<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Architecting Security</title>
	
	<link>http://www.architectingsecurity.com</link>
	<description />
	<lastBuildDate>Wed, 11 Jan 2012 13:12:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/architectingsecurity" /><feedburner:info uri="architectingsecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Web Application Security Check List, version 2</title>
		<link>http://feedproxy.google.com/~r/architectingsecurity/~3/X4fVdK6iZgI/</link>
		<comments>http://www.architectingsecurity.com/2012/01/11/web-app-sec-checklist-v2/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 12:40:28 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Secure SDLC]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[checklist]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owasp-tr]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=405</guid>
		<description>OWASP-Turkey published in 2010 a check list for web application security which provides various security controls for web application developers and system administrators. It was planned to create the second version of the check list. I have been involved in the project and within the past 6 months we have worked on the new check [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=X4fVdK6iZgI:UR3LERK22ws:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=X4fVdK6iZgI:UR3LERK22ws:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=X4fVdK6iZgI:UR3LERK22ws:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=X4fVdK6iZgI:UR3LERK22ws:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=X4fVdK6iZgI:UR3LERK22ws:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=X4fVdK6iZgI:UR3LERK22ws:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=X4fVdK6iZgI:UR3LERK22ws:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=X4fVdK6iZgI:UR3LERK22ws:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=X4fVdK6iZgI:UR3LERK22ws:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=X4fVdK6iZgI:UR3LERK22ws:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/architectingsecurity/~4/X4fVdK6iZgI" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.architectingsecurity.com/2012/01/11/web-app-sec-checklist-v2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.architectingsecurity.com/2012/01/11/web-app-sec-checklist-v2/</feedburner:origLink></item>
		<item>
		<title>Mahremiyet İhlalleri – 1 (Privacy Violations)</title>
		<link>http://feedproxy.google.com/~r/architectingsecurity/~3/60h_ebGSoGA/</link>
		<comments>http://www.architectingsecurity.com/2011/11/14/mahremiyetihlalleri/#comments</comments>
		<pubDate>Mon, 14 Nov 2011 15:11:19 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[mahremiyet ihlalleri]]></category>
		<category><![CDATA[privacy violations]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=288</guid>
		<description>Kişişel bilgilerin mahremiyeti dünyada birçok yerde olduğu gibi ne yazıkki Türkiye’de de pek dikkat edilmeyen ve de kolayca zaafiyete uğratılan bir konudur. Toplum genelinde mahremiyet bilinci oluşmadığından devlet kurumları olsun özel kurumlar ya da kişiler olsun ellerinde var olan kişişel bilgilerin mahremiyetini gözardı edip erişimin herkese açık olduğu İnternet ortamında bu bilgileri paylaşabiliyorlar. Bunun en [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=60h_ebGSoGA:L65Y2ScMkgY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=60h_ebGSoGA:L65Y2ScMkgY:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=60h_ebGSoGA:L65Y2ScMkgY:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=60h_ebGSoGA:L65Y2ScMkgY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=60h_ebGSoGA:L65Y2ScMkgY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=60h_ebGSoGA:L65Y2ScMkgY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=60h_ebGSoGA:L65Y2ScMkgY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=60h_ebGSoGA:L65Y2ScMkgY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=60h_ebGSoGA:L65Y2ScMkgY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=60h_ebGSoGA:L65Y2ScMkgY:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/architectingsecurity/~4/60h_ebGSoGA" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.architectingsecurity.com/2011/11/14/mahremiyetihlalleri/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		<feedburner:origLink>http://www.architectingsecurity.com/2011/11/14/mahremiyetihlalleri/</feedburner:origLink></item>
		<item>
		<title>Book Review: Secure and Resilient Software Development</title>
		<link>http://feedproxy.google.com/~r/architectingsecurity/~3/4bm3MWHbSMw/</link>
		<comments>http://www.architectingsecurity.com/2011/07/30/book-review-secure-and-resilient-software-development/#comments</comments>
		<pubDate>Sat, 30 Jul 2011 16:53:37 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Book Review]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Secure SDLC]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[book review]]></category>
		<category><![CDATA[bsimm]]></category>
		<category><![CDATA[clasp]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[samm]]></category>
		<category><![CDATA[secure coding]]></category>
		<category><![CDATA[secure sdlc]]></category>
		<category><![CDATA[security training]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=362</guid>
