<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet title="XSL formatting" type="text/xsl" href="http://blog.gioria.org/feed/rss2/xslt" ?><rss version="2.0"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:wfw="http://wellformedweb.org/CommentAPI/"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Mais Encore</title>
  <link>http://blog.gioria.org/</link>
  <atom:link href="http://blog.gioria.org/feed/rss2" rel="self" type="application/rss+xml"/>
  <description></description>
  <language>fr</language>
  <pubDate>Wed, 21 Jul 2010 04:52:27 +0200</pubDate>
  <copyright></copyright>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Dotclear</generator>
  
    
  <item>
    <title>Infection en masse en cours de sites ISS/ASP.... - UPDATE - 11/06/2010</title>
    <link>http://blog.gioria.org/post/2010/06/08/Infection-en-masse-en-cours-de-sites-ISS/ASP....</link>
    <guid isPermaLink="false">urn:md5:e09d1640b5c0b60bb413631b99b758c6</guid>
    <pubDate>Fri, 11 Jun 2010 22:31:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>OWASP</category>
        <category>appsec</category><category>appsecfr</category><category>asp.net</category><category>iis</category><category>malware</category><category>securite</category><category>security</category><category>sql inejction</category><category>sucuri</category>    
    <description>    &lt;p&gt;&lt;a href=&quot;http://feedproxy.google.com/~r/SucuriSecurity/~3/DSBHipHPwDk/mass-infection-of-iisasp-sites-robint-us.html&quot;&gt;
Une infection en masse de sites sous IIS et ASP.NET&lt;/a&gt; est en train de
s'effectuer. Il s'avère que les sites pointent tous vers le site
http://ww.robint.us/u.js. Le problème n'est pas limité à des petits sites, mais
des gros, voir très gros sont atteints.&lt;/p&gt;
D'après &lt;a href=&quot;http://www.google.fr/search?q=http://ww.robint.us/u.js&quot;&gt;Google&lt;/a&gt;, plus d'un
million de sites est déja infecté....(FR, CA, US, ....)
&lt;div&gt;&lt;br /&gt;
&lt;div&gt;UPDATE du 11/06/2010: une autre infection SQL fait aussi pointer
sur &lt;span class=&quot;Apple-style-span&quot; style=&quot; line-height: 20px;&quot;&gt;http://2677.in/yahoo.js&lt;/span&gt;&lt;br /&gt;
 
&lt;p&gt;(Via &lt;a href=&quot;http://feedproxy.google.com/~r/SucuriSecurity/&quot;&gt;Sucuri&lt;/a&gt;.)&lt;/p&gt;
&lt;p&gt;Technorati Tags: &lt;a href=&quot;http://technorati.com/tag/appsec&quot; rel=&quot;tag&quot;&gt;appsec&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/owasp&quot; rel=&quot;tag&quot;&gt;owasp&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/securite&quot; rel=&quot;tag&quot;&gt;securite&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/security&quot; rel=&quot;tag&quot;&gt;security&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/appsecfr&quot; rel=&quot;tag&quot;&gt;appsecfr&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/06/08/Infection-en-masse-en-cours-de-sites-ISS/ASP....#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/06/08/Infection-en-masse-en-cours-de-sites-ISS/ASP....#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/525492</wfw:commentRss>
      </item>
    
  <item>
    <title>OWASP ModSecurity Core Rule Set</title>
    <link>http://blog.gioria.org/post/2010/06/07/OWASP-ModSecurity-Core-Rule-Set</link>
    <guid isPermaLink="false">urn:md5:c2f21429237889a5609ef637f8dc2978</guid>
    <pubDate>Mon, 07 Jun 2010 23:56:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Links</category>
        <category>appsec</category><category>links</category><category>modsecurity</category><category>owasp</category><category>securite</category><category>security</category><category>waf</category>    
    <description>    &lt;p&gt;&lt;a href=&quot;http://owasp.blogspot.com/2010/06/owasp-modsecurity-core-rule-set.html&quot;&gt;OWASP
ModSecurity Core Rule Set&lt;/a&gt;: &amp;quot;&lt;/p&gt;
&lt;p style=&quot;margin:0px;text-indent:0px&quot;&gt;Hello OWASP Leaders. I wanted to let you
all know that a new version of the OWASP ModSecurity Core Rule Set (CRS) is now
available (v2.0.7).&lt;/p&gt;
&lt;p&gt;(Via &lt;a href=&quot;http://blog.gioria.org/post/2010/06/07/&quot;&gt;Jeff Williams Blog&lt;/a&gt;.)&lt;/p&gt;

&lt;p&gt;Technorati Tags: &lt;a href=&quot;http://technorati.com/tag/owasp&quot; rel=&quot;tag&quot;&gt;owasp&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/securite&quot; rel=&quot;tag&quot;&gt;securite&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/security&quot; rel=&quot;tag&quot;&gt;security&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/modsecurity&quot; rel=&quot;tag&quot;&gt;modsecurity&lt;/a&gt;&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/06/07/OWASP-ModSecurity-Core-Rule-Set#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/06/07/OWASP-ModSecurity-Core-Rule-Set#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/525198</wfw:commentRss>
      </item>
    
