<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>My Pen Test</title>
	<atom:link href="http://www.mypentest.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mypentest.com</link>
	<description>Penetration Testing Web applications</description>
	<pubDate>Thu, 05 Jun 2008 09:33:30 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Why HP is wrong about the Web Security Lifecycle</title>
		<link>http://www.mypentest.com/web-security-lifecycle/</link>
		<comments>http://www.mypentest.com/web-security-lifecycle/#comments</comments>
		<pubDate>Thu, 05 Jun 2008 02:44:00 +0000</pubDate>
		<dc:creator>Stuart Moncrieff</dc:creator>
		
		<category><![CDATA[WebInspect]]></category>

		<category><![CDATA[DevInspect]]></category>

		<category><![CDATA[HP Software]]></category>

		<category><![CDATA[QAInspect]]></category>

		<guid isPermaLink="false">http://www.mypentest.com/?p=41</guid>
		<description><![CDATA[In my first post I gave a very brief overview of the web security testing products offered by HP. Unfortunately people&#8217;s understanding of where the products should fit into the software development lifecycle is still weak. This is even the case inside HP.
Here is a current slide from HP Software&#8230;

The obvious, glaring problem with this [...]]]></description>
		<wfw:commentRss>http://www.mypentest.com/web-security-lifecycle/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Web Macro Recorder does not record</title>
		<link>http://www.mypentest.com/macro-recorder-does-not-record/</link>
		<comments>http://www.mypentest.com/macro-recorder-does-not-record/#comments</comments>
		<pubDate>Tue, 03 Jun 2008 09:31:24 +0000</pubDate>
		<dc:creator>Stuart Moncrieff</dc:creator>
		
		<category><![CDATA[WebInspect]]></category>

		<category><![CDATA[Web Macro Recorder]]></category>

		<guid isPermaLink="false">http://www.mypentest.com/?p=28</guid>
		<description><![CDATA[Something that confuses new users to WebInspect is that the Web Macro Recorder will not record any requests to http://127.0.0.1 or http://localhost. This can cause much head scratching for someone who just wants to try something out on their local machine.
The simple solution to this is to add an entry to your hosts file, and [...]]]></description>
		<wfw:commentRss>http://www.mypentest.com/macro-recorder-does-not-record/feed/</wfw:commentRss>
		</item>
		<item>
		<title>My car as an analogy for web security</title>
		<link>http://www.mypentest.com/web-security-car-analogy/</link>
		<comments>http://www.mypentest.com/web-security-car-analogy/#comments</comments>
		<pubDate>Sat, 17 May 2008 04:52:54 +0000</pubDate>
		<dc:creator>Stuart Moncrieff</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.mypentest.com/?p=26</guid>
		<description><![CDATA[I live in a bad neighbourhood&#8230;well, okay, not a really bad neighbourhood but its close proximity to the CBD and its abundance of funky bars, galleries and restaurants is neatly balanced by a high concentration of government housing that seems to go hand-in-hand with junkies panhandling outside the supermarket, groups of people drinking in the [...]]]></description>
		<wfw:commentRss>http://www.mypentest.com/web-security-car-analogy/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Seven Web Application Security Myths</title>
		<link>http://www.mypentest.com/web-security-myths/</link>
		<comments>http://www.mypentest.com/web-security-myths/#comments</comments>
		<pubDate>Sun, 04 May 2008 06:35:53 +0000</pubDate>
		<dc:creator>Stuart Moncrieff</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.mypentest.com/?p=36</guid>
		<description><![CDATA[
HTTPS will protect your application. Just because a user&#8217;s browser displays a lock icon when they visit your website, doesn&#8217;t mean that your website is secure. HTTP over SSL (HTTPS) only encrypts the traffic between the user and the web server, which prevents snooping of the user&#8217;s traffic. It does not prevent a user sending [...]]]></description>
		<wfw:commentRss>http://www.mypentest.com/web-security-myths/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Akamai - State of the Internet</title>
		<link>http://www.mypentest.com/akamai-state-of-the-internet/</link>
		<comments>http://www.mypentest.com/akamai-state-of-the-internet/#comments</comments>
		<pubDate>Fri, 04 Apr 2008 02:58:34 +0000</pubDate>
		<dc:creator>Stuart Moncrieff</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[Akamai]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[State of the Internet]]></category>

		<guid isPermaLink="false">http://www.mypentest.com/?p=32</guid>
		<description><![CDATA[Akamai, who provide transparent mirroring of web content for high-traffic websites, see a large sample of Internet traffic. They have started to report on some of the trends they see in their traffic patterns (while some not so subtle points about how good they are). Their first report covers Q1 2008 (January - March). The [...]]]></description>
		<wfw:commentRss>http://www.mypentest.com/akamai-state-of-the-internet/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Opening a laptop security cable with a toilet roll</title>
		<link>http://www.mypentest.com/opening-a-laptop-security-cable-with-a-toilet-roll/</link>
		<comments>http://www.mypentest.com/opening-a-laptop-security-cable-with-a-toilet-roll/#comments</comments>
		<pubDate>Tue, 25 Mar 2008 09:58:39 +0000</pubDate>
		<dc:creator>Stuart Moncrieff</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Kensington]]></category>