		<description>I have completed the review of the book &amp;#8220;Secure and Resilient Software Development&amp;#8221; for IACR (International Association for Cryptologic Research) book review program. The review can be summarized as follows: This book is a &amp;#8220;must read&amp;#8221; resource for security experts focusing on application security and for application designers and developers who need to integrate security [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=4bm3MWHbSMw:b4u2ZqEYRVk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=4bm3MWHbSMw:b4u2ZqEYRVk:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=4bm3MWHbSMw:b4u2ZqEYRVk:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=4bm3MWHbSMw:b4u2ZqEYRVk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=4bm3MWHbSMw:b4u2ZqEYRVk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=4bm3MWHbSMw:b4u2ZqEYRVk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=4bm3MWHbSMw:b4u2ZqEYRVk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=4bm3MWHbSMw:b4u2ZqEYRVk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=4bm3MWHbSMw:b4u2ZqEYRVk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=4bm3MWHbSMw:b4u2ZqEYRVk:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/architectingsecurity/~4/4bm3MWHbSMw" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.architectingsecurity.com/2011/07/30/book-review-secure-and-resilient-software-development/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.architectingsecurity.com/2011/07/30/book-review-secure-and-resilient-software-development/</feedburner:origLink></item>
		<item>
		<title>Book Review: Architecting Secure Software Systems</title>
		<link>http://feedproxy.google.com/~r/architectingsecurity/~3/7Xixrws1pMs/</link>
		<comments>http://www.architectingsecurity.com/2011/04/13/book-review-architecting-secure-software-systems/#comments</comments>
		<pubDate>Wed, 13 Apr 2011 16:13:10 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Book Review]]></category>
		<category><![CDATA[Database Security]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Secure SDLC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[book]]></category>
		<category><![CDATA[book review]]></category>
		<category><![CDATA[secure coding]]></category>
		<category><![CDATA[secure sdlc]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security training]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=321</guid>
		<description>I have recently completed the review of the book &amp;#8220;Architecting Secure Software Systems&amp;#8221; for IACR (International Association for Cryptologic Research) book review program. The review can be summarized as follows: This book focuses on both theoretical and practical aspects of designing secure software systems. While its theory part is quite well-written, its practical part is [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=7Xixrws1pMs:MyYBNlpexkw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=7Xixrws1pMs:MyYBNlpexkw:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=7Xixrws1pMs:MyYBNlpexkw:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=7Xixrws1pMs:MyYBNlpexkw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=7Xixrws1pMs:MyYBNlpexkw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=7Xixrws1pMs:MyYBNlpexkw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=7Xixrws1pMs:MyYBNlpexkw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=7Xixrws1pMs:MyYBNlpexkw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=7Xixrws1pMs:MyYBNlpexkw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=7Xixrws1pMs:MyYBNlpexkw:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/architectingsecurity/~4/7Xixrws1pMs" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.architectingsecurity.com/2011/04/13/book-review-architecting-secure-software-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.architectingsecurity.com/2011/04/13/book-review-architecting-secure-software-systems/</feedburner:origLink></item>
		<item>
		<title>Secure Coding Guidelines for Java</title>
		<link>http://feedproxy.google.com/~r/architectingsecurity/~3/fKqAkmmMNXM/</link>
		<comments>http://www.architectingsecurity.com/2011/03/14/secure-coding-guidelines-for-java/#comments</comments>
		<pubDate>Mon, 14 Mar 2011 19:14:29 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Secure SDLC]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[secure coding]]></category>
		<category><![CDATA[secure sdlc]]></category>
		<category><![CDATA[security training]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=291</guid>
		<description>I have published an (Turkish) article about secure coding guidelines for Java within OWASP-Turkey Documents. The article aims at helping IT-architects and developers to understand the main security aspects during design and development phases. The guideline contains generic countermeasures (e.g. Do not write repeated codes) as well as Java-specific countermeasures (e.g. How to use doPrivileged() [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=fKqAkmmMNXM:Z5pcI7SZKxI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=fKqAkmmMNXM:Z5pcI7SZKxI:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=fKqAkmmMNXM:Z5pcI7SZKxI:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=fKqAkmmMNXM:Z5pcI7SZKxI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=fKqAkmmMNXM:Z5pcI7SZKxI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=fKqAkmmMNXM:Z5pcI7SZKxI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=fKqAkmmMNXM:Z5pcI7SZKxI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=fKqAkmmMNXM:Z5pcI7SZKxI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=fKqAkmmMNXM:Z5pcI7SZKxI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=fKqAkmmMNXM:Z5pcI7SZKxI:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/architectingsecurity/~4/fKqAkmmMNXM" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.architectingsecurity.com/2011/03/14/secure-coding-guidelines-for-java/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.architectingsecurity.com/2011/03/14/secure-coding-guidelines-for-java/</feedburner:origLink></item>
