<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Acunetix Web Application Security Blog &#187; whitepapers</title>
	<atom:link href="http://www.acunetix.com/blog/category/web-security-zone/whitepapers/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.acunetix.com/blog</link>
	<description>Acunetix Web Application Security Blog</description>
	<lastBuildDate>Thu, 02 Feb 2012 15:03:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>A complete guide to securing a website</title>
		<link>http://www.acunetix.com/blog/web-security-zone/whitepapers/complete-guide-securing-website/</link>
		<comments>http://www.acunetix.com/blog/web-security-zone/whitepapers/complete-guide-securing-website/#comments</comments>
		<pubDate>Tue, 14 Dec 2010 15:09:19 +0000</pubDate>
		<dc:creator>Robert Abela</dc:creator>
				<category><![CDATA[web security zone]]></category>
		<category><![CDATA[whitepapers]]></category>
		<category><![CDATA[Acunetix WVS]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[penetration test]]></category>
		<category><![CDATA[security assessment]]></category>
		<category><![CDATA[web vulnerability scanner]]></category>
		<category><![CDATA[website security]]></category>
		<category><![CDATA[whitepaper]]></category>

		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=2786</guid>
		<description><![CDATA[To secure a website or a web application, one has to first understand the target application, how it works and the scope behind it.  Ideally, the penetration tester should have some basic knowledge of programming ...]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.acunetix.com/blog/wp-content/uploads/2010/12/web-security.png"><img class="alignleft size-full wp-image-2789" title="web security" src="http://www.acunetix.com/blog/wp-content/uploads/2010/12/web-security.png" alt="" width="150" height="123" /></a>To secure a website or a web application, one has to first understand the target application, how it works and the scope behind it.  Ideally, the penetration tester should have some basic knowledge of programming and scripting languages, and also web security.  A website security audit usually consists of two steps.  Most of the time, the first step usually is to launch an automated scan.  Afterwards, depending on the results and the website’s complexity, a manual penetration test follows.  To properly complete both the automated and manual audits, a number of tools are available, to simplify the process and make it efficient from the business point of view.</p>
<p>In this white paper we explain in detail how to do a complete website security audit and focus on using the right approach and tools.  We describe the whole process of securing a website in an easy to read step by step format; what needs to be done prior to launching an automated website vulnerability scan up till the manual penetration testing phase.</p>
<p>Click <a href="http://www.acunetix.com/websitesecurity/website-auditing-wp.htm" target="_self">here</a> to read the whitepaper <a href="http://www.acunetix.com/websitesecurity/website-auditing-wp.htm" target="_self">A complete guide to securing a website</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.acunetix.com/blog/web-security-zone/whitepapers/complete-guide-securing-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Application Firewalls do not replace secure development and operation of web applications</title>
		<link>http://www.acunetix.com/blog/web-security-zone/whitepapers/web-application-firewalls-do-not-replace-secure-development/</link>
		<comments>http://www.acunetix.com/blog/web-security-zone/whitepapers/web-application-firewalls-do-not-replace-secure-development/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 12:58:17 +0000</pubDate>
		<dc:creator>Robert Abela</dc:creator>
				<category><![CDATA[whitepapers]]></category>
		<category><![CDATA[advisories]]></category>
		<category><![CDATA[cross site request forgery]]></category>
		<category><![CDATA[cross site scripting]]></category>
		<category><![CDATA[denial of service]]></category>
		<category><![CDATA[waf]]></category>
		<category><![CDATA[web application firewall]]></category>
		<category><![CDATA[web vulnerability scanner]]></category>

		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=649</guid>
		<description><![CDATA[In eval($WAF); whitepaper, L. Nothdurfter, W.Neudorfer and M. Kirchner from the University of Applied Sciences Upper Austria, explain in detail how they evaluated the capabilities of some leading WAF’s (web application firewalls), and concluded that ...]]></description>
			<content:encoded><![CDATA[<p>In eval($WAF); whitepaper, L. Nothdurfter, W.Neudorfer and M. Kirchner from the University of Applied Sciences Upper Austria, explain in detail how they evaluated the capabilities of some leading WAF’s (web application firewalls), and concluded that although a WAF can raise the security level, secure development and operation of web applications should be of top priority.</p>
<p>As a matter of fact, while evaluating some leading web application firewalls, they also released 3 web application firewall advisories:</p>
<ul>
<li><a href="http://www.h4ck1nb3rg.at/wafs/advisory_artofdefence_hyperguard_200907.txt" target="_blank">Artofdefence Hyperguard Web Application Firewal (Remote Denial of Service)</a></li>
<li><a href="http://www.h4ck1nb3rg.at/wafs/advisory_phion_airlock_200907.txt" target="_blank">phion airlock Web Application Firewall (Remote Denial of Service via Management Interface (unauthenticated) and Command Execution</a></li>
