<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management and Compliance&#187; Website security</title>
	<atom:link href="http://blog.kraasecurity.com/tag/website-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Wed, 26 May 2010 02:45:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Web Security Testing has come of age</title>
		<link>http://blog.kraasecurity.com/2009/07/20/web-security-testing-has-come-of-age/</link>
		<comments>http://blog.kraasecurity.com/2009/07/20/web-security-testing-has-come-of-age/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 04:30:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[breach data]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hipaa security]]></category>
		<category><![CDATA[web security]]></category>
		<category><![CDATA[Website security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=86</guid>
		<description><![CDATA[Website security is the one of the most dangerous places for a company. If you look at a layered security approach, we start out with the internal network. There we have host security, patch management, host IDS and other server based technologies. Next we have the network security layers, network intrusion detection, network monitoring and [...]]]></description>
			<content:encoded><![CDATA[<p>Website security is the one of the most dangerous places for a company. If you look at a layered security approach, we start out with the internal network. There we have <strong>host security, patch management, host IDS </strong>and other server based technologies. Next we have the network security layers,<strong> network intrusion detection, network monitoring and firewall</strong> protection. So if we have the internal servers secured, the network protection place, what is left is that an attacker can possibly get into a secure environment?</p>
<p>The website is the open frontdoor to many companies. <strong>Security education</strong> for both the developers of website applications and the users of web sites is sadly lacking. If we look at most of the compliance regulations such as <strong>HIPAA </strong>or <strong>PCI</strong>, there is a component of education required, but most companies do not spend the time to provide more than a written manual that no one reads. In those same regulations, there are requirements for a <strong>Secure Development Lifecycle</strong> strategy, but how many web application developers actually follow a strict methodology?</p>
<p>So on Linkedin, I asked the quesion &#8220;what are the Web security tools&#8221; that are favored by the security community (<a href="http://www.linkedin.com/gbaha">www.linkedin.com/gbaha</a>). These can provide some help and insight for those looking to conduct some security testing. Some are paid and some are free. Here is the list in no particular order.</p>
<p>1) Foundstone             http://<a href="http://www.foundstone.com">www.foundstone.com</a><br />
2) Acunetix WVS        http://<a href="http://www.acunetix.com">www.acunetix.com</a><br />
3) Scrawlr                      <a href="https://h30406.www3.hp.com/">https://h30406.www3.hp.com/</a><br />
4) N-Stalker                  http://<a href="http://www.nstalker.com/">www.nstalker.com/</a><br />
5) Nikto                          <a href="http://cirt.net/nikto2">http://cirt.net/nikto2</a><br />
6) Scarab                       <a href="http://www.owasp.org">http://www.owasp.org</a><br />
7) WebInspect            http://<a href="http://www.hp.com">www.hp.com</a><br />
 <img src='http://blog.kraasecurity.com/wp-includes/images/smilies/icon_cool.gif' alt='8)' class='wp-smiley' /> Fiddler -                   http://<a href="http://www.fiddlertool.com">www.fiddlertool.com</a><br />
9) Samurai Web Testing Framework &#8211; <a href="http://samurai.inguardians.com/">http://samurai.inguardians.com/</a><br />
10) FireCAT -               http://<a href="http://www.security-database.com">www.security-database.com</a><br />
11) W3af                         <a href="http://w3af.sourceforge.net/">http://w3af.sourceforge.net/</a><br />
12) CORE Impact        <a href="http://www.coresecurity.com/content/web-app-pro">http://www.coresecurity.com/content/web-app-pro</a><br />
13) Appscan                 <a href="http://www-01.ibm.com/software/awdtools/appscan/">http://www-01.ibm.com/software/awdtools/appscan/</a></p>
<p>Having listed these and of course there a re a number of other tools, we can begin to secure the environment. (Please send me any comments on other tools you like). Running a tools is a first and easy step you can take to close that open web door (Webdoor, I am going to try and coin that phrase). If you can target tactical prablems, get them fixed quickly, you can then tackle the strategic problems that led to your web vulnerabilities.</p>
<p>The basic steps you want to take in website security are:<br />
1) Vulnerability testing<br />
2) Secure Code Review<br />
3) Architecture review<br />
4) Monitoring and Logging<br />
5) Consistent Testing (monthly) and Validation of Controls</p>
<p>Do not get lax when it comes to Web security. Its a bit black magic and a lot of hard work but as its the &#8220;webdoor&#8221; try and keep it closed.</p>
