<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Architecting Security</title>
	<atom:link href="http://www.architectingsecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.architectingsecurity.com</link>
	<description></description>
	<lastBuildDate>Tue, 24 Apr 2012 06:42:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Pentesting of Authentication Bypass via SQL-Injection with Burpsuite Intruder</title>
		<link>http://www.architectingsecurity.com/2012/04/23/pentesting-of-authentication-bypass-via-sql-injection-with-burpsuite-intruder/</link>
		<comments>http://www.architectingsecurity.com/2012/04/23/pentesting-of-authentication-bypass-via-sql-injection-with-burpsuite-intruder/#comments</comments>
		<pubDate>Mon, 23 Apr 2012 09:59:28 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Password Security]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[Appscan]]></category>
		<category><![CDATA[authentication bypass]]></category>
		<category><![CDATA[burp]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=460</guid>
		<description><![CDATA[A login process containing SQL injection vulnerability can be bypassed by attackers. They need to manipulate username or password parameters and thus access to the application (even as administrator) without knowing the original user credentials. This is known as &#8220;Authentication Bypass via SQL-Injection&#8221;. In this post, I want to explain how a penetration tester can [...]]]></description>
		<wfw:commentRss>http://www.architectingsecurity.com/2012/04/23/pentesting-of-authentication-bypass-via-sql-injection-with-burpsuite-intruder/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mahremiyet İhlalleri -2 (Privacy Violations)</title>
		<link>http://www.architectingsecurity.com/2012/03/07/mahremiyet-ihlalleri-2-privacy-violations/</link>
		<comments>http://www.architectingsecurity.com/2012/03/07/mahremiyet-ihlalleri-2-privacy-violations/#comments</comments>
		<pubDate>Wed, 07 Mar 2012 14:30:21 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[mahremiyet ihlalleri]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[Turkey]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=431</guid>
		<description><![CDATA[Bu yazımda mahremiyet ihlallerine konusuna devam etmek istiyorum. Bu seferki ihlali gerçekleştiren Maliye Bakanlığına bağlı Gelir İdaresi Başkanlığı. Bu devlet kurumu gerçekleştirdiği bir online uygulama ile kira geliri beyan işlemini İnternet ortamına taşımışlar. Hizmet güzel ancak uygulamaya girme işlemi hiç güvenli değil. Aşağıdaki resimde görüldüğü üzere uygulamaya girmek ve kişisel bilgilere erişmek için sadece T.C. [...]]]></description>
		<wfw:commentRss>http://www.architectingsecurity.com/2012/03/07/mahremiyet-ihlalleri-2-privacy-violations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Web Application Security Check List in English</title>
		<link>http://www.architectingsecurity.com/2012/02/28/the-web-application-security-check-list-in-english/</link>
		<comments>http://www.architectingsecurity.com/2012/02/28/the-web-application-security-check-list-in-english/#comments</comments>
		<pubDate>Tue, 28 Feb 2012 00:29:53 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Secure SDLC]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[checklist]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[secure sdlc]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=427</guid>
		<description><![CDATA[In my previous post, I did mention the web application security check list for auditors. The check list has been now translated into English. For the details, see the Google project site.]]></description>
		<wfw:commentRss>http://www.architectingsecurity.com/2012/02/28/the-web-application-security-check-list-in-english/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Application Security Check List, version 2</title>
		<link>http://www.architectingsecurity.com/2012/01/11/web-app-sec-checklist-v2/</link>
		<comments>http://www.architectingsecurity.com/2012/01/11/web-app-sec-checklist-v2/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 12:40:28 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Secure SDLC]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[checklist]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owasp-tr]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=405</guid>
		<description><![CDATA[OWASP-Turkey published in 2010 a check list for web application security which provides various security controls for web application developers and system administrators. It was planned to create the second version of the check list. I have been involved in the project and within the past 6 months we have worked on the new check [...]]]></description>
		<wfw:commentRss>http://www.architectingsecurity.com/2012/01/11/web-app-sec-checklist-v2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mahremiyet İhlalleri &#8211; 1 (Privacy Violations)</title>
		<link>http://www.architectingsecurity.com/2011/11/14/mahremiyetihlalleri/</link>
		<comments>http://www.architectingsecurity.com/2011/11/14/mahremiyetihlalleri/#comments</comments>
		<pubDate>Mon, 14 Nov 2011 15:11:19 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[mahremiyet ihlalleri]]></category>
		<category><![CDATA[privacy violations]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=288</guid>
		<description><![CDATA[Kişişel bilgilerin mahremiyeti dünyada birçok yerde olduğu gibi ne yazıkki Türkiye’de de pek dikkat edilmeyen ve de kolayca zaafiyete uğratılan bir konudur. Toplum genelinde mahremiyet bilinci oluşmadığından devlet kurumları olsun özel kurumlar ya da kişiler olsun ellerinde var olan kişişel bilgilerin mahremiyetini gözardı edip erişimin herkese açık olduğu İnternet ortamında bu bilgileri paylaşabiliyorlar. Bunun en [...]]]></description>
		<wfw:commentRss>http://www.architectingsecurity.com/2011/11/14/mahremiyetihlalleri/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Book Review: Secure and Resilient Software Development</title>
		<link>http://www.architectingsecurity.com/2011/07/30/book-review-secure-and-resilient-software-development/</link>
