<?xml version="1.0" encoding="ISO-8859-1"?>
<!-- generator="wordpress/2.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Mighty Seek</title>
	<link>http://www.mightyseek.com</link>
	<description>A podcast about web application security, as well as general web application development issues. The primary focus is on security and tries to explain things so that anyone can understand them since security issues affect everyone across an organization. Hopefully this show will be a resource for everyone involved in a software development project.</description>
	<pubDate>Tue, 04 Mar 2008 07:04:07 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2</generator>
	<language>en</language>
		<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;Dan Kuykendall </copyright>
		<managingEditor>dan@kuykendall.org (Dan Kuykendall)</managingEditor>
		<webMaster>dan@kuykendall.org(Dan Kuykendall)</webMaster>
		<category>Technolgy</category>
		<ttl>1440</ttl>
		<itunes:keywords>web application security development</itunes:keywords>
		<itunes:subtitle>A podcast about web application security, as well as general web application development issues. The primary focus is on security and tries to explain things so that anyone can understand them since security issues affect everyone across an organizatio...</itunes:subtitle>
		<itunes:summary>A podcast about web application security, as well as general web application development issues. The primary focus is on security and tries to explain things so that anyone can understand them since security issues affect everyone across an organization. Hopefully this show will be a resource for everyone involved in a software development project.</itunes:summary>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:category text="Technology"/>
<itunes:category text="Technology">
  <itunes:category text="Software How-To"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="Training"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>Dan Kuykendall</itunes:name>
			<itunes:email>dan@kuykendall.org</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://www.mightyseek.com/images/itunescover.jpg" />
		<image>
			<url>http://www.mightyseek.com/images/itunescover.jpg</url>
			<title>Mighty Seek</title>
			<link>http://www.mightyseek.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>My sons animation</title>
		<link>http://www.mightyseek.com/misc/my-sons-animation</link>
		<comments>http://www.mightyseek.com/misc/my-sons-animation#comments</comments>
		<pubDate>Sat, 02 Feb 2008 04:17:05 +0000</pubDate>
		<dc:creator>seek3r</dc:creator>
		
		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/misc/my-sons-animation</guid>
		<description><![CDATA[My 3rd grade sone did this awesome animation using Stickman, so I have to show it off.
]]></description>
			<content:encoded><![CDATA[<p>My 3rd grade sone did this awesome animation using <a href="http://www.cutoutpro.com/">Stickman</a>, so I have to show it off.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/misc/my-sons-animation/feed</wfw:commentRss>
	<!-- Media File exists for this post, but its not enabled for this feed -->
	</item>
		<item>
		<title>Coverage of web application scanners</title>
		<link>http://www.mightyseek.com/web-application-security/coverage-of-web-application-scanners</link>
		<comments>http://www.mightyseek.com/web-application-security/coverage-of-web-application-scanners#comments</comments>
		<pubDate>Tue, 16 Oct 2007 21:56:54 +0000</pubDate>
		<dc:creator>seek3r</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/web-application-security/coverage-of-web-application-scanners</guid>
		<description><![CDATA[My buddy rsnake over at Ha.ckers.org posted a report from Larry Suto about tests he performed on web application scanners and comparing how well they cover a web applications code base.
The report is intesting on many fronts, one of which is the fact that the tool I help build at NT OBJECTives came out on [...]]]></description>
			<content:encoded><![CDATA[<p>My buddy rsnake over at <a href="http://ha.ckers.org/blog/20071014/web-application-scanning-depth-statistics/">Ha.ckers.org</a> <a href="http://ha.ckers.org/blog/20071014/web-application-scanning-depth-statistics/">posted</a> <a href="http://ha.ckers.org/files/CoverageOfWebAppScanners.pdf">a report</a> from Larry Suto about tests he performed on web application scanners and comparing how well they cover a web applications code base.</p>
<p>The report is intesting on many fronts, one of which is the fact that the tool I help build at <a href="http://www.ntobjectives.com/">NT OBJECTives</a> came out on top, but also because its the first type of review thats looking at a statistic that really compares scanners in a quantifiable way.</p>
<p>Some comment on the site from users of the other products or from the vendors themselves have made the claim that web scanners are not designed to be &#8220;point and shoot&#8221; as they say, and that a human should be training the scanner to each web app. I think they are doing users a disservice to work from that assumption.</p>
<p>A scanner should do as much as it can on its own, and let humans do their own pen testing, and/or help point pen testers to areas of interest. If your a organization with hundreds or thousands of web apps that need testing, do you really have the man power to teach your &#8220;automated web scanner&#8221; how to test each of those apps?</p>
<p>Do you really have time to spend clinking on every link, and filling out every form on a website with some 3000+ pages, or do you want the scanner that does the best job of doing all of this for you?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/coverage-of-web-application-scanners/feed</wfw:commentRss>
		</item>
		<item>
		<title>podPress 8.3 Released - With Podango Support</title>
		<link>http://www.mightyseek.com/podpress/podpress-83-released-with-podango-support</link>
		<comments>http://www.mightyseek.com/podpress/podpress-83-released-with-podango-support#comments</comments>
		<pubDate>Fri, 28 Sep 2007 10:38:39 +0000</pubDate>
		<dc:creator>seek3r</dc:creator>
		
		<category><![CDATA[PodPress]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/misc/podpress-83-released-with-podango-support</guid>
		<description><![CDATA[For all the details, check out the changelog but this is one release that cleans up a ton of mess and adds in support for full integration with the Podango API.
Theres still a few tiny features I want to add in, but its in good shape, and I need sleep so I can run off [...]]]></description>
			<content:encoded><![CDATA[<p>For all the details, check out the <a href="http://www.mightyseek.com/podpress/changelog/" target="_blank">changelog</a> but this is one release that cleans up a ton of mess and adds in support for full integration with the <a href="http://www.podango.com">Podango </a>API.</p>
<p>Theres still a few tiny features I want to add in, but its in good shape, and I need sleep so I can run off to the Podcast Expo in a few hours.</p>
<p>UPDATE - Bug in this version&#8230; of course, so hang on for next release due out in a few hours</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podpress/podpress-83-released-with-podango-support/feed</wfw:commentRss>
		</item>
		<item>
		<title>The Ha.ckers.org Hacking Challenges</title>
		<link>http://www.mightyseek.com/web-application-security/the-hackersorg-hacking-challenges</link>
		<comments>http://www.mightyseek.com/web-application-security/the-hackersorg-hacking-challenges#comments</comments>
		<pubDate>Thu, 23 Aug 2007 21:40:23 +0000</pubDate>
		<dc:creator>seek3r</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/web-application-security/the-hackersorg-hacking-challenges</guid>
		<description><![CDATA[As many of you have seen, I have a &#8220;Hackme&#8221; site setup to go along with my podcast, and specifically for the Hands On Series podcasts. Well the current king of Web App Security blogging has setup a couple hacker challenges on his site. The ones on my site are really focused toward teaching, the [...]]]></description>
			<content:encoded><![CDATA[<p>As many of you have seen, I have a &#8220;<a href="http://hackme.ntobjectives.com/">Hackme</a>&#8221; site setup to go along with my podcast, and specifically for the <a href="http://www.mightyseek.com/category/hands-on-series">Hands On Series</a> podcasts. Well the current king of Web App Security blogging has setup a couple <a href="http://ha.ckers.org/blog/20070726/hackersorg-blackhat-challenge/">hacker</a> <a href="http://ha.ckers.org/blog/20070820/and-were-off-challenge-2-underway/">challenges</a> on his site. The ones on my site are really focused toward teaching, the ones on <a href="http://ha.ckers.org">ha.ckers.org</a> are setup for the fun, challenge and bragging rights.</p>
<p>I have had the mis-fortune of being completely swamped in work during the start of these last two, but when the third is up, Im cleaning my calender, turning off cell phones and ignoring any unnecessary chats so I can beat it as quickly as possible and get listed in the top ten. Knowing rSnake, I may decide to put together a small MightySeek team to work together to increase our chances, but I will see how it plays out.</p>
<p>Go have fun, and test your skills</p>
<ul>
<li><a href="http://ha.ckers.org/blog/20070726/hackersorg-blackhat-challenge/">Ha.ckers.org Challenge #1</a></li>
<li><a href="http://ha.ckers.org/blog/20070820/and-were-off-challenge-2-underway/">Ha.ckers.org Challenge #2</a></li>
</ul>
<p>Btw, #2 <a href="http://ha.ckers.org/blog/20070820/hackersorg-challenge-logic-flaw/">had a logic flaw</a> which really opens up the next one to additional scrutiny to see whats possible to find during the next one.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/the-hackersorg-hacking-challenges/feed</wfw:commentRss>
		</item>
		<item>
		<title>Evaluating Web Application Security Scanners</title>
		<link>http://www.mightyseek.com/web-application-security/evaluating-web-application-security-scanners</link>
		<comments>http://www.mightyseek.com/web-application-security/evaluating-web-application-security-scanners#comments</comments>
		<pubDate>Thu, 23 Aug 2007 21:09:44 +0000</pubDate>
		<dc:creator>seek3r</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/web-application-security/evaluating-web-application-security-scanners</guid>
		<description><![CDATA[Theres been alot of discussion lately about an issue thats near and dear to my heart. The capabilities and of web application security scanning is something I have been living and breathing for about 5 years with NT OBJECTIves. AT NTO I lead the development and research teams involved in building our own scanner called [...]]]></description>
			<content:encoded><![CDATA[<p>Theres been <a href="https://lists.owasp.org/pipermail/webappsec/2007-August/000411.html">alot</a> of <a href="http://www.webappsec.org/lists/websecurity/archive/2007-08/msg00071.html">discussion</a> lately about an issue thats near and dear to my heart. The capabilities and of web application security scanning is something I have been living and breathing for about 5 years with <a href="http://www.ntobjectives.com/">NT OBJECTIves</a>. AT NTO I lead the development and research teams involved in building our own scanner called <a href="http://www.ntobjectives.com/products/ntospider.php">NTOSpider</a>, and have been trying to increase what is possible to test for in an automated tool.</p>
<p>This is a really difficult and challenging issue, with a bunch of issues that are fuzzy at best. I have high hopes that the <a href="http://www.webappsec.org/projects/wassec/">WASSEC Project</a> thats being hosted by the <a href="http://www.webappsec.org/">Web Application Security Con</a><a href="http://www.webappsec.org/">sortium</a>, because its going to bring a bunch of us from the app sec tool vendor space and the web app sec community together to discuss the issue and attempt to come up with a good reference document for the ways to evaluate scanners.</p>
<p>I&#8217;m curious how we will be able to come up with any consensus, but with any luck and some hard work and compromise I think this could be a turning point to helping public understanding of this issue.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/evaluating-web-application-security-scanners/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordCamp Experience</title>
		<link>http://www.mightyseek.com/podcasting/wordcamp-experience</link>
		<comments>http://www.mightyseek.com/podcasting/wordcamp-experience#comments</comments>
		<pubDate>Mon, 23 Jul 2007 08:23:54 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasting]]></category>

