<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>justSayBAD &#187; Security</title>
	<atom:link href="http://www.justsaybad.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.justsaybad.com</link>
	<description>I'm really easy to get along with once you people learn to worship me</description>
	<lastBuildDate>Fri, 02 Jul 2010 14:51:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Ban pe IP</title>
		<link>http://www.justsaybad.com/ban-pe-ip/</link>
		<comments>http://www.justsaybad.com/ban-pe-ip/#comments</comments>
		<pubDate>Mon, 27 Jul 2009 11:37:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ban]]></category>
		<category><![CDATA[securitate]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=20</guid>
		<description><![CDATA[Foloseam pana de curand o metoda pentru a bana un IP chiar daca foloseste proxy transparent. Solutia pe care am folosit-o era urmatoarea functie :

function getip() {
if (isset($_SERVER["HTTP_X_FORWARDED_FOR"]))
foreach (explode(",",$_SERVER["HTTP_X_FORWARDED_FOR"]) as $ip) {
if (baseMod::validip(trim($ip))) {
return $ip;
}
}
$ipsl=array("HTTP_CLIENT_IP","HTTP_X_FORWARDED","HTTP_FORWARDED_FOR","HTTP_FORWARDED","HTTP_X_FORWARDED");
foreach ($ipsl as $tp)
{
if (isset($_SERVER[$tp]))
if (baseMod::validip($_SERVER[$tp]))
return $_SERVER[$tp];
}return $_SERVER["REMOTE_ADDR"];
}

IP-ul returnat in treceam in baza de date ca fiind banat&#8230; problema aici este [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/ban-pe-ip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Si daca totusi uitam!</title>
		<link>http://www.justsaybad.com/si-daca-totusi-uitam/</link>
		<comments>http://www.justsaybad.com/si-daca-totusi-uitam/#comments</comments>
		<pubDate>Wed, 18 Mar 2009 18:44:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[securitate]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[tutorial]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=19</guid>
		<description><![CDATA[Scriam in postul trecut cat de important este sa verifici tot input-ul de la utilizatori. Este de ajuns doar unu sa fie sarit si site-ul poate fi vulnerabil.
Dar daca totusi gresim si uitam sa validam un input ? Ce putem face in cazul in care site-ul este vulnerabil la SQL Injection?
Pentru astfel de cazuri folosesc [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/si-daca-totusi-uitam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securitate? ce e aia ?</title>
		<link>http://www.justsaybad.com/securitate-ce-e-aia/</link>
		<comments>http://www.justsaybad.com/securitate-ce-e-aia/#comments</comments>
		<pubDate>Sun, 08 Mar 2009 20:02:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[securitate]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=18</guid>
		<description><![CDATA[Dupa o lunga perioada de timp am revenit cu un nou post.. si sper ca de acum in colo sa scriu mai des.
Astazi va voi vorbi cum sa incepeti sa va asigurati site-ul si ce sa face ti pentru o mai multa siguranta la codare.
Pentru inceput ar trebui sa fie stiut ca absolut tot ceea [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/securitate-ce-e-aia/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SQL injection site fancourier</title>
		<link>http://www.justsaybad.com/sql-injection-site-fancourier/</link>
		<comments>http://www.justsaybad.com/sql-injection-site-fancourier/#comments</comments>
		<pubDate>Fri, 19 Sep 2008 17:15:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[fancourier]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=15</guid>
		<description><![CDATA[Astazi la indemnul unui coleg&#8230; am gasit din &#8220;greseala&#8221; posibilitatea de a face un SQL injection la search-ul pt. AWB la site-ul celor de la fancourier.
Mi se pare anormal ca site-ul unei firme de curierat destul de mare(22,4 milioane de EURO dupa 9 luni) sa aiba o securitate asa de proasta. Acest exploit fiind unul [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/sql-injection-site-fancourier/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