<li><a href="http://www.h4ck1nb3rg.at/wafs/advisory_radware_appwall_200907.txt" target="_blank">radware AppWall Web Application Firewall (Source code disclosure on management interface)</a></li>
</ul>
<p>Some facts about WAF’s, which anyone considering of buying a WAF instead of securing his web application should read(quotes from the white paper’s conclusion):</p>
<ol>
<li>the additional layer of defense (WAF) is partly porous and does not replace the secure development and operation of web applications.</li>
<li>It also must not be overseen that a web application firewall is an additional device that is placed between the client and the web server and is therefore an additional device that can have influence on the availability of the overall system.</li>
<li>It is also an additional system that can have vulnerabilities or other forms of implementation flaws and requires regular maintenance.</li>
<li>Additionally it has been shown that web application firewalls can also be the target of successful attacks (cross-site scripting flaws, cross-site request forgery, denial of service, command execution, etc.)</li>
<li>When defining rules for a specific web application or modifying the standard Ruleset it is very important to test the whole web application and all provided functions for their correct functionality.  This can for example be done using automated testing frameworks. In the course of the project often certain functionalities of the web applications used for testing have been rendered unfunctional because of predefined rules of the web application firewalls. As unexpected side effects like this can occur with every change of the rules or the web application itself, comprehensive testing is necessary.</li>
</ol>
<p><a href="http://www.h4ck1nb3rg.at/wafs/final_project_documentation.pdf" target="_blank">Click here</a> to read eval($WAF); whitepaper.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.acunetix.com/blog/web-security-zone/whitepapers/web-application-firewalls-do-not-replace-secure-development/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Why File Upload Forms are a major security threat</title>
		<link>http://www.acunetix.com/blog/web-security-zone/whitepapers/why-file-upload-forms-are-a-major-security-threat/</link>
		<comments>http://www.acunetix.com/blog/web-security-zone/whitepapers/why-file-upload-forms-are-a-major-security-threat/#comments</comments>
		<pubDate>Wed, 27 May 2009 13:52:19 +0000</pubDate>
		<dc:creator>Robert Abela</dc:creator>
				<category><![CDATA[whitepapers]]></category>
		<category><![CDATA[Acunetix WVS]]></category>
		<category><![CDATA[file upload forms]]></category>
		<category><![CDATA[secure file upload forms]]></category>
		<category><![CDATA[security issues]]></category>
		<category><![CDATA[well known web applications]]></category>

		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=623</guid>
		<description><![CDATA[File upload forms, nowadays can be found allover the internet.  In social network web applications, such as Facebook and Twitter, in blogs, forums, e-banking sites, YouTube and also in corporate support portals, to give the ...]]></description>
			<content:encoded><![CDATA[<p>File upload forms, nowadays can be found allover the internet.  In social network web applications, such as Facebook and Twitter, in blogs, forums, e-banking sites, YouTube and also in corporate support portals, to give the opportunity to the end user to efficiently share files with corporate employees.  Users are allowed to upload images, videos, avatars and many other types of files.</p>
<p>Though, the more functionality provided to the end user, the greater is the risk of having a vulnerable web application and the chance that such functionality will be abused from malicious users, to gain access to a specific website, or to compromise a server is very high.</p>
<p>The following white paper, talks about a number of common security issues and vulnerabilities encountered while auditing file upload forms in several well known web applications.  It also explains how to build secure file upload forms.</p>
<p>You can read this whitepaper from <a href="http://www.acunetix.com/websitesecurity/upload-forms-threat.htm" target="_self">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.acunetix.com/blog/web-security-zone/whitepapers/why-file-upload-forms-are-a-major-security-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Finding the right web application scanner; why black box scanning is not enough</title>
		<link>http://www.acunetix.com/blog/web-security-zone/whitepapers/finding-the-right-web-application-scanner-why-black-box-scanning-is-not-enough/</link>
		<comments>http://www.acunetix.com/blog/web-security-zone/whitepapers/finding-the-right-web-application-scanner-why-black-box-scanning-is-not-enough/#comments</comments>
		<pubDate>Thu, 06 Nov 2008 09:42:03 +0000</pubDate>
		<dc:creator>Robert Abela</dc:creator>
				<category><![CDATA[whitepapers]]></category>
		<category><![CDATA[Acunetix WVS]]></category>
		<category><![CDATA[acusensor technology]]></category>

		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=101</guid>
		<description><![CDATA[This white paper shows how Acunetix AcuSensor Technology increases accuracy by combining black box scanning techniques with feedback from sensors placed inside the source code while the source code is executed.
