<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-732257695511948254.post3893780502606221382..comments</id><updated>2009-12-10T08:01:38.621-08:00</updated><category term='hpp'/><category term='virtualization'/><category term='java'/><category term='tool'/><category term='joomla'/><category term='confidence'/><category term='vmware'/><category term='snagg'/><category term='security'/><category term='blackfire'/><category term='mac os x'/><category term='tomcat'/><category term='hacking'/><category term='exploit acquisition program'/><category term='cloud'/><category term='bug bounty program'/><category term='sql injection'/><category term='vasto'/><category term='forensics'/><category term='oracle'/><category term='black hat'/><category term='iphone'/><category term='daath'/><category term='disclosure'/><category term='typo3'/><category term='owasp'/><category term='ikki'/><category term='xss'/><category term='syscan'/><category term='ms access'/><category term='exploit'/><category term='vulnerability acquisition program'/><title type='text'>Comments on Nibble Security: Just press Exploit!</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.nibblesec.org/feeds/3893780502606221382/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3893780502606221382/comments/default'/><link rel='alternate' type='text/html' href='http://blog.nibblesec.org/2009/09/just-press-exploit.html'/><author><name>Claudio Criscione</name><uri>http://www.blogger.com/profile/12202628660778574382</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-732257695511948254.post-2124585357575534741</id><published>2009-12-10T08:01:38.621-08:00</published><updated>2009-12-10T08:01:38.621-08:00</updated><title type='text'>Certain web servers will process code in files wit...</title><content type='html'>Certain web servers will process code in files with certain extensions this list doesn&amp;#39;t include.&lt;br /&gt;&lt;br /&gt;PHP:&lt;br /&gt;.ph3&lt;br /&gt;.ph4&lt;br /&gt;.pht&lt;br /&gt;&lt;br /&gt;SSI:&lt;br /&gt;.shtml&lt;br /&gt;&lt;br /&gt;I believe this NOT to be a comprehensive list, either. This is a perfect example of why you must whitelist, not blacklist.&lt;br /&gt;&lt;br /&gt;(Nice find, btw ;D)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3893780502606221382/comments/default/2124585357575534741'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3893780502606221382/comments/default/2124585357575534741'/><link rel='alternate' type='text/html' href='http://blog.nibblesec.org/2009/09/just-press-exploit.html?showComment=1260460898621#c2124585357575534741' title=''/><author><name>Dan Crowley</name><uri>http://www.blogger.com/profile/01153564415918026524</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.nibblesec.org/2009/09/just-press-exploit.html' ref='tag:blogger.com,1999:blog-732257695511948254.post-3893780502606221382' source='http://www.blogger.com/feeds/732257695511948254/posts/default/3893780502606221382' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1789482724'/></entry></feed>
