<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: PHPIDS Threesome</title>
	<link>http://hackademix.net/2007/09/04/phpids-threesome/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Sun, 07 Sep 2008 01:11:06 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: .mario</title>
		<link>http://hackademix.net/2007/09/04/phpids-threesome/#comment-318</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Wed, 05 Sep 2007 15:33:28 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/04/phpids-threesome/#comment-318</guid>
		<description>Thanks for the info SIrDarckCat! I will put this link into the Google Group this weekend to discuss this option with the team..

Greetings,
.mario</description>
		<content:encoded><![CDATA[<p>Thanks for the info SIrDarckCat! I will put this link into the Google Group this weekend to discuss this option with the team..</p>
<p>Greetings,<br />
.mario</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://hackademix.net/2007/09/04/phpids-threesome/#comment-310</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Tue, 04 Sep 2007 16:15:33 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/04/phpids-threesome/#comment-310</guid>
		<description>mario:
you can use http://free-mysql.bizhostnet.com/ -- maybe add a table with a username and password xD
I think that with mysql is more than enough :P

Greetz!!</description>
		<content:encoded><![CDATA[<p>mario:<br />
you can use <a href="http://free-mysql.bizhostnet.com/" rel="nofollow">http://free-mysql.bizhostnet.com/</a> &#8212; maybe add a table with a username and password xD<br />
I think that with mysql is more than enough :P</p>
<p>Greetz!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://hackademix.net/2007/09/04/phpids-threesome/#comment-309</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Tue, 04 Sep 2007 15:57:09 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/04/phpids-threesome/#comment-309</guid>
		<description>@Giorgio: Will do!

@SirDarckCat: Yep - you're right. I've been switching between three blogs during fixing the rules and doing some daily business ;)

An SQL Injection sandbox is pretty hard to build but I will see what I can do this weekend. It will most probably built on my Server and not on the PHPIDS box. The problem though remains only that there can only be a limited amount of DBMS which makes the results pretty unsharp.</description>
		<content:encoded><![CDATA[<p>@Giorgio: Will do!</p>
<p>@SirDarckCat: Yep - you&#8217;re right. I&#8217;ve been switching between three blogs during fixing the rules and doing some daily business ;)</p>
<p>An SQL Injection sandbox is pretty hard to build but I will see what I can do this weekend. It will most probably built on my Server and not on the PHPIDS box. The problem though remains only that there can only be a limited amount of DBMS which makes the results pretty unsharp.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://hackademix.net/2007/09/04/phpids-threesome/#comment-307</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Tue, 04 Sep 2007 12:54:36 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/04/phpids-threesome/#comment-307</guid>
		<description>is it just me, or sla.ckers is a little forgotten?
now we post on each other blogs xD
I was wondering why today I got some refers from planet-websecurity.org, and (I thought I was added to the feed, but.. no hehe) well.. the PHPIDS hacking (un?)official contest is on (again).

As ma1 said, the SQL Injection filters are a little forgotten, but we should have a sandbox to test (as the script tags in php-ids), any way..

Greetz!!

PS. the window.name trick rules xD</description>
		<content:encoded><![CDATA[<p>is it just me, or sla.ckers is a little forgotten?<br />
now we post on each other blogs xD<br />
I was wondering why today I got some refers from planet-websecurity.org, and (I thought I was added to the feed, but.. no hehe) well.. the PHPIDS hacking (un?)official contest is on (again).</p>
<p>As ma1 said, the SQL Injection filters are a little forgotten, but we should have a sandbox to test (as the script tags in php-ids), any way..</p>
<p>Greetz!!</p>
<p>PS. the window.name trick rules xD</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2007/09/04/phpids-threesome/#comment-306</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Tue, 04 Sep 2007 12:20:14 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/04/phpids-threesome/#comment-306</guid>
		<description>@&lt;b&gt;Gareth Heyes&lt;/b&gt;:
thanks, that's why I didn't post comments on your blog  anymore -- not that a GreaseMonkey script couldn't do the trick, but enabling JS just to post a comment is against my faith ;)

@&lt;b&gt;christ1an&lt;/b&gt;:
thanks for the addition, I changed the feed to "full content" -- no big deal now, since I enabled both transparent gzip compression and caching for all the blog content...

@&lt;b&gt;.mario&lt;/b&gt;:
Thanks for the challenge. Let me know when you're ready for SQL Injections!</description>
		<content:encoded><![CDATA[<p>@<b>Gareth Heyes</b>:<br />
thanks, that&#8217;s why I didn&#8217;t post comments on your blog  anymore &#8212; not that a GreaseMonkey script couldn&#8217;t do the trick, but enabling JS just to post a comment is against my faith ;)</p>
<p>@<b>christ1an</b>:<br />
thanks for the addition, I changed the feed to &#8220;full content&#8221; &#8212; no big deal now, since I enabled both transparent gzip compression and caching for all the blog content&#8230;</p>
<p>@<b>.mario</b>:<br />
Thanks for the challenge. Let me know when you&#8217;re ready for SQL Injections!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://hackademix.net/2007/09/04/phpids-threesome/#comment-305</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Tue, 04 Sep 2007 11:43:01 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/04/phpids-threesome/#comment-305</guid>
		<description>Fixed, fixed and fixed!

I guess Christian just forgot - no offense intended at all. BTW - he just added your blog as far as I can see ;)

Greetings'n'thx!</description>
		<content:encoded><![CDATA[<p>Fixed, fixed and fixed!</p>
<p>I guess Christian just forgot - no offense intended at all. BTW - he just added your blog as far as I can see ;)</p>
<p>Greetings&#8217;n'thx!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: christ1an</title>
		<link>http://hackademix.net/2007/09/04/phpids-threesome/#comment-304</link>
		<dc:creator>christ1an</dc:creator>
		<pubDate>Tue, 04 Sep 2007 11:18:26 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/04/phpids-threesome/#comment-304</guid>
		<description>Thanks for your feedback. I have absolutely no clue why these vectors slip through our rules as I 've tried it before about 2 million times the same way. Consider them fixed. ;)

Ah and, be sure I don't have anything against you. It's just that I tend to forget about such things. You're added now but I'll release a new version of the planet next weekend anyway.

Hey could you provide a feed that contains the full text of your entries?</description>
		<content:encoded><![CDATA[<p>Thanks for your feedback. I have absolutely no clue why these vectors slip through our rules as I &#8216;ve tried it before about 2 million times the same way. Consider them fixed. ;)</p>
<p>Ah and, be sure I don&#8217;t have anything against you. It&#8217;s just that I tend to forget about such things. You&#8217;re added now but I&#8217;ll release a new version of the planet next weekend anyway.</p>
<p>Hey could you provide a feed that contains the full text of your entries?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://hackademix.net/2007/09/04/phpids-threesome/#comment-303</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 04 Sep 2007 11:10:31 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/04/phpids-threesome/#comment-303</guid>
		<description>Nice!

The biggest compliment I can pay you and Sirdarkcat is that I won't enable javascript looking at your sites LOL.

I was also wondering why your site wasn't included in the Planet Web Security. Come on Christ1an, you know he deserves to be on there.</description>
		<content:encoded><![CDATA[<p>Nice!</p>
<p>The biggest compliment I can pay you and Sirdarkcat is that I won&#8217;t enable javascript looking at your sites LOL.</p>
<p>I was also wondering why your site wasn&#8217;t included in the Planet Web Security. Come on Christ1an, you know he deserves to be on there.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
