<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Can You Hack Your Own Site? A Look at Some Essential Security Considerations</title>
	<atom:link href="http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential-security-considerations/feed/" rel="self" type="application/rss+xml" />
	<link>http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential-security-considerations/</link>
	<description>Web Development &#38; Design Tutorials</description>
	<lastBuildDate>Sat, 21 Nov 2009 18:53:09 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Allan</title>
		<link>http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential-security-considerations/#comment-134587</link>
		<dc:creator>Allan</dc:creator>
		<pubDate>Sat, 21 Nov 2009 17:03:45 +0000</pubDate>
		<guid isPermaLink="false">http://nettuts.com/?p=51#comment-134587</guid>
		<description>I totally agree with you but the downfall of doing so would be slow server performance!</description>
		<content:encoded><![CDATA[<p>I totally agree with you but the downfall of doing so would be slow server performance!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SplitFive</title>
		<link>http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential-security-considerations/#comment-129947</link>
		<dc:creator>SplitFive</dc:creator>
		<pubDate>Fri, 13 Nov 2009 05:11:55 +0000</pubDate>
		<guid isPermaLink="false">http://nettuts.com/?p=51#comment-129947</guid>
		<description>Very nice tutorial. I loved it.</description>
		<content:encoded><![CDATA[<p>Very nice tutorial. I loved it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mohammed yaghi</title>
		<link>http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential-security-considerations/#comment-122772</link>
		<dc:creator>mohammed yaghi</dc:creator>
		<pubDate>Fri, 23 Oct 2009 17:06:01 +0000</pubDate>
		<guid isPermaLink="false">http://nettuts.com/?p=51#comment-122772</guid>
		<description>really nice tots</description>
		<content:encoded><![CDATA[<p>really nice tots</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe</title>
		<link>http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential-security-considerations/#comment-117620</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Mon, 12 Oct 2009 06:50:32 +0000</pubDate>
		<guid isPermaLink="false">http://nettuts.com/?p=51#comment-117620</guid>
		<description>Nice Security Tips! :P</description>
		<content:encoded><![CDATA[<p>Nice Security Tips! <img src='http://net.tutsplus.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Myfacefriends</title>
		<link>http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential-security-considerations/#comment-84263</link>
		<dc:creator>Myfacefriends</dc:creator>
		<pubDate>Mon, 27 Jul 2009 03:56:28 +0000</pubDate>
		<guid isPermaLink="false">http://nettuts.com/?p=51#comment-84263</guid>
		<description>Thanks for this wonderful tuts!</description>
		<content:encoded><![CDATA[<p>Thanks for this wonderful tuts!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tutorials &#8212; B.B.Log</title>
		<link>http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential-security-considerations/#comment-84188</link>
		<dc:creator>tutorials &#8212; B.B.Log</dc:creator>
		<pubDate>Sun, 26 Jul 2009 19:54:46 +0000</pubDate>
		<guid isPermaLink="false">http://nettuts.com/?p=51#comment-84188</guid>
		<description>[...] http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential... http://php-ids.org/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential.." rel="nofollow">http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential..</a>. <a href="http://php-ids.org/" rel="nofollow">http://php-ids.org/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonli</title>
		<link>http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential-security-considerations/#comment-77864</link>
		<dc:creator>Jonli</dc:creator>
		<pubDate>Wed, 08 Jul 2009 09:11:43 +0000</pubDate>
		<guid isPermaLink="false">http://nettuts.com/?p=51#comment-77864</guid>
		<description>Good Article.I like it.
Cheers</description>
		<content:encoded><![CDATA[<p>Good Article.I like it.<br />
Cheers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anthony - Magictallguy</title>
		<link>http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential-security-considerations/#comment-73239</link>
		<dc:creator>Anthony - Magictallguy</dc:creator>
		<pubDate>Sat, 20 Jun 2009 02:29:48 +0000</pubDate>
		<guid isPermaLink="false">http://nettuts.com/?p=51#comment-73239</guid>
		<description>You can hope, but you can *never* assume that every visitor is friendly.
Always clean user input and output.
Don&#039;t let lazyiness be your downfall ;)</description>
		<content:encoded><![CDATA[<p>You can hope, but you can *never* assume that every visitor is friendly.<br />
Always clean user input and output.<br />
Don&#8217;t let lazyiness be your downfall <img src='http://net.tutsplus.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anthony - Magictallguy</title>
		<link>http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential-security-considerations/#comment-73237</link>
		<dc:creator>Anthony - Magictallguy</dc:creator>
		<pubDate>Sat, 20 Jun 2009 02:26:15 +0000</pubDate>
		<guid isPermaLink="false">http://nettuts.com/?p=51#comment-73237</guid>
		<description>Not necessarily. I have rushed an entire site before, and not once did anything get through my defences.
Not only that, but my &quot;defences&quot; were mostly simple PHP!

Scripting security isn&#039;t as hard as people make out - though the extra nudge in the right direction does help :P</description>
		<content:encoded><![CDATA[<p>Not necessarily. I have rushed an entire site before, and not once did anything get through my defences.<br />
Not only that, but my &#8220;defences&#8221; were mostly simple PHP!</p>
<p>Scripting security isn&#8217;t as hard as people make out &#8211; though the extra nudge in the right direction does help <img src='http://net.tutsplus.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anthony - Magictallguy</title>
		<link>http://net.tutsplus.com/tutorials/tools-and-tips/can-you-hack-your-own-site-a-look-at-some-essential-security-considerations/#comment-73234</link>
		<dc:creator>Anthony - Magictallguy</dc:creator>
		<pubDate>Sat, 20 Jun 2009 02:18:15 +0000</pubDate>
		<guid isPermaLink="false">http://nettuts.com/?p=51#comment-73234</guid>
		<description>You can very easily change all uppercase to text to lowercase - a simple PHP function exists for that.
strtolower().
Combine that with the replaceUnsafeWords(), and you&#039;ve got the uppercase bypass sorted.

As for the style=&quot;expression()&quot; attribute, wouldn&#039;t it be easy to simply add that into an array and strip anything hinting towards that?

You don&#039;t always have to go overboard and have 1,000,000 megabytes of security to do a few simple tasks that most existing PHP functions can handle - there&#039;s nothing wrong with keeps things *relatively* simple ;)</description>
		<content:encoded><![CDATA[<p>You can very easily change all uppercase to text to lowercase &#8211; a simple PHP function exists for that.<br />
strtolower().<br />
Combine that with the replaceUnsafeWords(), and you&#8217;ve got the uppercase bypass sorted.</p>
<p>As for the style=&#8221;expression()&#8221; attribute, wouldn&#8217;t it be easy to simply add that into an array and strip anything hinting towards that?</p>
<p>You don&#8217;t always have to go overboard and have 1,000,000 megabytes of security to do a few simple tasks that most existing PHP functions can handle &#8211; there&#8217;s nothing wrong with keeps things *relatively* simple <img src='http://net.tutsplus.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!--
This site's performance optimized by W3 Total Cache:

W3 Total Cache improves the user experience of your blog by caching
frequent operations, reducing the weight of various files and providing
transparent content delivery network integration.

Learn more about our WordPress Plugins: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/7 queries in 0.005 seconds using memcached
Content Delivery Network via 

Served from: psdtutsplus.com @ 2009-11-21 11:13:35 -->