<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Bonsai - Information Security Blog</title>
	<atom:link href="http://www.bonsai-sec.com/blog/index.php/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bonsai-sec.com/blog</link>
	<description>Information security news from the small tree</description>
	<lastBuildDate>Sun, 18 Oct 2009 18:06:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>Comment on Cross Site Scripting Payloads by andres.riancho</title>
		<link>http://www.bonsai-sec.com/blog/index.php/cross-site-scripting-payloads/comment-page-1/#comment-589</link>
		<dc:creator>andres.riancho</dc:creator>
		<pubDate>Sun, 18 Oct 2009 18:06:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.bonsai-sec.com/blog/?p=238#comment-589</guid>
		<description>&lt;a href=&quot;#comment-587&quot; rel=&quot;nofollow&quot;&gt;@Sébastien Duquette&lt;/a&gt; 
The feature has been in the trunk for some time now. You can find it in the GUI menu. Thanks!</description>
		<content:encoded><![CDATA[<p><a href="#comment-587" rel="nofollow">@Sébastien Duquette</a><br />
The feature has been in the trunk for some time now. You can find it in the GUI menu. Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cross Site Scripting Payloads by Sébastien Duquette</title>
		<link>http://www.bonsai-sec.com/blog/index.php/cross-site-scripting-payloads/comment-page-1/#comment-587</link>
		<dc:creator>Sébastien Duquette</dc:creator>
		<pubDate>Sun, 18 Oct 2009 01:02:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.bonsai-sec.com/blog/?p=238#comment-587</guid>
		<description>Nice feature. I updated w3af on Windows but couldn&#039;t find it. Do you have an idea when it will be added to trunk ?</description>
		<content:encoded><![CDATA[<p>Nice feature. I updated w3af on Windows but couldn&#8217;t find it. Do you have an idea when it will be added to trunk ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on moth &#8211; A VMware image with vulnerable web applications by System Advancements at the Monastery &#187; Blog Archive &#187; Learning By Doing: Hacker Challenges and Practice Sites</title>
		<link>http://www.bonsai-sec.com/blog/index.php/moth-vulnerable-vmware-image/comment-page-1/#comment-156</link>
		<dc:creator>System Advancements at the Monastery &#187; Blog Archive &#187; Learning By Doing: Hacker Challenges and Practice Sites</dc:creator>
		<pubDate>Sun, 23 Aug 2009 05:57:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.bonsai-sec.com/blog/?p=69#comment-156</guid>
		<description>[...] Web Application Attack and Audit Framework (w3af) project has created a VMware image, called Moth, which is a set of vulnerable Web Applications and scripts. The w3af core and it&#8217;s plugins [...]</description>
		<content:encoded><![CDATA[<p>[...] Web Application Attack and Audit Framework (w3af) project has created a VMware image, called Moth, which is a set of vulnerable Web Applications and scripts. The w3af core and it&#8217;s plugins [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Not the average SQL Injection by Adam Baldwin</title>
		<link>http://www.bonsai-sec.com/blog/index.php/not-the-average-sql-injection/comment-page-1/#comment-92</link>
		<dc:creator>Adam Baldwin</dc:creator>
		<pubDate>Thu, 23 Jul 2009 04:17:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.bonsai-sec.com/blog/?p=195#comment-92</guid>
		<description>I would have loved to have known this as well when I worked through a similar injection technique in March &#039;09 when working with OpenCart. I learned that subqueries are your friend. Great information both of you.

Reference:
http://www.ngenuity.org/wordpress/2009/05/12/ngenuity-2009-005-opencart-re-visited-exploit-included/
﻿﻿﻿﻿﻿http://www.ngenuity.org/wordpress/2009/03/10/ngenuity-2009-005-opencart-order-by-blind-sql-injection/</description>
		<content:encoded><![CDATA[<p>I would have loved to have known this as well when I worked through a similar injection technique in March &#8216;09 when working with OpenCart. I learned that subqueries are your friend. Great information both of you.</p>
<p>Reference:<br />
<a href="http://www.ngenuity.org/wordpress/2009/05/12/ngenuity-2009-005-opencart-re-visited-exploit-included/" rel="nofollow">http://www.ngenuity.org/wordpress/2009/05/12/ngenuity-2009-005-opencart-re-visited-exploit-included/</a><br />
﻿﻿﻿﻿﻿http://www.ngenuity.org/wordpress/2009/03/10/ngenuity-2009-005-opencart-order-by-blind-sql-injection/</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Not the average SQL Injection by andres.riancho</title>
		<link>http://www.bonsai-sec.com/blog/index.php/not-the-average-sql-injection/comment-page-1/#comment-87</link>
		<dc:creator>andres.riancho</dc:creator>
		<pubDate>Mon, 20 Jul 2009 14:32:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.bonsai-sec.com/blog/?p=195#comment-87</guid>
		<description>&lt;a href=&quot;#comment-85&quot; rel=&quot;nofollow&quot;&gt;@Bernardo&lt;/a&gt; 
I totally forgot about those slides! You&#039;re right, the slides 25 and 26 point this subject. 

