<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mostly Harmless &#187; Security</title>
	<atom:link href="http://blog.rowancrane.com/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.rowancrane.com</link>
	<description>Rowan Crane's Blog</description>
	<lastBuildDate>Mon, 05 Dec 2011 23:14:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Why displaying your friends list on social networking sites is a bad idea</title>
		<link>http://blog.rowancrane.com/2009/04/12/why-displaying-your-friends-list-on-social-networking-sites-is-a-bad-idea</link>
		<comments>http://blog.rowancrane.com/2009/04/12/why-displaying-your-friends-list-on-social-networking-sites-is-a-bad-idea#comments</comments>
		<pubDate>Sun, 12 Apr 2009 11:57:17 +0000</pubDate>
		<dc:creator>Rowan</dc:creator>
				<category><![CDATA[Internet Anonymity]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.rowancrane.com/?p=149</guid>
		<description><![CDATA[<p>This is obvious, but also clever in the way of many clever things in that the attack is only obvious after it&#8217;s been explained to you. In short, if an attacker sucessfully impersonates someone you know, or gives you the impression you may / should know them, they may be able to exploit you.</p> <p>Like [...]]]></description>
		<wfw:commentRss>http://blog.rowancrane.com/2009/04/12/why-displaying-your-friends-list-on-social-networking-sites-is-a-bad-idea/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How long can a vulnerable web script last online before it is compromised?</title>
		<link>http://blog.rowancrane.com/2008/12/13/how-long-can-a-vulnerable-web-script-last-online-before-it-is-compromised</link>
		<comments>http://blog.rowancrane.com/2008/12/13/how-long-can-a-vulnerable-web-script-last-online-before-it-is-compromised#comments</comments>
		<pubDate>Sat, 13 Dec 2008 14:10:21 +0000</pubDate>
		<dc:creator>Rowan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[Web Hosting]]></category>

		<guid isPermaLink="false">http://blog.rowancrane.com/?p=90</guid>
		<description><![CDATA[<p>Remember some years ago now all the (justifiable) furore around how long you could connect a vulnerable Windows PC to the net for before it got hacked / infected? The statistic ended up being 20 minutes, i.e not long at all.</p> <p>I&#8217;ve not seen any similar research (at least as widely publicised) for popular web [...]]]></description>
		<wfw:commentRss>http://blog.rowancrane.com/2008/12/13/how-long-can-a-vulnerable-web-script-last-online-before-it-is-compromised/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacked WordPress Recovery</title>
		<link>http://blog.rowancrane.com/2008/06/17/hacked-wordpress-recovery</link>
		<comments>http://blog.rowancrane.com/2008/06/17/hacked-wordpress-recovery#comments</comments>
		<pubDate>Tue, 17 Jun 2008 16:53:37 +0000</pubDate>
		<dc:creator>Rowan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Support]]></category>

		<guid isPermaLink="false">http://blog.rowancrane.com/?p=72</guid>
		<description><![CDATA[<p>Interesting to see this post from WP developer Donnacha, on removing various popular nasties from a wordpress install after it has been hacked or compromised.</p> <p>At work we often see instances where it is not possible to simply return a user&#8217;s CMS install to a pre-hack backup and then upgrade (the safest course of action) [...]]]></description>
		<wfw:commentRss>http://blog.rowancrane.com/2008/06/17/hacked-wordpress-recovery/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anonym.OS alternatives? &#8211; xB Machine</title>
		<link>http://blog.rowancrane.com/2008/01/23/anonymos-alternatives-xb-machine</link>
		<comments>http://blog.rowancrane.com/2008/01/23/anonymos-alternatives-xb-machine#comments</comments>
		<pubDate>Wed, 23 Jan 2008 17:54:08 +0000</pubDate>
		<dc:creator>Rowan</dc:creator>
				<category><![CDATA[Internet Anonymity]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.rowancrane.com/2008/01/23/anonymos-alternatives-xb-machine</guid>
		<description><![CDATA[<p>A couple of weeks ago I was wondering on what happened to Anonym.OS. After a little searching around I came across xB Machine.</p> <p>Xerobank appear to be one of those &#8220;secure browsing for a fee&#8221; organisations offering browser plugins and networks in order to protect your privacy while on the web in exchange for a [...]]]></description>
		<wfw:commentRss>http://blog.rowancrane.com/2008/01/23/anonymos-alternatives-xb-machine/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Read Crypto-gram and feel better?</title>
		<link>http://blog.rowancrane.com/2007/06/18/read-crypto-gram-and-feel-better</link>
		<comments>http://blog.rowancrane.com/2007/06/18/read-crypto-gram-and-feel-better#comments</comments>
		<pubDate>Mon, 18 Jun 2007 22:50:29 +0000</pubDate>
		<dc:creator>Rowan</dc:creator>
				<category><![CDATA[Personal Entries]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.rowancrane.com/2007/06/18/read-crypto-gram-and-feel-better/</guid>
		<description><![CDATA[<p>I&#8217;ve been a reader of Bruce Schneier&#8217;s CRYPTO-GRAM newsletter for some years now and it always inspires mixed feelings. Schneier writes with authority on security, terrorism and the psychology of both. At the danger of being misrepresentative, here&#8217;s a quote</p> <p> &#8220;We worry about airplane crashes and rampaging shooters instead of automobile crashes and domestic [...]]]></description>
		<wfw:commentRss>http://blog.rowancrane.com/2007/06/18/read-crypto-gram-and-feel-better/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tracking down vulnerable web apps on a hosting service</title>
		<link>http://blog.rowancrane.com/2007/03/03/tracking-down-vulnerable-web-apps-on-a-hosting-service</link>
		<comments>http://blog.rowancrane.com/2007/03/03/tracking-down-vulnerable-web-apps-on-a-hosting-service#comments</comments>
		<pubDate>Sat, 03 Mar 2007 15:23:38 +0000</pubDate>
		<dc:creator>Rowan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[Web Hosting]]></category>

		<guid isPermaLink="false">http://blog.rowancrane.com/2007/03/03/tracking-down-vulnerable-web-apps-on-a-hosting-service/</guid>
		<description><![CDATA[<p>Looks like one of the worst things that can happen to a web app project has happened to wordpress &#8211; one of their releases was compromised by a &#8220;cracker&#8221;</p> <p>http://wordpress.org/development/2007/03/upgrade-212/</p> <p>I was in the &#8220;at risk&#8221; group of recent installs so have upgraded as soon as I saw the news post. The difficulty for server [...]]]></description>
		<wfw:commentRss>http://blog.rowancrane.com/2007/03/03/tracking-down-vulnerable-web-apps-on-a-hosting-service/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

