<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Getting with the mod_rewrite voodoo</title>
	<atom:link href="http://www.oneafrikan.com/archives/2006/07/31/getting-with-the-mod_rewrite-voodoo/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.oneafrikan.com/archives/2006/07/31/getting-with-the-mod_rewrite-voodoo/</link>
	<description>Share what you know, Learn what you don't.  This is the evolution of one Afrikan.</description>
	<pubDate>Fri, 09 Jan 2009 22:35:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Gareth Knight</title>
		<link>http://www.oneafrikan.com/archives/2006/07/31/getting-with-the-mod_rewrite-voodoo/#comment-37771</link>
		<dc:creator>Gareth Knight</dc:creator>
		<pubDate>Thu, 03 Aug 2006 23:20:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.oneafrikan.com/archives/2006/07/31/getting-with-the-mod_rewrite-voodoo/#comment-37771</guid>
		<description>Yea yea yea... shecurity shmecurity!

Just kidding!!  Thanks for the heads up ;-)
Just so you know, I am doing input validation... wouldn't do it any other way...</description>
		<content:encoded><![CDATA[<p>Yea yea yea&#8230; shecurity shmecurity!</p>
<p>Just kidding!!  Thanks for the heads up <img src='http://www.oneafrikan.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> Just so you know, I am doing input validation&#8230; wouldn&#8217;t do it any other way&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://www.oneafrikan.com/archives/2006/07/31/getting-with-the-mod_rewrite-voodoo/#comment-37681</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Mon, 31 Jul 2006 07:34:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.oneafrikan.com/archives/2006/07/31/getting-with-the-mod_rewrite-voodoo/#comment-37681</guid>
		<description>1st things 1st, Apache has a &lt;a href="http://secunia.com/advisories/21197/" rel="nofollow"&gt;serious&lt;/a&gt; vulnerability with mod_rewrite that allows attackers to execute code on your web server, so make sure you've updated your apache before you get r00ted.

The one thing thats annoying us security peeps about Web 2.0 is that the SAME security mistakes are being made. Its like no-one has learnt anything from us poking holes in Web 1.0 and are hellbent on making the same mistakes.

Take this "hiding" of query strings that everyone is being made to do with Web 2.0. Great, your making it look prettier but i'll bet my camera kit that the developer isnt doing the correct input validation on the user-supplied input being passed back to the server.

On a daily basis now im still training developers on why this is a bad thing and im still getting that blank look.

One day...</description>
		<content:encoded><![CDATA[<p>1st things 1st, Apache has a <a href="http://secunia.com/advisories/21197/" rel="nofollow">serious</a> vulnerability with mod_rewrite that allows attackers to execute code on your web server, so make sure you&#8217;ve updated your apache before you get r00ted.</p>
<p>The one thing thats annoying us security peeps about Web 2.0 is that the SAME security mistakes are being made. Its like no-one has learnt anything from us poking holes in Web 1.0 and are hellbent on making the same mistakes.</p>
<p>Take this &#8220;hiding&#8221; of query strings that everyone is being made to do with Web 2.0. Great, your making it look prettier but i&#8217;ll bet my camera kit that the developer isnt doing the correct input validation on the user-supplied input being passed back to the server.</p>
<p>On a daily basis now im still training developers on why this is a bad thing and im still getting that blank look.</p>
<p>One day&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
