<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Take HTTP Methods Out of Your Security Decisions</title>
	<atom:link href="http://i8jesus.com/?feed=rss2&#038;p=23" rel="self" type="application/rss+xml" />
	<link>http://i8jesus.com/?p=23</link>
	<description>because arshan's too cheap to license OneNote</description>
	<lastBuildDate>Wed, 01 Sep 2010 06:10:02 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: arshan dabirsiaghi</title>
		<link>http://i8jesus.com/?p=23&#038;cpage=1#comment-7789</link>
		<dc:creator>arshan dabirsiaghi</dc:creator>
		<pubDate>Mon, 23 Mar 2009 15:41:22 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=23#comment-7789</guid>
		<description>There&#039;s no doubt that a few people knew of this technique years ago. The kernel panic paper Adam Muntner pointed out to me on web-sec was proof of that - regardless, I think it&#039;s in  common verbiage now. =]</description>
		<content:encoded><![CDATA[<p>There&#8217;s no doubt that a few people knew of this technique years ago. The kernel panic paper Adam Muntner pointed out to me on web-sec was proof of that &#8211; regardless, I think it&#8217;s in  common verbiage now. =]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kuza55</title>
		<link>http://i8jesus.com/?p=23&#038;cpage=1#comment-7767</link>
		<dc:creator>kuza55</dc:creator>
		<pubDate>Mon, 23 Mar 2009 10:44:22 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=23#comment-7767</guid>
		<description>&quot;This is so 2005&quot;: http://archives.neohapsis.com/archives/fulldisclosure/2005-07/0495.html

I just stumbled upon that again, and thought I might post it here to show I wasn&#039;t making shit up.</description>
		<content:encoded><![CDATA[<p>&#8220;This is so 2005&#8243;: <a href="http://archives.neohapsis.com/archives/fulldisclosure/2005-07/0495.html" rel="nofollow">http://archives.neohapsis.com/archives/fulldisclosure/2005-07/0495.html</a></p>
<p>I just stumbled upon that again, and thought I might post it here to show I wasn&#8217;t making shit up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Good Times in Toronto &#171; Trey Ford - Security Spin Control</title>
		<link>http://i8jesus.com/?p=23&#038;cpage=1#comment-1574</link>
		<dc:creator>Good Times in Toronto &#171; Trey Ford - Security Spin Control</dc:creator>
		<pubDate>Thu, 17 Jul 2008 13:38:57 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=23#comment-1574</guid>
		<description>[...] great discussion on recent court rulings and Internet directed legislation, former war stories, if Arian is really an 8.5 on hot-or-not, and why proper creole spices aren&#8217;t sold in Canada.  (no kidding mom, the guys up there [...]</description>
		<content:encoded><![CDATA[<p>[...] great discussion on recent court rulings and Internet directed legislation, former war stories, if Arian is really an 8.5 on hot-or-not, and why proper creole spices aren&#8217;t sold in Canada.  (no kidding mom, the guys up there [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan dabirsiaghi</title>
		<link>http://i8jesus.com/?p=23&#038;cpage=1#comment-302</link>
		<dc:creator>arshan dabirsiaghi</dc:creator>
		<pubDate>Mon, 02 Jun 2008 15:03:33 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=23#comment-302</guid>
		<description>@kuza, I disagree, and I think the amount of positive feedback we got proves our point.

@genghis, after hearing what&#039;s on the in-room menus at Amsterdam hotels I&#039;m ready to go anytime!</description>
		<content:encoded><![CDATA[<p>@kuza, I disagree, and I think the amount of positive feedback we got proves our point.</p>
<p>@genghis, after hearing what&#8217;s on the in-room menus at Amsterdam hotels I&#8217;m ready to go anytime!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kuza55</title>
		<link>http://i8jesus.com/?p=23&#038;cpage=1#comment-286</link>
		<dc:creator>kuza55</dc:creator>
		<pubDate>Sun, 01 Jun 2008 02:10:03 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=23#comment-286</guid>
		<description>@arshan:
And from that realisation to using other HTTP methods (including non-existent methods) is pretty trivial.</description>
		<content:encoded><![CDATA[<p>@arshan:<br />
And from that realisation to using other HTTP methods (including non-existent methods) is pretty trivial.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GenghisKhan</title>
		<link>http://i8jesus.com/?p=23&#038;cpage=1#comment-276</link>
		<dc:creator>GenghisKhan</dc:creator>
		<pubDate>Fri, 30 May 2008 23:37:16 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=23#comment-276</guid>
		<description>Hi Arshan,

Did you still have enough energy and time to travel to Amsterdam? Thnx for publishing the amazing whitepaper, video en blog. I&#039;m actually rechecking a couple code-review assignments ( in idle time :) ) and considering to send a news-letter to costumers. Keep up the good work.

Hoop to see you on a another AMAZING! OWASP AppSecc event.

