<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Windows Short (8.3) Filenames &#8211; A Security Nightmare?</title>
	<atom:link href="http://www.acunetix.com/blog/web-security-zone/articles/windows-short-8-3-filenames-web-security-problem/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.acunetix.com/blog/web-security-zone/windows-short-8-3-filenames-web-security-problem/</link>
	<description>Web Vulnerability Scanner</description>
	<lastBuildDate>Thu, 23 May 2013 22:23:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Rstar&#039;s Blog &#187; IIS短文件/文件夹漏洞(汇总整理)</title>
		<link>http://www.acunetix.com/blog/web-security-zone/windows-short-8-3-filenames-web-security-problem/#comment-638</link>
		<dc:creator>Rstar&#039;s Blog &#187; IIS短文件/文件夹漏洞(汇总整理)</dc:creator>
		<pubDate>Tue, 24 Jul 2012 08:24:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=5987#comment-638</guid>
		<description><![CDATA[[...] Soroush Dalili的文章，这篇文章里暴露了两个问题。 [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Soroush Dalili的文章，这篇文章里暴露了两个问题。 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kolektory słoneczne</title>
		<link>http://www.acunetix.com/blog/web-security-zone/windows-short-8-3-filenames-web-security-problem/#comment-637</link>
		<dc:creator>kolektory słoneczne</dc:creator>
		<pubDate>Mon, 23 Jul 2012 07:33:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=5987#comment-637</guid>
		<description><![CDATA[A interesting post right there mate . Thanks for posting !]]></description>
		<content:encoded><![CDATA[<p>A interesting post right there mate . Thanks for posting !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mark</title>
		<link>http://www.acunetix.com/blog/web-security-zone/windows-short-8-3-filenames-web-security-problem/#comment-636</link>
		<dc:creator>mark</dc:creator>
		<pubDate>Tue, 10 Jul 2012 07:59:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=5987#comment-636</guid>
		<description><![CDATA[Applications should store backups in the hidden folders such as app_data, then the issue does not rise. It&#039;s just an example of bad configuration if the backup files are in public folders that are exposed using http.]]></description>
		<content:encoded><![CDATA[<p>Applications should store backups in the hidden folders such as app_data, then the issue does not rise. It&#8217;s just an example of bad configuration if the backup files are in public folders that are exposed using http.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: IIS短文件/文件夹漏洞(汇总整理)- FreebuF.COM</title>
		<link>http://www.acunetix.com/blog/web-security-zone/windows-short-8-3-filenames-web-security-problem/#comment-635</link>
		<dc:creator>IIS短文件/文件夹漏洞(汇总整理)- FreebuF.COM</dc:creator>
		<pubDate>Mon, 09 Jul 2012 05:15:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=5987#comment-635</guid>
		<description><![CDATA[[...] Soroush Dalili的文章，这篇文章里暴露了两个问题。 [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Soroush Dalili的文章，这篇文章里暴露了两个问题。 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogdan Calin</title>
		<link>http://www.acunetix.com/blog/web-security-zone/windows-short-8-3-filenames-web-security-problem/#comment-634</link>
		<dc:creator>Bogdan Calin</dc:creator>
		<pubDate>Fri, 06 Jul 2012 08:19:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=5987#comment-634</guid>
		<description><![CDATA[None that I&#039;m aware of.]]></description>
		<content:encoded><![CDATA[<p>None that I&#8217;m aware of.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Raphael</title>
		<link>http://www.acunetix.com/blog/web-security-zone/windows-short-8-3-filenames-web-security-problem/#comment-633</link>
		<dc:creator>Raphael</dc:creator>
		<pubDate>Fri, 06 Jul 2012 01:30:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=5987#comment-633</guid>
		<description><![CDATA[Is there a SFN Disclosure Vulnerability about apache on windows?]]></description>
		<content:encoded><![CDATA[<p>Is there a SFN Disclosure Vulnerability about apache on windows?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.acunetix.com/blog/web-security-zone/windows-short-8-3-filenames-web-security-problem/#comment-632</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Tue, 03 Jul 2012 19:28:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=5987#comment-632</guid>
		<description><![CDATA[I really don&#039;t think that relying on a long/complex filename instead of moving it out of web root represents any kind of security measure.
Specially in a wordpress plugin, since you can have a web server with directory listing set to on.]]></description>
		<content:encoded><![CDATA[<p>I really don&#8217;t think that relying on a long/complex filename instead of moving it out of web root represents any kind of security measure.<br />
Specially in a wordpress plugin, since you can have a web server with directory listing set to on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sad</title>
		<link>http://www.acunetix.com/blog/web-security-zone/windows-short-8-3-filenames-web-security-problem/#comment-631</link>
		<dc:creator>Sad</dc:creator>
		<pubDate>Tue, 03 Jul 2012 18:26:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=5987#comment-631</guid>
		<description><![CDATA[Um, how is Linux affected by this problem? Linux doesn&#039;t automatically create and translate DOS compatible filenames.

And the solution is simple, disallow tilde altogether via htaccess or simply disallow [a-Z]{cnt}~{0-9}]]></description>
		<content:encoded><![CDATA[<p>Um, how is Linux affected by this problem? Linux doesn&#8217;t automatically create and translate DOS compatible filenames.</p>
<p>And the solution is simple, disallow tilde altogether via htaccess or simply disallow [a-Z]{cnt}~{0-9}</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogdan Calin</title>
		<link>http://www.acunetix.com/blog/web-security-zone/windows-short-8-3-filenames-web-security-problem/#comment-630</link>
		<dc:creator>Bogdan Calin</dc:creator>
		<pubDate>Tue, 03 Jul 2012 17:40:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=5987#comment-630</guid>
		<description><![CDATA[Yes, Linux is not affected by this problem. However the backup problem was just an example. Any web application that is using the name of a file as a security measure will be affected by this.]]></description>
		<content:encoded><![CDATA[<p>Yes, Linux is not affected by this problem. However the backup problem was just an example. Any web application that is using the name of a file as a security measure will be affected by this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon SC</title>
		<link>http://www.acunetix.com/blog/web-security-zone/windows-short-8-3-filenames-web-security-problem/#comment-629</link>
		<dc:creator>Simon SC</dc:creator>
		<pubDate>Tue, 03 Jul 2012 16:08:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=5987#comment-629</guid>
		<description><![CDATA[Interesting and useful advice. Of course, a solution would be to use a Linux or OS X computer running Apache -- that would offer better protection against this. But the registry addition is a good nugget.

Also, maybe backups should be stored off-site?]]></description>
		<content:encoded><![CDATA[<p>Interesting and useful advice. Of course, a solution would be to use a Linux or OS X computer running Apache &#8212; that would offer better protection against this. But the registry addition is a good nugget.</p>
<p>Also, maybe backups should be stored off-site?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
