a-preview-of-future-shows#comments</comments>
		<pubDate>Thu, 13 Apr 2006 17:11:47 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/04/13/catching-up-and-a-preview-of-future-shows/</guid>
		<description><![CDATA[In this edition of the Mighty Seek podcast I give a rundown of podPress and list out some ideas for the future podcasts. The site now has a forum for the podcast and general web application security discussion.
]]></description>
			<content:encoded><![CDATA[<p>In this edition of the Mighty Seek podcast I give a rundown of podPress and list out some ideas for the future podcasts. The site now has a <a href="http://www.mightyseek.com/forum/">forum for the podcast</a> and general web application security discussion.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/catching-up-and-a-preview-of-future-shows/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/16/0/MightySeek-12-2006-04-13-CheckingInAndPreviewUpcomingShows.mp3" length="28581883" type="audio/mpeg"/>
<itunes:duration>39:40</itunes:duration>
		<itunes:subtitle>In this edition of the Mighty Seek podcast I give a rundown of podPress and list out some ideas for the future podcasts. The site ...</itunes:subtitle>
		<itunes:summary>In this edition of the Mighty Seek podcast I give a rundown of podPress and list out some ideas for the future podcasts. The site now has a forum for the podcast and general web application security discussion.</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Engagement Cast Part 2</title>
		<link>http://www.mightyseek.com/web-application-security/security-engagement-cast-part-2</link>
		<comments>http://www.mightyseek.com/web-application-security/security-engagement-cast-part-2#comments</comments>
		<pubDate>Sat, 11 Mar 2006 17:13:13 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/03/11/security-engagement-cast-part-2/</guid>
		<description><![CDATA[In part 2 we discuss the planning and deliverables involved when doing a security engagement. Most of the discussion demonstrates the importance of understanding the boundaries, requirements and deliverables from the start.
]]></description>
			<content:encoded><![CDATA[<p>In part 2 we discuss the planning and deliverables involved when doing a security engagement. Most of the discussion demonstrates the importance of understanding the boundaries, requirements and deliverables from the start.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/security-engagement-cast-part-2/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/17/0/MightySeek-11-2006-03-08-SecurityEngagementCast.mp3" length="42814299" type="audio/mpeg"/>
<itunes:duration>59:26</itunes:duration>
		<itunes:subtitle>In part 2 we discuss the planning and deliverables involved when doing a security engagement. Most of the discussion demonstrates the importance of understanding the ...</itunes:subtitle>
		<itunes:summary>In part 2 we discuss the planning and deliverables involved when doing a security engagement. Most of the discussion demonstrates the importance of understanding the boundaries, requirements and deliverables from the start.</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Engagement Cast Part 1</title>
		<link>http://www.mightyseek.com/web-application-security/security-engagement-cast-part-1</link>
		<comments>http://www.mightyseek.com/web-application-security/security-engagement-cast-part-1#comments</comments>
		<pubDate>Thu, 09 Mar 2006 17:14:14 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/03/09/security-engagement-cast-part-1/</guid>
		<description><![CDATA[The first of two shows featuring my co-workers, Joe and Scott.
This show was recorded in the evening at our hotel room, so the sound quality is less than ideal. We are onsite in Texas doing a security engagement for a client, and get tired and wacky but wanted to share what goes into doing a [...]]]></description>
			<content:encoded><![CDATA[<p>The first of two shows featuring my co-workers, Joe and Scott.<br />
This show was recorded in the evening at our hotel room, so the sound quality is less than ideal. We are onsite in Texas doing a security engagement for a client, and get tired and wacky but wanted to share what goes into doing a security audit for a client.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/security-engagement-cast-part-1/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/18/0/MightySeek-10-2006-03-08-SecurityEngagementCast.mp3" length="37361834" type="audio/mpeg"/>
<itunes:duration>51:52</itunes:duration>
		<itunes:subtitle>The first of two shows featuring my co-workers, Joe and Scott.
This show was recorded in the evening at our hotel room, so the sound quality ...</itunes:subtitle>
		<itunes:summary>The first of two shows featuring my co-workers, Joe and Scott.
This show was recorded in the evening at our hotel room, so the sound quality is less than ideal. We are onsite in Texas doing a security engagement for a client, and get tired and wacky but wanted to share what goes into doing a security audit for a client.</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>What makes application security different than network security</title>
		<link>http://www.mightyseek.com/web-application-security/what-makes-application-security-different-than-network-security</link>
		<comments>http://www.mightyseek.com/web-application-security/what-makes-application-security-different-than-network-security#comments</comments>
		<pubDate>Fri, 03 Mar 2006 17:14:52 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/03/03/what-makes-application-security-different-than-network-security/</guid>
		<description><![CDATA[In this podcast I ramble on about what network security is, and then how web application security is an entirely different kind of beast.