I did all the testing to find a way to inject into ORDER BY without knowing about that previous research. I just hope my post helps somebody that finds it through Google while trying to do the same thing.</description>
		<content:encoded><![CDATA[<p><a href="#comment-85" rel="nofollow">@Bernardo</a><br />
I totally forgot about those slides! You&#8217;re right, the slides 25 and 26 point this subject. </p>
<p>I did all the testing to find a way to inject into ORDER BY without knowing about that previous research. I just hope my post helps somebody that finds it through Google while trying to do the same thing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Not the average SQL Injection by Bernardo</title>
		<link>http://www.bonsai-sec.com/blog/index.php/not-the-average-sql-injection/comment-page-1/#comment-85</link>
		<dc:creator>Bernardo</dc:creator>
		<pubDate>Mon, 20 Jul 2009 14:05:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.bonsai-sec.com/blog/?p=195#comment-85</guid>
		<description>I described this back in March &#039;09, http://www.slideshare.net/inquis/sql-injection-not-only-and-11 ;)</description>
		<content:encoded><![CDATA[<p>I described this back in March &#8216;09, <a href="http://www.slideshare.net/inquis/sql-injection-not-only-and-11" rel="nofollow">http://www.slideshare.net/inquis/sql-injection-not-only-and-11</a> ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Exploiting HTTP Content Negotiation by Bit more efficient brute forcing &#171; DiabloHorn</title>
		<link>http://www.bonsai-sec.com/blog/index.php/exploiting-http-content-negotiation/comment-page-1/#comment-81</link>
		<dc:creator>Bit more efficient brute forcing &#171; DiabloHorn</dc:creator>
		<pubDate>Thu, 16 Jul 2009 21:59:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.bonsai-sec.com/blog/?p=131#comment-81</guid>
		<description>[...] http://www.bonsai-sec.com/blog/index.php/exploiting-http-content-negotiation/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.bonsai-sec.com/blog/index.php/exploiting-http-content-negotiation/" rel="nofollow">http://www.bonsai-sec.com/blog/index.php/exploiting-http-content-negotiation/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on CONFidence and OWASP CtF by admin</title>
		<link>http://www.bonsai-sec.com/blog/index.php/confidence-and-owasp-ctf/comment-page-1/#comment-25</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Fri, 05 Jun 2009 13:19:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.bonsai-sec.com/blog/?p=51#comment-25</guid>
		<description>&lt;a href=&quot;#comment-24&quot; rel=&quot;nofollow&quot;&gt;@FluxFreddy&lt;/a&gt; 
Thanks, stay tunned because I&#039;m going to be writing at least two more posts, with the CtF level details, code, etc. Also, Pavol from tripkaci is going to write about how they solved a couple of the hard levels.</description>
		<content:encoded><![CDATA[<p><a href="#comment-24" rel="nofollow">@FluxFreddy</a><br />
Thanks, stay tunned because I&#8217;m going to be writing at least two more posts, with the CtF level details, code, etc. Also, Pavol from tripkaci is going to write about how they solved a couple of the hard levels.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on CONFidence and OWASP CtF by FluxFreddy</title>
		<link>http://www.bonsai-sec.com/blog/index.php/confidence-and-owasp-ctf/comment-page-1/#comment-24</link>
		<dc:creator>FluxFreddy</dc:creator>
		<pubDate>Fri, 05 Jun 2009 08:44:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.bonsai-sec.com/blog/?p=51#comment-24</guid>
		<description>Nice Writeup, Andrés! :)
And again, thanks for the CTF, we really enjoyed taking part.</description>
		<content:encoded><![CDATA[<p>Nice Writeup, Andrés! :)<br />
And again, thanks for the CTF, we really enjoyed taking part.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on moth &#8211; A VMware image with vulnerable web applications by KrisBelucci</title>
		<link>http://www.bonsai-sec.com/blog/index.php/moth-vulnerable-vmware-image/comment-page-1/#comment-22</link>
		<dc:creator>KrisBelucci</dc:creator>
		<pubDate>Tue, 02 Jun 2009 19:27:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.bonsai-sec.com/blog/?p=69#comment-22</guid>
		<description>Great post! Just wanted to let you know you have a new subscriber- me!</description>
		<content:encoded><![CDATA[<p>Great post! Just wanted to let you know you have a new subscriber- me!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
