<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Best Practice: Consider External Data Feeds Untrusted</title>
	<atom:link href="http://www.veracode.com/blog/2009/05/best-practice-consider-external-data-feeds-untrusted/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2009/05/best-practice-consider-external-data-feeds-untrusted/</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Fri, 10 Feb 2012 12:18:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Erzengel</title>
		<link>http://www.veracode.com/blog/2009/05/best-practice-consider-external-data-feeds-untrusted/comment-page-1/#comment-2739</link>
		<dc:creator>Erzengel</dc:creator>
		<pubDate>Wed, 06 May 2009 06:16:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=760#comment-2739</guid>
		<description>Looks like they fixed it, I&#039;m getting the NYT article when I click the link. It is a rather ironic article for it to happen on.</description>
		<content:encoded><![CDATA[<p>Looks like they fixed it, I&#8217;m getting the NYT article when I click the link. It is a rather ironic article for it to happen on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kingthorin</title>
		<link>http://www.veracode.com/blog/2009/05/best-practice-consider-external-data-feeds-untrusted/comment-page-1/#comment-2734</link>
		<dc:creator>kingthorin</dc:creator>
		<pubDate>Tue, 05 May 2009 19:21:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=760#comment-2734</guid>
		<description>It&#039;s a simple programming fact that input (whether from a user, file, or another site) should not be trusted. 

nytimes.com is IMHO guilty of a 21st century cardinal sin, they blindly syndicated content without any validation of the input.</description>
		<content:encoded><![CDATA[<p>It&#8217;s a simple programming fact that input (whether from a user, file, or another site) should not be trusted. </p>
<p>nytimes.com is IMHO guilty of a 21st century cardinal sin, they blindly syndicated content without any validation of the input.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andre Gironda</title>
		<link>http://www.veracode.com/blog/2009/05/best-practice-consider-external-data-feeds-untrusted/comment-page-1/#comment-2723</link>
		<dc:creator>Andre Gironda</dc:creator>
		<pubDate>Mon, 04 May 2009 23:58:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=760#comment-2723</guid>
		<description>External content coming through the integration or business tiers is a serious issue and one that web application security scanners and web application firewalls are very poor at solving (since they focus only on the content between the client tier and presentation tier, i.e. HTTP or SSL).</description>
		<content:encoded><![CDATA[<p>External content coming through the integration or business tiers is a serious issue and one that web application security scanners and web application firewalls are very poor at solving (since they focus only on the content between the client tier and presentation tier, i.e. HTTP or SSL).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