Thanks to this innovative technology ...]]></description>
			<content:encoded><![CDATA[<p>This white paper shows how Acunetix AcuSensor Technology increases accuracy by combining black box scanning techniques with feedback from sensors placed inside the source code while the source code is executed.</p>
<p>Thanks to this innovative technology there are many advantages and many more vulnerabilities can now be found which with a typical black box scanner approach cannot be found. Another main advantage of using such technology is that when reporting a found vunlerability, the report provides more debug information such as the stack trace, the line where the source code leads to the found vulnerability and much more. </p>
<p>This helps developers and pen testers solve the found vulnerabilities in a shorter time and helps them understand more what lead to the reported vulnerability.  This also is a mean to train developers to write more secure code in future web applications.</p>
<p>You can read this whitepaper <a href="http://www.acunetix.com/websitesecurity/rightwvs.htm" target="_self">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.acunetix.com/blog/web-security-zone/whitepapers/finding-the-right-web-application-scanner-why-black-box-scanning-is-not-enough/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Services &#8211; The technology and its security concerns</title>
		<link>http://www.acunetix.com/blog/web-security-zone/whitepapers/web-services-technology-security/</link>
		<comments>http://www.acunetix.com/blog/web-security-zone/whitepapers/web-services-technology-security/#comments</comments>
		<pubDate>Mon, 08 Oct 2007 16:23:14 +0000</pubDate>
		<dc:creator>Robert Abela</dc:creator>
				<category><![CDATA[web security zone]]></category>
		<category><![CDATA[whitepapers]]></category>
		<category><![CDATA[automated scanning]]></category>
		<category><![CDATA[buffer overflow]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web services]]></category>
		<category><![CDATA[whitepaper]]></category>
		<category><![CDATA[xml injection]]></category>

		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=2691</guid>
		<description><![CDATA[This white paper examines the technology behind Web Services, how the system is made available to the user, and the way connections are made to back-end (and therefore sensitive) data. These different elements come together ...]]></description>
			<content:encoded><![CDATA[<p>This white paper examines the technology behind Web Services, how the system is made available to the user, and the way connections are made to back-end (and therefore sensitive) data. These different elements come together to make Web Services a portal for users to access data, but also provide different entry points which may be exploited for illegitimate purposes. These security flaws bring about the need for an added security-assessing component in the Acunetix WVS solution. Support for Web Services vulnerability scanning is now provided by a dedicated component which is specifically designed to detect exploitable entry-points in a Web Services system.</p>
<p>Click <a href="http://www.acunetix.com/websitesecurity/web-services-wp.htm" target="_self">here</a> to read the <a href="http://www.acunetix.com/websitesecurity/web-services-wp.htm" target="_self">Web Services &#8211; The technology and its security concerns</a> whitepaper.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.acunetix.com/blog/web-security-zone/whitepapers/web-services-technology-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Acunetix Publishes PCI Compliance Guide</title>
		<link>http://www.acunetix.com/blog/news/acunetix-pci-compliance-guide/</link>
		<comments>http://www.acunetix.com/blog/news/acunetix-pci-compliance-guide/#comments</comments>
		<pubDate>Wed, 30 May 2007 09:09:10 +0000</pubDate>
		<dc:creator>Robert Abela</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[web security zone]]></category>
		<category><![CDATA[whitepapers]]></category>
		<category><![CDATA[acunetix]]></category>
		<category><![CDATA[guidelines]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[pci compliance]]></category>
		<category><![CDATA[PCI DSS]]></category>

		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=2098</guid>
		<description><![CDATA[The paper aims to help companies meet impending PCI requirements
London, UK – May 30, 2007 – Businesses that rely on payment by credit cards are required to comply with the PCI security standards by September 2007. ...]]></description>
			<content:encoded><![CDATA[<p><strong>The paper aims to help companies meet impending PCI requirements</strong></p>
