<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Casaba Security &#187; Chris Weber</title>
	<atom:link href="http://www.casabasecurity.com/blog/author/chris/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.casabasecurity.com/blog</link>
	<description>Building and breaking software and robots</description>
	<lastBuildDate>Tue, 31 Aug 2010 18:27:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>IDNA2008 hits the standards track &#8211; visually confusing strings remain a threat</title>
		<link>http://www.casabasecurity.com/blog/2010/08/idna2008-hits-the-standards-track-visually-confusing-strings-remain-a-threat/</link>
		<comments>http://www.casabasecurity.com/blog/2010/08/idna2008-hits-the-standards-track-visually-confusing-strings-remain-a-threat/#comments</comments>
		<pubDate>Tue, 31 Aug 2010 18:27:09 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[Unicode]]></category>
		<category><![CDATA[confusables]]></category>
		<category><![CDATA[IDN]]></category>

		<guid isPermaLink="false">http://www.casabasecurity.com/blog/?p=216</guid>
		<description><![CDATA[After many years of engineering efforts, the Internationalizing Domain Names in Applications (IDNA) protocol had a major update released from its original 2003 standard. Although named IDNA2008, it hit the standards track in August 2010. It&#8217;s worth noting in section &#8220;4.4 Visually Confusable Characters&#8221; of RFC 5890: It is worth noting that there are no [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2010/08/idna2008-hits-the-standards-track-visually-confusing-strings-remain-a-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watcher 1.4.0 released</title>
		<link>http://www.casabasecurity.com/blog/2010/05/watcher-1-4-0-released/</link>
		<comments>http://www.casabasecurity.com/blog/2010/05/watcher-1-4-0-released/#comments</comments>
		<pubDate>Tue, 25 May 2010 19:32:01 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false">http://www.casabasecurity.com/blog/?p=213</guid>
		<description><![CDATA[A new update to the Watcher passive Web-vulnerability scanner has been released. Based on user feedback we&#8217;ve built out the Wiki documentation on Codeplex with more details about the issues identified by each Watcher check. Inside the tool, a reference is now included as a link back to the Wiki. I hope to improve the [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2010/05/watcher-1-4-0-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watcher 1.3.0 released</title>
		<link>http://www.casabasecurity.com/blog/2010/02/watcher-1-3-0-released/</link>
		<comments>http://www.casabasecurity.com/blog/2010/02/watcher-1-3-0-released/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 17:40:59 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[TFS]]></category>
		<category><![CDATA[VIEWSTATE]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false">http://www.casabasecurity.com/blog/?p=203</guid>
		<description><![CDATA[A new update to the Watcher passive vulnerability detection and security testing tool has been released. Watcher is an open source addon to the Fiddler Web proxy that aids developers, auditors, and penetration testers in finding Web-application security issues as well as hot-spots for deeper review. Among other things, we&#8217;ve added new checks to identify [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2010/02/watcher-1-3-0-released/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Preventing Security Development Errors: Lessons Learned at Windows Live by Using ASP.NET MVC</title>
		<link>http://www.casabasecurity.com/blog/2009/11/preventing-security-development-errors-lessons-learned-at-windows-live-by-using-asp-net-mvc/</link>
		<comments>http://www.casabasecurity.com/blog/2009/11/preventing-security-development-errors-lessons-learned-at-windows-live-by-using-asp-net-mvc/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 21:42:45 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Code Review]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[ASP.NET]]></category>
		<category><![CDATA[MVC]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Casaba had the opportunity to contribute to a new Microsoft paper regarding ASP.NET MVC security. It&#039;s online through the SDL pages, and here&#39;s the paper&#39;s direct link. A short summary of the paper follows. The SDL preaches &#039;secure by default&#039;. When Windows Live moved to ASP.Net MVC, they used that opportunity to build mitigations into [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2009/11/preventing-security-development-errors-lessons-learned-at-windows-live-by-using-asp-net-mvc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unicode security vulnerabilities &#8211; presentation from Internationalization and Unicode Conference 33</title>
		<link>http://www.casabasecurity.com/blog/2009/10/unicode-security-vulnerabilities-presentation-from-internationalization-and-unicode-conference-33/</link>
