<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>The HP Security Laboratory Blog</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/default.aspx</link><description>HP Application Security Center blogs and forums covering all aspects of Web Application Security</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/TheSpiLaboratory" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><title>Top Five Web Application Vulnerabilities 10/27/09 - 11/8/09</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/PSWNJQoijyQ/top-five-web-application-vulnerabilities-10-27-09-11-8-09.aspx</link><pubDate>Mon, 09 Nov 2009 20:29:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108525</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=108525</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/09/top-five-web-application-vulnerabilities-10-27-09-11-8-09.aspx#comments</comments><description>1) HP Power Manager Management Web Server Login Remote Code Execution Vulnerability HP Power Manager is susceptible to a remote code execution vulnerability via the login form of the web based management web server due to improper bounds-checking of user...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/09/top-five-web-application-vulnerabilities-10-27-09-11-8-09.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108525" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/lpPbgP0Yvi8pXe05TbFucwWBG3w/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/lpPbgP0Yvi8pXe05TbFucwWBG3w/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/lpPbgP0Yvi8pXe05TbFucwWBG3w/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/lpPbgP0Yvi8pXe05TbFucwWBG3w/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=PSWNJQoijyQ:z_Rld6vjhCw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=PSWNJQoijyQ:z_Rld6vjhCw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=PSWNJQoijyQ:z_Rld6vjhCw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=PSWNJQoijyQ:z_Rld6vjhCw:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=PSWNJQoijyQ:z_Rld6vjhCw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=PSWNJQoijyQ:z_Rld6vjhCw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=PSWNJQoijyQ:z_Rld6vjhCw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/PSWNJQoijyQ" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/SQL+Injection/default.aspx">SQL Injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/cross-site++scripting/default.aspx">cross-site  scripting</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/ibm+lotus+connections/default.aspx">ibm lotus connections</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/cross-site+request+forgery/default.aspx">cross-site request forgery</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/xerox+fiery+webtools/default.aspx">xerox fiery webtools</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/roundcube/default.aspx">roundcube</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/oracle+weblogic+server/default.aspx">oracle weblogic server</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/hp+power+manager/default.aspx">hp power manager</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/09/top-five-web-application-vulnerabilities-10-27-09-11-8-09.aspx</feedburner:origLink></item><item><title>Now Hiring: HP Security Center Pen Tester</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/5hJ2mkvWwlo/hp-security-center-penetration-testing-job-posting.aspx</link><pubDate>Thu, 05 Nov 2009 18:40:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108506</guid><dc:creator>mark.painter</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=108506</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/05/hp-security-center-penetration-testing-job-posting.aspx#comments</comments><description>HP is looking for a qualified Sr. Application Security Consultant that has deep Application Security experience. Consultant should have experience with performing Web Application Assessments, Network Penetration Testing, and be capable of manually exploiting...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/05/hp-security-center-penetration-testing-job-posting.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108506" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/izatbfwsff1EvYh8vvPgkdRnit4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/izatbfwsff1EvYh8vvPgkdRnit4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/izatbfwsff1EvYh8vvPgkdRnit4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/izatbfwsff1EvYh8vvPgkdRnit4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=5hJ2mkvWwlo:cejWbNZThfo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=5hJ2mkvWwlo:cejWbNZThfo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=5hJ2mkvWwlo:cejWbNZThfo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=5hJ2mkvWwlo:cejWbNZThfo:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=5hJ2mkvWwlo:cejWbNZThfo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=5hJ2mkvWwlo:cejWbNZThfo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=5hJ2mkvWwlo:cejWbNZThfo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/5hJ2mkvWwlo" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/pen+tester/default.aspx">pen tester</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/job+posting/default.aspx">job posting</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/05/hp-security-center-penetration-testing-job-posting.aspx</feedburner:origLink></item><item><title>Take your %00 and shove it</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/pT2rTsetx8Q/take-your-00-and-shove-it.aspx</link><pubDate>Wed, 04 Nov 2009 11:05:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108474</guid><dc:creator>matt wood</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=108474</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/04/take-your-00-and-shove-it.aspx#comments</comments><description>We&amp;#39;ve recently been optimizing our Local File Inclusion (LFI) audit engine. Part of that effort has included poking around in different frameworks (php, .NET, java, ruby/rails, python, perl... etc) and seeing how many ways a developer might fall prey...