		<item>
		<title>Secure Software Development with SAMM</title>
		<link>http://feedproxy.google.com/~r/architectingsecurity/~3/PTp5JqjhuVE/</link>
		<comments>http://www.architectingsecurity.com/2011/02/03/secure-software-development-with-samm/#comments</comments>
		<pubDate>Thu, 03 Feb 2011 13:07:36 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Secure SDLC]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[samm]]></category>
		<category><![CDATA[secure sdlc]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=279</guid>
		<description>SAMM (Software Assurance Maturity Model) is an OWASP project and provides well-structured strategy and guidelines for integration of security within software development processes. In the 7th issue of Web Security Magazine managed by OWASP-Turkey, I have written an introduction article to SAMM. In this article, I focused mainly on the following topics: What is SAMM [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=PTp5JqjhuVE:dQ7Bt6_ca-s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=PTp5JqjhuVE:dQ7Bt6_ca-s:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=PTp5JqjhuVE:dQ7Bt6_ca-s:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=PTp5JqjhuVE:dQ7Bt6_ca-s:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=PTp5JqjhuVE:dQ7Bt6_ca-s:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=PTp5JqjhuVE:dQ7Bt6_ca-s:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=PTp5JqjhuVE:dQ7Bt6_ca-s:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=PTp5JqjhuVE:dQ7Bt6_ca-s:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=PTp5JqjhuVE:dQ7Bt6_ca-s:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=PTp5JqjhuVE:dQ7Bt6_ca-s:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/architectingsecurity/~4/PTp5JqjhuVE" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.architectingsecurity.com/2011/02/03/secure-software-development-with-samm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.architectingsecurity.com/2011/02/03/secure-software-development-with-samm/</feedburner:origLink></item>
		<item>
		<title>Feedbacks from Application Pentest</title>
		<link>http://feedproxy.google.com/~r/architectingsecurity/~3/xUg7KI9G0-E/</link>
		<comments>http://www.architectingsecurity.com/2010/12/07/feedbacks-from-application-pentest/#comments</comments>
		<pubDate>Tue, 07 Dec 2010 16:02:08 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[Appscan]]></category>
		<category><![CDATA[pentest]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=190</guid>
		<description>I have recently completed penetration testing of a SAP portal application for a customer. It was a short-time (5 days) assignment which required execution of tool-supported automatic pentest (with IBM Appscan), manual pentest and preparation of final presentation that explains findings and countermeasures. In such short time pentests, it is very important that test plan [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=xUg7KI9G0-E:E5gdRaWgWxQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=xUg7KI9G0-E:E5gdRaWgWxQ:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=xUg7KI9G0-E:E5gdRaWgWxQ:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=xUg7KI9G0-E:E5gdRaWgWxQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=xUg7KI9G0-E:E5gdRaWgWxQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=xUg7KI9G0-E:E5gdRaWgWxQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=xUg7KI9G0-E:E5gdRaWgWxQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=xUg7KI9G0-E:E5gdRaWgWxQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=xUg7KI9G0-E:E5gdRaWgWxQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=xUg7KI9G0-E:E5gdRaWgWxQ:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/architectingsecurity/~4/xUg7KI9G0-E" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.architectingsecurity.com/2010/12/07/feedbacks-from-application-pentest/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.architectingsecurity.com/2010/12/07/feedbacks-from-application-pentest/</feedburner:origLink></item>
		<item>
		<title>Password Patterns</title>
		<link>http://feedproxy.google.com/~r/architectingsecurity/~3/Xhnbxvpm7aw/</link>
		<comments>http://www.architectingsecurity.com/2010/09/11/password-patterns/#comments</comments>
		<pubDate>Fri, 10 Sep 2010 23:01:21 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Password Security]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[pattern]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=122</guid>