]]></description>
			<content:encoded><![CDATA[<p>In this podcast I ramble on about what network security is, and then how web application security is an entirely different kind of beast.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/what-makes-application-security-different-than-network-security/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/19/0/MightySeek-09-2006-03-03-WebAppSecVSNetworkSec.mp3" length="29669450" type="audio/mpeg"/>
<itunes:duration>41:11</itunes:duration>
		<itunes:subtitle>In this podcast I ramble on about what network security is, and then how web application security is an entirely different kind of beast. </itunes:subtitle>
		<itunes:summary>In this podcast I ramble on about what network security is, and then how web application security is an entirely different kind of beast.</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Cross Site Scripting&#8230; Exposing your users to attack, hijacking and data theft</title>
		<link>http://www.mightyseek.com/web-application-security/cross-site-scripting-exposing-your-users-to-attack-hijacking-and-data-theft</link>
		<comments>http://www.mightyseek.com/web-application-security/cross-site-scripting-exposing-your-users-to-attack-hijacking-and-data-theft#comments</comments>
		<pubDate>Fri, 10 Feb 2006 17:59:37 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/02/10/cross-site-scripting-exposing-your-users-to-attack-hijacking-and-data-theft/</guid>
		<description><![CDATA[With Cross Site Scripting (XSS) the focus changes away from server attacks to user attacks facilitated by the server. This podcast covers the issues involved and additional show notes will be coming shortly.
While your waiting, here is a great resource.
http://www.cgisecurity.com/articles/xss-faq.shtml 
]]></description>
			<content:encoded><![CDATA[<p>With Cross Site Scripting (XSS) the focus changes away from server attacks to user attacks facilitated by the server. This podcast covers the issues involved and additional show notes will be coming shortly.</p>
<p>While your waiting, here is a great resource.</p>
<p><a href="http://www.cgisecurity.com/articles/xss-faq.shtml">http://www.cgisecurity.com/articles/xss-faq.shtml </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/cross-site-scripting-exposing-your-users-to-attack-hijacking-and-data-theft/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/28/0/MightySeek-08-2006-02-10-CrossSiteScripting.mp3" length="25533532" type="audio/mpeg"/>
<itunes:duration>35:26</itunes:duration>
		<itunes:subtitle>With Cross Site Scripting (XSS) the focus changes away from server attacks to user attacks facilitated by the server. This podcast covers the issues involved ...</itunes:subtitle>
		<itunes:summary>With Cross Site Scripting (XSS) the focus changes away from server attacks to user attacks facilitated by the server. This podcast covers the issues involved and additional show notes will be coming shortly.
While your waiting, here is a great resource.
http://www.cgisecurity.com/articles/xss-faq.shtml </itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security during the Software Development Life Cycle</title>
		<link>http://www.mightyseek.com/web-application-security/security-during-the-software-development-life-cycle</link>
		<comments>http://www.mightyseek.com/web-application-security/security-during-the-software-development-life-cycle#comments</comments>
		<pubDate>Tue, 10 Jan 2006 17:56:56 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/09/14/security-during-the-software-development-life-cycle/</guid>
		<description><![CDATA[Software Development Life Cycle (SDLC) is a major buzz word in the industry right now, but what many are still ignoring is how well a security design/plan can be integrated. This podcast and slideshow hopes to explain how this gets done.
]]></description>
			<content:encoded><![CDATA[<p>Software Development Life Cycle (SDLC) is a major buzz word in the industry right now, but what many are still ignoring is how well a security design/plan can be integrated. This podcast and slideshow hopes to explain how this gets done.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/security-during-the-software-development-life-cycle/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/26/0/MightySeek-07-2006-01-10-SoftwareDevelopmentLifeCycle.mp3" length="26315231" type="audio/mpeg"/>
<itunes:duration>36:31</itunes:duration>
		<itunes:subtitle>Software Development Life Cycle (SDLC) is a major buzz word in the industry right now, but what many are still ignoring is how well a ...</itunes:subtitle>
		<itunes:summary>Software Development Life Cycle (SDLC) is a major buzz word in the industry right now, but what many are still ignoring is how well a security design/plan can be integrated. This podcast and slideshow hopes to explain how this gets done.</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Intro to SQL Injection Attacks</title>
		<link>http://www.mightyseek.com/web-application-security/intro-to-sql-injection-attacks</link>
		<comments>http://www.mightyseek.com/web-application-security/intro-to-sql-injection-attacks#comments</comments>
		<pubDate>Fri, 09 Dec 2005 18:02:14 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2005/12/09/intro-to-sql-injection-attacks/</guid>
		<description><![CDATA[In this podcast we have our first guest lecturer by way of a previously recorded slideshow from Mike Shema. In the presentation he gives an overview of SQL Injection attacks and has a few examples. I think the the content is still valuable even without the slides, but for the full experience of the presentation [...]]]></description>
			<content:encoded><![CDATA[<p>In this podcast we have our first guest lecturer by way of a previously recorded slideshow from Mike Shema. In the presentation he gives an overview of SQL Injection attacks and has a few examples. I think the the content is still valuable even without the slides, but for the full experience of the presentation you may want to see it for youselves.</p>
<p><a href="http://www.ntobjectives.com/know/onlinetraining.php">Free whitepapers and presentations about web application security, by NT OBJECTives. </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/intro-to-sql-injection-attacks/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/29/0/MightySeek-06-2005-12-09-IntroToSQLInjection.mp3" length="14737667" type="audio/mpeg"/>
<itunes:duration>20:26</itunes:duration>
		<itunes:subtitle>In this podcast we have our first guest lecturer by way of a previously recorded slideshow from Mike Shema. In the presentation he gives an ...</itunes:subtitle>
		<itunes:summary>In this podcast we have our first guest lecturer by way of a previously recorded slideshow from Mike Shema. In the presentation he gives an overview of SQL Injection attacks and has a few examples. I think the the content is still valuable even without the slides, but for the full experience of the presentation you may want to see it for youselves.