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/04/take-your-00-and-shove-it.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108474" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/69ewG8ytOQsYFuCNARFPxbW5Jo8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/69ewG8ytOQsYFuCNARFPxbW5Jo8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/69ewG8ytOQsYFuCNARFPxbW5Jo8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/69ewG8ytOQsYFuCNARFPxbW5Jo8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=pT2rTsetx8Q:y4tDU8uNkyY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=pT2rTsetx8Q:y4tDU8uNkyY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=pT2rTsetx8Q:y4tDU8uNkyY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=pT2rTsetx8Q:y4tDU8uNkyY:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=pT2rTsetx8Q:y4tDU8uNkyY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=pT2rTsetx8Q:y4tDU8uNkyY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=pT2rTsetx8Q:y4tDU8uNkyY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/pT2rTsetx8Q" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/PHP/default.aspx">PHP</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Null+Byte/default.aspx">Null Byte</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Audit+Engines/default.aspx">Audit Engines</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Local+File+Inclusion/default.aspx">Local File Inclusion</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/LFI/default.aspx">LFI</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/google+code/default.aspx">google code</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/_2500_00+byte/default.aspx">%00 byte</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/04/take-your-00-and-shove-it.aspx</feedburner:origLink></item><item><title>HP Application Security Center at OWASP DC 11/11-13</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/5gVBomVjue4/hp-application-security-center-at-owasp-dc-11-11-13.aspx</link><pubDate>Tue, 03 Nov 2009 21:26:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108497</guid><dc:creator>mark.painter</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=108497</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/03/hp-application-security-center-at-owasp-dc-11-11-13.aspx#comments</comments><description>The HP Application Security Center has several presentations at the upcoming OWASP Global Summit In Washington, DC. Ryan English, Rafal Los, Dennis Hurst and Kim Dinerman will all be there. More information about the summit can be found here: OWASP Global...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/03/hp-application-security-center-at-owasp-dc-11-11-13.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108497" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/yzKLdFKosDJpoz_-9a0w7XdXCfs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/yzKLdFKosDJpoz_-9a0w7XdXCfs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/yzKLdFKosDJpoz_-9a0w7XdXCfs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/yzKLdFKosDJpoz_-9a0w7XdXCfs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=5gVBomVjue4:5dHXNS6lHLs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=5gVBomVjue4:5dHXNS6lHLs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=5gVBomVjue4:5dHXNS6lHLs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=5gVBomVjue4:5dHXNS6lHLs:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=5gVBomVjue4:5dHXNS6lHLs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=5gVBomVjue4:5dHXNS6lHLs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=5gVBomVjue4:5dHXNS6lHLs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/5gVBomVjue4" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/owasp/default.aspx">owasp</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/SANS/default.aspx">SANS</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/RSA/default.aspx">RSA</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Dennis+Hurst/default.aspx">Dennis Hurst</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Caleb+Sima/default.aspx">Caleb Sima</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Matt+Wood/default.aspx">Matt Wood</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/03/hp-application-security-center-at-owasp-dc-11-11-13.aspx</feedburner:origLink></item><item><title>WebInspect Tips: Changing settings to improve scans</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/Az3_rRoSTNY/webinspect-tips-changing-settings-to-improve-scans.aspx</link><pubDate>Wed, 28 Oct 2009 19:41:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108475</guid><dc:creator>todd.densmore</dc:creator><slash:comments>3</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=108475</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/28/webinspect-tips-changing-settings-to-improve-scans.aspx#comments</comments><description>Although running WebInspect with &amp;lsquo;out of the box&amp;rsquo; scans settings might be the easiest way to start a scan, it is almost sure to produce unexpected results. Configuring any web application scanner is tricky, but by following these simple steps...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/28/webinspect-tips-changing-settings-to-improve-scans.