		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podcasting/wordcamp-experience</guid>
		<description><![CDATA[I had a pretty interesting day yesterday.
After being up till close to 2am I woke up at 5:30am, showered and drove to the airport to do my 10am talk at WordCamp 2007.
My flight landed at 8:30am and I was picked up by my old buddy Joe Engo. After a couple wrong turns we finally got [...]]]></description>
			<content:encoded><![CDATA[<p>I had a pretty interesting day yesterday.<br />
After being up till close to 2am I woke up at 5:30am, showered and drove to the airport to do <a href="http://2007.wordcamp.org/schedule/podcasting/" target="_blank">my 10am talk</a> at <a href="http://2007.wordcamp.org/" target="_blank">WordCamp 2007</a>.<br />
My flight landed at 8:30am and I was picked up by my old buddy Joe Engo. After a couple wrong turns we finally got to the event location at 9:30 in time to get setup.</p>
<p><a href="http://www.mightyseek.com/wp-content/uploads/2007/07/mightyseek_at_wordcamp.jpg" title="mightyseek_at_wordcamp.jpg"><img src="http://www.mightyseek.com/wp-content/uploads/2007/07/mightyseek_at_wordcamp.thumbnail.jpg" alt="mightyseek_at_wordcamp.jpg" /> </a>I finally had a chance to meet <a href="http://photomatt.net/" target="_blank">Matt Mullenweg</a>, and was thoroughly impressed, this is one young man to watch. To think that at 23, hes at the head of a project thats impacted so many people, and has gained so much interest and respect, <strong>and </strong>has managed to build a business model around an open sourced app&#8230; no easy feat.</p>
<p>So then it sets in. I&#8217;m the opening presenter to this conference&#8230; I&#8217;ve really been too busy to have thought much about my talk at <a href="http://2007.wordcamp.org/" target="_blank">WordCamp</a> the preceding couple of weeks because work has been crazy busy. But standing there getting setup to open the conference I got a bit nervous. Its also been a couple years since doing one of these types of things, so I really started feeling completely unprepared.</p>
<p>Matt introduces me and I ask the audience a few questions about whos familiar with podcasting (everyone) and how many podcasters are out there (a few). Well, this kind of took some thunder out of my slides intended to be used to help explain podcasting basics. I had to think quick to adjust my talk and explain my views of how I feel podcasting to be a little more personal and blah blah. Was a bit of a slow start.</p>
<p>So I figured I could launch into the stuff about <a href="http://www.mightyseek.com/podpress" target="_blank">podPress</a> and show of the features and talk some praise of <a href="http://www.wordpress.org/" target="_blank">WordPress</a>, which I started&#8230; and then the Internet connection went dead. Just as I was starting to feel a little comfortable&#8230;<br />
With some quick action by the <a href="http://automattic.com/" target="_blank">Automattic</a> team I got back online and was quickly followed by the audience and was able to start cracking some lame jokes and getting into a groove about <a href="http://www.mightyseek.com/podpress" target="_blank">podPress</a>, podcasting and <a href="http://www.wordpress.org/" target="_blank">WordPress</a>.</p>
<p>Even with the slow start, I felt like I was finally able to connect and coherently discuss some of the things I am passionate about, and hopefully show how easy it is to get into podcasting, the cool features of <a href="http://www.mightyseek.com/podpress" target="_blank">podPress</a> and the amazing platform <a href="http://www.wordpress.org/" target="_blank">WordPress</a> provided that enabled me to create the feature set. The talk was video taped, so as soon as I get a copy of the video I will be adding the media to this post so it will end up in my feed as a video podcast.</p>
<p>As soon as my talk was over, I chatted with a few people in the lobby for about half and hour, and then headed to the airport to get back home. Next year, as a speaker or not, I&#8217;m going to make sure to plan better so I can stay for the entire weekend.</p>
<p><strong>Update</strong>: The video is now available.<br />
<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" width="437" height="370" id="viddler">
<param name="movie" value="http://www.viddler.com/player/fcbfce91/" />
<param name="allowScriptAccess" value="always" />
<param name="allowFullScreen" value="true" /><embed src="http://www.viddler.com/player/fcbfce91/" width="437" height="370" type="application/x-shockwave-flash" allowScriptAccess="always" allowFullScreen="true" name="viddler" ></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasting/wordcamp-experience/feed</wfw:commentRss>
		</item>
		<item>
		<title>Forums back online</title>
		<link>http://www.mightyseek.com/podcasting/forums-back-online</link>
		<comments>http://www.mightyseek.com/podcasting/forums-back-online#comments</comments>
		<pubDate>Sun, 22 Jul 2007 07:13:08 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasting]]></category>