		<category><![CDATA[lock picking]]></category>

		<guid isPermaLink="false">http://www.mypentest.com/opening-a-laptop-security-cable-with-a-toilet-roll/</guid>
		<description><![CDATA[
Lock Picked with Toilet Paper Tube










]]></description>
		<wfw:commentRss>http://www.mypentest.com/opening-a-laptop-security-cable-with-a-toilet-roll/feed/</wfw:commentRss>
		</item>
		<item>
		<title>WebInspect Scan Signatures</title>
		<link>http://www.mypentest.com/webinspect-signatures/</link>
		<comments>http://www.mypentest.com/webinspect-signatures/#comments</comments>
		<pubDate>Mon, 04 Feb 2008 06:03:02 +0000</pubDate>
		<dc:creator>Stuart Moncrieff</dc:creator>
		
		<category><![CDATA[WebInspect]]></category>

		<guid isPermaLink="false">http://www.mypentest.com/?p=34</guid>
		<description><![CDATA[WebInspect is definitely not a stealthy tool; and that&#8217;s fine, because you shouldn&#8217;t be secretly auditing anyone&#8217;s website. Here are a few of the signs that WebInspect leaves when doing a crawl and audit of a website.
WebInspect Scan Signature: The webinspect scan signature is a request that webinspect sends to the server with the text [...]]]></description>
		<wfw:commentRss>http://www.mypentest.com/webinspect-signatures/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Google Hacking for Penetration Testers (free e-book download)</title>
		<link>http://www.mypentest.com/google-hacking-free-ebook/</link>
		<comments>http://www.mypentest.com/google-hacking-free-ebook/#comments</comments>
		<pubDate>Wed, 02 Jan 2008 04:58:13 +0000</pubDate>
		<dc:creator>Stuart Moncrieff</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[e-book]]></category>

		<category><![CDATA[Google hacking]]></category>

		<guid isPermaLink="false">http://www.mypentest.com/google-hacking-free-ebook/</guid>
		<description><![CDATA[Super-fast posting mode&#8230;

Slashdot review of Google Hacking for Penetration Testers
The book on the publisher&#8217;s website
http://www.syngress.com/catalog/?pid=3150
Google Hacking database (from the author)
http://johnny.ihackstuff.com/ghdb.php
Google Hacking on Wikipedia
http://en.wikipedia.org/wiki/Google_hacking
Author&#8217;s website
http://johnny.ihackstuff.com/
Direct download of the PDF of the book (33MB) (removed)
http://www.scribd.com/word/download/319798?extension=pdf
Flash-based online reader of the book (removed)
http://www.scribd.com/doc/319798/Google-Hacking-for-Penetration-Testers
New version of the book to be released sometime soon

Update: a new version of the book has [...]]]></description>
		<wfw:commentRss>http://www.mypentest.com/google-hacking-free-ebook/feed/</wfw:commentRss>
		</item>
		<item>
		<title>WebInspect free download (15-day trial)</title>
		<link>http://www.mypentest.com/webinspect-free-download/</link>
		<comments>http://www.mypentest.com/webinspect-free-download/#comments</comments>
		<pubDate>Sat, 08 Dec 2007 09:25:38 +0000</pubDate>
		<dc:creator>Stuart Moncrieff</dc:creator>
		
		<category><![CDATA[WebInspect]]></category>

		<guid isPermaLink="false">http://www.mypentest.com/webinspect-free-download/</guid>
		<description><![CDATA[For those who want to have a look at what WebInspect can do, there is a free 15-day trial available. Note that you will need to provide a valid email address to receive your trial license key, and you will also need to install SQL Server 2005 or SQL Server 2005 Express Edition (free download [...]]]></description>
		<wfw:commentRss>http://www.mypentest.com/webinspect-free-download/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HP acquires SPI Dynamics</title>
		<link>http://www.mypentest.com/hp-acquires-spi-dynamics/</link>
		<comments>http://www.mypentest.com/hp-acquires-spi-dynamics/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 04:20:43 +0000</pubDate>
		<dc:creator>Stuart Moncrieff</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[DevInspect]]></category>

		<category><![CDATA[HP Software]]></category>

		<category><![CDATA[QAInspect]]></category>

		<category><![CDATA[SPI Dynamics]]></category>

		<category><![CDATA[WebInspect]]></category>

		<guid isPermaLink="false">http://www.mypentest.com/?p=5</guid>
		<description><![CDATA[On June 19, HP announced in a press release that it had signed an agreement to acquire SPI Dynamics, a software company specialising in web security testing tools. The deal was finalised on August 1, and it is only now that theses new tools are reaching the wider pool of technical people (like me) at [...]]]></description>
		<wfw:commentRss>http://www.mypentest.com/hp-acquires-spi-dynamics/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