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108475" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/TtFWWbbipM4Qk5UP6TqM-qXqPiA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TtFWWbbipM4Qk5UP6TqM-qXqPiA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/TtFWWbbipM4Qk5UP6TqM-qXqPiA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TtFWWbbipM4Qk5UP6TqM-qXqPiA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=Az3_rRoSTNY:CgiwuIy3PGc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=Az3_rRoSTNY:CgiwuIy3PGc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=Az3_rRoSTNY:CgiwuIy3PGc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=Az3_rRoSTNY:CgiwuIy3PGc:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=Az3_rRoSTNY:CgiwuIy3PGc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=Az3_rRoSTNY:CgiwuIy3PGc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=Az3_rRoSTNY:CgiwuIy3PGc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/Az3_rRoSTNY" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/WebInspect/default.aspx">WebInspect</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/web+application+security/default.aspx">web application security</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/configuration/default.aspx">configuration</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/28/webinspect-tips-changing-settings-to-improve-scans.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 10/12/09 - 10/25/09</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/oWMutxR8boE/top-five-web-application-vulnerabilities-10-12-09-10-25-09.aspx</link><pubDate>Mon, 26 Oct 2009 21:11:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108464</guid><dc:creator>mark.painter</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=108464</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/26/top-five-web-application-vulnerabilities-10-12-09-10-25-09.aspx#comments</comments><description>1) TYPO3 Core Multiple Vulnerabilities TYPO3 is susceptible to multiple remote vulnerabilities including SQL-injection, Cross-Site Scripting, information disclosure, frame and session hijacking, and shell-command-execution issues. Each of these issues...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/26/top-five-web-application-vulnerabilities-10-12-09-10-25-09.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108464" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/yUF_A7X33-qBwZSys4ynu5GDmIU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/yUF_A7X33-qBwZSys4ynu5GDmIU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/yUF_A7X33-qBwZSys4ynu5GDmIU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/yUF_A7X33-qBwZSys4ynu5GDmIU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=oWMutxR8boE:LU2f8o9uZX4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=oWMutxR8boE:LU2f8o9uZX4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=oWMutxR8boE:LU2f8o9uZX4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=oWMutxR8boE:LU2f8o9uZX4:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=oWMutxR8boE:LU2f8o9uZX4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=oWMutxR8boE:LU2f8o9uZX4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=oWMutxR8boE:LU2f8o9uZX4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/oWMutxR8boE" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/SQL+Injection/default.aspx">SQL Injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/cross-site++scripting/default.aspx">cross-site  scripting</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/HTML++Injection/default.aspx">HTML  Injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/TYPO3/default.aspx">TYPO3</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/IBM+Rational+RequisitePro/default.aspx">IBM Rational RequisitePro</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/NaviCOPA/default.aspx">NaviCOPA</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/26/top-five-web-application-vulnerabilities-10-12-09-10-25-09.aspx</feedburner:origLink></item><item><title>Organizations are not adequately protecting E-health records</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/ZxsXPKgpJZ4/organizations-are-not-adequately-protecting-e-health-records.aspx</link><pubDate>Fri, 23 Oct 2009 20:09:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108460</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=108460</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/23/organizations-are-not-adequately-protecting-e-health-records.aspx#comments</comments><description>The American Recovery and Reinvestment Act of 2009 (aka the stimulus package) included funds to both implement electronic health records and rules to specifically improve personal health information breach notification rules. It&amp;rsquo;s ironic, then,...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/23/organizations-are-not-adequately-protecting-e-health-records.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108460" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/HQHOOCUsDX9KM302wpxsg5gJK2c/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HQHOOCUsDX9KM302wpxsg5gJK2c/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/HQHOOCUsDX9KM302wpxsg5gJK2c/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HQHOOCUsDX9KM302wpxsg5gJK2c/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ZxsXPKgpJZ4:VQoGL4jqC_M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ZxsXPKgpJZ4:VQoGL4jqC_M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=ZxsXPKgpJZ4:VQoGL4jqC_M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ZxsXPKgpJZ4:VQoGL4jqC_M:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ZxsXPKgpJZ4:VQoGL4jqC_M:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=ZxsXPKgpJZ4:VQoGL4jqC_M:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ZxsXPKgpJZ4:VQoGL4jqC_M:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/ZxsXPKgpJZ4" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/hipaa/default.aspx">hipaa</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/personal+health+information/default.aspx">personal health information</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/breach/default.aspx">breach</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/stimulus+package/default.aspx">stimulus package</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/e-health+records/default.aspx">e-health records</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/23/organizations-are-not-adequately-protecting-e-health-records.