<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xml:base="https://www.webmaster-forums.net/crss/node/1043334" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title></title>
    <link>https://www.webmaster-forums.net/crss/node/1043334</link>
    <description></description>
    <language>en</language>
          <item>
    <title>I&#039;m excited to say that part</title>
    <link>https://www.webmaster-forums.net/web-programming-and-application-development/check-out-videos-how-protect-your-website-against-hacker#comment-1242284</link>
    <description> &lt;p&gt;I&#039;m excited to say that part 2 of my video series is available at &lt;a href=&quot;http://www.aachen-method.com&quot; title=&quot;www.aachen-method.com&quot;&gt;www.aachen-method.com&lt;/a&gt;. I&#039;m covering Cross-Site Scripting (XSS) and how you can protect your website against it. Over the past couple of weeks I was super busy with my other projects so I couldn&#039;t focus on this course, but that&#039;s all behind me now and I can work more on this. &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/smile.png&quot; title=&quot;Smiling&quot; alt=&quot;Smiling&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Being able to secure your code against CSRF and XSS attacks is a critical skill in being able to charge higher rates as a freelancer, so don&#039;t skip these videos.&lt;/p&gt;
&lt;p&gt;I also recorded a new introductory video for you where I talk about how people (read: employers) can&#039;t help the perception that expensive equals best. This is supposed to serve as a sneak peek of part 3 of my video series and it&#039;s a somewhat simplified version of the reality. I&#039;m not suggesting that you should just start charging $500/hour like a lawyer and half a dozen hot chicks will immediately surround you because they will think you are the s***.&lt;/p&gt;
&lt;p&gt;I&#039;m also giving a 100% honest explanation on why I&#039;m giving away all this content. Hint: It&#039;s not what you think. Definitely watch this video first.&lt;/p&gt;
&lt;p&gt;Make sure you sign up for my newsletter so I can notify you right away when I release more killer videos. I promise I won&#039;t give your address to anyone and I will never spam you. You can remove your address from the list at any time simply by clicking on the unsubscribe link that is included in every e-mail.&lt;/p&gt;
&lt;p&gt;P.S.: Yeah, I&#039;m posting this on a Tuesday afternoon when I&#039;m supposed to be working. I guess I procrastinate way too much. &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/wink.png&quot; title=&quot;Wink&quot; alt=&quot;Wink&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
&lt;p&gt;P.P.S.: Here&#039;s the link again: &lt;a href=&quot;http://www.aachen-method.com&quot; title=&quot;www.aachen-method.com&quot;&gt;www.aachen-method.com&lt;/a&gt;&lt;/p&gt;
 </description>
     <pubDate>Tue, 02 Jun 2009 15:25:36 +0000</pubDate>
 <dc:creator>Arne1983</dc:creator>
 <guid isPermaLink="false">comment 1242284 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title>Securing PHP application is</title>
    <link>https://www.webmaster-forums.net/web-programming-and-application-development/check-out-videos-how-protect-your-website-against-hacker#comment-1242165</link>
    <description> &lt;p&gt;Securing PHP application is an issue for me and i dont know how it could be done. Your videos are very informative as i am a newbie in PHP. Do post more on them.&lt;/p&gt;
 </description>
     <pubDate>Sat, 30 May 2009 14:59:08 +0000</pubDate>
 <dc:creator>pulseraiser</dc:creator>
 <guid isPermaLink="false">comment 1242165 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title>The good thing about Drupal</title>
    <link>https://www.webmaster-forums.net/web-programming-and-application-development/check-out-videos-how-protect-your-website-against-hacker#comment-1239770</link>
    <description> &lt;p&gt;The good thing about Drupal is me not to bother about security.  As long as I am up to date, I can focus on my content and do the things I need to do.  If a vulnerability is being discovered, I simply do the upgrade timely and I am secure again.  All I have to do is do the upgrade without, and I don&#039;t need to know what was the vulnerability, how it works and how the security group deal with it.  All I know is I need to do the upgrade.&lt;/p&gt;
&lt;p&gt;Your video is good.  I am not a pro in public speaking and English is not my everyday language, but I understand you loud and clear.  Good luck and thank you for sharing this.&lt;/p&gt;
 </description>
     <pubDate>Wed, 25 Mar 2009 10:15:27 +0000</pubDate>
 <dc:creator>RTFVerterra</dc:creator>
 <guid isPermaLink="false">comment 1239770 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title>In fact, I received a notice</title>
    <link>https://www.webmaster-forums.net/web-programming-and-application-development/check-out-videos-how-protect-your-website-against-hacker#comment-1239480</link>
    <description> &lt;p&gt;In fact, I received a notice about a CSRF that was patched in a contrib Drupal module today:&lt;/p&gt;
&lt;p&gt;Greg Knaddison (reported by) also creates the excellent &quot;&lt;a href=&quot;http://www.masteringdrupal.com/&quot;&gt;Mastering Drupal&lt;/a&gt;&quot; videos (including the free SEO series!)&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;* Advisory ID: DRUPAL-SA-CONTRIB-2009-010&lt;br /&gt;