		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podcasting/forums-back-online</guid>
		<description><![CDATA[Thanks to the generous sponsorship of Podango the MightySeek/podPress forums are back online!
]]></description>
			<content:encoded><![CDATA[<p>Thanks to the generous sponsorship of <a href="http://www.podango.com/learn-more/podpress.php">Podango </a>the MightySeek/podPress forums are back online!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasting/forums-back-online/feed</wfw:commentRss>
		</item>
		<item>
		<title>The Sierra Network (ImagiNation) - Lives again</title>
		<link>http://www.mightyseek.com/misc/imagination-lives-again</link>
		<comments>http://www.mightyseek.com/misc/imagination-lives-again#comments</comments>
		<pubDate>Tue, 03 Jul 2007 17:15:14 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/misc/imagination-innthe-sierra-network-tsn-lives-again</guid>
		<description><![CDATA[Back in the early 90&#8217;s, yes back even before most had even heard of the Internet and the geeks spent most of their time on BBS&#8217;s there were a few online services trying to get going. AOL, Prodigy and CompuServe were fairly well known, but there was one other that stole my heart. It was [...]]]></description>
			<content:encoded><![CDATA[<p>Back in the early 90&#8217;s, yes back even before most had even heard of the Internet and the geeks spent most of their time on BBS&#8217;s there were a few online services trying to get going. AOL, Prodigy and CompuServe were fairly well known, but there was one other that stole my heart. It was the <a href="http://en.wikipedia.org/wiki/ImagiNation_Network" target="_blank">ImagiNation Network</a> and primarily MedievaLand and its first game <a href="http://en.wikipedia.org/wiki/The_Shadow_of_Yserbius" target="_blank">The Shadow of Yserbius</a>.</p>
<p>Way back before World of Warcraft, Never Winter Nights, Ultima Online there was <a href="http://en.wikipedia.org/wiki/The_Shadow_of_Yserbius" target="_blank">The Shadow of Yserbius</a> which really set the bar for online gaming.</p>
<p>The whole network was unbelievable in its scope. You could play the D&amp;D style Yserbius, card games at the club house, gamble at CasinoLand, have simulated dog fights in the Red Baron game, play the popular Boogers game, and ever get help with your home work.<br />
To this day I have not seen anything to match the fun and variety that I had the privilege to experience back in the days when I was spending thousands of dollars and endless hours experiencing life &#8220;online&#8221;.</p>
<p>I have cherished my memories of those days and have copies of all the old software and hacks which I have kept faithfully for the last 15 years. I have joined a couple efforts to re-create the world, but all have failed&#8230; until now. A guy that goes by the name of byoung was able to <a href="http://innrevival.googlepages.com/" target="_blank">re-create the server</a> so that the old client software is able to work in <a href="http://dosbox.sourceforge.net/" target="_blank">DosBox</a> which redirects the modem calls over TCP/IP. <a href="http://innrevival.googlepages.com/" target="_blank">His website</a> has all the software and directions to get setup very easily. It took me all of 10 mins to get everything installed and working. <strong><em>**To make it even easier to get started use <a href="http://www.mightyseek.com/innrevival-installer/">the installer</a> I created**<br />
</em></strong><br />
I spent about 4 hours online yesterday playing <a href="http://en.wikipedia.org/wiki/The_Shadow_of_Yserbius" target="_blank">The Shadow of Yserbius</a> with a few other people and building up my character. Oh man have I forgotten a ton, but the memories flooding back are a total blast. Even if you never played back in the day, I encourage you to get setup with it and join the growing community of users. If you let me know you will be in, I will be glad to join you for any game you like. Im having fun re-discovering all the cool stuff in this world of ImagiNation.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/misc/imagination-lives-again/feed</wfw:commentRss>
		</item>
		<item>
		<title>iPhone - I dont get the hype</title>
		<link>http://www.mightyseek.com/misc/iphone-i-dont-get-the-hype</link>
		<comments>http://www.mightyseek.com/misc/iphone-i-dont-get-the-hype#comments</comments>
		<pubDate>Sat, 30 Jun 2007 03:06:56 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/misc/iphone-i-dont-get-the-hype</guid>
		<description><![CDATA[Its crazy&#8230; I really just dont get this crazyness over an insanely priced cell phone. Now keep in mind, I live with my video iPod, it goes everwhere with me and most of the TV and movies I see these days are on the thing. I also look forward to the day that I can [...]]]></description>
			<content:encoded><![CDATA[<p>Its crazy&#8230; I really just dont get this crazyness over an insanely priced cell phone. Now keep in mind, I <strong>live </strong>with my video iPod, it goes everwhere with me and most of the TV and movies I see these days are on the thing. I also look forward to the day that I can have a single device so that I dont have to carry the iPod and cell phone.</p>
<p>However, the iPhone just isnt it for me. Its cool, and its heading toward the dream of having a single device, but for $600 and having to switch to a crappy cell phone carrier, NO THANKS. Aside from the price and cell phone carrier monopoly, I really just cant stand touch pad phone buttons. I need to be able to dial without looking, and can only do  that with actual buttons. Touch screens wear out, and become a pain to push the button you want. Im sure you are all experienced in using the touch screens at the market when you pay by debit card, and the hassles when they start wearing out. Do we really want that on our cell phone, where we have a $600 price tag to replace the thing. No me.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/misc/iphone-i-dont-get-the-hype/feed</wfw:commentRss>
		</item>
		<item>
		<title>Planet Websecurity</title>
		<link>http://www.mightyseek.com/web-application-security/planet-websecurity</link>
		<comments>http://www.mightyseek.com/web-application-security/planet-websecurity#comments</comments>
		<pubDate>Fri, 29 Jun 2007 07:55:16 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/web-application-security/planet-websecurity</guid>
		<description><![CDATA[For those trying to follow the latest news of our web app sec community, someone has finally setup a feed planet called Planet Websecurity that I&#8217;m really impressed with. No, at this time MightySeek is not yet part of the RSS mashup, but I do hope to be at some point.
For those not familiar with [...]]]></description>
			<content:encoded><![CDATA[<p>For those trying to follow the latest news of our web app sec community, someone has finally setup a <a href="http://www.planetplanet.org/" target="_blank">feed planet</a> called <a href="http://planet-websecurity.org/feed/" target="_blank">Planet Websecurity</a> that I&#8217;m really impressed with. No, at this time MightySeek is not yet part of the RSS mashup, but I do hope to be at some point.</p>
<p>For those not familiar with Planet sites, they are basically RSS readers which download other RSS feeds and merge together into a single feed. This means you can subscribe to one and get all the postings from all the feeds in the Planet.</p>
<p>Visit <a href="http://planet-websecurity.org/feed/" target="_blank">Planet Websecurity</a> to see this in action</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/planet-websecurity/feed</wfw:commentRss>
		</item>
		<item>
		<title>Why is it so hard to code secure web apps?</title>
		<link>http://www.mightyseek.com/web-application-security/why-is-it-so-hard-to-code-secure-web-apps</link>
		<comments>http://www.mightyseek.com/web-application-security/why-is-it-so-hard-to-code-secure-web-apps#comments</comments>
		<pubDate>Fri, 29 Jun 2007 07:46:27 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/web-application-security/why-is-it-so-hard-to-code-secure-web-apps</guid>
		<description><![CDATA[    After my run in with vBulletin I began a search for a secure and stable open sourced forum solution. My first thought was to find out what was running on sla.kers.org so I put in a call to rsnake and was told to keep looking because his solution sucked as well [...]]]></description>
			<content:encoded><![CDATA[<p>    After my run in with <a href="http://www.mightyseek.com/podpress/run-in-with-vbulletin-leasing-software-is-intolerable" target="_blank">vBulletin</a> I began a search for a secure and stable open sourced forum solution. My first thought was to find out what was running on <a href="http://sla.ckers.org/forum/" target="_blank">sla.kers.org</a> so I put in a call to rsnake and was told to keep looking because his solution sucked as well and that he was still on the hunt for a replacement. I&#8217;ve been looking at a bunch of the apps out there and so far I havent been all that impressed with the security design of the forum apps I&#8217;ve looked at.</p>
<p>This makes me wonder if web app sec is ever going to succeed, or if the web is just doomed to have problems for all time. Forum software is a very good example of the problem with many web apps, and web app development in general. To start its a very simple application, which if done right can be done securely. Of course the major challenge is that your taking user input and displaying it to other users. This immediately means your storing the data most likely into a database, which means you must secure against SQL Injection attacks. OK, thats not too hard, so that can be done. Next you need to make sure your filtering the inputs on the way in to remove any HTML tagging and escaping on the way out to be safe. The XSS part is a bit harder because there are clever people out there using a <a href="http://ha.ckers.org/xss.html" target="_blank">ton of different ways</a> to bypass any filtering/escaping you do.  However, this can be accomplished with some focused attention, and you will then have a simple, secure and stable forum application.</p>
<p>So whats wrong with this? Feature creep.<br />
Now that you have a basic forum in place, people will want to be able to format their text, which means you need to allow some  HTML tags, or have some custom tags like BBCode which you then convert to real HTML tags. At this point things are starting to get a little tougher, but with diligence its still all workable. Next users want to upload attachments, have avatars, have all sorts of moderation features, and so on and so on. Then to make matters even worse, new developers join the project and they are not always as aware or concerned about security issues, and soon the application is as buggy and vulnerable as the forum software you are trying to replace.</p>
<p>Is this solvable? Yes, but only with diligence, hard work and auditing. Did I mention hard work?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/why-is-it-so-hard-to-code-secure-web-apps/feed</wfw:commentRss>
		</item>
		<item>
		<title>Run in with vBulletin - leasing software is intolerable</title>
		<link>http://www.mightyseek.com/podpress/run-in-with-vbulletin-leasing-software-is-intolerable</link>
		<comments>http://www.mightyseek.com/podpress/run-in-with-vbulletin-leasing-software-is-intolerable#comments</comments>
		<pubDate>Fri, 29 Jun 2007 07:27:42 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[PodPress]]></category>

		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podpress/run-in-with-vbulletin-leasing-software-is-intolerable</guid>
		<description><![CDATA[I had been using vBulletin for a little over a year when I started podPress and wanted a place for users to create a community and to provide support. The forums have been very successful and tend to have on the order of 20-30 postings a day, with many more viewers.  Now vBulletin is commercial [...]]]></description>
			<content:encoded><![CDATA[<p>I had been using vBulletin for a little over a year when I started podPress and wanted a place for users to create a community and to provide support. The forums have been very successful and tend to have on the order of 20-30 postings a day, with many more viewers.  Now vBulletin is commercial software, so I had to pay $85 to use it, and figured that donations would cover the costs and I mistakenly had thought the way the licensing worked is that after one year I could keep running the forums, but could no longer get updates which seemed fair enough to me.<br />
Well, the license I did buy doesnt allow for that, and I had to find out the hard way. After my license had been expired a couple months I received an email saying I was in violation, which I ignored on the assumption that it was a mistake or SPAM. I mean, why would software I paid for become invalid to use? It does when you purchase leased software!  <a href="http://www.mightyseek.com/podpress/run-in-with-vbulletin-leasing-software-is-intolerable#more-71" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podpress/run-in-with-vbulletin-leasing-software-is-intolerable/feed</wfw:commentRss>
		</item>
		<item>
		<title>SQL Injection mention on hype-free</title>
		<link>http://www.mightyseek.com/web-application-security/sql-injection-mention-on-hype-free</link>
		<comments>http://www.mightyseek.com/web-application-security/sql-injection-mention-on-hype-free#comments</comments>
		<pubDate>Fri, 27 Apr 2007 07:35:42 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Hands On Series]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podcasts/sql-injection-mention-on-hype-free</guid>
		<description><![CDATA[Every once in awhile I try and find out if anyone is noticing my podcast. Well I stumbled on a mention of the SQL Injection hands on episode on hype-free.
]]></description>
			<content:encoded><![CDATA[<p>Every once in awhile I try and find out if anyone is noticing my podcast. Well I stumbled on a <a href="http://hype-free.blogspot.com/2007/04/sql-injections-what-they-are-and-how-to.html">mention of the SQL Injection hands on</a> episode on hype-free.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/sql-injection-mention-on-hype-free/feed</wfw:commentRss>
		</item>
		<item>
		<title>MightySeek Interviews rsnake</title>
		<link>http://www.mightyseek.com/web-application-security/mightyseek-interviews-rsnake</link>
		<comments>http://www.mightyseek.com/web-application-security/mightyseek-interviews-rsnake#comments</comments>
		<pubDate>Thu, 19 Apr 2007 07:45:27 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podcasts/mightyseek-interviews-rsnake</guid>
		<description><![CDATA[Today I had the pleasure of meeting up with a celeb of the web app sec world&#8230;. rsnake of the ha.ckers.org website. I hope you enjoy the interview, but I made a huge mistake with the recording. Here I was with my first interview, I hook up my mic and load up the recording software [...]]]></description>
			<content:encoded><![CDATA[<p>Today I had the pleasure of meeting up with a celeb of the web app sec world&#8230;. rsnake of the <a href="http://ha.ckers.org/" target="_blank">ha.ckers.org</a> website. I hope you enjoy the interview, but I made a huge mistake with the recording. Here I was with my first interview, I hook up my mic and load up the recording software and then completely forget to switch to the mic input to my good mic, and end up doing the recording on the lame mic thats built into my laptop.</p>
<p>In any case, here ya go.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/mightyseek-interviews-rsnake/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/56/0/MightySeek-18-2007-04-18-rsnakeInterview.mp3" length="30225059" type="audio/mpeg"/>
<itunes:duration>41:57</itunes:duration>
		<itunes:subtitle>Today I had the pleasure of meeting up with a celeb of the web app sec world.... rsnake of the ha.ckers.org website. I hope you ...</itunes:subtitle>
		<itunes:summary>Today I had the pleasure of meeting up with a celeb of the web app sec world.... rsnake of the ha.ckers.org website. I hope you enjoy the interview, but I made a huge mistake with the recording. Here I was with my first interview, I hook up my mic and load up the recording software and then completely forget to switch to the mic input to my good mic, and end up doing the recording on the lame mic thats built into my laptop.