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 9/28/09 - 10/11/09</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/QWXE89OkrtY/top-five-web-application-vulnerabilities-9-28-09-10-11-09.aspx</link><pubDate>Mon, 12 Oct 2009 20:12:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108381</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=108381</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/12/top-five-web-application-vulnerabilities-9-28-09-10-11-09.aspx#comments</comments><description>1) Juniper Networks JUNOS J-Web Multiple Cross-Site Scripting And HTML Injection Vulnerabilities Juniper Networks JUNOS is susceptible to multiple Cross-Site Scripting and HTML Injection vulnerabilities. Successful exploitation of these vulnerabilities...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/12/top-five-web-application-vulnerabilities-9-28-09-10-11-09.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108381" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Qu5AjXHsXKXIYMRgshaPV1Y4PMY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Qu5AjXHsXKXIYMRgshaPV1Y4PMY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Qu5AjXHsXKXIYMRgshaPV1Y4PMY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Qu5AjXHsXKXIYMRgshaPV1Y4PMY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=QWXE89OkrtY:jZUriOWr_lI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=QWXE89OkrtY:jZUriOWr_lI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=QWXE89OkrtY:jZUriOWr_lI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=QWXE89OkrtY:jZUriOWr_lI:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=QWXE89OkrtY:jZUriOWr_lI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=QWXE89OkrtY:jZUriOWr_lI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=QWXE89OkrtY:jZUriOWr_lI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/QWXE89OkrtY" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/cross-site++scripting/default.aspx">cross-site  scripting</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/HTML++Injection/default.aspx">HTML  Injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/novell++edirectory/default.aspx">novell  edirectory</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/juniper/default.aspx">juniper</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/kayako/default.aspx">kayako</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/symantec/default.aspx">symantec</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/interspire/default.aspx">interspire</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/12/top-five-web-application-vulnerabilities-9-28-09-10-11-09.aspx</feedburner:origLink></item><item><title>85% of IT security decision makers think successful external attacks very unlikely</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/gThiMXYNvJs/85-of-it-security-decision-makers-think-successful-external-attacks-very-unlikely.aspx</link><pubDate>Fri, 09 Oct 2009 19:19:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108362</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=108362</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/09/85-of-it-security-decision-makers-think-successful-external-attacks-very-unlikely.aspx#comments</comments><description>A new report this week from ITC reveals that eighty-five percent of IT security decision makers think that losing data via an external threat is &amp;quot;very unlikely.&amp;quot; Wow. Once upon a time, anyone involved in application security had a need to educate...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/09/85-of-it-security-decision-makers-think-successful-external-attacks-very-unlikely.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108362" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/F6i0bKFuYMC1whZt4sfczvCghp4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/F6i0bKFuYMC1whZt4sfczvCghp4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/F6i0bKFuYMC1whZt4sfczvCghp4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/F6i0bKFuYMC1whZt4sfczvCghp4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=gThiMXYNvJs:x97xpcHGfQw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=gThiMXYNvJs:x97xpcHGfQw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=gThiMXYNvJs:x97xpcHGfQw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=gThiMXYNvJs:x97xpcHGfQw:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=gThiMXYNvJs:x97xpcHGfQw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=gThiMXYNvJs:x97xpcHGfQw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=gThiMXYNvJs:x97xpcHGfQw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/gThiMXYNvJs" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/web+application+security/default.aspx">web application security</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/hackers/default.aspx">hackers</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/09/85-of-it-security-decision-makers-think-successful-external-attacks-very-unlikely.aspx</feedburner:origLink></item><item><title>Budget pressures still leading to increased risks</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/M9qDyM1LQBM/budget-pressures-still-leading-to-increased-risks.aspx</link><pubDate>Mon, 05 Oct 2009 19:21:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108339</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=108339</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/05/budget-pressures-still-leading-to-increased-risks.aspx#comments</comments><description>The Independent Oracle Users Group (IOUG) just released a database security survey of their members. As we&amp;#39;ve recently seen a lot, budget pressures are once again leading to increased risks. Organizations know there is a problem, understand it&amp;#39;s...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/05/budget-pressures-still-leading-to-increased-risks.