  <item>
    <title>AppSec DC</title>
    <link>http://blog.gioria.org/post/2010/06/04/AppSec-DC</link>
    <guid isPermaLink="false">urn:md5:611cae98528502b8a3be7980afc9f1f0</guid>
    <pubDate>Fri, 04 Jun 2010 23:17:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Links</category>
        <category>appsec</category><category>conferences</category><category>owasp</category>    
    <description>    &lt;p&gt;&lt;a href=&quot;http://owasp.blogspot.com/2010/06/appsec-dc.html&quot;&gt;AppSec DC&lt;/a&gt;:
&amp;quot;&lt;/p&gt;
&lt;div&gt;Colleagues,&lt;br /&gt;
&lt;p&gt;Building on the success of AppSec DC 2009, OWASP is pleased to announce the
OWASP AppSecDC 2010 conference held at the Walter E. Washington Convention
Center on November 8th through 11th 2010. Plenary sessions will be on November
10th and 11th preceded by Web Application Security Training on November 8th and
9th.&lt;br /&gt;&lt;/p&gt;
We are seeking presentations on the following topics:&lt;br /&gt;&lt;/div&gt;
- OWASP Tools and Projects&lt;br /&gt;
- Cloud Application Security&lt;br /&gt;
- Government Approaches to Application Security&lt;br /&gt;
- Application Security Case Studies&lt;br /&gt;
- Application Security and Business Risks&lt;br /&gt;
- Metrics for Application Security&lt;br /&gt;
- Web Services Security&lt;br /&gt;
- Source Code Review&lt;br /&gt;
- Web Application Security Testing&lt;br /&gt;
- Secure Coding Practices&lt;br /&gt;
- Privacy Concerns&lt;br /&gt;
- Vulnerabilities/Exploits in the Web App World&lt;br /&gt;
- Defense &amp;amp; Countermeasures in the Web App World&lt;br /&gt;
- Other web application security topics&lt;br /&gt;
&lt;br /&gt;
Submit papers to &lt;a href=&quot;http://www.easychair.org/conferences/?conf=appsecdc2010&quot; title=&quot;http://www.easychair.org/conferences/?conf=appsecdc2010&quot;&gt;http://www.easychair.org/conferences/?conf=appsecdc2010&lt;/a&gt;.
Submission deadline is July 31st 2010. Inquires can be made to &lt;a href=&quot;mailto:cfp@appsecdc.org&quot; title=&quot;cfp@appsecdc.org&quot;&gt;cfp@appsecdc.org&lt;/a&gt;.&lt;br /&gt;
Additional information can be found in the FAQ. You will have to sign up for an
EasyChair account at &lt;a href=&quot;https://www.easychair.org/account/signup.cgi&quot; title=&quot;https://www.easychair.org/account/signup.cgi?iid=23866&quot;&gt;https://www.easychair.org/account/signup.cgi&lt;/a&gt;.&lt;br /&gt;

&lt;br /&gt;
Conference Website: &lt;a href=&quot;https://www.owasp.org/index.php/OWASP_AppSec_DC_2010&quot; title=&quot;https://www.owasp.org/index.php/OWASP_AppSec_DC_2010&quot;&gt;https://www.owasp.org/index.php/OWASP_AppSec_DC_2010&lt;/a&gt;&lt;br /&gt;

FAQ: &lt;a href=&quot;https://www.owasp.org/index.php/OWASP_AppSec_DC_2010_-_FAQ&quot; title=&quot;https://www.owasp.org/index.php/OWASP_AppSec_DC_2010_-_FAQ&quot;&gt;https://www.owasp.org/index.php/OWASP_AppSec_DC_2010_-_FAQ&lt;/a&gt;&lt;br /&gt;

&lt;br /&gt;
Please forward to all interested practitioners and colleagues.&lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
The AppSec DC Program Committee
&lt;div&gt;&lt;img width=&quot;1&quot; height=&quot;1&quot; src=&quot;https://blogger.googleusercontent.com/tracker/3544150258492345305-745556785455667171?l=owasp.blogspot.com&quot; alt=&quot;&quot; /&gt;&lt;/div&gt;
&amp;quot;
&lt;p&gt;(Via &lt;a href=&quot;http://blog.gioria.org/post/2010/06/04/&quot;&gt;Jeff Williams Feed&lt;/a&gt;.)&lt;/p&gt;

&lt;p&gt;Technorati Tags: &lt;a href=&quot;http://technorati.com/tag/OWASP&quot; rel=&quot;tag&quot;&gt;OWASP&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/Security&quot; rel=&quot;tag&quot;&gt;Security&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/appsec&quot; rel=&quot;tag&quot;&gt;appsec&lt;/a&gt;&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/06/04/AppSec-DC#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/06/04/AppSec-DC#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/524552</wfw:commentRss>
      </item>
    
  <item>
    <title>OWASP Ireland 2010</title>
    <link>http://blog.gioria.org/post/2010/06/04/OWASP-Ireland-2010</link>
    <guid isPermaLink="false">urn:md5:f62a0e94f8a802110ea10e7061789405</guid>
    <pubDate>Fri, 04 Jun 2010 23:16:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
            