		<comments>http://www.casabasecurity.com/blog/2009/10/unicode-security-vulnerabilities-presentation-from-internationalization-and-unicode-conference-33/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 19:24:44 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Unicode]]></category>
		<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I&#039;m attaching my slides from the Unicode conference last week in San Jose, California. I&#039;m getting much feedback for code-level action items. Providing details for code review and static analysis is in the works, with a focus on major frameworks such as ICU, .NET, and Java. You can download the presentation here.]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2009/10/unicode-security-vulnerabilities-presentation-from-internationalization-and-unicode-conference-33/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unibomber tool for specialized XSS testing</title>
		<link>http://www.casabasecurity.com/blog/2009/07/unibomber-tool-for-specialized-xss-testing/</link>
		<comments>http://www.casabasecurity.com/blog/2009/07/unibomber-tool-for-specialized-xss-testing/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 01:04:31 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Unicode]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[John Hernandez has been working hard at Casaba to build a specialized testing tool that automates some of the unique techniques we use to find cross-sites scripting bugs (XSS). At Black Hat I&#039;m planning to demo what we have so far. It automates the testing process greatly, by auto-injecting a canary and ID into each [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2009/07/unibomber-tool-for-specialized-xss-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft SDL blog post about Watcher</title>
		<link>http://www.casabasecurity.com/blog/2009/04/microsoft-sdl-blog-post-about-watcher/</link>
		<comments>http://www.casabasecurity.com/blog/2009/04/microsoft-sdl-blog-post-about-watcher/#comments</comments>
		<pubDate>Sat, 18 Apr 2009 20:22:37 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[SDL]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Microsoft mentioned Watcher&#039;s usefulness in Web-security testing and SDL requirements verification. We&#039;re working to make this tool better so please share your success stories, bugs or false positives with us.]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2009/04/microsoft-sdl-blog-post-about-watcher/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watcher v1.1.0 released</title>
		<link>http://www.casabasecurity.com/blog/2009/04/watcher-v1-1-0-released/</link>
		<comments>http://www.casabasecurity.com/blog/2009/04/watcher-v1-1-0-released/#comments</comments>
		<pubDate>Sun, 12 Apr 2009 16:44:02 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[We&#039;ve made some significant improvements to the Watcher web security and compliance auditing tool in version 1.1.0. Some new checks have been added, bug fixes, and performance improvements. I wanted to point out that Watcher helps not only in testing and auditing Web applications, but it has checks to assess the security strength of the [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2009/04/watcher-v1-1-0-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Eric Lawrence introduces Watcher tool at MIX09 Conference</title>
		<link>http://www.casabasecurity.com/blog/2009/03/eric-lawrence-introduces-watcher-tool-at-mix09-conference/</link>
		<comments>http://www.casabasecurity.com/blog/2009/03/eric-lawrence-introduces-watcher-tool-at-mix09-conference/#comments</comments>
		<pubDate>Sat, 21 Mar 2009 05:23:42 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I&#039;m happy to say IE8 Security Program Manager and Fiddler author Eric Lawrence announced our Watcher tool at MIX09 today. Check out his talk at http://videos.visitmix.com/MIX09/T54F it&#039;s an eye opener for Web developers &#8211; introducing us to the new features of IE8 while also covering state-of-the-art secure development practices for today&#039;s Web applications. Unfortunately CodePlex [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2009/03/eric-lawrence-introduces-watcher-tool-at-mix09-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watcher security tool for web applications</title>
		<link>http://www.casabasecurity.com/blog/2009/03/watcher-security-tool-for-web-applications/</link>
		<comments>http://www.casabasecurity.com/blog/2009/03/watcher-security-tool-for-web-applications/#comments</comments>
		<pubDate>Thu, 12 Mar 2009 04:06:15 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Watcher is being released under an Open Source license. With over 30 checks in its first release, it helps you find issues in your web-apps fast and effortlessly. Watcher is a Fiddler plugin that passively audits a web application for a variety of security issues. It acts as an assistant to the developer, tester, or [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2009/03/watcher-security-tool-for-web-applications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