		<comments>http://www.architectingsecurity.com/2011/07/30/book-review-secure-and-resilient-software-development/#comments</comments>
		<pubDate>Sat, 30 Jul 2011 16:53:37 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Book Review]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Secure SDLC]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[book review]]></category>
		<category><![CDATA[bsimm]]></category>
		<category><![CDATA[clasp]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[samm]]></category>
		<category><![CDATA[secure coding]]></category>
		<category><![CDATA[secure sdlc]]></category>
		<category><![CDATA[security training]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=362</guid>
		<description><![CDATA[I have completed the review of the book &#8220;Secure and Resilient Software Development&#8221; for IACR (International Association for Cryptologic Research) book review program. The review can be summarized as follows: This book is a &#8220;must read&#8221; resource for security experts focusing on application security and for application designers and developers who need to integrate security [...]]]></description>
		<wfw:commentRss>http://www.architectingsecurity.com/2011/07/30/book-review-secure-and-resilient-software-development/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Book Review: Architecting Secure Software Systems</title>
		<link>http://www.architectingsecurity.com/2011/04/13/book-review-architecting-secure-software-systems/</link>
		<comments>http://www.architectingsecurity.com/2011/04/13/book-review-architecting-secure-software-systems/#comments</comments>
		<pubDate>Wed, 13 Apr 2011 16:13:10 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Book Review]]></category>
		<category><![CDATA[Database Security]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Secure SDLC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[book]]></category>
		<category><![CDATA[book review]]></category>
		<category><![CDATA[secure coding]]></category>
		<category><![CDATA[secure sdlc]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security training]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=321</guid>
		<description><![CDATA[I have recently completed the review of the book &#8220;Architecting Secure Software Systems&#8221; for IACR (International Association for Cryptologic Research) book review program. The review can be summarized as follows: This book focuses on both theoretical and practical aspects of designing secure software systems. While its theory part is quite well-written, its practical part is [...]]]></description>
		<wfw:commentRss>http://www.architectingsecurity.com/2011/04/13/book-review-architecting-secure-software-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure Coding Guidelines for Java</title>
		<link>http://www.architectingsecurity.com/2011/03/14/secure-coding-guidelines-for-java/</link>
		<comments>http://www.architectingsecurity.com/2011/03/14/secure-coding-guidelines-for-java/#comments</comments>
		<pubDate>Mon, 14 Mar 2011 19:14:29 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Secure SDLC]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[secure coding]]></category>
		<category><![CDATA[secure sdlc]]></category>
		<category><![CDATA[security training]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=291</guid>
		<description><![CDATA[I have published an (Turkish) article about secure coding guidelines for Java within OWASP-Turkey Documents. The article aims at helping IT-architects and developers to understand the main security aspects during design and development phases. The guideline contains generic countermeasures (e.g. Do not write repeated codes) as well as Java-specific countermeasures (e.g. How to use doPrivileged() [...]]]></description>
		<wfw:commentRss>http://www.architectingsecurity.com/2011/03/14/secure-coding-guidelines-for-java/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Secure Software Development with SAMM</title>
		<link>http://www.architectingsecurity.com/2011/02/03/secure-software-development-with-samm/</link>
		<comments>http://www.architectingsecurity.com/2011/02/03/secure-software-development-with-samm/#comments</comments>
		<pubDate>Thu, 03 Feb 2011 13:07:36 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Secure SDLC]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[samm]]></category>
		<category><![CDATA[secure sdlc]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=279</guid>
		<description><![CDATA[SAMM (Software Assurance Maturity Model) is an OWASP project and provides well-structured strategy and guidelines for integration of security within software development processes. In the 7th issue of Web Security Magazine managed by OWASP-Turkey, I have written an introduction article to SAMM. In this article, I focused mainly on the following topics: What is SAMM [...]]]></description>
		<wfw:commentRss>http://www.architectingsecurity.com/2011/02/03/secure-software-development-with-samm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Feedbacks from Application Pentest</title>
		<link>http://www.architectingsecurity.com/2010/12/07/feedbacks-from-application-pentest/</link>
		<comments>http://www.architectingsecurity.com/2010/12/07/feedbacks-from-application-pentest/#comments</comments>
		<pubDate>Tue, 07 Dec 2010 16:02:08 +0000</pubDate>
		<dc:creator>Emin</dc:creator>
				<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[Appscan]]></category>
		<category><![CDATA[pentest]]></category>

		<guid isPermaLink="false">http://www.architectingsecurity.com/?p=190</guid>
		<description><![CDATA[I have recently completed penetration testing of a SAP portal application for a customer. It was a short-time (5 days) assignment which required execution of tool-supported automatic pentest (with IBM Appscan), manual pentest and preparation of final presentation that explains findings and countermeasures. In such short time pentests, it is very important that test plan [...]]]></description>
		<wfw:commentRss>http://www.architectingsecurity.com/2010/12/07/feedbacks-from-application-pentest/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced

Served from: www.architectingsecurity.com @ 2012-05-21 03:49:32 -->
