<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Acunetix Web Application Security Blog</title>
	<atom:link href="http://www.acunetix.com/blog/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.acunetix.com/blog</link>
	<description>Acunetix Web Application Security Blog</description>
	<lastBuildDate>Wed, 25 Jan 2012 13:32:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on FAQ: How can I backup my Acunetix WVS settings? by Robert Abela</title>
		<link>http://www.acunetix.com/blog/docs/backup-acunetix-settings-customizations/#comment-13973</link>
		<dc:creator>Robert Abela</dc:creator>
		<pubDate>Wed, 25 Jan 2012 13:32:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4704#comment-13973</guid>
		<description>Hi Dave,

Good point.  We will add it to the blog post.  In the meantime, if you need to re-install Acunetix Web Vulnerability Scanner on another server, simply send an email to our sales on sales@acunetix.com and they will give you further instructions.

Looking forward to hearing from you.</description>
		<content:encoded><![CDATA[<p>Hi Dave,</p>
<p>Good point.  We will add it to the blog post.  In the meantime, if you need to re-install Acunetix Web Vulnerability Scanner on another server, simply send an email to our sales on <a href="mailto:sales@acunetix.com">sales@acunetix.com</a> and they will give you further instructions.</p>
<p>Looking forward to hearing from you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FAQ: How can I backup my Acunetix WVS settings? by Dave Wood</title>
		<link>http://www.acunetix.com/blog/docs/backup-acunetix-settings-customizations/#comment-13971</link>
		<dc:creator>Dave Wood</dc:creator>
		<pubDate>Sun, 22 Jan 2012 23:22:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4704#comment-13971</guid>
		<description>Tha&#039;s a helpful article guys, but you failed to explain the most important consideration - the licensing!
How do we unregister the installation so that it may be redeployed on a rebuilt hardware for instance?
Or assuming one does not have this luxury due to catastrophic system failure; how does one go about activating after a new rebuild?

Thanks for a great product.</description>
		<content:encoded><![CDATA[<p>Tha&#8217;s a helpful article guys, but you failed to explain the most important consideration &#8211; the licensing!<br />
How do we unregister the installation so that it may be redeployed on a rebuilt hardware for instance?<br />
Or assuming one does not have this luxury due to catastrophic system failure; how does one go about activating after a new rebuild?</p>
<p>Thanks for a great product.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VIDEO: Acunetix Web Vulnerability Scanner 8 &#8211; What&#8217;s New? by administrator</title>
		<link>http://www.acunetix.com/blog/docs/video-wvs-8-whats-new/#comment-13914</link>
		<dc:creator>administrator</dc:creator>
		<pubDate>Wed, 04 Jan 2012 07:29:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4714#comment-13914</guid>
		<description>Hi Alan,

Thank you for showing interest in our BETA.

Please drop us an email on beta@acunetix.com.</description>
		<content:encoded><![CDATA[<p>Hi Alan,</p>
<p>Thank you for showing interest in our BETA.</p>
<p>Please drop us an email on <a href="mailto:beta@acunetix.com">beta@acunetix.com</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Preventing XSS Attacks by Louises Web Security &#187; VIDEO: How Cross-Site Scripting (XSS) Works</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/preventing-xss-attacks/#comment-13891</link>
		<dc:creator>Louises Web Security &#187; VIDEO: How Cross-Site Scripting (XSS) Works</dc:creator>
		<pubDate>Sat, 31 Dec 2011 00:32:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=2897#comment-13891</guid>
		<description>[...] this video tutorial I demonstrate what an XSS attack is to show you how a hacker can use XSS vulnerabilities to hack into your website. I start the [...]</description>
		<content:encoded><![CDATA[<p>[...] this video tutorial I demonstrate what an XSS attack is to show you how a hacker can use XSS vulnerabilities to hack into your website. I start the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Properly Scoping your Web Security Assessments by Louises Web Security &#187; Improving Web Security by Working With What You’ve Got</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/properly-scoping-web-security-assessments/#comment-13890</link>
		<dc:creator>Louises Web Security &#187; Improving Web Security by Working With What You’ve Got</dc:creator>
