<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: The PHP App Insecurity Top 20</title>
	<atom:link href="http://www.cerias.purdue.edu/weblogs/coj/secure-it-practices/post-86/the-php-app-security-top-20/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cerias.purdue.edu/weblogs/coj/secure-it-practices/post-86/the-php-app-security-top-20/</link>
	<description>Privacy, Security and Information Assurance issues</description>
	<pubDate>Fri, 16 May 2008 03:36:21 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: GiGi</title>
		<link>http://www.cerias.purdue.edu/weblogs/coj/secure-it-practices/post-86/the-php-app-security-top-20/#comment-48438</link>
		<dc:creator>GiGi</dc:creator>
		<pubDate>Thu, 19 Apr 2007 16:41:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.cerias.purdue.edu/weblogs/coj/secure-it-practices/post-86/the-php-app-security-top-20/#comment-48438</guid>
		<description>So what can we do about it?

Not using those software or use something else, even Microsoft product does not save neither.

Can Firwall help a lot but how?</description>
		<content:encoded><![CDATA[<p>So what can we do about it?</p>
<p>Not using those software or use something else, even Microsoft product does not save neither.</p>
<p>Can Firwall help a lot but how?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ed Finkler</title>
		<link>http://www.cerias.purdue.edu/weblogs/coj/secure-it-practices/post-86/the-php-app-security-top-20/#comment-48428</link>
		<dc:creator>Ed Finkler</dc:creator>
		<pubDate>Thu, 19 Apr 2007 15:12:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.cerias.purdue.edu/weblogs/coj/secure-it-practices/post-86/the-php-app-security-top-20/#comment-48428</guid>
		<description>It might give a hint, but it could also be very misleading.  PHP is a unique case in terms of widespread popularity and shallow learning curve.  Doing "oranges to oranges" comparisons between a forum written in Perl and one done in PHP, and trying to extrapolate that to judge the security "potential" of the language itself, would be ignoring a huge number of significant variables.  Even the data I present here isn't black and white, as there are a lot of issues that could contribute to higher or lower ratings.</description>
		<content:encoded><![CDATA[<p>It might give a hint, but it could also be very misleading.  PHP is a unique case in terms of widespread popularity and shallow learning curve.  Doing &#8220;oranges to oranges&#8221; comparisons between a forum written in Perl and one done in PHP, and trying to extrapolate that to judge the security &#8220;potential&#8221; of the language itself, would be ignoring a huge number of significant variables.  Even the data I present here isn&#8217;t black and white, as there are a lot of issues that could contribute to higher or lower ratings.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://www.cerias.purdue.edu/weblogs/coj/secure-it-practices/post-86/the-php-app-security-top-20/#comment-48409</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Thu, 19 Apr 2007 12:43:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.cerias.purdue.edu/weblogs/coj/secure-it-practices/post-86/the-php-app-security-top-20/#comment-48409</guid>
		<description>I think it would be far more interesting to merge this list with one for Perl, Python, Ruby, Java, and .net based applications as well. A broad sampling of applications from all those platforms would give a hint as to how difficult it is to code a secure web applications in each language.</description>
		<content:encoded><![CDATA[<p>I think it would be far more interesting to merge this list with one for Perl, Python, Ruby, Java, and .net based applications as well. A broad sampling of applications from all those platforms would give a hint as to how difficult it is to code a secure web applications in each language.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