    <description>    &lt;p&gt;&lt;a href=&quot;http://owasp.blogspot.com/2010/06/owasp-ireland-2010.html&quot;&gt;OWASP
Ireland 2010&lt;/a&gt;: &amp;quot;&lt;/p&gt;
&lt;div&gt;Hello everyone,&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;The OWASP Ireland 2010 agenda is shaping up well and registration is to
open soon.&lt;/div&gt;
&lt;div&gt;We are still happy to accept presentation proposals until early
August.&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;The sponsorship deck for OWASP Ireland is available here &lt;a href=&quot;http://www.owasp.org/images/c/c8/OWASP_sponsorship_Master.pdf&quot;&gt;http://www.owasp.org/images/c/c8/OWASP_sponsorship_Master.pdf&lt;/a&gt;
and is limited in places.&lt;/div&gt;
&lt;div&gt;Training shall be announced very soon also consisting of one days training
on the 16th of September.&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;Our Key Note speakers are legendary again this year:&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;Professor Fred Piper (Royal Holloway University)&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;
&lt;p style=&quot;margin:0cm 0cm 0pt;text-align:justify&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;span style=&quot;font-size:100%&quot;&gt;&lt;span style=&quot;font-size:85%&quot;&gt;&lt;strong&gt;Keynote: 'The changing face of
cryptography'&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;margin:0cm 0cm 0pt;text-align:justify&quot;&gt;&lt;/p&gt;
&lt;p style=&quot;margin:0cm 0cm 0pt;text-align:justify&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;span style=&quot;font-size:100%&quot;&gt;&lt;span style=&quot;font-size:85%&quot;&gt;Fred Piper was
appointed Professor of Mathematics at the University of London in 1975 and has
worked in information security since 1979. In 1985, he formed a company, Codes
&amp;amp; Ciphers Ltd, which offers consultancy advice in all aspects of
information security. He has acted as a consultant to over 80 companies
including a number of financial institutions and major industrial companies in
the UK, Europe, Asia, Australia, South Africa and the USA. The consultancy work
has been varied and has included algorithm design and analysis, work on EFTPOS
and ATM networks, data systems, security audits, risk analysis and the
formulation of security policies. He has lectured worldwide on information
security, both academically and commercially, has published more than 100
papers and is joint author of Cipher Systems (1982), one of the first books to
be published on the subject of protection of communications, Secure Speech
Communications (1985), Digital Signatures - Security &amp;amp; Controls (1999) and
Cryptography: A Very Short Introduction (2002).&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;margin:0cm 0cm 0pt;text-align:justify&quot;&gt;&lt;/p&gt;
&lt;p style=&quot;margin:0cm 0cm 0pt;text-align:justify&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;margin:0cm 0cm 0pt;text-align:justify&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;strong&gt;Damien Gordo&lt;/strong&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;strong&gt;n Phd (Dublin institute of Technology)&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;margin:0cm 0cm 0pt;text-align:justify&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;strong&gt;Keynote: 'Hackers and Hollywood: The Implications of the
Popular Media Representation of Computer Hacking'&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;margin:0cm 0cm 0pt;text-align:justify&quot;&gt;&lt;/p&gt;
&lt;p style=&quot;margin:0cm 0cm 0pt;text-align:justify&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Damian Gordon is a lecturer with the School of Computing at the Dublin
Institute of Technology and is Programme Co-ordinator for the School's Masters
in Computing (Assistive Technology). He was primary researcher on two EU funded
projects whose particular focus was looking at issues associated with
technoacceptance - the ILT and the E4 projects - and was Educational Advisor
for the Ireland-China EMERSION project. His research interests include
Differentiated Instruction, Computer Security, Technostress, ICT and Special
Needs, Virtual Learning Environments, Image reconstruction from specular
reflections, and Lateral Thinking Techniques.&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;br /&gt;
--&lt;br /&gt;
Eoin Keary&lt;br /&gt;
OWASP Global Board Member&lt;br /&gt;
OWASP Code Review Guide Lead Author
&lt;div&gt;&lt;img width=&quot;1&quot; height=&quot;1&quot; src=&quot;https://blogger.googleusercontent.com/tracker/3544150258492345305-6653626236434211127?l=owasp.blogspot.com&quot; alt=&quot;&quot; /&gt;&lt;/div&gt;
&amp;quot;
&lt;p&gt;(Via &lt;a href=&quot;http://blog.gioria.org/post/2010/06/04/&quot;&gt;Jeff Williams Feeds&lt;/a&gt;.)&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/06/04/OWASP-Ireland-2010#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/06/04/OWASP-Ireland-2010#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/524551</wfw:commentRss>
      </item>
    
  <item>
    <title>Inline Detection of Evil JavaScript</title>
    <link>http://blog.gioria.org/post/2010/06/02/Inline-Detection-of-Evil-JavaScript</link>
    <guid isPermaLink="false">urn:md5:959939f815f1c2c6be0edfccd1eeb7ad</guid>
    <pubDate>Wed, 02 Jun 2010 23:02:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Links</category>
        <category>appsec</category><category>links</category><category>research</category><category>securite</category><category>security</category>    
    <description>    &lt;p&gt;&lt;a href=&quot;http://feedproxy.google.com/~r/zscaler/research/~3/MocS8XJnzSo/inline-detection-of-evil-javascript.html&quot;&gt;
Inline Detection of Evil JavaScript&lt;/a&gt;: &amp;quot;&lt;a href=&quot;http://1.bp.blogspot.com/_TIeEMQaNHSw/S-m4c2qq_3I/AAAAAAAAANc/g9E211RZgOY/s1600/Screen+shot+2010-05-11+at+4.05.32+PM.png&quot;&gt;&lt;img style=&quot;float:right;margin:0pt 0pt 10px 10px;width:133px;height:200px&quot; src=&quot;http://1.bp.blogspot.com/_TIeEMQaNHSw/S-m4c2qq_3I/AAAAAAAAANc/g9E211RZgOY/s200/Screen+shot+2010-05-11+at+4.05.32+PM.png&quot; alt=&quot;&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;Exploit kits are a much more common threat on the web
than they used to be. In order to evade detection, the kits frequently contain
logic to obfuscate, or hide, the meaning behind the content that they serve to
the victim. Additionally, with each visit to the exploit page, the obfuscation
techniques will differ slightly so that static, content signatures will be
unable to detect the threat. Other threats contain obfuscated JavaScript (JS)
which sets up the page to exploit a vulnerability and launch a payload (for
example, 'spraying' the heap with shellcode). Still other threats inject
obfuscated JS into legitimate sites, which after decoding embeds a hidden
(0-pixel) IFrame to malicious content. As we have seen in the past, the JS
encodings vary greatly with each incident, and many instances are encoded
multiple times and may contain non-standard JS (reference past blog posts, such
as &lt;a href=&quot;http://research.zscaler.com/2010/05/more-and-more-obfuscation-being-used-in.html&quot;&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;(Via &lt;a href=&quot;http://blog.gioria.org/post/2010/06/02/&quot;&gt;Zscaler Research blog&lt;/a&gt;.)&lt;/p&gt;

