<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Comprehensive Vulnerability Scanner</title>
	<atom:link href="http://blogsecurity.net/news/comprehensive-vulnerability-scanner/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/news/comprehensive-vulnerability-scanner</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Wordpress Themes</title>
		<link>http://blogsecurity.net/news/comprehensive-vulnerability-scanner/comment-page-1#comment-12370</link>
		<dc:creator>Wordpress Themes</dc:creator>
		<pubDate>Sun, 27 Jul 2008 23:19:03 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/news/comprehensive-vulnerability-scanner/#comment-12370</guid>
		<description>great tools</description>
		<content:encoded><![CDATA[<p>great tools</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlogSecurity &#187; Blog Archive &#187; BlogSecurify Demo Video!</title>
		<link>http://blogsecurity.net/news/comprehensive-vulnerability-scanner/comment-page-1#comment-11575</link>
		<dc:creator>BlogSecurity &#187; Blog Archive &#187; BlogSecurify Demo Video!</dc:creator>
		<pubDate>Mon, 09 Jun 2008 09:46:25 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/news/comprehensive-vulnerability-scanner/#comment-11575</guid>
		<description>[...] guys are going to love our new wp-scanner and blog security testing service! We&#8217;ll be adding loads more tests and support multiple blog types not just [...]</description>
		<content:encoded><![CDATA[<p>[...] guys are going to love our new wp-scanner and blog security testing service! We&#8217;ll be adding loads more tests and support multiple blog types not just [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Linden</title>
		<link>http://blogsecurity.net/news/comprehensive-vulnerability-scanner/comment-page-1#comment-11445</link>
		<dc:creator>Tim Linden</dc:creator>
		<pubDate>Wed, 21 May 2008 13:47:29 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/news/comprehensive-vulnerability-scanner/#comment-11445</guid>
		<description>I&#039;d probably give it a try. You could even go the daily scanning route and bill monthly for it and make some cash from it.</description>
		<content:encoded><![CDATA[<p>I&#8217;d probably give it a try. You could even go the daily scanning route and bill monthly for it and make some cash from it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://blogsecurity.net/news/comprehensive-vulnerability-scanner/comment-page-1#comment-11286</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Mon, 19 May 2008 07:36:49 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/news/comprehensive-vulnerability-scanner/#comment-11286</guid>
		<description>@Michael:

The last version is checking for a HTML comment inside the blog&#039;s markup to determine if it&#039;s allowed to be scanned or not. I think this is not a good idea - since a vulnerable blog&#039;s markup can be changed (XSS, SQLi etc.) to enable the scanner and search for more. Best method imho is to check for a specific file in the webroot - like in Google Analytics or the webmaster tools.</description>
		<content:encoded><![CDATA[<p>@Michael:</p>
<p>The last version is checking for a HTML comment inside the blog&#8217;s markup to determine if it&#8217;s allowed to be scanned or not. I think this is not a good idea &#8211; since a vulnerable blog&#8217;s markup can be changed (XSS, SQLi etc.) to enable the scanner and search for more. Best method imho is to check for a specific file in the webroot &#8211; like in Google Analytics or the webmaster tools.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Clark</title>
		<link>http://blogsecurity.net/news/comprehensive-vulnerability-scanner/comment-page-1#comment-11258</link>
		<dc:creator>Michael Clark</dc:creator>
		<pubDate>Sun, 18 May 2008 15:29:14 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/news/comprehensive-vulnerability-scanner/#comment-11258</guid>
		<description>Keep in mind that a service like this could easily be abused. I&#039;d guess that most cheapie-hosters wouldn&#039;t want their clients probing their servers with a service like this. I guess that&#039;s one advantage of charging a fee, to weed out crackers.</description>
		<content:encoded><![CDATA[<p>Keep in mind that a service like this could easily be abused. I&#8217;d guess that most cheapie-hosters wouldn&#8217;t want their clients probing their servers with a service like this. I guess that&#8217;s one advantage of charging a fee, to weed out crackers.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