		<pubDate>Sat, 31 Dec 2011 00:31:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=3752#comment-13890</guid>
		<description>[...] that you’re thoughtful and careful about money and that the decisions you’re making regarding Web security are in the best interests of the business. You can be frugal and show management that you’re [...]</description>
		<content:encoded><![CDATA[<p>[...] that you’re thoughtful and careful about money and that the decisions you’re making regarding Web security are in the best interests of the business. You can be frugal and show management that you’re [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on &#8220;Time to market&#8221; no longer the security excuse by Louises Web Security &#187; Improving Web Security by Working With What You’ve Got</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/web-development-security-risk/#comment-13882</link>
		<dc:creator>Louises Web Security &#187; Improving Web Security by Working With What You’ve Got</dc:creator>
		<pubDate>Fri, 30 Dec 2011 02:29:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=3896#comment-13882</guid>
		<description>[...] November 5, 2011 at 6:02 am  As I wrote about in a previous post, we’re in the era of cutting back – if not completely eliminating – all non-essential [...]</description>
		<content:encoded><![CDATA[<p>[...] November 5, 2011 at 6:02 am  As I wrote about in a previous post, we’re in the era of cutting back – if not completely eliminating – all non-essential [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VIDEO: Acunetix Web Vulnerability Scanner 8 &#8211; What&#8217;s New? by Alan Wlasuk</title>
		<link>http://www.acunetix.com/blog/docs/video-wvs-8-whats-new/#comment-13873</link>
		<dc:creator>Alan Wlasuk</dc:creator>
		<pubDate>Thu, 29 Dec 2011 14:16:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4714#comment-13873</guid>
		<description>How do I sign up for the Beta program?</description>
		<content:encoded><![CDATA[<p>How do I sign up for the Beta program?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VIDEO: Acunetix Web Vulnerability Scanner 8 &#8211; What&#8217;s New? by Robert Abela</title>
		<link>http://www.acunetix.com/blog/docs/video-wvs-8-whats-new/#comment-13529</link>
		<dc:creator>Robert Abela</dc:creator>
		<pubDate>Fri, 09 Dec 2011 09:48:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4714#comment-13529</guid>
		<description>Hi Mikhail,

Thank you for showing interest in our product.

We are still not sure when it will be released.  It all depends on the feedback we get from BETA testers.  Things seem to be going very well, so the official release is very near :)</description>
		<content:encoded><![CDATA[<p>Hi Mikhail,</p>
<p>Thank you for showing interest in our product.</p>
<p>We are still not sure when it will be released.  It all depends on the feedback we get from BETA testers.  Things seem to be going very well, so the official release is very near <img src='http://www.acunetix.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Critical XSS Flaw Discovered in Barack Obama&#8217;s Website by TXT小说下载</title>
		<link>http://www.acunetix.com/blog/news/obama-email-servers-hacked-xss/#comment-13457</link>
		<dc:creator>TXT小说下载</dc:creator>
		<pubDate>Mon, 05 Dec 2011 10:19:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4307#comment-13457</guid>
		<description>Very nice bug and very hard to detect or exploit this kind of issue. Godd work anyway</description>
		<content:encoded><![CDATA[<p>Very nice bug and very hard to detect or exploit this kind of issue. Godd work anyway</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VIDEO: Acunetix Web Vulnerability Scanner 8 &#8211; What&#8217;s New? by Mikhail</title>
		<link>http://www.acunetix.com/blog/docs/video-wvs-8-whats-new/#comment-13452</link>
		<dc:creator>Mikhail</dc:creator>
		<pubDate>Sun, 04 Dec 2011 17:35:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4714#comment-13452</guid>
		<description>and when will be the official release?</description>
		<content:encoded><![CDATA[<p>and when will be the official release?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Acunetix Web Vulnerability Scanner 8 BETA Available Now by BoiteaWeb</title>
		<link>http://www.acunetix.com/blog/releases/acunetix-wvs-8-beta/#comment-13435</link>
		<dc:creator>BoiteaWeb</dc:creator>
		<pubDate>Fri, 02 Dec 2011 09:03:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4508#comment-13435</guid>
		<description>Thank you Robert.