In any case, here ya go.</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>PHP Security and the Month of PHP Bugs</title>
		<link>http://www.mightyseek.com/web-application-security/php-security-and-the-month-of-php-bugs</link>
		<comments>http://www.mightyseek.com/web-application-security/php-security-and-the-month-of-php-bugs#comments</comments>
		<pubDate>Sat, 10 Mar 2007 01:20:01 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podcasts/php-security-and-the-month-of-php-bugs</guid>
		<description><![CDATA[In this episode is discuss PHP security. Up till this point I have talked about web app sec in general, but I break from this in honor of the Month Of PHP Bugs that is going on through March.
PHP has frequently been blamed for security problems in applications written in PHP which really is no [...]]]></description>
			<content:encoded><![CDATA[<p>In this episode is discuss PHP security. Up till this point I have talked about web app sec in general, but I break from this in honor of the <a href="http://www.php-security.org/" target="_blank">Month Of PHP Bugs</a> that is going on through March.</p>
<p>PHP has frequently been blamed for security problems in applications written in PHP which really is no fault of the language and engine itself.  It would be like everyone blaming C and C++ as being insecure, and the cause of tons of security problems. Most of the time the problem is the developers who use the languages, not the languages themselves. However, there are security problems in the PHP codebase which need to be fixed and is what is being highlighted by the <a href="http://www.php-security.org/" target="_blank">Month Of PHP Bugs</a>.</p>
<p>So in this episode I discuss these issues, some of my past projects and some various other issues in PHP&#8230;  Its so good to be back at the mic, even tho I am still recovering from the flu and had my voice start failing me at the end.<br />
Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/php-security-and-the-month-of-php-bugs/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/53/0/MightySeek-17-2007-03-09-MonthOfPHPBugs.mp3" length="47224361" type="audio/mpeg"/>
<itunes:duration>65:34</itunes:duration>
		<itunes:subtitle>In this episode is discuss PHP security. Up till this point I have talked about web app sec in general, but I break from this ...</itunes:subtitle>
		<itunes:summary>In this episode is discuss PHP security. Up till this point I have talked about web app sec in general, but I break from this in honor of the Month Of PHP Bugs that is going on through March.
PHP has frequently been blamed for security problems in applications written in PHP which really is no fault of the language and engine itself.  It would be like everyone blaming C and C++ as being insecure, and the cause of tons of security problems. Most of the time the problem is the developers who use the languages, not the languages themselves. However, there are security problems in the PHP codebase which need to be fixed and is what is being highlighted by the Month Of PHP Bugs.
So in this episode I discuss these issues, some of my past projects and some various other issues in PHP...  Its so good to be back at the mic, even tho I am still recovering from the flu and had my voice start failing me at the end.
Enjoy!
</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>podPress more than one year old</title>
		<link>http://www.mightyseek.com/podpress/podpress-more-than-one-year-old</link>
		<comments>http://www.mightyseek.com/podpress/podpress-more-than-one-year-old#comments</comments>
		<pubDate>Mon, 05 Mar 2007 10:21:44 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[PodPress]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podpress/podpress-more-than-one-year-old</guid>
		<description><![CDATA[Today I was pondering the success of the podPress project since it started which got me to trying to remember how long its been. So a quick look at the change log shows that I released the first version on Feb 2nd of 2006.
So, its only a year and one month old!
What started as a [...]]]></description>
			<content:encoded><![CDATA[<p>Today I was pondering the success of the podPress project since it started which got me to trying to remember how long its been. So a quick look at the change log shows that I released the first version on Feb 2nd of 2006.</p>
<p>So, its only a year and one month old!</p>
<p>What started as a quick hack to wordpress that I wanted to use to bring attention to my little podcast, has become far more widely appreciated and used than I could have ever guessed.<br />
I want to thank you all for your support and thanks that I get in forum posts, emails and paypal donations. They all matter very much to me, and encourage my development to continue.</p>
<p>A special thanks also to macx who, over the last couple of months has really taking the initial quick little stats feature and turned it into something impressive. Its always great fun when I can chat about code with another developer and enjoy the collaborative artistic effort that software development can be.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podpress/podpress-more-than-one-year-old/feed</wfw:commentRss>
		</item>
		<item>
		<title>Stranger Things Podcast - Wow</title>
		<link>http://www.mightyseek.com/podcasting/stranger-things-podcast-wow</link>
		<comments>http://www.mightyseek.com/podcasting/stranger-things-podcast-wow#comments</comments>
		<pubDate>Sat, 03 Mar 2007 10:08:15 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasting]]></category>

		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/misc/stranger-things-podcast-wow</guid>
		<description><![CDATA[As a long time podcasting fan and supporter of the community I have been a fan of many shows, and impressed by a bunch of them. Some of my favorites (and I know I&#8217;ll end up forgetting some) have been Slice of Sci/Fi, Escape Pod, Filmspotting, The Signal, The Bitterest Pill, Verge of the Fringe, [...]]]></description>
			<content:encoded><![CDATA[<p>As a long time podcasting fan and supporter of the community I have been a fan of many shows, and impressed by a bunch of them. Some of my favorites (and I know I&#8217;ll end up forgetting some) have been <a href="http://www.sliceofscifi.com/">Slice of Sci/Fi</a>, <a href="http://www.escapepod.org/">Escape Pod</a>, <a href="http://www.filmspotting.net/">Filmspotting</a>, <a href="http://signal.serenityfirefly.com/">The Signal</a>, <a href="http://www.thebitterestpill.com/">The Bitterest Pill</a>, <a href="http://vergeofthefringe.blogspot.com/">Verge of the Fringe</a>, <a href="http://www.zefrank.com/theshow/">zeFrank</a>, <a href="http://www.tikibartv.com/">TikiBarTV</a> and numerous <a href="http://www.podiobooks.com/">Podiobooks </a>(<a href="http://www.scottsigler.net/">Sigler</a>, <a href="http://www.podiobooks.com/podiobooks/book.php?ID=40">Selznick</a>, <a href="http://www.podiobooks.com/podiobooks/book.php?ID=103">JC Hutchins</a>, etc), along with many many more.</p>
<p>So when I say I was blown away by the efforts of <strong><a href="http://www.strangerthings.tv">Stranger Things</a> (<a href="http://www.strangerthings.tv">http://www.strangerthings.tv</a>)</strong>, its not from a lack of experience with the brillance and creativity in this community. Its because its quite an impressive accomplishment. Audio is one thing, and it takes skill and hard work to do it well. Short video clips like those from <a href="http://www.zefrank.com/theshow/">zeFrank </a>and<a href="http://www.tikibartv.com/">TikiBarTV </a>are also quite a bit of work and take great talent. But to produce a 30 minute long episode with decent acting, a cool story (from self-pimping <a href="http://www.scottsigler.net/">Sigler</a>) and very nice special effects&#8230; and to make it a free podcast. Wow.</p>
<p>I have a hell of a time just trying to get my show out once a month, and even that is wayyy behind on getting some episodes out (one is coming soon btw).</p>
<p>Anyways, my props to the <a href="http://www.strangerthings.tv">Stranger Things</a> team, and I hope you are able to continue gaining an audience and some sponsorship/donations to help keep your show going.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasting/stranger-things-podcast-wow/feed</wfw:commentRss>
		</item>
		<item>
		<title>A Month of PHP Security Bugs</title>
		<link>http://www.mightyseek.com/web-application-security/a-month-of-php-security-bugs</link>
		<comments>http://www.mightyseek.com/web-application-security/a-month-of-php-security-bugs#comments</comments>
		<pubDate>Thu, 01 Mar 2007 20:21:30 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/web-application-security/a-month-of-php-security-bugs</guid>
		<description><![CDATA[The folks at the Hardened PHP Project (makers of Suhosin) have started their Month of PHP Bugs initiative.  				This initiative is an effort to improve the security of PHP by bringing awareness to various security problems in PHP itself. This does not directly impact any PHP applications, but instead the language itself. As far [...]]]></description>
			<content:encoded><![CDATA[<p>The folks at the <a href="http://www.hardened-php.net/" target="_blank">Hardened PHP Project</a> (makers of <a href="http://www.suhosin.org/" target="_blank">Suhosin</a>) have started their <a href="http://www.php-security.org/" target="_blank">Month of PHP Bugs</a> initiative.  				This initiative is an effort to improve the security of PHP by bringing awareness to various security problems in PHP itself. This does not directly impact any PHP applications, but instead the language itself. As far as I understand, the plan is to disclose issues that can be resolved by way of just using <a href="http://www.suhosin.org/" target="_blank">Suhosin</a> or the  <a href="http://www.hardened-php.net/" target="_blank">Hardened PHP Project</a>. Hopefully the PHP core team will finally wake up and start implementing some of the recommendations being suggested.</p>
<p>note: this post is likley to become a podcast if I can finish recording the show.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/a-month-of-php-security-bugs/feed</wfw:commentRss>
		</item>
		<item>
		<title>Dan Kuykendall on CrazyEngineers</title>
		<link>http://www.mightyseek.com/podpress/dan-kuykendall-on-crazyengineers</link>
		<comments>http://www.mightyseek.com/podpress/dan-kuykendall-on-crazyengineers#comments</comments>
		<pubDate>Fri, 26 Jan 2007 17:51:11 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[PodPress]]></category>