 * Project: Plus 1 (third-party module)&lt;br /&gt;
 * Version: 6.x&lt;br /&gt;
 * Date: 2009 March 18&lt;br /&gt;
 * Security risk: Not critical&lt;br /&gt;
 * Exploitable from: Remote&lt;br /&gt;
 * Vulnerability: Cross-site request forgery (CSRF)&lt;/p&gt;
&lt;p&gt;-------- DESCRIPTION ---------------------------------------------------------&lt;/p&gt;
&lt;p&gt;The Plus 1 module provides a voting widget for content that records votes&lt;br /&gt;
using Ajax.&lt;/p&gt;
&lt;p&gt;The URL for voting is vulnerable to cross-site request forgeries (CSRF [1])&lt;br /&gt;
making it possible for users to unknowingly vote for content.&lt;/p&gt;
&lt;p&gt;-------- VERSIONS AFFECTED ---------------------------------------------------&lt;/p&gt;
&lt;p&gt; * Versions of Plus 1 prior to 6.x-2.6&lt;/p&gt;
&lt;p&gt;Drupal core is not affected. If you do not use the contributed Plus 1 module,&lt;br /&gt;
there is nothing you need to do.&lt;/p&gt;
&lt;p&gt;-------- SOLUTION ------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;Install the latest version:&lt;/p&gt;
&lt;p&gt; * If you use Plus 1 for Drupal 6.x upgrade to Plus 1 6.x-2.6 [2]&lt;/p&gt;
&lt;p&gt;See also the Plus 1 project page [3].&lt;/p&gt;
&lt;p&gt;-------- REPORTED BY ---------------------------------------------------------&lt;/p&gt;
&lt;p&gt;Greg Knaddison of the Drupal security team.&lt;/p&gt;
&lt;p&gt;-------- FIXED BY ------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;Greg Knaddison, Ben Jeavons, Neil Drumm, and Caroline Schnapp.&lt;/p&gt;
&lt;p&gt;-------- CONTACT -------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;The security contact for Drupal can be reached at security at drupal.org or&lt;br /&gt;
via the form at &lt;a href=&quot;http://drupal.org/contact&quot; title=&quot;http://drupal.org/contact&quot;&gt;http://drupal.org/contact&lt;/a&gt; [4].&lt;/p&gt;
&lt;p&gt;[1] &lt;a href=&quot;http://en.wikipedia.org/wiki/Csrf&quot; title=&quot;http://en.wikipedia.org/wiki/Csrf&quot;&gt;http://en.wikipedia.org/wiki/Csrf&lt;/a&gt;&lt;br /&gt;
[2] &lt;a href=&quot;http://drupal.org/node/405672&quot; title=&quot;http://drupal.org/node/405672&quot;&gt;http://drupal.org/node/405672&lt;/a&gt;&lt;br /&gt;
[3] &lt;a href=&quot;http://drupal.org/project/plus1&quot; title=&quot;http://drupal.org/project/plus1&quot;&gt;http://drupal.org/project/plus1&lt;/a&gt;&lt;br /&gt;
[4] &lt;a href=&quot;http://drupal.org/contact&quot; title=&quot;http://drupal.org/contact&quot;&gt;http://drupal.org/contact&lt;/a&gt;&lt;br /&gt;
_______________________________________________&lt;br /&gt;
Security-news mailing list&lt;br /&gt;
&lt;a href=&quot;mailto:Security-news@drupal.org&quot;&gt;Security-news@drupal.org&lt;/a&gt;&lt;br /&gt;
http://lists.drupal.org/listinfo/security-news&lt;/p&gt;&lt;/blockquote&gt;
 </description>
     <pubDate>Wed, 18 Mar 2009 19:20:54 +0000</pubDate>
 <dc:creator>decibel.places</dc:creator>
 <guid isPermaLink="false">comment 1239480 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title>Website security is</title>
    <link>https://www.webmaster-forums.net/web-programming-and-application-development/check-out-videos-how-protect-your-website-against-hacker#comment-1239455</link>
    <description> &lt;p&gt;Website security is definitely something n00bs don&#039;t focus on enough.  SQL injection is another hot topic as well.&lt;/p&gt;
 </description>
     <pubDate>Wed, 18 Mar 2009 01:18:20 +0000</pubDate>
 <dc:creator>pr0gr4mm3r</dc:creator>
 <guid isPermaLink="false">comment 1239455 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title>Hi Arne, welcome to TWF! 
I</title>
    <link>https://www.webmaster-forums.net/web-programming-and-application-development/check-out-videos-how-protect-your-website-against-hacker#comment-1239453</link>
    <description> &lt;p&gt;Hi Arne, welcome to TWF! &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/grin.png&quot; title=&quot;Laugh&quot; alt=&quot;Laugh&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
&lt;p&gt;I viewed your introductory video and found it quite informative and nearly professional - I plan to come back to learn some more.&lt;/p&gt;
&lt;p&gt;I often debate security issues with another member here. Thank you for sharing your knowledge!&lt;/p&gt;
&lt;p&gt;My only criticism would be that once in a while you are difficult to understand, a word or two are hard to make out. This does not affect the overall content, but perhaps you could try to talk slower and more clearly. I have been a professional public speaker, and it takes training to learn how to talk to an audience and be understood.&lt;/p&gt;
&lt;p&gt;I am sure as time goes on and you become less nervous you will become a pro!&lt;/p&gt;
&lt;p&gt;CSRF is one exploit commonly discovered in Drupal contrib modules - I know because I receive the Drupal security reports and often I see that a CSRF vulnerability has been discovered and patched.&lt;/p&gt;
 </description>
     <pubDate>Wed, 18 Mar 2009 00:35:12 +0000</pubDate>
 <dc:creator>decibel.places</dc:creator>
 <guid isPermaLink="false">comment 1239453 at https://www.webmaster-forums.net</guid>
  </item>
  </channel>
</rss>