&lt;p&gt;Technorati Tags: &lt;a href=&quot;http://technorati.com/tag/security&quot; rel=&quot;tag&quot;&gt;security&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/securite&quot; rel=&quot;tag&quot;&gt;securite&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/owasp&quot; rel=&quot;tag&quot;&gt;owasp&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/zscaler&quot; rel=&quot;tag&quot;&gt;zscaler&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/appsec&quot; rel=&quot;tag&quot;&gt;appsec&lt;/a&gt;&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/06/02/Inline-Detection-of-Evil-JavaScript#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/06/02/Inline-Detection-of-Evil-JavaScript#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/524064</wfw:commentRss>
      </item>
    
  <item>
    <title>Now available: Microsoft SDL version 5</title>
    <link>http://blog.gioria.org/post/2010/05/31/Now-available%3A-Microsoft-SDL-version-5</link>
    <guid isPermaLink="false">urn:md5:b01959a728e2d0e0412e363e58c7140d</guid>
    <pubDate>Mon, 31 May 2010 08:47:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Links</category>
        <category>appsec</category><category>links</category><category>microsoft</category><category>sdl</category>    
    <description>    &lt;p&gt;&lt;a href=&quot;http://blogs.msdn.com/b/sdl/archive/2010/04/01/now-available-sdl-process-guidance-version-5.aspx&quot;&gt;
Now available: Microsoft SDL version 5&lt;/a&gt;: &amp;quot;&lt;/p&gt;
&lt;p style=&quot;margin:0in 0in 10pt&quot;&gt;&lt;span&gt;&lt;span&gt;Jeremy Dallman here to announce that
we are releasing the latest version of the &lt;a href=&quot;http://go.microsoft.com/?linkid=9724944&quot;&gt;&lt;span style=&quot;line-height:115%&quot;&gt;Microsoft Security Development Lifecycle process guidance –
Version 5 (SDLv5)&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;(Via &lt;a href=&quot;http://blogs.msdn.com/b/sdl/&quot;&gt;Microsoft SDL blog&lt;/a&gt;.)&lt;/p&gt;
&lt;p&gt;Technorati Tags: &lt;a href=&quot;http://technorati.com/tag/Security&quot; rel=&quot;tag&quot;&gt;Security&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/SDL&quot; rel=&quot;tag&quot;&gt;SDL&lt;/a&gt;,
&lt;a href=&quot;http://technorati.com/tag/links&quot; rel=&quot;tag&quot;&gt;links&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/microsoft&quot; rel=&quot;tag&quot;&gt;microsoft&lt;/a&gt;&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/05/31/Now-available%3A-Microsoft-SDL-version-5#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/05/31/Now-available%3A-Microsoft-SDL-version-5#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/523108</wfw:commentRss>
      </item>
    
  <item>
    <title>OWASP AppSec Research 2010</title>
    <link>http://blog.gioria.org/post/2010/05/30/OWASP-AppSec-Research-2010</link>
    <guid isPermaLink="false">urn:md5:f5a8686b5003ab33d42cffb00c621211</guid>
    <pubDate>Sun, 30 May 2010 22:48:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Links</category>
        <category>appsec</category><category>appsec2010</category><category>links</category><category>owasp</category>    
    <description>    &lt;p&gt;&lt;a href=&quot;http://www.owasp.org/index.php/OWASP_AppSec_Research_2010_-_Stockholm,_Sweden&quot;&gt;
OWASP AppSec Research 2010&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
It's time to create a digital storm and invite the world to &lt;a href=&quot;http://www.owasp.org/index.php/OWASP_AppSec_Research_2010_-_Stockholm,_Sweden&quot;&gt;
OWASP AppSec Research 2010&lt;/a&gt; this summer. We have a fabulous program and will
celebrate with a gala dinner at Stockholm City Hall
(http://international.stockholm.se/Tourism-and-history/The-Famous-City-Hall/Events-and-receptions/Rent-the-Halls).&lt;/p&gt;
&lt;p&gt;(Via &lt;a href=&quot;http://owasp.blogspot.com&quot;&gt;OWASP Blog&lt;/a&gt;.)&lt;/p&gt;

&lt;p&gt;Technorati Tags: &lt;a href=&quot;http://technorati.com/tag/OWASP&quot; rel=&quot;tag&quot;&gt;OWASP&lt;/a&gt;, &lt;a href=&quot;http://technorati.com/tag/Security&quot; rel=&quot;tag&quot;&gt;Security&lt;/a&gt;&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/05/30/OWASP-AppSec-Research-2010#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/05/30/OWASP-AppSec-Research-2010#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/523040</wfw:commentRss>
      </item>
    