		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/misc/dan-kuykendall-on-crazyengineers</guid>
		<description><![CDATA[I did an interview thats been posted on CrazyEngineers.com.
Go check out the interview, along with the forum thread discussion.
]]></description>
			<content:encoded><![CDATA[<p>I did <a href="http://www.crazyengineers.com/index.php?categoryid=22&amp;p2_articleid=13">an interview</a> thats been posted on <a href="http://www.crazyengineers.com/">CrazyEngineers.com</a>.</p>
<p>Go check out <a href="http://www.crazyengineers.com/index.php?categoryid=22&amp;p2_articleid=13">the interview</a>, along with the <a href="http://www.crazyengineers.com/forum/showthread.php?t=592">forum thread discussion</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podpress/dan-kuykendall-on-crazyengineers/feed</wfw:commentRss>
		</item>
		<item>
		<title>Universal PDF XSS</title>
		<link>http://www.mightyseek.com/web-application-security/universal-pdf-xss</link>
		<comments>http://www.mightyseek.com/web-application-security/universal-pdf-xss#comments</comments>
		<pubDate>Sun, 07 Jan 2007 03:16:55 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/web-application-security/universal-pdf-xss</guid>
		<description><![CDATA[Cross Site scripting attacks are getting even more dangerous these days, and exploitable in many new creative ways. I will be discussing this issue in my next podcast, till then read up on it here or at ha.ckers.org
]]></description>
			<content:encoded><![CDATA[<p>Cross Site scripting attacks are getting even more dangerous these days, and exploitable in many new creative ways. I will be discussing this issue in my next podcast, till then <a href="http://www.gnucitizen.org/blog/universal-pdf-xss-after-party/">read up on it here</a> or a<a href="http://ha.ckers.org/blog/20070103/pdf-xss-can-compromise-your-machine/">t ha.ckers.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/universal-pdf-xss/feed</wfw:commentRss>
		</item>
		<item>
		<title>podPress - New powered by logo</title>
		<link>http://www.mightyseek.com/podpress/podpress-new-powered-by-logo</link>
		<comments>http://www.mightyseek.com/podpress/podpress-new-powered-by-logo#comments</comments>
		<pubDate>Mon, 11 Dec 2006 20:18:41 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[PodPress]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podpress/podpress-new-powered-by-logo</guid>
		<description><![CDATA[Today I got an email from the Daddo of the http://driftkikker.com/ website and he sent over a new Powered By logo to replace the lame one I threw together some time back.
My best effort                               [...]]]></description>
			<content:encoded><![CDATA[<p>Today I got an email from the Daddo of the <a href="http://driftkikker.com/">http://driftkikker.com/</a> website and he sent over a new Powered By logo to replace the lame one I threw together some time back.</p>
<p>My best effort                                          vs                                          Daddo<br />
<img src="http://www.mightyseek.com/images/powered_by_podpress_large2.jpg" title="My skillz" alt="My skillz" height="144" width="144" />        <img src="http://www.mightyseek.com/images/powered_by_podpress.jpg" alt="My skillz" /></p>
<p>Daddo wins!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podpress/podpress-new-powered-by-logo/feed</wfw:commentRss>
		</item>
		<item>
		<title>Still alive and kicking</title>
		<link>http://www.mightyseek.com/misc/still-alive-and-kicking</link>
		<comments>http://www.mightyseek.com/misc/still-alive-and-kicking#comments</comments>
		<pubDate>Fri, 08 Dec 2006 19:11:57 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/misc/still-alive-and-kicking</guid>
		<description><![CDATA[I know its been fairly quiet from me. No new versions of podPress and no new podcasts. The absense has been due to an extremely busy schedule, and a slight bit of lazyness on my part. Ive been doing TONS of reseach, and not had the energy to push out my findings just yet.
Well thats [...]]]></description>
			<content:encoded><![CDATA[<p>I know its been fairly quiet from me. No new versions of podPress and no new podcasts. The absense has been due to an extremely busy schedule, and a slight bit of lazyness on my part. Ive been doing TONS of reseach, and not had the energy to push out my findings just yet.</p>
<p>Well thats all changing now. Today I released a new version of podPress and am preping to push out a podcast in the next day or two.<br />
Thanks for all of you still out there watching, I&#8217;ll make sure to avoid big gaps like this again.</p>
<p>Seek3r</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/misc/still-alive-and-kicking/feed</wfw:commentRss>
		</item>
		<item>
		<title>Dan on Slice of SciFi</title>
		<link>http://www.mightyseek.com/podcasting/dan-on-slice-of-scifi</link>
		<comments>http://www.mightyseek.com/podcasting/dan-on-slice-of-scifi#comments</comments>
		<pubDate>Thu, 05 Oct 2006 21:32:22 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasting]]></category>

		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/misc/dan-on-slice-of-scifi</guid>
		<description><![CDATA[While at the PPME I met up with the legendary Evo Terra and got to sit in on a recording of the great Slice of SciFi podcast, which was quite alot of fun. It was recorded in Evo&#8217;s hotel room with a bunch of us hanging out in there. Amoung the live audience Mattew Wayne [...]]]></description>
			<content:encoded><![CDATA[<p>While at the PPME I met up with the legendary <a href="http://en.wikipedia.org/wiki/Evo_Terra">Evo Terra</a> and got to sit in on a recording of the great <a href="http://www.sliceofscifi.com/2006/10/04/slice-of-scifi-77/">Slice of SciFi podcast</a>, which was quite alot of fun. It was recorded in Evo&#8217;s hotel room with a bunch of us hanging out in there. Amoung the live audience Mattew Wayne Selznick (author of <a href="http://www.bravemenrun.com/">Brave Men Run</a>), podcasting &#8220;good guy&#8221; Paul Puri (founder of the <a href="http://www.podcastguild.org/">Podcasters Guild</a>), podcasting &#8220;mean guy&#8221;  Steve Eley (<a href="http://www.escapepod.org/">Escape Pod</a>), and fellow security podcasters Michael Santarcangelo (<a href="http://www.securitycatalyst.com/">Security Catalyst</a>) and Martin McKeay (<a href="http://www.mckeay.net/">Network Security Podcast</a>).</p>
<p>I was pretty silent thru most of it, but toward the end Evo went around the room introducing each of us and asking a few questions. I hassled them a little (all in good fun) and got quite a laugh/boo out of it. It was a great time and it alone was worth getting to the PPME for me.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasting/dan-on-slice-of-scifi/feed</wfw:commentRss>
		</item>
		<item>
		<title>Dan with Friends of the Fringe</title>
		<link>http://www.mightyseek.com/podcasting/dan-with-friends-of-the-fringe</link>
		<comments>http://www.mightyseek.com/podcasting/dan-with-friends-of-the-fringe#comments</comments>
		<pubDate>Mon, 02 Oct 2006 22:15:39 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasting]]></category>

		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/misc/dan-with-friends-of-the-fringe</guid>
		<description><![CDATA[I sat in with the LA Podcasters gang at the PPME and was in on a recording of Friends of the Fringe, which was pretty fun.

Im the guy on the right with the green shirt and this hat
]]></description>
			<content:encoded><![CDATA[<p>I sat in with the LA Podcasters gang at the <a href="http://www.portablemediaexpo.com/">PPME</a> and was in on <a href="http://vergeofthefringe.blogspot.com/2006/10/live-from-podcast-expo-2006-friends-of.html">a recording of </a><a href="http://vergeofthefringe.blogspot.com/2006/10/live-from-podcast-expo-2006-friends-of.html">Friends of the Fringe</a>, which was pretty fun.</p>
<p><img src="http://lapodcasters.com/images/VF06expo300.jpg" /></p>
<p>Im the guy on the right with the green shirt and this hat<a href="http://www.mightyseek.com/images/mightyseek_hat.jpg"><img width="91" height="85" align="middle" src="http://www.mightyseek.com/images/mightyseek_hat.gif" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasting/dan-with-friends-of-the-fringe/feed</wfw:commentRss>
		</item>
		<item>
		<title>MightySeek coming back online slowly</title>
		<link>http://www.mightyseek.com/misc/hello-world</link>
		<comments>http://www.mightyseek.com/misc/hello-world#comments</comments>
		<pubDate>Wed, 13 Sep 2006 14:09:16 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">351482043</guid>
		<description><![CDATA[We had a total system failure, and of course I didnt have a backup worth using to get things back online. I am working to get the site fully back up and will be doing so as quickly as possible,
Mighty Seek
]]></description>
			<content:encoded><![CDATA[<p>We had a total system failure, and of course I didnt have a backup worth using to get things back online. I am working to get the site fully back up and will be doing so as quickly as possible,</p>
<p>Mighty Seek</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/misc/hello-world/feed</wfw:commentRss>
		</item>
		<item>
		<title>Jeremiah Grossmans XSS BlackHat Presentation</title>
		<link>http://www.mightyseek.com/web-application-security/jeremiah-grossmans-xss-blackhat-presentation</link>
		<comments>http://www.mightyseek.com/web-application-security/jeremiah-grossmans-xss-blackhat-presentation#comments</comments>
		<pubDate>Fri, 08 Sep 2006 22:48:02 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/09/08/jeremiah-grossmans-xss-blackhat-presentation/</guid>
		<description><![CDATA[If you didnt get to BlackHat this year, then you may have heard about the really cool presentation about Cross Site Scripting. He uses XSS to hack intranets by writing a port scanner in javascript. If your into web app sec, you need to see this. It also really puts a point on the need [...]]]></description>
			<content:encoded><![CDATA[<p>If you didnt get to BlackHat this year, then you may have heard about the really cool presentation about Cross Site Scripting. He uses XSS to hack intranets by writing a port scanner in javascript. If your into web app sec, you need to see this. It also really puts a point on the need to start learning about this issue and the very large problems XSS can cause. So get over to my XSS Hands on Series and start following along!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/jeremiah-grossmans-xss-blackhat-presentation/feed</wfw:commentRss>
	<!-- Media File exists for this post, but its not enabled for this feed -->
	</item>
		<item>
		<title>Behind the Mic: Interviews Dan Kuykendall</title>
		<link>http://www.mightyseek.com/podcasting/behind-the-mic-interviews-dan-kuykendall</link>
		<comments>http://www.mightyseek.com/podcasting/behind-the-mic-interviews-dan-kuykendall#comments</comments>
		<pubDate>Thu, 07 Sep 2006 22:48:01 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasting]]></category>

