<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.infosupport.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Erik Oppedijk - All Comments</title><link>http://blogs.infosupport.com/blogs/eriko/default.aspx</link><description>ASP.NET, Security and Robotics Developer Studio</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>re: URL Security flaw - or not?</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2009/04/02/security.aspx#166814</link><pubDate>Fri, 05 Feb 2010 06:43:27 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:166814</guid><dc:creator>Joy</dc:creator><description>&lt;p&gt;Great! The articles so far have been full of great material. Glad to hear the serious will continue. Keep &amp;#39;em coming!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=166814" width="1" height="1"&gt;</description></item><item><title>re: ASP.NET Vulnerability testing with CAT.NET</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2009/08/26/asp-net-vulnerability-testing-with-cat-net.aspx#35484</link><pubDate>Wed, 04 Nov 2009 03:13:12 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:35484</guid><dc:creator>cat sneezing</dc:creator><description>&lt;p&gt;i have been also used cat anlysis for some reasons and project it helps me a lot to lessen my load of works.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=35484" width="1" height="1"&gt;</description></item><item><title>re: ASP.NET Vulnerability testing with CAT.NET</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2009/08/26/asp-net-vulnerability-testing-with-cat-net.aspx#16743</link><pubDate>Thu, 27 Aug 2009 07:18:39 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:16743</guid><dc:creator>Rolf Huisman</dc:creator><description>&lt;p&gt;I&amp;#39;ve used CAT.Net to analyse some projects in the past and its a great tool for spotting low hanging fruit. It should however be noted that the amount of false positives is quite high in large SAAS applications.&lt;/p&gt;
&lt;p&gt; &amp;nbsp; Lucky for us, ASP.NET will stop most of these attacks for &lt;/p&gt;
&lt;p&gt; &amp;nbsp; us, by filtering on HTML tags, and unicode attacks, but it is &lt;/p&gt;
&lt;p&gt; &amp;nbsp; always a good practice to encode all output&lt;/p&gt;
&lt;p&gt;In the default setting ASP 2.0 and higher will filter this. However the filtering isn&amp;#39;t perfect (BID 20753) and there have been some patches to address this (always use a fully updated ASP.net instance). However, I still found people turning this security off (by using ValidateRequest=&amp;quot;false&amp;quot;) because they want another webpart (content editor) &amp;nbsp;to work. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=16743" width="1" height="1"&gt;</description></item><item><title>BizTalk 2006 R3 announced</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2008/04/23/BizTalk-2006-R3-announced.aspx#16524</link><pubDate>Sat, 08 Aug 2009 17:00:26 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:16524</guid><dc:creator>NewsPeeps</dc:creator><description>&lt;p&gt;Thank you for submitting this cool story - Trackback from NewsPeeps&lt;/p&gt;
&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=16524" width="1" height="1"&gt;</description></item><item><title>BizTalk 2006 R2 Deep Dive - 19th may</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2008/04/18/BizTalk-2006-R2-Deep-Dive-_2D00_-19th-may.aspx#16523</link><pubDate>Sat, 08 Aug 2009 17:00:25 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:16523</guid><dc:creator>NewsPeeps</dc:creator><description>&lt;p&gt;Thank you for submitting this cool story - Trackback from NewsPeeps&lt;/p&gt;
&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=16523" width="1" height="1"&gt;</description></item><item><title>RoboChallenge 2008 Kickoff</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2007/11/09/RoboChallenge-2008-Kickoff.aspx#16522</link><pubDate>Sat, 08 Aug 2009 17:00:23 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:16522</guid><dc:creator>NewsPeeps</dc:creator><description>&lt;p&gt;Thank you for submitting this cool story - Trackback from NewsPeeps&lt;/p&gt;
&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=16522" width="1" height="1"&gt;</description></item><item><title>Preparing for Robochallenge 2007</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2007/06/05/Robochallenge-2007.aspx#16519</link><pubDate>Sat, 08 Aug 2009 17:00:17 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:16519</guid><dc:creator>NewsPeeps</dc:creator><description>&lt;p&gt;Thank you for submitting this cool story - Trackback from NewsPeeps&lt;/p&gt;
