<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7122745763234660283.post876119765982040850..comments</id><updated>2010-05-11T22:03:21.335-07:00</updated><category term='jQuery'/><category term='Web Attacks'/><category term='Advisory'/><category term='Applet Security'/><category term='Http Request Splitting'/><category term='Application Security'/><category term='Http Parameter Pollution'/><category term='malware'/><category term='Cross Site Scripting'/><category term='Dom Xss'/><category term='DOMinator'/><category term='WWeb Security'/><category term='Banking'/><category term='Java'/><category term='Information Disclosure'/><category term='Omniture'/><category term='Spring MVC'/><category term='Expression Language Injection'/><category term='Java Security'/><category term='twitter'/><category term='Sharepoint'/><category term='Web Security'/><category term='Client Side HTTP Parameter Pollution'/><category term='JNLP Security'/><category term='JSON'/><category term='Liferay'/><category term='Same Origin Policy'/><category term='Arbitrary Code Execution'/><title type='text'>Comments on Minded Security Blog: OWASP-Italy interviewed by Repubblica.it</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.mindedsecurity.com/feeds/876119765982040850/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/876119765982040850/comments/default'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/12/owasp-italy-interviewed-by-repubblicait.html'/><author><name>Minded Security</name><uri>http://www.blogger.com/profile/01503616812076743415</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-2453213087180680642</id><published>2009-12-18T16:58:28.525-08:00</published><updated>2009-12-18T16:58:28.525-08:00</updated><title type='text'>It&amp;#39;s very important to outline that SQL Inject...</title><content type='html'>It&amp;#39;s very important to outline that SQL Injection attacks can be used directly to steal credit card data if the affected site is an e-commerce site.&lt;br /&gt;&lt;br /&gt;Many online shops have the payment gateway configurations stored inside the database. An attacker could modify these information via SQL injection of course and then route the billing requests to his evil payment proxy. Hey, this is not a Phishing Attack, just a trick to transparently sniff the user data.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/876119765982040850/comments/default/2453213087180680642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/876119765982040850/comments/default/2453213087180680642'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/12/owasp-italy-interviewed-by-repubblicait.html?showComment=1261184308525#c2453213087180680642' title=''/><author><name>Giorgio Fedon</name><uri>http://www.blogger.com/profile/10261243238330266276</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_vcTLhf3MjL0/SX2S-u9P_iI/AAAAAAAAAAg/1fZmsX7wtRE/S220/giorgio_fedon.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/12/owasp-italy-interviewed-by-repubblicait.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-876119765982040850' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/876119765982040850' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1631116005'/></entry></feed>