		<category><![CDATA[PodPress]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/09/13/behind-the-mic-interviews-dan-kuykendall/</guid>
		<description><![CDATA[I had the great pleasure of being interviewed about podPress by the one and only Michael Geoghegan. I got in a small plug for my podcast as well, so Im pretty happy.
The Podcast Academy: Dan Kuykendall
]]></description>
			<content:encoded><![CDATA[<p>I had the great pleasure of being interviewed about podPress by the one and only Michael Geoghegan. I got in a small plug for my podcast as well, so Im pretty happy.</p>
<p><a href="http://pa.gigavox.com/shows/detail1556.html">The Podcast Academy: Dan Kuykendall</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasting/behind-the-mic-interviews-dan-kuykendall/feed</wfw:commentRss>
	<!-- Media File exists for this post, but its not enabled for this feed -->
	</item>
		<item>
		<title>Hands On Series - Cross Site Scripting (XSS) Part 1</title>
		<link>http://www.mightyseek.com/web-application-security/hands-on-series-cross-site-scripting-xss-part-1</link>
		<comments>http://www.mightyseek.com/web-application-security/hands-on-series-cross-site-scripting-xss-part-1#comments</comments>
		<pubDate>Mon, 28 Aug 2006 03:57:40 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Hands On Series]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podcasts/hands-on-series-cross-site-scripting-xss-part-1</guid>
		<description><![CDATA[The &#8220;Hands on Series&#8221; continues!

In this episode we start dealing with Cross Site Scripting (XSS) attacks. 
CSS = Cascading Style Sheets
XSS = Cross Site Scripting
Cross Site Scripting is a technique used to add script to a trusted site that will be executed on other users browsers.
A key element to XSS is that one user can [...]]]></description>
			<content:encoded><![CDATA[<p>The &#8220;Hands on Series&#8221; continues!<br />
<br />
In this episode we start dealing with Cross Site Scripting (XSS) attacks. </p>
<p>CSS = Cascading Style Sheets<br />
XSS = Cross Site Scripting</p>
<p>Cross Site Scripting is a technique used to add script to a trusted site that will be executed on other users browsers.<br />
A key element to XSS is that one user can submit data to a website that will later be displayed for other users.<br />
It is nessesary that the bad guy NOT mess up the HTML structure, otherwise the result will be web defacement rather then attacking other users.</p>
<p>The <a href="http://hackme.ntobjectives.com/" target="_new"><b>hackme site</b></a> has been updated and improved (more about that in a moment)</p>
<p>and now includes a section for XSS which we will be using in this episode.<br />
<a id="more-59"></a><br /> <a href="http://www.mightyseek.com/web-application-security/hands-on-series-cross-site-scripting-xss-part-1#more-14" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/hands-on-series-cross-site-scripting-xss-part-1/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/14/0/MightySeek-16-2006-07-28-HandOnSeriesXSS.mp3" length="27508399" type="audio/mpeg"/>
<itunes:duration>38:10</itunes:duration>
		<itunes:subtitle>The #8220;Hands on Series#8221; continues!

In this episode we start dealing with Cross Site Scripting (XSS) attacks. 
CSS = Cascading Style Sheets
XSS = Cross Site Scripting
Cross ...</itunes:subtitle>
		<itunes:summary>The #8220;Hands on Series#8221; continues!

In this episode we start dealing with Cross Site Scripting (XSS) attacks. 
CSS = Cascading Style Sheets
XSS = Cross Site Scripting
Cross Site Scripting is a technique used to add script to a trusted site that will be executed on other users browsers.
A key element to XSS is that one user can submit data to a website that will later be displayed for other users.
It is nessesary that the bad guy NOT mess up the HTML structure, otherwise the result will be web defacement rather then attacking other users.
The hackme site has been updated and improved (more about that in a moment)

and now includes a section for XSS which we will be using in this episode.
</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Hands,On,Series,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>podPress reviewed on Upon Further Review » Episode 3</title>
		<link>http://www.mightyseek.com/podcasting/podpress-reviewed-on-upon-further-review-%c2%bb-episode-3</link>
		<comments>http://www.mightyseek.com/podcasting/podpress-reviewed-on-upon-further-review-%c2%bb-episode-3#comments</comments>
		<pubDate>Sat, 29 Jul 2006 22:45:43 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasting]]></category>

		<category><![CDATA[PodPress]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/07/29/podpress-reviewed-on-upon-further-review-%c2%bb-episode-3/</guid>
		<description><![CDATA[In the latest episode of Upon Further Review the podPress plugin (and me) was reviewed. Im happy to say we got a 4.5 out of 5 rating and in general alot of glowing praise.
The podcast itself is very well done for an episode #3, and theres lots of other good stuff in the episode so [...]]]></description>
			<content:encoded><![CDATA[<p>In the latest episode of <a href="http://www.furtherreview.net/?p=15">Upon Further Review</a> the podPress plugin (and me) was reviewed. Im happy to say we got a 4.5 out of 5 rating and in general alot of glowing praise.</p>
<p>The podcast itself is very well done for an episode #3, and theres lots of other good stuff in the episode so have fun listening.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasting/podpress-reviewed-on-upon-further-review-%c2%bb-episode-3/feed</wfw:commentRss>
		</item>
		<item>
		<title>MightySeek on (IN)SECURE Magazine</title>
		<link>http://www.mightyseek.com/web-application-security/mightyseek-on-insecure-magazine</link>
		<comments>http://www.mightyseek.com/web-application-security/mightyseek-on-insecure-magazine#comments</comments>
		<pubDate>Sat, 08 Jul 2006 22:43:20 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasting]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/07/08/mightyseek-on-insecure-magazine/</guid>
		<description><![CDATA[The MightySeek podcast got a cool mention in the lastest issue of (IN)SECURE Magazine.
]]></description>
			<content:encoded><![CDATA[<p>The MightySeek podcast got a cool mention in the lastest issue of <a href="http://www.insecuremag.com/">(IN)SECURE Magazine</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/mightyseek-on-insecure-magazine/feed</wfw:commentRss>
		</item>
		<item>
		<title>Mighty Seek Podcast #15 - News and Misc Topics</title>
		<link>http://www.mightyseek.com/web-application-security/mighty-seek-podcast-15-news-and-misc-topics</link>
		<comments>http://www.mightyseek.com/web-application-security/mighty-seek-podcast-15-news-and-misc-topics#comments</comments>
		<pubDate>Fri, 26 May 2006 22:41:15 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/05/26/mighty-seek-podcast-15-news-and-misc-topics/</guid>
		<description><![CDATA[A quick in between to the Hands On Series, I chat about some news and issues of the day.
Turkish Hacker defaces 38,000 websites hosted on GoDaddy
Flawed USC admissions site allowed access to applicant data
Breach case could curtail Web flaw finders
Man charged with accessing USC student data
Tsunami appeal site &#8216;hacker&#8217; found guilty
]]></description>
			<content:encoded><![CDATA[<p>A quick in between to the Hands On Series, I chat about some news and issues of the day.</p>
<p><a href="http://www.zone-h.org/en/news/read/id=206009/">Turkish Hacker defaces 38,000 websites hosted on GoDaddy</a></p>
<p><a href="http://www.securityfocus.com/news/11239">Flawed USC admissions site allowed access to applicant data</a></p>
<p><a href="http://www.securityfocus.com/news/11389/1">Breach case could curtail Web flaw finders</a></p>
<p><a href="http://www.securityfocus.com/brief/191">Man charged with accessing USC student data</a></p>
<p><a href="http://news.zdnet.co.uk/0,39020330,39226548,00.htm">Tsunami appeal site &#8216;hacker&#8217; found guilty</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/mighty-seek-podcast-15-news-and-misc-topics/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/9/0/MightySeek-15-2006-05-23-NewsAndMiscTopics.mp3" length="24381600" type="audio/mpeg"/>
<itunes:duration>33:50</itunes:duration>
		<itunes:subtitle>A quick in between to the Hands On Series, I chat about some news and issues of the day.