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108339" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/coM6X48mlYTiF-_UhP-i2ErdFaU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/coM6X48mlYTiF-_UhP-i2ErdFaU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/coM6X48mlYTiF-_UhP-i2ErdFaU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/coM6X48mlYTiF-_UhP-i2ErdFaU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=M9qDyM1LQBM:ZwSFuIG7V48:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=M9qDyM1LQBM:ZwSFuIG7V48:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=M9qDyM1LQBM:ZwSFuIG7V48:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=M9qDyM1LQBM:ZwSFuIG7V48:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=M9qDyM1LQBM:ZwSFuIG7V48:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=M9qDyM1LQBM:ZwSFuIG7V48:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=M9qDyM1LQBM:ZwSFuIG7V48:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/M9qDyM1LQBM" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/breach/default.aspx">breach</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/database/default.aspx">database</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/05/budget-pressures-still-leading-to-increased-risks.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 9/14/09 - 9/27/09</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/15pcbcLq8Wg/top-five-web-application-vulnerabilities-9-14-09-9-27-09.aspx</link><pubDate>Mon, 28 Sep 2009 20:43:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:107566</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=107566</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/28/top-five-web-application-vulnerabilities-9-14-09-9-27-09.aspx#comments</comments><description>1) Novell GroupWise WebAccess Cross-Site Scripting Vulnerability Novell GroupWise WebAccess is susceptible to a Cross-Site Scripting vulnerability. An attacker can leverage this vulnerability to execute script code in the browser of an unsuspecting user...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/28/top-five-web-application-vulnerabilities-9-14-09-9-27-09.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=107566" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/87W4ryBDx5gEVbOUwegr3PNTWAY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/87W4ryBDx5gEVbOUwegr3PNTWAY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/87W4ryBDx5gEVbOUwegr3PNTWAY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/87W4ryBDx5gEVbOUwegr3PNTWAY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=15pcbcLq8Wg:fiViu_33QQE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=15pcbcLq8Wg:fiViu_33QQE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=15pcbcLq8Wg:fiViu_33QQE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=15pcbcLq8Wg:fiViu_33QQE:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=15pcbcLq8Wg:fiViu_33QQE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=15pcbcLq8Wg:fiViu_33QQE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=15pcbcLq8Wg:fiViu_33QQE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/15pcbcLq8Wg" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/SQL+Injection/default.aspx">SQL Injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Novell+GroupWise+WebAccess/default.aspx">Novell GroupWise WebAccess</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/cross-site++scripting/default.aspx">cross-site  scripting</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/HTML++Injection/default.aspx">HTML  Injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/IBM+Lotus+Quickr/default.aspx">IBM Lotus Quickr</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/IBM+Web+Application+Server/default.aspx">IBM Web Application Server</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/OSSIM/default.aspx">OSSIM</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/28/top-five-web-application-vulnerabilities-9-14-09-9-27-09.aspx</feedburner:origLink></item><item><title>60% of Internet attacks now conducted against web applications</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/nDHRPXQwFj8/60-of-internet-attacks-now-conducted-against-web-applications.aspx</link><pubDate>Fri, 25 Sep 2009 14:57:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:106938</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=106938</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/25/60-of-internet-attacks-now-conducted-against-web-applications.aspx#comments</comments><description>New studies have gone a long way in confirming that certain web application security trends are accelerating. The SANS Top Cyber Security Risks report reveals that a full 60% of Internet attacks are now conducted against web applications. It&amp;#39;s no...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/25/60-of-internet-attacks-now-conducted-against-web-applications.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=106938" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ry5YChF74qRkMo1SthDtEgdJegs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ry5YChF74qRkMo1SthDtEgdJegs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ry5YChF74qRkMo1SthDtEgdJegs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ry5YChF74qRkMo1SthDtEgdJegs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=nDHRPXQwFj8:GpEtOuG0QAs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=nDHRPXQwFj8:GpEtOuG0QAs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=nDHRPXQwFj8:GpEtOuG0QAs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=nDHRPXQwFj8:GpEtOuG0QAs:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=nDHRPXQwFj8:GpEtOuG0QAs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=nDHRPXQwFj8:GpEtOuG0QAs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=nDHRPXQwFj8:GpEtOuG0QAs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/nDHRPXQwFj8" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/SQL+Injection/default.aspx">SQL Injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/cross-site++scripting/default.aspx">cross-site  scripting</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/SANS/default.aspx">SANS</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/25/60-of-internet-attacks-now-conducted-against-web-applications.aspx</feedburner:origLink></item><item><title>Is your .svn showing (like 3300 other sites)?