		<description>In December 2009, a critical data breach in the Internet has been experienced. Around 32 million user passwords of rockyou.com web portal were stolen by a hacker which had used SQL injection for his attack. He got all passwords and made them anonymously (i.e. without usernames) available in the Internet to download. Security experts started [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=Xhnbxvpm7aw:Bat49a_3iwk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=Xhnbxvpm7aw:Bat49a_3iwk:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=Xhnbxvpm7aw:Bat49a_3iwk:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=Xhnbxvpm7aw:Bat49a_3iwk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=Xhnbxvpm7aw:Bat49a_3iwk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=Xhnbxvpm7aw:Bat49a_3iwk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=Xhnbxvpm7aw:Bat49a_3iwk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=Xhnbxvpm7aw:Bat49a_3iwk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=Xhnbxvpm7aw:Bat49a_3iwk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=Xhnbxvpm7aw:Bat49a_3iwk:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/architectingsecurity/~4/Xhnbxvpm7aw" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.architectingsecurity.com/2010/09/11/password-patterns/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		<feedburner:origLink>http://www.architectingsecurity.com/2010/09/11/password-patterns/</feedburner:origLink></item>
		<item>
		<title>Encryption with Enterprise Security API (ESAPI)</title>
		<link>http://feedproxy.google.com/~r/architectingsecurity/~3/xX5GznWGnX8/</link>
		<comments>http://www.architectingsecurity.com/2010/08/13/encryption-with-enterprise-security-api-esapi/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 22:30:06 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[aes]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[secure coding]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=24</guid>
		<description>OWASP Enterprise Security API (ESAPI) provides a security control library for helping programmers to integrate security into their applications. It is not a new framework, but it provides a common interface and reference implementations that can be benefited from other frameworks. Security is a complex issue. The &amp;#8220;weakest chain&amp;#8221; is a well-known problem. If you [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=xX5GznWGnX8:L7-omzj16z0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=xX5GznWGnX8:L7-omzj16z0:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=xX5GznWGnX8:L7-omzj16z0:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=xX5GznWGnX8:L7-omzj16z0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=xX5GznWGnX8:L7-omzj16z0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=xX5GznWGnX8:L7-omzj16z0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=xX5GznWGnX8:L7-omzj16z0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=xX5GznWGnX8:L7-omzj16z0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=xX5GznWGnX8:L7-omzj16z0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=xX5GznWGnX8:L7-omzj16z0:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/architectingsecurity/~4/xX5GznWGnX8" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.architectingsecurity.com/2010/08/13/encryption-with-enterprise-security-api-esapi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.architectingsecurity.com/2010/08/13/encryption-with-enterprise-security-api-esapi/</feedburner:origLink></item>
		<item>
		<title>My Comments for Security Reportage</title>
		<link>http://feedproxy.google.com/~r/architectingsecurity/~3/crG4vIGQ3Sc/</link>
		<comments>http://www.architectingsecurity.com/2010/07/05/my-comments-for-security-reportage/#comments</comments>
		<pubDate>Mon, 05 Jul 2010 00:11:08 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[certificates]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Turkey]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=263</guid>
		<description>There is a series of security reportages organized by Turkish network security community and published within their security bulletins. For the 25th issue, I have given my comments for the following questions in the reportage: Can you introduce yourself? How did you start working on security? How do you see information security in Turkey? What [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=crG4vIGQ3Sc:1xYLCnj3qwY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=crG4vIGQ3Sc:1xYLCnj3qwY:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=crG4vIGQ3Sc:1xYLCnj3qwY:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=crG4vIGQ3Sc:1xYLCnj3qwY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=crG4vIGQ3Sc:1xYLCnj3qwY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=crG4vIGQ3Sc:1xYLCnj3qwY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=crG4vIGQ3Sc:1xYLCnj3qwY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=crG4vIGQ3Sc:1xYLCnj3qwY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?i=crG4vIGQ3Sc:1xYLCnj3qwY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/architectingsecurity?a=crG4vIGQ3Sc:1xYLCnj3qwY:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/architectingsecurity?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/architectingsecurity/~4/crG4vIGQ3Sc" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.architectingsecurity.com/2010/07/05/my-comments-for-security-reportage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.architectingsecurity.com/2010/07/05/my-comments-for-security-reportage/</feedburner:origLink></item>
	</channel>
</rss><!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced

Served from: www.architectingsecurity.com @ 2012-02-27 03:19:32 -->