  <item>
    <title>The OWASP Top Ten and ESAPI – Part 6 – Cross Site Request Forgery (CSRF)</title>
    <link>http://blog.gioria.org/post/2010/05/30/The-OWASP-Top-Ten-and-ESAPI-%E2%80%93-Part-6-%E2%80%93-Cross-Site-Request-Forgery-%28CSRF%29</link>
    <guid isPermaLink="false">urn:md5:8a6280a03157a1877ed58bb38d188000</guid>
    <pubDate>Sun, 30 May 2010 22:46:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Links</category>
        <category>esapi</category><category>links</category><category>owasp</category>    
    <description>    &lt;p&gt;&lt;a href=&quot;http://feedproxy.google.com/~r/jtmelton/~3/UFvGzsYPR-A/&quot;&gt;The OWASP
Top Ten and ESAPI – Part 6 – Cross Site Request Forgery (CSRF)&lt;/a&gt;:
&amp;quot;&lt;img style=&quot;float:left;margin-right:10px;border:none&quot; src=&quot;http://www.gravatar.com/avatar.php?gravatar_id=1c9918a7a9b1394ec9f25a3d30b5b9df&amp;amp;default=http://use.perl.org/images/pix.gif&quot; alt=&quot;No Gravatar&quot; width=&quot;40&quot; height=&quot;40/&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This article will describe how to protect your J2EE application from Cross
Site Request Forgery (CSRF/XSRF) attacks using ESAPI. As with all of the detail
articles in this series, if you need a refresher on OWASP or ESAPI, please see
the intro article &lt;a href=&quot;http://www.jtmelton.com/2009/01/03/the-owasp-top-ten-and-esapi/&quot;&gt;The OWASP Top
Ten and ESAPI&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(Via &lt;a href=&quot;http://www.jtmelton.com/&quot;&gt;John Melton Blog&lt;/a&gt;.)&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/05/30/The-OWASP-Top-Ten-and-ESAPI-%E2%80%93-Part-6-%E2%80%93-Cross-Site-Request-Forgery-%28CSRF%29#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/05/30/The-OWASP-Top-Ten-and-ESAPI-%E2%80%93-Part-6-%E2%80%93-Cross-Site-Request-Forgery-%28CSRF%29#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/523039</wfw:commentRss>
      </item>
    
  <item>
    <title>Announcing the MSF-Agile+SDL Process Template for TFS 2010 - The Security Development Lifecycle - Site Home - MSDN Blogs</title>
    <link>http://blog.gioria.org/post/2010/05/30/Announcing-the-MSF-AgileSDL-Process-Template-for-TFS-2010-The-Security-Development-Lifecycle-Site-Home-MSDN-Blogs</link>
    <guid isPermaLink="false">urn:md5:f5fa150920c55d28052f2f1f0b5d1e24</guid>
    <pubDate>Sun, 30 May 2010 19:53:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Links</category>
        <category>appsec</category><category>links</category><category>microsoft</category><category>sdl</category>    
    <description>    &lt;p&gt;&lt;a href=&quot;http://blogs.msdn.com/b/sdl/archive/2010/05/27/announcing-the-msf-agile-sdl-process-template-for-tfs-2010.aspx&quot;&gt;
Announcing the MSF-Agile+SDL Process Template for TFS 2010 - The Security
Development Lifecycle - Site Home - MSDN Blogs&lt;/a&gt;: &amp;quot;&amp;quot;&lt;/p&gt;
&lt;p&gt;(Via &lt;a href=&quot;http://blog.gioria.org/post/2010/05/30/&quot;&gt;http://blogs.msdn.com/b/sdl/&lt;/a&gt;Microsoft SDL Blog.)&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/05/30/Announcing-the-MSF-AgileSDL-Process-Template-for-TFS-2010-The-Security-Development-Lifecycle-Site-Home-MSDN-Blogs#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/05/30/Announcing-the-MSF-AgileSDL-Process-Template-for-TFS-2010-The-Security-Development-Lifecycle-Site-Home-MSDN-Blogs#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/522991</wfw:commentRss>
      </item>
    
  <item>
    <title>Static Analysis Worst Practices</title>
    <link>http://blog.gioria.org/post/2010/05/30/Enterprise-Architecture%3A-From-Incite-comes-Insight...%3A-Static-Analysis-Worst-Practices</link>
    <guid isPermaLink="false">urn:md5:97a561172be741d7d4de0b6114bcad9c</guid>
    <pubDate>Sun, 30 May 2010 17:09:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Links</category>
        <category>code review</category><category>links</category><category>static analysis</category>    
    <description>    &lt;p&gt;&lt;a href=&quot;http://duckdown.blogspot.com/2010/05/static-analysis-worst-practices.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+mcgovern+%28Enterprise+Architecture%3A+From+Incite+comes+Insight...%29&quot;&gt;
Static Analysis Worst Practices&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;(Via &lt;a href=&quot;http://duckdown.blogspot.com/2010/05/static-analysis-worst-practices.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+mcgovern+%28Enterprise+Architecture%3A+From+Incite+comes+Insight...%29&quot;&gt;
&lt;/a&gt;James McGovern Blog.)&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/05/30/Enterprise-Architecture%3A-From-Incite-comes-Insight...%3A-Static-Analysis-Worst-Practices#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/05/30/Enterprise-Architecture%3A-From-Incite-comes-Insight...%3A-Static-Analysis-Worst-Practices#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/522956</wfw:commentRss>
      </item>
    
  <item>
    <title>Nouvelle catégorie</title>
    <link>http://blog.gioria.org/post/2010/05/30/Nouvelle-cat%C3%A9gorie</link>
    <guid isPermaLink="false">urn:md5:66a22bc1059af78d86703c1bee50713b</guid>
    <pubDate>Sun, 30 May 2010 16:40:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Links</category>
        <category>links</category>    
    <description>    Ajout d'une nouvelle catégorie pour vous faire partager mes bons (et moins bons
? ) liens sur la sécurité applicative.&lt;br /&gt;
Un petit équivalent a mes RT &lt;a href=&quot;http://www.twitter.com/spoint&quot;&gt;twitter&lt;/a&gt;, meme si certains liens ne sont pas
forcément sur twitter</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/05/30/Nouvelle-cat%C3%A9gorie#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/05/30/Nouvelle-cat%C3%A9gorie#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/522943</wfw:commentRss>
      </item>
    
