<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>Information Security, Privacy and Regulatory Compliance - Comments</title>
    <link>http://keithpachulski.securitytactics.com/</link>
    <description>Information Security, Privacy and Regulatory Compliance - Keith A. Pachulski - http://keithpachulski.securitytactics.com</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.5.2 - http://www.s9y.org/</generator>
    <pubDate>Thu, 09 Sep 2010 08:44:17 GMT</pubDate>

    <image>
        <url>http://keithpachulski.securitytactics.com/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: Information Security, Privacy and Regulatory Compliance - Comments - Information Security, Privacy and Regulatory Compliance - Keith A. Pachulski - http://keithpachulski.securitytactics.com</title>
        <link>http://keithpachulski.securitytactics.com/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>school grants: RANT: Non-existent 'analyst' befriends security experts</title>
    <link>http://keithpachulski.securitytactics.com/index.php?/archives/35-RANT-Non-existent-analyst-befriends-security-experts.html#c23</link>
            <category></category>
    
    <comments>http://keithpachulski.securitytactics.com/index.php?/archives/35-RANT-Non-existent-analyst-befriends-security-experts.html#comments</comments>
    <wfw:comment>http://keithpachulski.securitytactics.com/wfwcomment.php?cid=35</wfw:comment>

    

    <author>nospam@example.com (school grants)</author>
    <content:encoded>
    Pretty nice post. I just stumbled upon your blog and wanted to say that I have really enjoyed browsing your blog posts. In any case I’ll be subscribing to your feed and I hope you write again soon!  
    </content:encoded>

    <pubDate>Wed, 28 Jul 2010 13:57:47 -0400</pubDate>
    <guid isPermaLink="false">http://keithpachulski.securitytactics.com/index.php?/archives/35-guid.html#c23</guid>
    
</item>
<item>
    <title>seto: Nmap 5 UDP Application Recognition</title>
    <link>http://keithpachulski.securitytactics.com/index.php?/archives/2-Nmap-5-UDP-Application-Recognition.html#c20</link>
            <category></category>
    
    <comments>http://keithpachulski.securitytactics.com/index.php?/archives/2-Nmap-5-UDP-Application-Recognition.html#comments</comments>
    <wfw:comment>http://keithpachulski.securitytactics.com/wfwcomment.php?cid=2</wfw:comment>

    

    <author>nospam@example.com (seto)</author>
    <content:encoded>
    nice post...thx  
    </content:encoded>

    <pubDate>Thu, 22 Jul 2010 12:42:14 -0400</pubDate>
    <guid isPermaLink="false">http://keithpachulski.securitytactics.com/index.php?/archives/2-guid.html#c20</guid>
    
</item>
<item>
    <title>Tyler Krpata: UPDATED - Money Laundering - The Next Generation</title>
    <link>http://keithpachulski.securitytactics.com/index.php?/archives/21-UPDATED-Money-Laundering-The-Next-Generation.html#c16</link>
            <category></category>
    
    <comments>http://keithpachulski.securitytactics.com/index.php?/archives/21-UPDATED-Money-Laundering-The-Next-Generation.html#comments</comments>
    <wfw:comment>http://keithpachulski.securitytactics.com/wfwcomment.php?cid=21</wfw:comment>

    

    <author>nospam@example.com (Tyler Krpata)</author>
    <content:encoded>
    Please feel free to report this kind of activity originating from Constant Contact to &lt;a href=&quot;mailto:&amp;#97;b&amp;#117;s&amp;#101;&amp;#64;&amp;#99;&amp;#111;&amp;#110;s&amp;#116;&amp;#97;nt&amp;#99;&amp;#111;n&amp;#116;act.&amp;#99;o&amp;#109;.&quot;&gt;ab&amp;#117;&amp;#115;e&amp;#64;&amp;#99;o&amp;#110;s&amp;#116;&amp;#97;n&amp;#116;&amp;#99;&amp;#111;n&amp;#116;act&amp;#46;c&amp;#111;m&amp;#46;&lt;/a&gt; This particular account has already been terminated. Sorry for the inconvenience.  
    </content:encoded>

    <pubDate>Fri, 30 Apr 2010 20:56:37 -0400</pubDate>
    <guid isPermaLink="false">http://keithpachulski.securitytactics.com/index.php?/archives/21-guid.html#c16</guid>
    
</item>
<item>
    <title>Jason 'XenoPhage' Frisvold: Evolution of the USB Malware Device</title>
    <link>http://keithpachulski.securitytactics.com/index.php?/archives/18-Evolution-of-the-USB-Malware-Device.html#c14</link>
            <category></category>
    
    <comments>http://keithpachulski.securitytactics.com/index.php?/archives/18-Evolution-of-the-USB-Malware-Device.html#comments</comments>
    <wfw:comment>http://keithpachulski.securitytactics.com/wfwcomment.php?cid=18</wfw:comment>

    

    <author>nospam@example.com (Jason 'XenoPhage' Frisvold)</author>
    <content:encoded>
    Couple of quick notes here..&lt;br /&gt;
&lt;br /&gt;
First off, this is PHP specific security, so if an attacker can get a perl or bash script in there, all bets are off.  Using something else like mod_security might help here, but there are still ways around that as well.&lt;br /&gt;
&lt;br /&gt;
I highly recommend using Stefan Esser&#039;s excellent Suhosin module..  By default it secures a good portion of PHP, including auto-encryption of session files, better random number handling, and more.  http://www.hardened-php.net/suhosin/index.html&lt;br /&gt;
&lt;br /&gt;
If you&#039;re running apache, make sure you set up some general apache security as well.  At the very least, set ServerTokens to ProductOnly to prevent too much information leakage.  It&#039;s a bit of security by obscurity, but it helps..  Defense in depth, eh?  
    </content:encoded>

    <pubDate>Mon, 26 Apr 2010 16:55:39 -0400</pubDate>
    <guid isPermaLink="false">http://keithpachulski.securitytactics.com/index.php?/archives/18-guid.html#c14</guid>
    
</item>
<item>
    <title>Modern Celt: The Bot(net) evolution...</title>
    <link>http://keithpachulski.securitytactics.com/index.php?/archives/8-The-Botnet-evolution....html#c1</link>
            <category></category>
    
    <comments>http://keithpachulski.securitytactics.com/index.php?/archives/8-The-Botnet-evolution....html#comments</comments>
    <wfw:comment>http://keithpachulski.securitytactics.com/wfwcomment.php?cid=8</wfw:comment>

    

    <author>nospam@example.com (Modern Celt)</author>
    <content:encoded>
    Very nicely done.  
    </content:encoded>

    <pubDate>Mon, 07 Dec 2009 23:02:18 -0500</pubDate>
    <guid isPermaLink="false">http://keithpachulski.securitytactics.com/index.php?/archives/8-guid.html#c1</guid>
    
</item>

</channel>
</rss>