Free whitepapers and presentations about web application security, by NT OBJECTives. </itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Whats the DBA got ta do with it?</title>
		<link>http://www.mightyseek.com/web-application-security/whats-the-dba-got-ta-do-with-it</link>
		<comments>http://www.mightyseek.com/web-application-security/whats-the-dba-got-ta-do-with-it#comments</comments>
		<pubDate>Mon, 14 Nov 2005 18:03:53 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2005/11/14/whats-the-dba-got-ta-do-with-it/</guid>
		<description><![CDATA[A discussion to show that a database administrator must not shirk his duties over to the web application developer, and the web application developer should not seize full control over the database as is normally the case. Database administrator have a key role to play when developing a secure and robust web application.
]]></description>
			<content:encoded><![CDATA[<p>A discussion to show that a database administrator must not shirk his duties over to the web application developer, and the web application developer should not seize full control over the database as is normally the case. Database administrator have a key role to play when developing a secure and robust web application.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/whats-the-dba-got-ta-do-with-it/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/30/0/MightySeek-05-2005-11-14-WebAppSecAndDBA.mp3" length="8202648" type="audio/mpeg"/>
<itunes:duration>11:22</itunes:duration>
		<itunes:subtitle>A discussion to show that a database administrator must not shirk his duties over to the web application developer, and the web application developer should ...</itunes:subtitle>
		<itunes:summary>A discussion to show that a database administrator must not shirk his duties over to the web application developer, and the web application developer should not seize full control over the database as is normally the case. Database administrator have a key role to play when developing a secure and robust web application.</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>What is Web App Security?</title>
		<link>http://www.mightyseek.com/web-application-security/what-is-web-app-security</link>
		<comments>http://www.mightyseek.com/web-application-security/what-is-web-app-security#comments</comments>
		<pubDate>Wed, 08 Jun 2005 18:05:25 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2005/06/08/what-is-web-app-security/</guid>
		<description><![CDATA[What is Web Application Security?
In this I attempt to give a very basic explaination of what web app sec is about and why its new and less familiair.
]]></description>
			<content:encoded><![CDATA[<p>What is Web Application Security?</p>
<p>In this I attempt to give a very basic explaination of what web app sec is about and why its new and less familiair.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/what-is-web-app-security/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/31/0/MightySeek-04-2005_06_08-WhatIsWebAppSecurity.mp3" length="14540374" type="audio/mpeg"/>
<itunes:duration>20:10</itunes:duration>
		<itunes:subtitle>What is Web Application Security?

In this I attempt to give a very basic explaination of what web app sec is about and why its new ...</itunes:subtitle>
		<itunes:summary>What is Web Application Security?

In this I attempt to give a very basic explaination of what web app sec is about and why its new and less familiair. </itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Web App Security 101 - Be paranoid, instead of being a victim</title>
		<link>http://www.mightyseek.com/web-application-security/web-app-security-101-be-paranoid-instead-of-being-a-victim</link>
		<comments>http://www.mightyseek.com/web-application-security/web-app-security-101-be-paranoid-instead-of-being-a-victim#comments</comments>
		<pubDate>Mon, 02 May 2005 18:09:08 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2005/05/02/web-app-security-101-be-paranoid-instead-of-being-a-victim/</guid>
		<description><![CDATA[Discussion about my involvement with podcastalley.com, using castblaster and my excitement with podcasting. Then I kick off a Web App Security 101
]]></description>
			<content:encoded><![CDATA[<p>Discussion about my involvement with podcastalley.com, using castblaster and my excitement with podcasting. Then I kick off a Web App Security 101</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/web-app-security-101-be-paranoid-instead-of-being-a-victim/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/32/0/MightySeek-03-2005_05_02-WebAppSecurity101.mp3" length="22920645" type="audio/mpeg"/>
<itunes:duration>31:49</itunes:duration>
		<itunes:subtitle>Discussion about my involvement with podcastalley.com, using castblaster and my excitement with podcasting. Then I kick off a Web App Security 101 </itunes:subtitle>
		<itunes:summary>Discussion about my involvement with podcastalley.com, using castblaster and my excitement with podcasting. Then I kick off a Web App Security 101</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
	</channel>
</rss>