  <item>
    <title>Denim Group, Ltd.: OWASP San Antonio Slides for OpenSAMM Presentation Online</title>
    <link>http://blog.gioria.org/post/2010/05/30/Denim-Group%2C-Ltd.%3A-OWASP-San-Antonio-Slides-for-OpenSAMM-Presentation-Online</link>
    <guid isPermaLink="false">urn:md5:3133fb0d49963349330c1e6b0bcf250d</guid>
    <pubDate>Sun, 30 May 2010 16:30:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Links</category>
        <category>links</category><category>owasp</category><category>samm</category>    
    <description>    &lt;p&gt;&lt;a href=&quot;http://blog.denimgroup.com/denim_group/2010/05/owasp-san-antonio-slides-for-opensamm-presentation-online.html&quot;&gt;
Denim Group, Ltd.: OWASP San Antonio Slides for OpenSAMM Presentation
Online&lt;/a&gt;: &amp;quot;Denim Group, Ltd.&lt;/p&gt;
&lt;p&gt;(Via &lt;a href=&quot;http://blog.gioria.org/post/2010/05/30/&quot;&gt;&lt;/a&gt;.)&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/05/30/Denim-Group%2C-Ltd.%3A-OWASP-San-Antonio-Slides-for-OpenSAMM-Presentation-Online#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/05/30/Denim-Group%2C-Ltd.%3A-OWASP-San-Antonio-Slides-for-OpenSAMM-Presentation-Online#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/522942</wfw:commentRss>
      </item>
    
  <item>
    <title>Metasploit Class Videos  (Hacking Illustrated Series InfoSec Tutorial Videos)</title>
    <link>http://blog.gioria.org/post/2010/05/30/Metasploit-Class-Videos%C2%A0-%28Hacking-Illustrated-Series-InfoSec-Tutorial-Videos%29</link>
    <guid isPermaLink="false">urn:md5:eb820ed940f0a5a1f533d49b7d0bdf40</guid>
    <pubDate>Sun, 30 May 2010 16:00:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Links</category>
        <category>learning</category><category>links</category><category>metasploit</category><category>securite</category>    
    <description>    &lt;p&gt;&lt;a href=&quot;http://www.irongeek.com/i.php?page=videos/metasploit-class&quot;&gt;Metasploit Class
Videos  (Hacking Illustrated Series InfoSec Tutorial Videos)&lt;/a&gt;: &amp;quot;&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/05/30/Metasploit-Class-Videos%C2%A0-%28Hacking-Illustrated-Series-InfoSec-Tutorial-Videos%29#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/05/30/Metasploit-Class-Videos%C2%A0-%28Hacking-Illustrated-Series-InfoSec-Tutorial-Videos%29#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/522932</wfw:commentRss>
      </item>
    
  <item>
    <title>Recensement.....</title>
    <link>http://blog.gioria.org/post/2010/05/30/Recensement.....</link>
    <guid isPermaLink="false">urn:md5:38d33f1a478af1c712ad20e6f07836b0</guid>
    <pubDate>Sun, 30 May 2010 15:22:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>owasp</category><category>passwd</category><category>securite</category>    
    <description>    Alors, ca commence a faire beaucoup de site qui vous renvoie votre mot de
passe....&lt;br /&gt;
Alors si on faisait une petite liste(non représentative, mais ca aidera....) :
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;http://www.sarenza.com&quot;&gt;Sarenza.com&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.grandvoyageur-sncf.com/&quot;&gt;SNCF - Grand Voyageur&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;.....&lt;/li&gt;
&lt;/ul&gt;
Pour rappel le renvoi des mots de passes est considéré comme un failed par les
bonnes pratiques de dév.... S.</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/05/30/Recensement.....#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/05/30/Recensement.....#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/522926</wfw:commentRss>
      </item>
    
  <item>
    <title>Une semaine avec Android....</title>
    <link>http://blog.gioria.org/post/2010/05/16/Une-semaine-avec-Android....</link>
    <guid isPermaLink="false">urn:md5:23c1dc5c334ea1952b032ecc6133ab89</guid>
    <pubDate>Sun, 16 May 2010 23:35:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Divers</category>
        <category>android</category><category>google</category><category>mobile</category>    
    <description>    Voila, j'ai enfin laché &lt;a href=&quot;http://www.apple.com/iphone&quot;&gt;l'Iphone&lt;/a&gt; et
je suis passé lundi dernier sur un HTC Legend (le Desire était pas disponible
avant plusieurs semaines a priori....). J'ai souvent été un early-adopter des
technologie mail/mobile (mon premier était un HP sous Windows Mobile en
2002)...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Et les raisons qui m'ont poussé à quitter l'IPhone sont multiples (pourtant je
reste sur du MacOSX car c'est réellement un super OS/Matériel), en voici
quelques une :&lt;br /&gt;
- Problème avec le forfait Data : &lt;a href=&quot;http://www.sfr.fr&quot;&gt;SFR&lt;/a&gt; a décidé
du jour au lendemain de &amp;quot;bloquer&amp;quot; les VPN&lt;br /&gt;
si l'on ne souscrivait pas une offre spécifique illimitée data (limitée à 1Go
quand même....). Donc re-racker pour avoir un peu de sécurité sur ses
connexions pro&lt;br /&gt;
- Problème avec l'autonomie : pas assez pour mon usage - Problème du client de
mail : faut dire ce qu'y est, il est quand meme très pourri le client
Apple&lt;br /&gt;
- Pas de tools, (enfin tres peu) de type : OpenVPN, VNC, Shell etc....En tout
ca si on ne le jailbreak pas....&lt;br /&gt;
&lt;br /&gt;
Bref, byebye Steve on my mobile, welcome Larry &amp;amp;&amp;amp; Sergey.&lt;br /&gt;
Alors mes premières impressions sont plutôt bien favorables :&lt;br /&gt;
- Autonomie correcte : plus d'une journée en utilisation normale&lt;br /&gt;
- Applications OK: pour l'instant je n'ai pas trouvé les applications que je
n'utilisais pas sur l'IPhone et qui me feraient défaut.&lt;br /&gt;
-Mail : Ben c'est gmail le client...donc rien a dire de plus, il me convient.
En plus ya une application PGP....&lt;br /&gt;
- Photos : nickel, rien a dire - Audio/Radio : pas encore rééllement tester,
mais ca le fera normalement cette semaine&lt;br /&gt;
-Stabilité : pas de plantage, pas de reboot, mais un peu quand meme de kill de
taches parfois pour que ca fonctionne un peu &amp;quot;mieux&amp;quot;.&lt;br /&gt;
Donc je suis plutôt impressionné et assez content actuellement. Bref, a suivre</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/05/16/Une-semaine-avec-Android....#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/05/16/Une-semaine-avec-Android....#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/517358</wfw:commentRss>
      </item>
    
