<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: OWASP Top 10 &#8211; Room for Improvement</title>
	<atom:link href="http://michaeldaw.org/news/news-250906-0/feed" rel="self" type="application/rss+xml" />
	<link>http://michaeldaw.org/news/news-250906-0</link>
	<description>Weekly humour</description>
	<lastBuildDate>Thu, 07 May 2009 20:09:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: maluc</title>
		<link>http://michaeldaw.org/news/news-250906-0/comment-page-1#comment-192</link>
		<dc:creator>maluc</dc:creator>
		<pubDate>Mon, 09 Oct 2006 09:31:06 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/projects/owasp-top-10-room-for-improvement/#comment-192</guid>
		<description>Late to the party again, but oh well:

Although you may argue that A2 is broad enough to cover it, CSRF certainly deserves a point of it&#039;s own.  It&#039;s one of the top three web app problems (behind SQL and XSS injections) and has very different mitigation techniques from any other bullet on the list..

If someone who&#039;s logged into their bank account goes to visit my website, with an image embedded pointing to http://bank.com/index.php?cmd=changepass&amp;newpass=WideOpen .. thats a wide open hole.

It&#039;s a fairly comprehensive list otherwise though .. and when limited to only 10 points, i find it more than adequate.

-maluc</description>
		<content:encoded><![CDATA[<p>Late to the party again, but oh well:</p>
<p>Although you may argue that A2 is broad enough to cover it, CSRF certainly deserves a point of it&#8217;s own.  It&#8217;s one of the top three web app problems (behind SQL and XSS injections) and has very different mitigation techniques from any other bullet on the list..</p>
<p>If someone who&#8217;s logged into their bank account goes to visit my website, with an image embedded pointing to <a href="http://bank.com/index.php?cmd=changepass&amp;newpass=WideOpen" rel="nofollow">http://bank.com/index.php?cmd=changepass&amp;newpass=WideOpen</a> .. thats a wide open hole.</p>
<p>It&#8217;s a fairly comprehensive list otherwise though .. and when limited to only 10 points, i find it more than adequate.</p>
<p>-maluc</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david.kierznowski</title>
		<link>http://michaeldaw.org/news/news-250906-0/comment-page-1#comment-71</link>
		<dc:creator>david.kierznowski</dc:creator>
		<pubDate>Mon, 25 Sep 2006 09:15:51 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/projects/owasp-top-10-room-for-improvement/#comment-71</guid>
		<description>Daniel,

Good to see you have a life :)
 
I can totally understand your point of view. Life&#039;s balancing act is always a challenge. However, the project states that it is &quot;sponsored&quot; by Aspect Security. I expect outdated material from open source projects, but I would have expected &quot;sponsored&quot; material to be a little better?</description>
		<content:encoded><![CDATA[<p>Daniel,</p>
<p>Good to see you have a life :)</p>
<p>I can totally understand your point of view. Life&#8217;s balancing act is always a challenge. However, the project states that it is &#8220;sponsored&#8221; by Aspect Security. I expect outdated material from open source projects, but I would have expected &#8220;sponsored&#8221; material to be a little better?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://michaeldaw.org/news/news-250906-0/comment-page-1#comment-67</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Mon, 25 Sep 2006 08:18:38 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/projects/owasp-top-10-room-for-improvement/#comment-67</guid>
		<description>David,

Your totally right and we are aware that the Top 10 needs updating. Behind the scenes we are doing just that. I am currently working on the ASP.NET Top 10 and others are updating it to reflect todays web applications and their insecurities.

As with many organisations that rely on people&#039;s free time to do the work, progress is slow. I have a day job and also a life. We would love to see all these companies adopting it offering some support for us to move forward and actually spend more time, but in reality that wont happen. 

The Top 10 does have a place in todays web enabled Internet and we are fully aware of the need to get it updated ASAP!


Daniel
OWASP</description>
		<content:encoded><![CDATA[<p>David,</p>
<p>Your totally right and we are aware that the Top 10 needs updating. Behind the scenes we are doing just that. I am currently working on the ASP.NET Top 10 and others are updating it to reflect todays web applications and their insecurities.</p>
<p>As with many organisations that rely on people&#8217;s free time to do the work, progress is slow. I have a day job and also a life. We would love to see all these companies adopting it offering some support for us to move forward and actually spend more time, but in reality that wont happen. </p>
<p>The Top 10 does have a place in todays web enabled Internet and we are fully aware of the need to get it updated ASAP!</p>
<p>Daniel<br />
OWASP</p>
]]></content:encoded>
	</item>
</channel>
</rss>