I&#039;m glad to become a beta tester for WSV8 !</description>
		<content:encoded><![CDATA[<p>Thank you Robert.<br />
I&#8217;m glad to become a beta tester for WSV8 !</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VIDEO: Acunetix Web Vulnerability Scanner 8 &#8211; What&#8217;s New? by Robert Abela</title>
		<link>http://www.acunetix.com/blog/docs/video-wvs-8-whats-new/#comment-13392</link>
		<dc:creator>Robert Abela</dc:creator>
		<pubDate>Wed, 30 Nov 2011 08:42:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4714#comment-13392</guid>
		<description>Hi Mikhail,

Thank you for showing interest in our product.  The new version is still in BETA.  Once there is an official release, you will be alerted to upgrade.</description>
		<content:encoded><![CDATA[<p>Hi Mikhail,</p>
<p>Thank you for showing interest in our product.  The new version is still in BETA.  Once there is an official release, you will be alerted to upgrade.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VIDEO: Acunetix Web Vulnerability Scanner 8 &#8211; What&#8217;s New? by MIkhail</title>
		<link>http://www.acunetix.com/blog/docs/video-wvs-8-whats-new/#comment-13238</link>
		<dc:creator>MIkhail</dc:creator>
		<pubDate>Fri, 25 Nov 2011 00:16:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4714#comment-13238</guid>
		<description>If released new version, why i can&#039;t see in &quot;program update&quot; new build is available Acunetix 8?</description>
		<content:encoded><![CDATA[<p>If released new version, why i can&#8217;t see in &#8220;program update&#8221; new build is available Acunetix 8?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MySQL.com Victim of SQL Injection Attack by Louises Web Security &#187; SQL Injection – The Web Flaw That Keeps on Giving</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/mysql-com-victim-of-sql-injection/#comment-13110</link>
		<dc:creator>Louises Web Security &#187; SQL Injection – The Web Flaw That Keeps on Giving</dc:creator>
		<pubDate>Sun, 20 Nov 2011 00:49:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=3220#comment-13110</guid>
		<description>[...] in the past year, we’ve seen numerous high-profile SQL injection attacks against businesses such as Barracuda Networks, Expedia and HBGary. If it’s happening to [...]</description>
		<content:encoded><![CDATA[<p>[...] in the past year, we’ve seen numerous high-profile SQL injection attacks against businesses such as Barracuda Networks, Expedia and HBGary. If it’s happening to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Preventing XSS Attacks by Louises Web Security &#187; Critical XSS Flaw Discovered in Barack Obama’s Website</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/preventing-xss-attacks/#comment-13109</link>
		<dc:creator>Louises Web Security &#187; Critical XSS Flaw Discovered in Barack Obama’s Website</dc:creator>
		<pubDate>Sun, 20 Nov 2011 00:49:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=2897#comment-13109</guid>
		<description>[...] time that the president’s website was targeted. About a year ago SecurityShell reported a similar XSS vulnerability on their [...]</description>
		<content:encoded><![CDATA[<p>[...] time that the president’s website was targeted. About a year ago SecurityShell reported a similar XSS vulnerability on their [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Statistics from 10,000 leaked Hotmail passwords by 500 Most Common Passwords &#124; Negative Foo</title>
		<link>http://www.acunetix.com/blog/news/statistics-from-10000-leaked-hotmail-passwords/#comment-13097</link>
		<dc:creator>500 Most Common Passwords &#124; Negative Foo</dc:creator>
		<pubDate>Fri, 18 Nov 2011 23:46:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=750#comment-13097</guid>
		<description>[...] recent post at Acunetix shows statistics on 10,000 recently leaked Hotmail passwords. The ten most common passwords on [...]</description>
		<content:encoded><![CDATA[<p>[...] recent post at Acunetix shows statistics on 10,000 recently leaked Hotmail passwords. The ten most common passwords on [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Statistics from 10,000 leaked Hotmail passwords by Seguridad Informática: recomendaciones básicas para los usuarios</title>
		<link>http://www.acunetix.com/blog/news/statistics-from-10000-leaked-hotmail-passwords/#comment-13055</link>
		<dc:creator>Seguridad Informática: recomendaciones básicas para los usuarios</dc:creator>
		<pubDate>Wed, 16 Nov 2011 18:02:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=750#comment-13055</guid>
		<description>[...] sobre las contraseñas más comunes usadas en Hotmail (en inglés) www.acunetix.com/blog/websecuritynews/s&#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] sobre las contraseñas más comunes usadas en Hotmail (en inglés) <a href="http://www.acunetix.com/blog/websecuritynews/s&#8230" rel="nofollow">http://www.acunetix.com/blog/websecuritynews/s&#8230</a>; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Why people violate security policies by wifihead</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/why-violate-security-policies/#comment-12982</link>
