<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/" 
	xmlns:atom="http://www.w3.org/2005/Atom" 
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" 
>
<channel>
	<title>NT OBJECTives Web Application Security Blog</title>
	<atom:link href="http://www.ntobjectives.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ntobjectives.com/blog/feed/</link>
	<description>NT OBJECTives Web Application Security Scanning</description>
	<image>
		<title>NT OBJECTives Web Application Security Blog</title>
		<link>http://www.ntobjectives.com/blog/feed/</link>
		<url>http://www.ntobjectives.com/images/nto_rss.jpg</url>
		<width>144</width>
		<height>144</height>
	</image>
	<pubDate>Fri, 10 Sep 2010 12:22:37 -0700</pubDate>
	<language>en</language>
	<itunes:category text="Technology">
		<itunes:category text="Tech News"/>
	</itunes:category>
	<itunes:category text="Education">
	  <itunes:category text="Training"/>
	</itunes:category>
	<itunes:category text="Technology"/>
	<itunes:owner>
		<itunes:name>Dan Kuykendall</itunes:name>
		<itunes:email>dan@kuykendall.org</itunes:email>
	</itunes:owner>
	<itunes:block>No</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.ntobjectives.com/images/nto_itunescover.jpg" />
	<item>
		<title>NT OBJECTives Response to the Larry Suto Report</title>
		<link>http://www.ntobjectives.com/blog/response-to-2010-suto-report</link>
		<pubDate>Sun, 21 Feb 2010 00:00:00 -0800</pubDate>
		<itunes:keywords>web, application, security</itunes:keywords>
		<itunes:subtitle>NT OBJECTives Web Application Security Scanning</itunes:subtitle>
		<itunes:summary>NT OBJECTives Web Application Security News</itunes:summary>
		<itunes:author>NT OBJECTives</itunes:author>
		<dc:creator>Dan Kuykendall, Co-CEO/CTO</dc:creator>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<guid isPermaLink="false">http://www.ntobjectives.com/blog/response-to-2010-suto-report</guid>
		<description><![CDATA[IntroductionWhen the latest report from Larry Suto was set to come out and we had seen previews of the results, our first reaction was "Wow, we did great, but why did we miss those 9 vulns?!" followed by "Whoa - why did the other scanners miss so many vulnerabiities?" and then "Oh no, here we go again. Another round of getting unfairly blasted by the other vendors and their users".  We certainly were not disappointed by the response from the other vendors and their users, but overall things seem [...]]]></description>
		<content:encoded><![CDATA[<h2><span style="font-weight: bold; text-decoration: underline;">Introduction</span></h2>When the <a target="_blank" href="http://ha.ckers.org/blog/20100203/accuracy-and-time-costs-of-web-application-security-scanner-report/">latest report from Larry Suto</a> was set to come out and we had seen previews of the results, our first reaction was "<span style="font-style: italic;">Wow, we did great, but why did we miss those 9 vulns?!</span>" followed by "<span style="font-style: italic;">Whoa - why did the other scanners miss so many vulnerabiities?</span>" and then "<span style="font-style: italic;">Oh no, here we go again. Another round of getting unfairly blasted by the other vendors and their users</span>".<br /><br />We certainly were not disappointed by the response from the other vendors and their users, but overall things seem to be different than they were in 2007 when Larry did his first report. In the latest report it is clear that Larry had learned at least two things from his first experience. <br /><br />The first was that he needed better supporting data which he has certainly done this time by including the full breakdown of the vulns by site and vendor. The second was that he would need to provide for "Trained" scans, because most of the vendors made quite a protest that it was impossible to get proper results without it. My personal feeling on the matter is that "Point-and-shoot" is the most likely way that users will run scans and for that reason <span style="font-weight: bold;">it is the responsibility of the scanner to do as much as possible on its own</span>.<br /><br />Because Larry did the "Trained" scanning this time around, this only leaves the other vendors with the ability to claim that he didn&#8217;t do a good enough job with the training. I think Jeremiah Grossman states it the best in his post "<span style="font-style: italic;">Scanner vendors should take into consideration that Larry Suto is certainly more sophisticated than the average [...]]]></content:encoded>
	</item>
	<item>
		<title>Detecting Persistent Cross-Site Scripting</title>
		<link>http://www.ntobjectives.com/blog/DetectingPersistentCross-SiteScripting</link>
		<pubDate>Wed, 11 Nov 2009 00:00:00 -0800</pubDate>
		<itunes:keywords>web, application, security</itunes:keywords>
		<itunes:subtitle>NT OBJECTives Web Application Security Scanning</itunes:subtitle>
		<itunes:summary>NT OBJECTives Web Application Security News</itunes:summary>
		<itunes:author>NT OBJECTives</itunes:author>
		<dc:creator>NT OBJECTives</dc:creator>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<guid isPermaLink="false">http://www.ntobjectives.com/blog/DetectingPersistentCross-SiteScripting</guid>