Turkish Hacker defaces 38,000 websites hosted on ...</itunes:subtitle>
		<itunes:summary>A quick in between to the Hands On Series, I chat about some news and issues of the day.

Turkish Hacker defaces 38,000 websites hosted on GoDaddy
Flawed USC admissions site allowed access to applicant data
Breach case could curtail Web flaw finders
Man charged with accessing USC student data
Tsunami appeal site #8216;hacker#8217; found guilty</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>The Security Roundtable » Featured in the iTunes Music Store</title>
		<link>http://www.mightyseek.com/podcasting/the-security-roundtable-%c2%bb-featured-in-the-itunes-music-store</link>
		<comments>http://www.mightyseek.com/podcasting/the-security-roundtable-%c2%bb-featured-in-the-itunes-music-store#comments</comments>
		<pubDate>Wed, 24 May 2006 23:40:05 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasting]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/09/13/the-security-roundtable-%c2%bb-featured-in-the-itunes-music-store/</guid>
		<description><![CDATA[The Security Roundtable » Blog Archive » SRT in the iTunes Music Store
The podcasting group Im a part of now has its own Artist Group in iTunes and is featured on the podcasting home page. Im pretty excited about this and look forward to any new listeners that join in due to the exposure.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securityroundtable.com/?p=5">The Security Roundtable » Blog Archive » SRT in the iTunes Music Store</a></p>
<p>The podcasting group Im a part of now has its own Artist Group in iTunes and is featured on the podcasting home page. Im pretty excited about this and look forward to any new listeners that join in due to the exposure.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasting/the-security-roundtable-%c2%bb-featured-in-the-itunes-music-store/feed</wfw:commentRss>
		</item>
		<item>
		<title>Network Security Blog: Network Security Podcast, Episode 28</title>
		<link>http://www.mightyseek.com/podcasts/network-security-blog-network-security-podcast-episode-28</link>
		<comments>http://www.mightyseek.com/podcasts/network-security-blog-network-security-podcast-episode-28#comments</comments>
		<pubDate>Wed, 24 May 2006 22:35:32 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/05/24/network-security-blog-network-security-podcast-episode-28/</guid>
		<description><![CDATA[Network Security Blog: Network Security Podcast, Episode 28
Tonight I appear as co-host/guest of the Network Security Podcast with Martin McKeay. This podcast is a fellow Security Round Table podcast, and I had alot of fun being able to discuss more general security issues.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.mckeay.net/secure/2006/05/network_security_podcast_episo_25.html">Network Security Blog: Network Security Podcast, Episode 28</a></p>
<p>Tonight I appear as co-host/guest of the <a href="http://www.mckeay.net">Network Security Podcast</a> with Martin McKeay. This podcast is a fellow <a href="http://www.securityroundtable.com/">Security Round Table</a> podcast, and I had alot of fun being able to discuss more general security issues.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasts/network-security-blog-network-security-podcast-episode-28/feed</wfw:commentRss>
		</item>
		<item>
		<title>Questions for podcast with Dan (PodPress developer)</title>
		<link>http://www.mightyseek.com/podcasts/questions-for-podcast-with-dan-podpress-developer</link>
		<comments>http://www.mightyseek.com/podcasts/questions-for-podcast-with-dan-podpress-developer#comments</comments>
		<pubDate>Thu, 18 May 2006 22:31:14 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasts]]></category>

		<category><![CDATA[PodPress]]></category>

		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/05/18/questions-for-podcast-with-dan-podpress-developer/</guid>
		<description><![CDATA[James Woodcock will be interviewing me in the coming days, and so posted this on the forums.
Click here to get to the forum topic
Dan (Mighty Seek) developer of the PodPress plugin for Wordpress, will be interviewed in one of my future blogcasts on my website.
If you have any questions you would like him to answer [...]]]></description>
			<content:encoded><![CDATA[<p>James Woodcock will be interviewing me in the coming days, and so posted this on the forums.</p>
<p><a href="http://www.mightyseek.com/forum/showthread.php?t=251">Click here to get to the forum topic</a></p>
<p>Dan (Mighty Seek) developer of the PodPress plugin for Wordpress, will be interviewed in one of my future blogcasts on my website.</p>
<p>If you have any questions you would like him to answer about either his PodPress plugin or security, please ring my automated (non-premium) voicemail on UK: 0207 193 3092 or Worldwide: +44 207 193 3092 or for free on skype id: glidem</p>
<p>The best questions will be included in the show&#8230;..<br />
__________________<br />
>> <a href="http://www.jameswoodcock.co.uk/?p=252">Hear more about PodPress, in my audio interview with Dan Kuykendall</a> <<</p>
<p><a href="http://www.jameswoodcock.co.uk">http://www.jameswoodcock.co.uk</a> - My personal online diary covering the internet that I find of interest including audio interviews, music, gaming, technology, gadgets, websites, free downloads and general articles.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasts/questions-for-podcast-with-dan-podpress-developer/feed</wfw:commentRss>
		</item>
		<item>
		<title>Hands On Series - SQL Injection Part 1</title>
		<link>http://www.mightyseek.com/web-application-security/hands-on-series-sql-injection</link>
		<comments>http://www.mightyseek.com/web-application-security/hands-on-series-sql-injection#comments</comments>
		<pubDate>Fri, 28 Apr 2006 21:56:15 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Hands On Series]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/podcasts/hands-on-series-sql-injection</guid>
		<description><![CDATA[The start of the “Hands on Series”, which means that there are actual
hands on excersises to go along with these shows.

I feel that its time to go beyond the concepts, the chatter about what bad guys can do,
and actually show you directly. Let you see for yourself the saying goes.
I recommend that you listen to [...]]]></description>
			<content:encoded><![CDATA[<p>The start of the “Hands on Series”, which means that there are actual<br />
hands on excersises to go along with these shows.</p>
<p></p>
<p>I feel that its time to go beyond the concepts, the chatter about what bad guys can do,<br />
and actually show you directly. Let you see for yourself the saying goes.</p>
<p>I recommend that you listen to these episodes while viewing the hacking test site and<br />
have the show notes visible and ready to cut and paste from.</p>
<ul>
<li><a href="http://hackme.ntobjectives.com/">http://hackme.ntobjectives.com/</a> - The new site setup for you to practice web app hacking.
<p>Includes <a href="http://hackme.ntobjectives.com/sql_inject/SQLInjectionAttacks.txt">detailed notes</a> and samples that can be used to practice with.</li>
<li><a href="http://www.mightyseek.com/web-hacking-toolkit/">Web App Hacking Toolkit</a> - Collection of tools and links helpful for web security.</li>
<li><a href="http://jonathancoulton.com/">Jonathan Coulton’s Things a Week</a> - Where the Code Monkey song came from.</li>
</ul>
<p> <a href="http://www.mightyseek.com/web-application-security/hands-on-series-sql-injection#more-5" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/hands-on-series-sql-injection/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/5/0/MightySeek-14-2006-04-28-HandOnSeriesSQLInjection.mp3" length="41814674" type="audio/mpeg"/>
<itunes:duration>58:03</itunes:duration>
		<itunes:subtitle>The start of the ldquo;Hands on Seriesrdquo;, which means that there are actual
hands on excersises to go along with these shows.

I feel that its time ...</itunes:subtitle>
		<itunes:summary>The start of the ldquo;Hands on Seriesrdquo;, which means that there are actual
hands on excersises to go along with these shows.

I feel that its time to go beyond the concepts, the chatter about what bad guys can do,
and actually show you directly. Let you see for yourself the saying goes.
I recommend that you listen to these episodes while viewing the hacking test site and
have the show notes visible and ready to cut and paste from.

http://hackme.ntobjectives.com/ - The new site setup for you to practice web app hacking.

Includes detailed notes and samples that can be used to practice with.
Web App Hacking Toolkit - Collection of tools and links helpful for web security.
Jonathan Coultonrsquo;s Things a Week - Where the Code Monkey song came from.

</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Hands,On,Series,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>InformationWeek &#124; Web App Hack Incidents Are Up</title>
		<link>http://www.mightyseek.com/web-application-security/informationweek-web-app-hack-incidents-are-up</link>
		<comments>http://www.mightyseek.com/web-application-security/informationweek-web-app-hack-incidents-are-up#comments</comments>
		<pubDate>Fri, 14 Apr 2006 18:09:58 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/04/14/informationweek-web-app-hack-incidents-are-up/</guid>
		<description><![CDATA[InformationWeek &#124; Web Application Security &#124; Web App Hack Incidents Are Up As Businesses Take Cover &#124; April 12, 2006
First a bug ‘duh!”
And then I get to move into the “finally someones talking about this in the mainstream press”.
Not that Information Week is read by grandma or the average joe on the street, but for [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.informationweek.com/industries/showArticle.jhtml?articleID=185300842">InformationWeek | Web Application Security | Web App Hack Incidents Are Up As Businesses Take Cover | April 12, 2006</a></p>
<p>First a bug ‘duh!”<br />
And then I get to move into the “finally someones talking about this in the mainstream press”.</p>
<p>Not that Information Week is read by grandma or the average joe on the street, but for info tech community its pretty well known.</p>
<p>The things I like about the article is that they get it. The problems are basicly bad coding practices that are at the root of the problem. This is of course the primary topic in my podcast, so start listening and following my advice to deal with these issues!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/informationweek-web-app-hack-incidents-are-up/feed</wfw:commentRss>
		</item>
		<item>
		<title>Privilage Escalation Attacks</title>
		<link>http://www.mightyseek.com/web-application-security/privilage-escalation-attacks</link>
		<comments>http://www.mightyseek.com/web-application-security/privilage-escalation-attacks#comments</comments>
		<pubDate>Fri, 14 Apr 2006 17:10:39 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/04/14/privilage-escalation-attacks/</guid>
		<description><![CDATA[In this podcast I discuss a type of attack that allows users to basicly do things they are not supposed to do, without ever having to hack the admin type of accounts. So without having to figure out the admin password it is often possible to do administrative functions by simply attempting them.
The problem is [...]]]></description>
			<content:encoded><![CDATA[<p>In this podcast I discuss a type of attack that allows users to basicly do things they are not supposed to do, without ever having to hack the admin type of accounts. So without having to figure out the admin password it is often possible to do administrative functions by simply attempting them.</p>
<p>The problem is around validation against access controls at every point of execution. Too often the access controls are done to control the navigational structure, meaning that the menus do not have links to the admin functionality, but if you know what the URL is then you can just type it into your browser and get there. Thats bad design in the app, and it is VERY common.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/privilage-escalation-attacks/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/15/0/MightySeek-13-2006-04-14-PrivilegeEscalation.mp3" length="15073162" type="audio/mpeg"/>
<itunes:duration>20:55</itunes:duration>
		<itunes:subtitle>In this podcast I discuss a type of attack that allows users to basicly do things they are not supposed to do, without ever having ...</itunes:subtitle>
		<itunes:summary>In this podcast I discuss a type of attack that allows users to basicly do things they are not supposed to do, without ever having to hack the admin type of accounts. So without having to figure out the admin password it is often possible to do administrative functions by simply attempting them.