&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=16519" width="1" height="1"&gt;</description></item><item><title>Robotics Studio 1.5 CTP</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2007/04/07/Robotics-Studio-1.5-CTP.aspx#16521</link><pubDate>Sat, 08 Aug 2009 17:00:14 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:16521</guid><dc:creator>NewsPeeps</dc:creator><description>&lt;p&gt;Thank you for submitting this cool story - Trackback from NewsPeeps&lt;/p&gt;
&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=16521" width="1" height="1"&gt;</description></item><item><title>New BizTalk User Group (BTUG) meeting</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2007/03/07/New-BizTalk-User-Group-_2800_BTUG_2900_-meeting.aspx#16520</link><pubDate>Sat, 08 Aug 2009 17:00:12 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:16520</guid><dc:creator>NewsPeeps</dc:creator><description>&lt;p&gt;Thank you for submitting this cool story - Trackback from NewsPeeps&lt;/p&gt;
&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=16520" width="1" height="1"&gt;</description></item><item><title>RTM time, Virtual PC 2007 and SQL 2005 SP2</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2007/02/19/RTM-time_2C00_-Virtual-PC-2007-and-SQL-2005-SP2.aspx#16517</link><pubDate>Sat, 08 Aug 2009 17:00:11 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:16517</guid><dc:creator>NewsPeeps</dc:creator><description>&lt;p&gt;Thank you for submitting this cool story - Trackback from NewsPeeps&lt;/p&gt;
&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=16517" width="1" height="1"&gt;</description></item><item><title>re: Cross-Site Request Forgeries (CSRF) explained</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2009/07/22/cross-site-request-forgeries.aspx#16429</link><pubDate>Tue, 28 Jul 2009 12:54:22 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:16429</guid><dc:creator>Erik Oppedijk</dc:creator><description>&lt;p&gt;Even with session cookies you are vulnerable during browsing, and the attacker has an extra time window of about 20 minutes if you forget to sign out.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=16429" width="1" height="1"&gt;</description></item><item><title>re: Cross-Site Request Forgeries (CSRF) explained</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2009/07/22/cross-site-request-forgeries.aspx#16424</link><pubDate>Mon, 27 Jul 2009 18:59:53 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:16424</guid><dc:creator>timm</dc:creator><description>&lt;p&gt;that&amp;#39;s one the reasons most secure website&amp;#39;s only use browser session based cookies for authentication... baking a persistent cookie can burn your fingers :)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=16424" width="1" height="1"&gt;</description></item><item><title>Cross-Site Request Forgeries (CSRF) explained - Erik Oppedijk - blog community</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2009/07/22/cross-site-request-forgeries.aspx#16407</link><pubDate>Thu, 23 Jul 2009 14:52:44 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:16407</guid><dc:creator>NewsPeeps</dc:creator><description>&lt;p&gt;Thank you for submitting this cool story - Trackback from NewsPeeps&lt;/p&gt;
&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=16407" width="1" height="1"&gt;</description></item><item><title>re: URL Security flaw - or not?</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2009/04/02/security.aspx#15638</link><pubDate>Wed, 15 Apr 2009 08:45:11 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:15638</guid><dc:creator>frankg</dc:creator><description>&lt;p&gt;En het is zeker geen theoretisch probleem. Heb je dit gelezen? &lt;a rel="nofollow" target="_new" href="http://www.nu.nl/internet/1944739/site-geschillencommissie-was-jarenlang-lek.html"&gt;www.nu.nl/.../site-geschillencommissie-was-jarenlang-lek.html&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=15638" width="1" height="1"&gt;</description></item><item><title>re: URL Security flaw - or not?</title><link>http://blogs.infosupport.com/blogs/eriko/archive/2009/04/02/security.aspx#15567</link><pubDate>Fri, 03 Apr 2009 18:18:07 GMT</pubDate><guid isPermaLink="false">56f6167b-0c51-4839-ab2d-34653eeb5c9c:15567</guid><dc:creator>willemm</dc:creator><description>&lt;p&gt;It gets even worse: By moving the information to a hidden field, a cookie or what not you create new problems that require an even more complex solution. And that while the real solution to the problem is pretty simple to implement using some roles and a few settings ;)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.infosupport.com/aggbug.aspx?PostID=15567" width="1" height="1"&gt;</description></item></channel></rss>