		<dc:creator>wifihead</dc:creator>
		<pubDate>Thu, 03 Nov 2011 21:52:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4421#comment-12982</guid>
		<description>I appreciate the fact that #1 stated &quot;Users don’t appreciate the business reasons behind the policies&quot;. This to me is the major reason for failures and non-compliance. When we analyze the implications, it falls directly on the lap of upper management. Too many times things, both hardware and software, solutions, rules, regulations and a myriad of others are introduced into the network without communication. People are innately sensible. If a user is presented with a proposed change and is educated as to the why, how, when and where, most will fall in.The problems show up when there was no structure before, everything went everywhere, and suddenly users are told to buckle up.Any user who values his/her job will comply if they are educated and are aware of the consequences of non-compliance.I agree that in most environments the users are aware that policies will not be enforced because they are cognizant that the network is understaffed.I think that incentives can go a long way in having users comply. Just sayin.</description>
		<content:encoded><![CDATA[<p>I appreciate the fact that #1 stated &#8220;Users don’t appreciate the business reasons behind the policies&#8221;. This to me is the major reason for failures and non-compliance. When we analyze the implications, it falls directly on the lap of upper management. Too many times things, both hardware and software, solutions, rules, regulations and a myriad of others are introduced into the network without communication. People are innately sensible. If a user is presented with a proposed change and is educated as to the why, how, when and where, most will fall in.The problems show up when there was no structure before, everything went everywhere, and suddenly users are told to buckle up.Any user who values his/her job will comply if they are educated and are aware of the consequences of non-compliance.I agree that in most environments the users are aware that policies will not be enforced because they are cognizant that the network is understaffed.I think that incentives can go a long way in having users comply. Just sayin.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VIDEO: How Cross-Site Scripting (XSS) Works by Wladimir</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/video-how-cross-site-scripting-xss-works/#comment-12979</link>
		<dc:creator>Wladimir</dc:creator>
		<pubDate>Thu, 03 Nov 2011 12:33:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4372#comment-12979</guid>
		<description>better this ... impossible...</description>
		<content:encoded><![CDATA[<p>better this &#8230; impossible&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VIDEO: How Cross-Site Scripting (XSS) Works by Logan</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/video-how-cross-site-scripting-xss-works/#comment-12967</link>
		<dc:creator>Logan</dc:creator>
		<pubDate>Thu, 27 Oct 2011 14:18:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4372#comment-12967</guid>
		<description>Thanks! Makes XSS easier to understand with your example</description>
		<content:encoded><![CDATA[<p>Thanks! Makes XSS easier to understand with your example</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Authentication Tester Tool by Tinychat Vulnerabilities &#38; Talking with the CEO &#171; Work for the Internet</title>
		<link>http://www.acunetix.com/blog/docs/authentication-tester/#comment-12961</link>
		<dc:creator>Tinychat Vulnerabilities &#38; Talking with the CEO &#171; Work for the Internet</dc:creator>
		<pubDate>Tue, 25 Oct 2011 04:59:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=1885#comment-12961</guid>
		<description>[...] names and analytics of the top 60,000 users on Tinychat. When it comes to cracking accounts, Acunetix&#8217;s Authentication Tester is a huge luxury. It works nicely on just about 80% of the sites I&#8217;ve played with. Bryan is [...]</description>
		<content:encoded><![CDATA[<p>[...] names and analytics of the top 60,000 users on Tinychat. When it comes to cracking accounts, Acunetix&#8217;s Authentication Tester is a huge luxury. It works nicely on just about 80% of the sites I&#8217;ve played with. Bryan is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VIDEO: How Cross-Site Scripting (XSS) Works by JJ</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/video-how-cross-site-scripting-xss-works/#comment-12952</link>
		<dc:creator>JJ</dc:creator>
		<pubDate>Mon, 24 Oct 2011 01:37:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4372#comment-12952</guid>
		<description>nice and informative indeed - nice to see it in practice too</description>
		<content:encoded><![CDATA[<p>nice and informative indeed &#8211; nice to see it in practice too</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Statistics from 10,000 leaked Hotmail passwords by 97views</title>