  <item>
    <title>Pub de mauvais gout ?</title>
    <link>http://blog.gioria.org/post/2010/05/05/Pub-de-mauvais-gout</link>
    <guid isPermaLink="false">urn:md5:c3cb58e93e1c5d9ee31fe51da79f7b27</guid>
    <pubDate>Wed, 05 May 2010 21:41:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Divers</category>
        <category>divers</category><category>linkedin</category><category>network</category>    
    <description>    Franchement.... Est-ce que la, sur cette image
&lt;div style=&quot;text-align:center;&quot;&gt;&lt;img src=&quot;http://blog.gioria.org/public/pole_emploi.png&quot; alt=&quot;pole emploi.png&quot; border=&quot;0&quot; width=&quot;925&quot; height=&quot;117&quot; /&gt;&lt;/div&gt;
ya pas un truc qui choque ?</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/05/05/Pub-de-mauvais-gout#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/05/05/Pub-de-mauvais-gout#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/514088</wfw:commentRss>
      </item>
    
  <item>
    <title>Sortie de la nouvelle version du TOP10 OWASP</title>
    <link>http://blog.gioria.org/post/2010/04/19/Sortie-de-la-nouvelle-version-du-TOP10-OWASP</link>
    <guid isPermaLink="false">urn:md5:c2b9e4e5331da73ef316f0708af82ef4</guid>
    <pubDate>Mon, 19 Apr 2010 10:28:00 +0200</pubDate>
    <dc:creator>S.</dc:creator>
        <category>OWASP</category>
        <category>owasp</category><category>securite</category><category>security</category><category>top10</category>    
    <description>&lt;p&gt;L'OWASP Top10 2010 est ENFIN sorti !&lt;/p&gt;    &lt;p&gt;Nouvelle version, nouvelle approche, réécriture complète et bientôt nouvelle
traduction.&lt;/p&gt;
&lt;p&gt;La nouvelle version est disponible comme d'habitude sur le WIKI :
http://www.owasp.org/index.php/Top10&lt;/p&gt;
&lt;p&gt;A bientot, pour une première analyse&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/04/19/Sortie-de-la-nouvelle-version-du-TOP10-OWASP#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/04/19/Sortie-de-la-nouvelle-version-du-TOP10-OWASP#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/510049</wfw:commentRss>
      </item>
    
  <item>
    <title>Appel a Contribution - Rencontres Mondiales du Logiciel Libres - Bordeaux 6-11 Juillet 2010</title>
    <link>http://blog.gioria.org/post/2010/03/18/Appel-a-Contribution-Rencontres-Mondiales-du-Logiciel-Libres-Bordeaux-6-11-Juillet-2010</link>
    <guid isPermaLink="false">urn:md5:48a2fe060ebfc8c6c33cb0919face56f</guid>
    <pubDate>Thu, 18 Mar 2010 11:35:00 +0100</pubDate>
    <dc:creator>S.</dc:creator>
            
    <description>&lt;p&gt;Le Chapitre Français de l'OWASP soutient les RMLL 2010 et participera a des
sessions techniques autour de la sécurité Web.&lt;/p&gt;    &lt;p&gt;Les Rencontres Mondiales du Logiciel Libre (RMLL) sont un cycle de
conférences autour du logiciel libre. Ces Rencontres sont annuelles, existent
depuis 2000 et se déroulent depuis 2003 dans une ville différente chaque année.
Elles sont gratuites et libres d’accès à tous. Les RMLL 2010 se dérouleront à
Bordeaux du 6 au 11 juillet.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;L'appel a Contribution/Conférences est ouvert jusqu'au 15/04/2010, n'hésitez
pas à soumettre quelque chose :&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;http://2010.rmll.info /Appel-a-conferences.html?lang=fr&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/03/18/Appel-a-Contribution-Rencontres-Mondiales-du-Logiciel-Libres-Bordeaux-6-11-Juillet-2010#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/03/18/Appel-a-Contribution-Rencontres-Mondiales-du-Logiciel-Libres-Bordeaux-6-11-Juillet-2010#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/500554</wfw:commentRss>
      </item>
    