The problem is around validation against access controls at every point of execution. Too often the access controls are done to control the navigational structure, meaning that the menus do not have links to the admin functionality, but if you know what the URL is then you can just type it into your browser and get there. Thats bad design in the app, and it is VERY common. </itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Catching up and a preview of future shows</title>
		<link>http://www.mightyseek.com/web-application-security/catching-up-and-a-preview-of-future-shows</link>
		<comments>http://www.mightyseek.com/web-application-security/catching-up-and-a-preview-of-future-shows#comments</comments>
		<pubDate>Thu, 13 Apr 2006 17:11:47 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/04/13/catching-up-and-a-preview-of-future-shows/</guid>
		<description><![CDATA[In this edition of the Mighty Seek podcast I give a rundown of podPress and list out some ideas for the future podcasts. The site now has a forum for the podcast and general web application security discussion.
]]></description>
			<content:encoded><![CDATA[<p>In this edition of the Mighty Seek podcast I give a rundown of podPress and list out some ideas for the future podcasts. The site now has a <a href="http://www.mightyseek.com/forum/">forum for the podcast</a> and general web application security discussion.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/catching-up-and-a-preview-of-future-shows/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/16/0/MightySeek-12-2006-04-13-CheckingInAndPreviewUpcomingShows.mp3" length="28581883" type="audio/mpeg"/>
<itunes:duration>39:40</itunes:duration>
		<itunes:subtitle>In this edition of the Mighty Seek podcast I give a rundown of podPress and list out some ideas for the future podcasts. The site ...</itunes:subtitle>
		<itunes:summary>In this edition of the Mighty Seek podcast I give a rundown of podPress and list out some ideas for the future podcasts. The site now has a forum for the podcast and general web application security discussion.</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>For-Pay Only Podcasting (Password Protected)</title>
		<link>http://www.mightyseek.com/podcasting/for-pay-only-podcasting-password-protected</link>
		<comments>http://www.mightyseek.com/podcasting/for-pay-only-podcasting-password-protected#comments</comments>
		<pubDate>Mon, 13 Mar 2006 17:56:57 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Podcasting]]></category>

		<category><![CDATA[PodPress]]></category>

		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/03/13/for-pay-only-podcasting-password-protected/</guid>
		<description><![CDATA[Today I learned about iTunes support for password protected podcasts, and am thinking about the security issues, planning out how I can support this in PodPress as well as what this means for podcasting in general. 
Overall I think this is very cool for podcasting, because it can open the doors for various content providers [...]]]></description>
			<content:encoded><![CDATA[<p>Today I learned about iTunes support for password protected podcasts, and am thinking about the security issues, planning out how I can support this in PodPress as well as what this means for podcasting in general. </p>
<p>Overall I think this is very cool for podcasting, because it can open the doors for various content providers to jump in and start offering content. It may also allow existing podcasters to start offering special pay-only content. I know many want everything for free, but Im not opposed to paying people for the time and talent they pour into creating great content.</p>
<p>That aside, I was most curious about the technical issues involved. So I dug in&#8230;<br />
<a id="more-34"></a><br />
Last week I heard that radio talk show host <a href="http://www.rushlimbaugh.com/home/daily/site_030806/content/rush_24_7.member.html">Rush Limbaugh announced</a> that his show would be available from within iTunes. For several months his show was available as a &#8220;podcast&#8221; which meant his subscribers could download MP3&#8217;s a few hours after each show aired. At the time this happened, I dug into the custom downloader, sniffed out the traffic and figured out how it all worked. It wasnt complicated, but it wasnt a real podcast, there was no RSS feed with enclosures, and no way standard podcatchers could ever support it.</p>
<p>Now the landscape has changed, and this is a new solution that works with iTunes. I still didnt know how it was going to work, but my guess was that it had to do with HTTP BasicAuth. This morning the website had the link, and I had my Paros Proxy. I configured my computer to run thru the local proxy, and I went about getting the show into my iTunes, recording all the network traffic along the way.</p>
<p>It turned out to be much easier than I expected. It did use HTTP BasicAuth, and it only does so for the rss feed.<br />
So what we have is a link to the RSS feed, but with the protocol defined as itpc, which I assume to mean ITunesPodCast and is something that iTunes is registered to handle.</p>
<p>So the link looks something like this:<br/><br />
<b>itpc://rss.premiereradio.net/podcast/rushlimb.xml</b></p>
<p>Note: Just because the protocol is itpc instead of http, does not mean you couldnt go to this URL with your browser</p>
<p><b>http://rss.premiereradio.net/podcast/rushlimb.xml</b></p>
<p>If you try, you will get a password prompt. This is using standard HTTP BasicAuth, and once you give your credentials you would get the RSS Feed.<br />
The feed itself is a standard iTunes compliant RSS2 document like we are all used to. As far as the MP3 files themselves, there is only security by obscurity. I will not give an actual URL to one of the MP3 files, but its something along the lines of</p>
<p><b>http://rss.premiereradio.net/download/rushlimb /username/48123789787qe98/rushlimb/2006/03/ Rush%20Limbaugh%20-%20Mar%2010%202006%20-%20Hour%201.mp3</b></p>
<p>If you had the actual URL, you could download the MP3 without any sort of authentication. Of course, security by obscrurity is not an ideal solution, but in the case of this type of content it serves the need. It should also be easy use the same HTTP BasicAuth to protect the MP3 files is so desired.</p>
<p>I have also found out that the popular podcatcher <a href="http://juicereceiver.sourceforge.net">Juice</a> supports HTTP BasicAuth as well, so using this solution really seems the way to go. </p>
<p>I believe I can add support into PodPress for all this at some point, and the bottom line is that this is an interesting and exciting development in the Podcasting world.</p>
<p>- Additional Resources - </p>
<p>* Just found out about <a href="http://www.potionfactory.com/blog/2006/02/20/password-protecting-a-podcast/">another blogger who did a write up here</a></p>
<p>* <a href="http://juicereceiver.sourceforge.net">http://juicereceiver.sourceforge.net</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/podcasting/for-pay-only-podcasting-password-protected/feed</wfw:commentRss>
		</item>
		<item>
		<title>Security Engagement Cast Part 2</title>
		<link>http://www.mightyseek.com/web-application-security/security-engagement-cast-part-2</link>
		<comments>http://www.mightyseek.com/web-application-security/security-engagement-cast-part-2#comments</comments>
		<pubDate>Sat, 11 Mar 2006 17:13:13 +0000</pubDate>
		<dc:creator>dan</dc:creator>
		
		<category><![CDATA[Web Application Security]]></category>

		<category><![CDATA[Podcasts]]></category>

		<guid isPermaLink="false">http://www.mightyseek.com/2006/03/11/security-engagement-cast-part-2/</guid>
		<description><![CDATA[In part 2 we discuss the planning and deliverables involved when doing a security engagement. Most of the discussion demonstrates the importance of understanding the boundaries, requirements and deliverables from the start.
]]></description>
			<content:encoded><![CDATA[<p>In part 2 we discuss the planning and deliverables involved when doing a security engagement. Most of the discussion demonstrates the importance of understanding the boundaries, requirements and deliverables from the start.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mightyseek.com/web-application-security/security-engagement-cast-part-2/feed</wfw:commentRss>
			<enclosure url="http://www.mightyseek.com/podpress_trac/feed/17/0/MightySeek-11-2006-03-08-SecurityEngagementCast.mp3" length="42814299" type="audio/mpeg"/>
<itunes:duration>59:26</itunes:duration>
		<itunes:subtitle>In part 2 we discuss the planning and deliverables involved when doing a security engagement. Most of the discussion demonstrates the importance of understanding the ...</itunes:subtitle>
		<itunes:summary>In part 2 we discuss the planning and deliverables involved when doing a security engagement. Most of the discussion demonstrates the importance of understanding the boundaries, requirements and deliverables from the start.</itunes:summary>
		<itunes:keywords>Web,Application,Security,,Podcasts</itunes:keywords>
		<itunes:author>Dan Kuykendall</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
	</channel>
</rss>