		<link>http://www.acunetix.com/blog/news/statistics-from-10000-leaked-hotmail-passwords/#comment-12888</link>
		<dc:creator>97views</dc:creator>
		<pubDate>Mon, 17 Oct 2011 15:51:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=750#comment-12888</guid>
		<description>the phishing kit used most probably was badly designed, since it was one that didn’t further authenticated the users to the Hotmail/Live website. I think it just returned an error message after grabbing the credentials.</description>
		<content:encoded><![CDATA[<p>the phishing kit used most probably was badly designed, since it was one that didn’t further authenticated the users to the Hotmail/Live website. I think it just returned an error message after grabbing the credentials.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VIDEO: How Cross-Site Scripting (XSS) Works by Jacks</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/video-how-cross-site-scripting-xss-works/#comment-12874</link>
		<dc:creator>Jacks</dc:creator>
		<pubDate>Sun, 16 Oct 2011 06:42:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4372#comment-12874</guid>
		<description>Wow.Great video.Very informative and well presented.</description>
		<content:encoded><![CDATA[<p>Wow.Great video.Very informative and well presented.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VIDEO: How Cross-Site Scripting (XSS) Works by George</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/video-how-cross-site-scripting-xss-works/#comment-12849</link>
		<dc:creator>George</dc:creator>
		<pubDate>Wed, 12 Oct 2011 15:32:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4372#comment-12849</guid>
		<description>The scream is a little loud...</description>
		<content:encoded><![CDATA[<p>The scream is a little loud&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Improving Web Security by Working With What You’ve Got by Improving Web Security by Working With What You’ve Got &#124; National Cyber Security</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/improving-web-security/#comment-12772</link>
		<dc:creator>Improving Web Security by Working With What You’ve Got &#124; National Cyber Security</dc:creator>
		<pubDate>Thu, 06 Oct 2011 11:31:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4121#comment-12772</guid>
		<description>[...] As I wrote about in a previous post, we’re in the era of cutting back – if not completely eliminating – all non-essential expenditures. The thing is what may seem to be non-essential to management may actually be essential to the business. There could just be a disconnect — or communication breakdown — between you, your team, and the managers ultimately making the decisions. Politics and opinions aside, you have to think creatively about how you can make small improvements in Web application security across numerous areas of the business if you’re going to move your Web security program forward. How can you do this? You need to prove that you’re thoughtful and careful about money and that the decisions you’re making regarding Web security are in the best interests of the business. You can be frugal and show management that you’re willing and able to cut back, deal with what you’ve got and find ways to make things work better that may have been overlooked the past. For example, one thing I see quite often is network administrators and security managers not taking advantage of Web security (continue reading&#8230;) [...]</description>
		<content:encoded><![CDATA[<p>[...] As I wrote about in a previous post, we’re in the era of cutting back – if not completely eliminating – all non-essential expenditures. The thing is what may seem to be non-essential to management may actually be essential to the business. There could just be a disconnect — or communication breakdown — between you, your team, and the managers ultimately making the decisions. Politics and opinions aside, you have to think creatively about how you can make small improvements in Web application security across numerous areas of the business if you’re going to move your Web security program forward. How can you do this? You need to prove that you’re thoughtful and careful about money and that the decisions you’re making regarding Web security are in the best interests of the business. You can be frugal and show management that you’re willing and able to cut back, deal with what you’ve got and find ways to make things work better that may have been overlooked the past. For example, one thing I see quite often is network administrators and security managers not taking advantage of Web security (continue reading&#8230;) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Explaining the “why” of Web application security by Explaining the “why” of Web application security &#124; National Cyber Security</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/why-webapp-security/#comment-12726</link>
		<dc:creator>Explaining the “why” of Web application security &#124; National Cyber Security</dc:creator>