Genghis (Amsterdam)</description>
		<content:encoded><![CDATA[<p>Hi Arshan,</p>
<p>Did you still have enough energy and time to travel to Amsterdam? Thnx for publishing the amazing whitepaper, video en blog. I&#8217;m actually rechecking a couple code-review assignments ( in idle time <img src='http://i8jesus.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ) and considering to send a news-letter to costumers. Keep up the good work.</p>
<p>Hoop to see you on a another AMAZING! OWASP AppSecc event.</p>
<p>Genghis (Amsterdam)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan dabirsiaghi</title>
		<link>http://i8jesus.com/?p=23&#038;cpage=1#comment-274</link>
		<dc:creator>arshan dabirsiaghi</dc:creator>
		<pubDate>Fri, 30 May 2008 01:01:41 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=23#comment-274</guid>
		<description>@kuza55, GET/POST jumps are pretty trivial and the need for those jumps come up way more often than this. Rogan even made us a WebScarab script that automatically translates from one to another with certain triggers a few years ago, and it comes in quite handy.</description>
		<content:encoded><![CDATA[<p>@kuza55, GET/POST jumps are pretty trivial and the need for those jumps come up way more often than this. Rogan even made us a WebScarab script that automatically translates from one to another with certain triggers a few years ago, and it comes in quite handy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kuza55</title>
		<link>http://i8jesus.com/?p=23&#038;cpage=1#comment-273</link>
		<dc:creator>kuza55</dc:creator>
		<pubDate>Thu, 29 May 2008 22:52:01 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=23#comment-273</guid>
		<description>@arshan
Haha, I wish I could find a year to go along with it, but I can&#039;t remember what year it was and I can&#039;t seem to find the reference I saw to it atm (some hacking team&#039;s site got owned because they were doing this, and they posted something (to a list probably...) saying this is how it happened since people thought it had been completely owned somehow, except in their case they had blocked GET, and the attacker had used POST, so I thought it was a pretty obvious leap from that to your paper), but I am still looking for it...

I&#039;m not surprised that someone else came up with it, I&#039;m surprised that it took people this long when it had been publicly mentioned before.

Oh, and this time I didn&#039;t use the word lame (and have no plans to), I used the word spam :p I was honestly under the impression that many people would know about this.</description>
		<content:encoded><![CDATA[<p>@arshan<br />
Haha, I wish I could find a year to go along with it, but I can&#8217;t remember what year it was and I can&#8217;t seem to find the reference I saw to it atm (some hacking team&#8217;s site got owned because they were doing this, and they posted something (to a list probably&#8230;) saying this is how it happened since people thought it had been completely owned somehow, except in their case they had blocked GET, and the attacker had used POST, so I thought it was a pretty obvious leap from that to your paper), but I am still looking for it&#8230;</p>
<p>I&#8217;m not surprised that someone else came up with it, I&#8217;m surprised that it took people this long when it had been publicly mentioned before.</p>
<p>Oh, and this time I didn&#8217;t use the word lame (and have no plans to), I used the word spam :p I was honestly under the impression that many people would know about this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan dabirsiaghi</title>
		<link>http://i8jesus.com/?p=23&#038;cpage=1#comment-263</link>
		<dc:creator>arshan dabirsiaghi</dc:creator>
		<pubDate>Thu, 29 May 2008 12:13:54 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=23#comment-263</guid>
		<description>@kuza, it doesn&#039;t matter. I talked to a few people who know you better and they say this was a pretty standard response and that I shouldn&#039;t get too worked up about it. =]

Though they predicted you would&#039;ve said a year, i.e., &quot;this is so 2005&quot;, or something.

Either:
a) you did know it and you didn&#039;t share it, or
b) you didn&#039;t know and are trying to appear all knowing

If it&#039;s a, then why on earth would it be surprising for someone else to discover it and write it up to share? Lame, even?

If it&#039;s b, well, it&#039;s b.

After something new comes out, you can always say you already knew it, and assholes always will. It&#039;s a conveniently unverifiable way of claiming how el8 you are.</description>
		<content:encoded><![CDATA[<p>@kuza, it doesn&#8217;t matter. I talked to a few people who know you better and they say this was a pretty standard response and that I shouldn&#8217;t get too worked up about it. =]</p>
<p>Though they predicted you would&#8217;ve said a year, i.e., &#8220;this is so 2005&#8243;, or something.</p>
<p>Either:<br />
a) you did know it and you didn&#8217;t share it, or<br />
b) you didn&#8217;t know and are trying to appear all knowing</p>
<p>If it&#8217;s a, then why on earth would it be surprising for someone else to discover it and write it up to share? Lame, even?</p>
<p>If it&#8217;s b, well, it&#8217;s b.</p>
<p>After something new comes out, you can always say you already knew it, and assholes always will. It&#8217;s a conveniently unverifiable way of claiming how el8 you are.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan dabirsiaghi</title>
		<link>http://i8jesus.com/?p=23&#038;cpage=1#comment-262</link>
		<dc:creator>arshan dabirsiaghi</dc:creator>
		<pubDate>Thu, 29 May 2008 11:54:45 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=23#comment-262</guid>
		<description>@niels, do you have any idea what circumstances allowed that behavior? Certain PHP/Apache versions?</description>
		<content:encoded><![CDATA[<p>@niels, do you have any idea what circumstances allowed that behavior? Certain PHP/Apache versions?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