		<description><![CDATA[This white paper explains how these attacks work and will discuss the difference between Non-Persistent Cross-Site Scripting and the far more dangerous Persistent Cross-Site Scripting variations. We will highlight the challenge presented to Web Application Security Scanners and how only NTOSpider solves them.]]></description>
		<content:encoded><![CDATA[This white paper explains how these attacks work and will discuss the difference between Non-Persistent Cross-Site Scripting and the far more dangerous Persistent Cross-Site Scripting variations. We will highlight the challenge presented to Web Application Security Scanners and how only NTOSpider solves them.]]></content:encoded>
		<enclosure url="http://www.ntobjectives.com/files/PersistentCrossSiteScripting.pdf" type="application/pdf"/>
	</item>
	<item>
		<title>Phishanomics: The Economics of Phishing, the iframe attack and the Brand ROI of Security Spending</title>
		<link>http://www.ntobjectives.com/blog/Phishanomics-TheEconomicsofPhishing,theiframeattackandtheBrandROIofSecuritySpending</link>
		<pubDate>Sat, 06 Jun 2009 00:00:00 -0700</pubDate>
		<itunes:keywords>web, application, security</itunes:keywords>
		<itunes:subtitle>NT OBJECTives Web Application Security Scanning</itunes:subtitle>
		<itunes:summary>NT OBJECTives Web Application Security News</itunes:summary>
		<itunes:author>NT OBJECTives</itunes:author>
		<dc:creator>NT OBJECTives</dc:creator>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<guid isPermaLink="false">http://www.ntobjectives.com/blog/Phishanomics-TheEconomicsofPhishing,theiframeattackandtheBrandROIofSecuritySpending</guid>
		<description><![CDATA[This paper will argue that the iframe attack (popularized by the Bank of India hack) has fundamentally altered the way that security professionals must defend less important websites. By allowing phishers to leverage a company’s brand to steal from users, the iframe attack has made an entirely new class of formerly unimportant sites into material security concerns.]]></description>
		<content:encoded><![CDATA[This paper will argue that the iframe attack (popularized by the Bank of India hack) has fundamentally altered the way that security professionals must defend less important websites. By allowing phishers to leverage a company’s brand to steal from users, the iframe attack has made an entirely new class of formerly unimportant sites into material security concerns.]]></content:encoded>
		<enclosure url="http://www.ntobjectives.com/files/Phishanomics.pdf" type="application/pdf"/>
	</item>
	<item>
		<title>Is Your Website Already Infected?</title>
		<link>http://www.ntobjectives.com/blog/IsYourWebsiteAlreadyInfected</link>
		<pubDate>Fri, 20 Mar 2009 00:00:00 -0700</pubDate>
		<itunes:keywords>web, application, security</itunes:keywords>
		<itunes:subtitle>NT OBJECTives Web Application Security Scanning</itunes:subtitle>
		<itunes:summary>NT OBJECTives Web Application Security News</itunes:summary>
		<itunes:author>NT OBJECTives</itunes:author>
		<dc:creator>NT OBJECTives</dc:creator>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<guid isPermaLink="false">http://www.ntobjectives.com/blog/IsYourWebsiteAlreadyInfected</guid>
		<description><![CDATA[Analyzing and Detecting Malicious Content. This paper asks a questionmany web admins would rather not face. Is your website already infectedwith malicious content? How to find out and what to do about it.]]></description>
		<content:encoded><![CDATA[Analyzing and Detecting Malicious Content. This paper asks a questionmany web admins would rather not face. Is your website already infectedwith malicious content? How to find out and what to do about it.]]></content:encoded>
		<enclosure url="http://www.ntobjectives.com/files/IsYourWebsiteAlreadyInfected.pdf" type="application/pdf"/>
	</item>
	<item>
		<title>Security Snake Oil</title>
		<link>http://www.ntobjectives.com/blog/SecuritySnakeOil</link>
		<pubDate>Tue, 03 Feb 2009 00:00:00 -0800</pubDate>
		<itunes:keywords>web, application, security</itunes:keywords>
		<itunes:subtitle>NT OBJECTives Web Application Security Scanning</itunes:subtitle>
		<itunes:summary>NT OBJECTives Web Application Security News</itunes:summary>
		<itunes:author>NT OBJECTives</itunes:author>
		<dc:creator>NT OBJECTives</dc:creator>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<guid isPermaLink="false">http://www.ntobjectives.com/blog/SecuritySnakeOil</guid>
		<description><![CDATA[Why Known Vulnerability Checks for Web Applications Simply Don’t Work.This paper explains the ineffectiveness of known vuln checkers such as Nikto, Wikto and other such solutions added to network scanning tools.]]></description>
		<content:encoded><![CDATA[Why Known Vulnerability Checks for Web Applications Simply Don’t Work.This paper explains the ineffectiveness of known vuln checkers such as Nikto, Wikto and other such solutions added to network scanning tools.]]></content:encoded>
		<enclosure url="http://www.ntobjectives.com/files/SecuritySnakeOil.pdf" type="application/pdf"/>
	</item>
</channel>
</rss>