<p>London, UK – May 30, 2007 – <strong>Businesses that rely on payment by credit cards are required to comply with the PCI security standards by September 2007. Non compliance could result in loss of merchant account, severe fines and lawsuits. In view of these new regulations, Acunetix has published a PCI Compliance Guide to help companies understand the concept behind the Payment Card Industry as well as documenting the steps needed to reach compliance.</strong></p>
<p><strong>PCI Compliance at a glance<br />
</strong><a href="http://www.acunetix.com/blog/wp-content/uploads/2010/09/PCI-Logo.png"><img class="alignleft size-full wp-image-2099" title="PCI Logo" src="http://www.acunetix.com/blog/wp-content/uploads/2010/09/PCI-Logo.png" alt="" width="150" height="52" /></a>PCI Compliance  is a structured security checklist which aims at securing financial data, and helps to distinguish the secure and reliable businesses from the risky ones. The Payment Card Industry Data Security Standard was created in a joint effort by the major credit card companies: American Express, Visa, MasterCard and Discover to monitor and develop the PCI standard. Consumers who use credit/debit cards online to purchase products or services risk suffering financial losses when businesses process their transactions through systems which are not secure. The PCI standard aims to stop the cause of online financial and identity theft from its source by ensuring the systems which process and store customer details are secure.</p>
<p><strong>The Compliance Regulations</strong><br />
The PCI compliance specification describes a set of requirements which participating businesses must observe to ensure that correct measures are taken to secure all data, both internal and externally exposed. The <a href="../../websitesecurity/PCI-Compliance.pdf">Acunetix PCI Compliance Guide</a> describes the following categories in detail:</p>
<ol>
<li>Secure Network Design and Maintenance</li>
<li>Cardholder Data Protection</li>
<li>Vulnerability Management Program Maintenance</li>
<li>Strong Access Control Measures Implementation</li>
<li>Regular Network Testing and Monitoring</li>
<li>Information Security Policy Maintenance</li>
</ol>
<p><strong>Security Assessment Tools<br />
</strong>All businesses which apply the <a href="../websitesecurity/pci-compliance-wp.htm">PCI compliance</a> procedure must use the services of approved companies to perform compliance security scans. The results of these scans are issued in detailed compliance reports which are then used for approval by the specific card company requirements. The PCI Compliance specification is more than just a rule-set to which organizations must abide. It is also a guideline which provides a method to trace and secure all the potential security flaws which might be exploited. Detecting these potential exploits is made easier by using tools such as <a href="../../vulnerability-scanner/">web vulnerability scanners</a> and network scanners.</p>
<p>The PCI Compliance Guide is available at: <a href="../../websitesecurity/PCI-Compliance.pdf">http://www.acunetix.com/websitesecurity/PCI-Compliance.pdf</a></p>
<p><strong>About Acunetix Web Vulnerability Scanner<br />
</strong><a href="../../vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a> ensures website security by automatically checking for <a href="../vulnerability-scanner/sql-injection.htm">SQL injection</a>, <a href="../websitesecurity/xss.htm">Cross site scripting</a> and other vulnerabilities. It checks password strength on authentication pages and automatically audits shopping carts, forms, dynamic content and other web applications. As the scan is being completed, the software produces detailed reports that pinpoint where vulnerabilities exist. Acunetix WVS Reporting Application allows security alerts to be presented in a document which abides by the PCI specification.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.acunetix.com/blog/news/acunetix-pci-compliance-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Payment Card Industry Compliance</title>
		<link>http://www.acunetix.com/blog/web-security-zone/whitepapers/payment-card-industry-compliance/</link>
		<comments>http://www.acunetix.com/blog/web-security-zone/whitepapers/payment-card-industry-compliance/#comments</comments>
		<pubDate>Tue, 08 May 2007 16:17:12 +0000</pubDate>
		<dc:creator>Robert Abela</dc:creator>
				<category><![CDATA[web security zone]]></category>
		<category><![CDATA[whitepapers]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[merchant]]></category>
		<category><![CDATA[payment card industry compliance]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=2687</guid>