		<pubDate>Fri, 30 Sep 2011 16:42:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4137#comment-12726</guid>
		<description>[...] Looking at the bigger picture of application security it seems that no one else really hears us. Sure, product managers, marketing, legal, HR and even certain people in management say they understand what’s at stake. But are they really on board? Business leaders have learned that they must teach, train and develop their employees. Otherwise, they can’t expect people to perform at their highest levels. The same goes for us working in and around IT and Web application security. We can try to be high and mighty telling people the sky is falling because our Web applications aren’t secure. We can tell people all day – every day – that they can’t do this, that or the other – all in the name of Web security. But we have to be realistic and ask: how’s that working for us? Skipping formal teaching, training, and development, and instead forcing Web security on other people doesn’t work all that well. It’s like trying force a religion or political ideology on others and expecting them to just say “Okay, whatever you say.” People and politics just don’t work that way. In fact, many people couldn’t care less about Web application security. Just because something is important to us doesn’t mean (continue reading&#8230;) [...]</description>
		<content:encoded><![CDATA[<p>[...] Looking at the bigger picture of application security it seems that no one else really hears us. Sure, product managers, marketing, legal, HR and even certain people in management say they understand what’s at stake. But are they really on board? Business leaders have learned that they must teach, train and develop their employees. Otherwise, they can’t expect people to perform at their highest levels. The same goes for us working in and around IT and Web application security. We can try to be high and mighty telling people the sky is falling because our Web applications aren’t secure. We can tell people all day – every day – that they can’t do this, that or the other – all in the name of Web security. But we have to be realistic and ask: how’s that working for us? Skipping formal teaching, training, and development, and instead forcing Web security on other people doesn’t work all that well. It’s like trying force a religion or political ideology on others and expecting them to just say “Okay, whatever you say.” People and politics just don’t work that way. In fact, many people couldn’t care less about Web application security. Just because something is important to us doesn’t mean (continue reading&#8230;) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SQL Injection &#8211; The Web Flaw That Keeps on Giving by Episode 480 &#8211; Holy Flyin’ SCADA systems, Evil Face Cookies, Seattle Wardrivers, BEAST Slayer, SQLi, Sony &#124; InfoSec Daily</title>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/sql-injection-prevalent-hack/#comment-12697</link>
		<dc:creator>Episode 480 &#8211; Holy Flyin’ SCADA systems, Evil Face Cookies, Seattle Wardrivers, BEAST Slayer, SQLi, Sony &#124; InfoSec Daily</dc:creator>
		<pubDate>Tue, 27 Sep 2011 01:16:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4296#comment-12697</guid>
		<description>[...] Source: &#160;http://www.acunetix.com/blog/web-security-zone/articles/sql-injection-prevalent-hack/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Source: &nbsp;<a href="http://www.acunetix.com/blog/web-security-zone/articles/sql-injection-prevalent-hack/" rel="nofollow">http://www.acunetix.com/blog/web-security-zone/articles/sql-injection-prevalent-hack/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Critical XSS Flaw Discovered in Barack Obama&#8217;s Website by Darius</title>
		<link>http://www.acunetix.com/blog/news/obama-email-servers-hacked-xss/#comment-12660</link>
		<dc:creator>Darius</dc:creator>
		<pubDate>Thu, 22 Sep 2011 09:47:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=4307#comment-12660</guid>
		<description>Now the description is much better then the first article. Very nice bug and very hard to detect or exploit this kind of issue. Godd work anyway</description>
		<content:encoded><![CDATA[<p>Now the description is much better then the first article. Very nice bug and very hard to detect or exploit this kind of issue. Godd work anyway</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hackers Slurp over a million user accounts from Washington Post by Salman</title>
		<link>http://www.acunetix.com/blog/news/million-user-accounts-from-washington-post-stolen/#comment-12659</link>
		<dc:creator>Salman</dc:creator>
		<pubDate>Thu, 22 Sep 2011 08:57:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=3799#comment-12659</guid>
		<description>Are they not encrypting every bit of data which enters their (unprotected) databases?</description>
		<content:encoded><![CDATA[<p>Are they not encrypting every bit of data which enters their (unprotected) databases?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