</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/2FDCtmS_9A0/is-your-svn-showing-like-3320-other-sites.aspx</link><pubDate>Thu, 24 Sep 2009 15:13:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:106552</guid><dc:creator>Chris Sullo</dc:creator><slash:comments>3</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=106552</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/24/is-your-svn-showing-like-3320-other-sites.aspx#comments</comments><description>TechCrunch has an article (pointing back to a Russian security company blog post (translated link)), detailing a scan of 2,253,388 web sites which yielded an amazing 3,320 Subversion&amp;#39;s .svn directories. In case you&amp;#39;re you&amp;#39;re not familiar with...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/24/is-your-svn-showing-like-3320-other-sites.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=106552" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/p1QDgwwhanrwM3tQLx0zf2g46IU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/p1QDgwwhanrwM3tQLx0zf2g46IU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/p1QDgwwhanrwM3tQLx0zf2g46IU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/p1QDgwwhanrwM3tQLx0zf2g46IU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=2FDCtmS_9A0:6_BnybpSpec:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=2FDCtmS_9A0:6_BnybpSpec:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=2FDCtmS_9A0:6_BnybpSpec:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=2FDCtmS_9A0:6_BnybpSpec:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=2FDCtmS_9A0:6_BnybpSpec:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=2FDCtmS_9A0:6_BnybpSpec:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=2FDCtmS_9A0:6_BnybpSpec:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/2FDCtmS_9A0" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/24/is-your-svn-showing-like-3320-other-sites.aspx</feedburner:origLink></item><item><title>%3c has always been a friend of mine</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/CMKKeaAPNQM/3c-has-always-a-friend-of-mine.aspx</link><pubDate>Thu, 17 Sep 2009 15:59:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:104556</guid><dc:creator>billyhoffman</dc:creator><slash:comments>4</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=104556</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/17/3c-has-always-a-friend-of-mine.aspx#comments</comments><description>Ask a developer what&amp;#39;s the ASCII code of &amp;quot;A&amp;quot; and most should be able to tell you 65. The good ones will tell you 0x41. If you ask them they should be able to tell you some more off the top of their head. Space... 32, quote... 34, &amp;quot;a&amp;quot;...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/17/3c-has-always-a-friend-of-mine.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=104556" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/DRe_QeAYkO_c_mIo7N2NGfz27UY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DRe_QeAYkO_c_mIo7N2NGfz27UY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/DRe_QeAYkO_c_mIo7N2NGfz27UY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DRe_QeAYkO_c_mIo7N2NGfz27UY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=CMKKeaAPNQM:bwF9bt-ei9g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=CMKKeaAPNQM:bwF9bt-ei9g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=CMKKeaAPNQM:bwF9bt-ei9g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=CMKKeaAPNQM:bwF9bt-ei9g:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=CMKKeaAPNQM:bwF9bt-ei9g:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=CMKKeaAPNQM:bwF9bt-ei9g:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=CMKKeaAPNQM:bwF9bt-ei9g:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/CMKKeaAPNQM" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/17/3c-has-always-a-friend-of-mine.aspx</feedburner:origLink></item><item><title>HTML 5 Form Tags a Risk?</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/WnPMl9Wnvio/html-5-form-tags-a-risk.aspx</link><pubDate>Thu, 17 Sep 2009 14:01:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:104534</guid><dc:creator>Chris Sullo</dc:creator><slash:comments>3</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=104534</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/17/html-5-form-tags-a-risk.aspx#comments</comments><description>I&amp;#39;ve tried to keep up with new HTML 5 features, but Billy recently pointed out that INPUT tags have the ability to set regular expression patterns for validation directly in the markup. I think this is nifty and, at least in the demo I tried , a very...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/17/html-5-form-tags-a-risk.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=104534" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Mv13qnVsxWS-taDmQgslovveh5o/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Mv13qnVsxWS-taDmQgslovveh5o/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Mv13qnVsxWS-taDmQgslovveh5o/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Mv13qnVsxWS-taDmQgslovveh5o/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=WnPMl9Wnvio:ZHWSCHf5l9k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=WnPMl9Wnvio:ZHWSCHf5l9k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=WnPMl9Wnvio:ZHWSCHf5l9k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=WnPMl9Wnvio:ZHWSCHf5l9k:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=WnPMl9Wnvio:ZHWSCHf5l9k:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=WnPMl9Wnvio:ZHWSCHf5l9k:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=WnPMl9Wnvio:ZHWSCHf5l9k:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/WnPMl9Wnvio" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/input+validation/default.aspx">input validation</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/HTML+5/default.aspx">HTML 5</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/17/html-5-form-tags-a-risk.aspx</feedburner:origLink></item></channel></rss>