		<description><![CDATA[Securing both Merchant and Customer data
This white paper introduces the Payment Card Industry Compliance standard, and the security threats which brought about the need to standardize the data protection of both merchants and customers. The ...]]></description>
			<content:encoded><![CDATA[<p><strong>Securing both Merchant and Customer data</strong></p>
<p>This white paper introduces the Payment Card Industry Compliance standard, and the security threats which brought about the need to standardize the data protection of both merchants and customers. The internet is no longer just a source of information, but it is a trading universe where thousands of credit and debit card transactions are carried out every second. Private data is transmitted and stored online through systems which have been exploited numerous times, resulting in immense financial repercussions on both traders and buyers. PCI Compliance is a structured security checklist which aims at securing financial data, and helps to distinguish the secure and reliable businesses from the risky ones. This compliance structure is also used in the Acunetix WVS Reporting Application, and allows security alerts to be presented in a document which abides by the PCI specification.</p>
<p>Click <a href="http://www.acunetix.com/websitesecurity/pci-compliance-wp.htm" target="_self">here</a> to read the <a href="http://www.acunetix.com/websitesecurity/pci-compliance-wp.htm" target="_self">Payment Card Industry Compliance</a> whitepaper</p>
]]></content:encoded>
			<wfw:commentRss>http://www.acunetix.com/blog/web-security-zone/whitepapers/payment-card-industry-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are AJAX applications vulnerable to Hack Attacks?</title>
		<link>http://www.acunetix.com/blog/web-security-zone/whitepapers/ajax-applications-vulnerable-hack-attacks/</link>
		<comments>http://www.acunetix.com/blog/web-security-zone/whitepapers/ajax-applications-vulnerable-hack-attacks/#comments</comments>
		<pubDate>Thu, 08 Mar 2007 15:34:06 +0000</pubDate>
		<dc:creator>Robert Abela</dc:creator>
				<category><![CDATA[web security zone]]></category>
		<category><![CDATA[whitepapers]]></category>
		<category><![CDATA[ajax applications]]></category>
		<category><![CDATA[ajax security]]></category>
		<category><![CDATA[hack attacks]]></category>
		<category><![CDATA[whitepaper]]></category>

		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=2681</guid>
		<description><![CDATA[This paper reviews AJAX technologies with specific reference to JavaScript and Ajax Security.  It briefly documents the kinds of vulnerability classes that should raise security concerns among developers, website owners and the respective visitors. The ...]]></description>
			<content:encoded><![CDATA[<p>This paper reviews AJAX technologies with specific reference to <a href="http://www.acunetix.com/websitesecurity/javascript.htm" target="_self">JavaScript</a> and <a href="http://www.acunetix.com/websitesecurity/ajax.htm" target="_self">Ajax Security</a>.  It briefly documents the kinds of vulnerability classes that should raise security concerns among developers, website owners and the respective visitors. The proposed solution suggests auditing AJAX and JavaScript based applications with a web vulnerability scanner that not only parses the HTML code of a webpage to identify embedded JavaScript, but also executes the code. Automating the process is also key when considering the increasing complexity of such web applications.</p>
<p>Download the White Paper on <a href="http://www.acunetix.com/websitesecurity/ajax_applications.pdf" target="_blank">Ajax application security</a>.</p>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;"><span class="Apple-style-span" style="border-collapse: separate; color: #000000; font-family: 'Times New Roman'; font-size: 16px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"><span class="Apple-style-span" style="color: #2d2d2d; font-family: Verdana,sans-serif; font-size: 11px; line-height: 16px; text-align: left;">his paper reviews AJAX technologies with specific reference to<span class="Apple-converted-space"> </span><a style="margin: 0px; padding: 0px; border-width: 0px; outline-width: 0px; font-weight: normal; font-style: inherit; font-size: 11px; font-family: inherit; vertical-align: baseline; color: #e20a16; text-decoration: none;" href="../../websitesecurity/javascript.htm">JavaScript</a> and<span class="Apple-converted-space"> </span><a style="margin: 0px; padding: 0px; border-width: 0px; outline-width: 0px; font-weight: normal; font-style: inherit; font-size: 11px; font-family: inherit; vertical-align: baseline; color: #e20a16; text-decoration: none;" href="../../websitesecurity/ajax.htm">Ajax Security</a>.  