<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Owning Rails 2.0 Cookies at OWASP</title>
	<atom:link href="http://blog.phishme.com/2007/11/owning-rails-20-cookies-at-owasp/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.phishme.com/2007/11/owning-rails-20-cookies-at-owasp/</link>
	<description>Internet Security Professionals comment on innovative phishing ploys, social engineering techniques, and the latest hacks. Bashing or bowing to the latest and greatest news in the security community. Keep up to speed with what phishers, hackers, and spammers are doing or just listen in on the latest geek rants. PhishMe is your one stop blog for the latest in anti-phishing and security news.</description>
	<lastBuildDate>Mon, 15 Mar 2010 18:32:47 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: b3nn</title>
		<link>http://blog.phishme.com/2007/11/owning-rails-20-cookies-at-owasp/comment-page-1/#comment-69</link>
		<dc:creator>b3nn</dc:creator>
		<pubDate>Wed, 21 Nov 2007 05:46:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phishme.com/2007/11/owning-rails-20-cookies-at-owasp/#comment-69</guid>
		<description>Sorry, updated the link for “cookie_store.rb” which did take you to an older version of the file. Brute forcing the HMAC is still possible. I&#039;m sure there are cases where this type of session storage would make sense, but from a security stand point, it makes me nervous that this will be the default storage option.</description>
		<content:encoded><![CDATA[<p>Sorry, updated the link for “cookie_store.rb” which did take you to an older version of the file. Brute forcing the HMAC is still possible. I&#8217;m sure there are cases where this type of session storage would make sense, but from a security stand point, it makes me nervous that this will be the default storage option.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy Kemper</title>
		<link>http://blog.phishme.com/2007/11/owning-rails-20-cookies-at-owasp/comment-page-1/#comment-67</link>
		<dc:creator>Jeremy Kemper</dc:creator>
		<pubDate>Tue, 20 Nov 2007 22:52:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phishme.com/2007/11/owning-rails-20-cookies-at-owasp/#comment-67</guid>
		<description>Please see my comment on Part II debunking the claim of brute-force attack.</description>
		<content:encoded><![CDATA[<p>Please see my comment on Part II debunking the claim of brute-force attack.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PhishMe &#187; Owning Rails 2.0 Cookies at OWASP: Part II</title>
		<link>http://blog.phishme.com/2007/11/owning-rails-20-cookies-at-owasp/comment-page-1/#comment-62</link>
		<dc:creator>PhishMe &#187; Owning Rails 2.0 Cookies at OWASP: Part II</dc:creator>
		<pubDate>Mon, 19 Nov 2007 19:05:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phishme.com/2007/11/owning-rails-20-cookies-at-owasp/#comment-62</guid>
		<description>[...] OWASP conference proved to be a great ground to bring up this topic of the proposed Rails 2.0 cookie storage [...]</description>
		<content:encoded><![CDATA[<p>[...] OWASP conference proved to be a great ground to bring up this topic of the proposed Rails 2.0 cookie storage [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: higB</title>
		<link>http://blog.phishme.com/2007/11/owning-rails-20-cookies-at-owasp/comment-page-1/#comment-61</link>
		<dc:creator>higB</dc:creator>
		<pubDate>Thu, 15 Nov 2007 15:58:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phishme.com/2007/11/owning-rails-20-cookies-at-owasp/#comment-61</guid>
		<description>Great find Corey! Maybe it&#039;s not too late for this to be reconsidered.</description>
		<content:encoded><![CDATA[<p>Great find Corey! Maybe it&#8217;s not too late for this to be reconsidered.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.217 seconds -->