  <item>
    <title>SNCF, on change de slogan et ca ira mieux...</title>
    <link>http://blog.gioria.org/post/2010/03/17/SNCF</link>
    <guid isPermaLink="false">urn:md5:31e6de53808c872dc2474bf5dfcfd969</guid>
    <pubDate>Wed, 17 Mar 2010 15:17:00 +0100</pubDate>
    <dc:creator>S.</dc:creator>
        <category>Sécurité</category>
        <category>failed</category><category>securite</category><category>sncf</category>    
    <description>    &lt;p&gt;Encore une fois la &lt;a href=&quot;http://www.lemonde.fr/societe/article/2010/03/17/les-coordonnees-de-millions-de-clients-de-la-sncf-disponibles-sur-le-net_1320321_3224.html&quot;&gt;
SNCF fait parler d'elle.&lt;/a&gt;..On va se demander si c'est pas juste une
opération de communication....&lt;br /&gt;
Déja hier, &lt;a href=&quot;http://www.itespresso.fr/explosion-dans-un-tgv-le-site-internet-de-la-sncf-deraille-34205.html&quot;&gt;
l'exercice&lt;/a&gt; a été &lt;a href=&quot;http://www.sncf.com/resources/fr_FR/press/kits/PR0001_20100316.pdf&quot;&gt;loupé&lt;/a&gt;....&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;Et dire que leur slogan est&lt;strong&gt; : « &lt;a href=&quot;http://fr.wikipedia.org/wiki/Groupe_SNCF&quot;&gt;des idées d'avanc&lt;/a&gt;e
»&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Maintenant on parle juste des données de tous les abonnés qui étaient dispos
par une faille....Et dire que ces gens dépensent des millions et ne sont pas
capable de &amp;quot;coder&amp;quot; proprement..... Je leur suggère de lire au minimum le
&lt;a href=&quot;http://www.owasp.org/index.php/Top10&quot;&gt;Top10 OWASP&lt;/a&gt;(même que si ils
le veulent je suis prêt a me déplacer pour leur présenter la
chose.....)&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Je me dis même qu'a priori ils ont des &lt;a href=&quot;http://www.slideshare.net/Eagle42/2010-0310web-applications-firewalls-v-08&quot;&gt;Web
Applications Firewalls&lt;/a&gt;, vu que c'est maintenant quasi-obligatoire dans
toute structure de cette taille...J'espère juste qu'ils ne les avaient pas mis
en place à ce moment la.....&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Bref, je leur souhaite une bonne lecture de ce que nous avons présenté à
&lt;a href=&quot;http://www.confoo.ca&quot;&gt;Confoo&lt;/a&gt; avec Antonio :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;http://www.slideshare.net/Eagle42/2010-0311sdlcv02&quot;&gt;SDLC simple et
concret&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.slideshare.net/starbuck3000/owasp-top10-2010-rc1&quot;&gt;OWASP
Top10&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.slideshare.net/starbuck3000/web-application-security-how-to-start&quot;&gt;Web
Application Security, where to start&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Enfin, c'est pas grave, ils vont encore nous augmenter le prix des billets
et des abonnements pour payer les embarras générés par ces petits problèmes de
&amp;quot;communication&amp;quot;.&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/03/17/SNCF#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/03/17/SNCF#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/500330</wfw:commentRss>
      </item>
    
  <item>
    <title>Busy...Busy....</title>
    <link>http://blog.gioria.org/post/2010/03/17/Busy...Busy....</link>
    <guid isPermaLink="false">urn:md5:e93b9dcd8206375c5e939bba534f2787</guid>
    <pubDate>Wed, 17 Mar 2010 14:48:00 +0100</pubDate>
    <dc:creator>S.</dc:creator>
        <category>OWASP</category>
        <category>owasp</category>    
    <description>    &lt;p&gt;My last updated come a long time ago. Sorry to miss my blog.&lt;br /&gt;
I think I must to setup a reminder every sunday for an article.&lt;br /&gt;
Well, &lt;a href=&quot;http://www.confoo.ca&quot;&gt;Confoo&lt;/a&gt; was great, we (me and &lt;a href=&quot;http://securecoding.ch/&quot;&gt;Antonio&lt;/a&gt;, &lt;a href=&quot;http://commedansdubeurre.ch/&quot;&gt;AF French Site&lt;/a&gt; ) was absolutely excited to
talk and to spend a small week in Montreal.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;We have upload our slides on slideshare&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;http://www.slideshare.net/Eagle42&quot;&gt;Me&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.slideshare.net/starbuck3000&quot;&gt;AF&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;So, Confoo was a great experience. We got Security track in a Developer
World ! Thanks &lt;a href=&quot;http://blog.gioria.org/post/2010/03/17/ph-il.ca&quot;&gt;Philippe&lt;/a&gt; for this great idea, and we hope
to see you in France/Geneva or Montreal soon !&lt;/p&gt;
&lt;p&gt;By the way, just check the update on the &lt;a href=&quot;http://www.owasp.org/index.php/Category:OWASP_Fuzzing_Code_Database#tab=Statements&quot;&gt;
OWASP Fuzzing Database&lt;/a&gt; :&lt;/p&gt;
&lt;p&gt;and OWASP &lt;a href=&quot;http://owasp.blogspot.com/2010/03/owasp-jbrofuzz-20-fuzzer-released.html&quot;&gt;Jbrofuzz&lt;/a&gt;
is released&lt;/p&gt;</description>
    
    
    
          <comments>http://blog.gioria.org/post/2010/03/17/Busy...Busy....#comment-form</comments>
      <wfw:comment>http://blog.gioria.org/post/2010/03/17/Busy...Busy....#comment-form</wfw:comment>
      <wfw:commentRss>http://blog.gioria.org/feed/atom/comments/500318</wfw:commentRss>
      </item>
    
</channel>
</rss>