It briefly documents the kinds of vulnerability classes that should raise security concerns among developers, website owners and the respective visitors. The proposed solution suggests auditing AJAX and JavaScript based applications with a web vulnerability scanner that not only parses the HTML code of a webpage to identify embedded JavaScript, but also executes the code. Automating the process is also key when considering the increasing complexity of such web applications.</span></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.acunetix.com/blog/web-security-zone/whitepapers/ajax-applications-vulnerable-hack-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Audit your Website security with Acunetix Web Vulnerability Scanner</title>
		<link>http://www.acunetix.com/blog/web-security-zone/whitepapers/audit-website-security-acunetix-web-vulnerability-scanner/</link>
		<comments>http://www.acunetix.com/blog/web-security-zone/whitepapers/audit-website-security-acunetix-web-vulnerability-scanner/#comments</comments>
		<pubDate>Mon, 12 Feb 2007 15:00:29 +0000</pubDate>
		<dc:creator>Robert Abela</dc:creator>
				<category><![CDATA[web security zone]]></category>
		<category><![CDATA[whitepapers]]></category>
		<category><![CDATA[Acunetix WVS]]></category>
		<category><![CDATA[getting started]]></category>
		<category><![CDATA[how to]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[website security]]></category>
		<category><![CDATA[whitepaper]]></category>

		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=2673</guid>
		<description><![CDATA[A practical “how to” using Acunetix Web Vulnerability Scanner &#8211; Auditing the security of your website with Acunetix WVS is easy. Acunetix WVS performs most of the steps in an automated manner and therefore giving ...]]></description>
			<content:encoded><![CDATA[<p>A practical “how to” using <a href="http://www.acunetix.com/vulnerability-scanner/" target="_self">Acunetix Web Vulnerability Scanner</a> &#8211; Auditing the security of your website with Acunetix WVS is easy. Acunetix WVS performs most of the steps in an automated manner and therefore giving you a good idea of your website security simply by launching a scan and reviewing the alerts. This White Paper walks you through the process of launching a security audit of your website using the Scan wizard (Refers to Acunetix WVS v.3)</p>
<p>Click <a href="http://www.acunetix.com/websitesecurity/website-auditing-wp.htm" target="_self">here</a> to read the whitepaper <a href="http://www.acunetix.com/websitesecurity/website-auditing-wp.htm" target="_self">Audit your Website Security with Acunetix Web Vulnerability Scanner</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.acunetix.com/blog/web-security-zone/whitepapers/audit-website-security-acunetix-web-vulnerability-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PHP and SQL Security</title>
		<link>http://www.acunetix.com/blog/web-security-zone/whitepapers/php-sql-security/</link>
		<comments>http://www.acunetix.com/blog/web-security-zone/whitepapers/php-sql-security/#comments</comments>
		<pubDate>Thu, 01 Feb 2007 10:45:59 +0000</pubDate>
		<dc:creator>Robert Abela</dc:creator>
				<category><![CDATA[web security zone]]></category>
		<category><![CDATA[whitepapers]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[scripts]]></category>
		<category><![CDATA[secure coding]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[whitepaper]]></category>

		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=2669</guid>
		<description><![CDATA[This white paper looks at some of the issues that should be considered every time a PHP script is written. Problems such as SQL Injections, Directory Traversal and other technical vulnerabilities, with well-designed code and ...]]></description>
			<content:encoded><![CDATA[<p>This white paper looks at some of the issues that should be considered every time a PHP script is written. Problems such as <a href="http://www.acunetix.com/websitesecurity/sql-injection.htm" target="_self">SQL Injections</a>, <a href="http://www.acunetix.com/websitesecurity/directory-traversal.htm" target="_self">Directory Traversal</a> and other technical vulnerabilities, with well-designed code and some basic security experience, can be eliminated entirely.</p>
<p>Click <a href="http://www.acunetix.com/websitesecurity/php-wp.htm" target="_self">here</a> to read the PHP and SQL Security whitepaper</p>
]]></content:encoded>
			<wfw:commentRss>http://www.acunetix.com/blog/web-security-zone/whitepapers/php-sql-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