<p>Gary Bahadur</p>
<p><a href="mailto:baha@kraasecurity.com">baha@kraasecurity.com</a></p>
<p><a href="http://www.kraasecurity.com">http://www.kraasecurity.com</a></p>
<p><a href="http://blog.kraasecurity.com">http://blog.kraasecurity.com</a></p>
<p><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" src="http://img.zemanta.com/pixy.gif?x-id=050a75a1-022d-8f14-a07a-0b5aef9c2026" alt="" /></div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 101px; width: 1px; height: 1px;"><!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 		A:link { so-language: zxx } --><span style="background: #ffff00 none repeat scroll 0% 0%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;">S</span><span style="text-decoration: none;"><span style="font-family: Arial,sans-serif;"><span style="font-size: x-small;"><span style="font-style: normal;"><strong><span style="background: #ffff00 none repeat scroll 0% 0%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;">ecurity penetration test</span></strong></span></span></span></span><span style="text-decoration: none;"><span style="font-family: Arial,sans-serif;"><span style="font-size: x-small;"><span style="font-style: normal;"><strong> (</strong></span></span></span></span><span style="color: #000080;"><span lang="zxx"><span style="text-decoration: underline;"><a href="http://www.kraasecurity.com/freewebsitetest"><span style="text-decoration: none;"><span style="font-family: Arial,sans-serif;"><span style="font-size: x-small;"><span style="font-style: normal;"><strong>http://www.kraasecurity.com/freewebsitetest</strong></span></span></span></span></a></span></span></span><span style="text-decoration: none;"><span style="font-family: Arial,sans-serif;"><span style="font-size: x-small;"><span style="font-style: normal;"><strong>)</strong></span></span></span></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/07/20/web-security-testing-has-come-of-age/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Assessments are the next wave</title>
		<link>http://blog.kraasecurity.com/2009/07/12/hipaa-assessments-are-the-next-wave/</link>
		<comments>http://blog.kraasecurity.com/2009/07/12/hipaa-assessments-are-the-next-wave/#comments</comments>
		<pubDate>Sun, 12 Jul 2009 21:06:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Government Security]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[hipaa security]]></category>
		<category><![CDATA[Managed Vulnerability Scanning]]></category>
		<category><![CDATA[Website security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/2009/07/12/hipaa-assessments-are-the-next-wave/</guid>
		<description><![CDATA[In February, CVS was ordered to pay a fine of 2.5million dollars by the FTC. This fine was because their employees threw out personal information about patients. Who knew poor recycling programs could cost so much? HIPAA has been around for a number of years but not until recently did we see that it has [...]]]></description>
			<content:encoded><![CDATA[<p>In February, CVS was ordered to pay a fine of 2.5million dollars by the FTC. This fine was because their employees threw out personal information about patients. Who knew poor recycling programs could cost so much? HIPAA has been around for a number of years but not until recently did we see that it has teeth and companies are going to be held accountable.  CVS has to have an assessment every other year now for 20 years. And assessments are not cheap! Assessments based on the <strong>Security Rule</strong> cover many areas of technology controls such as <strong>Firewall</strong> protection, <strong>Antivirus</strong>, <strong>Encryption</strong>, <strong>Vulnerability Scanning</strong> and much more. I am sure conducting an assessment rather than getting fines would have been much cheaper for CVS.</p>
<p>The definition of a Covered Entity for HIPAA compliance really reaches out to more companies than just hospitals and doctors offices. Not only companies like CVS will get fined but business partners of hopsitals and doctors offices storing patient data will be in trouble if they do not conduct <strong>Risk Assessments</strong>.</p>
<p>There are a number of ways to conduct these assessments, make them practical and stay out of trouble with &#8220;The Man&#8221;. One company that is pretty helpful in this regard is <strong>RiskWatch</strong>, http://www.riskwatch.com  Their software allows you to conduct <strong>HIPAA</strong>, <strong>PCI</strong>, <strong>Red Flag Rule</strong> and other types of assessments.</p>
<p>For security professional, these regululations provide a strong insentive for companies to get their act together regarding privacy and security of data. Its unfortunate they have to be fined first to get them to the ball rolling. But hopefully, more will take a proactive stance for compliance but also to get an ongoing security program in place.</p>
<p>Regards<br />
Gary Bahadur<br />
<!--  /* Font Definitions */ @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-alt:HigherStandards-Light; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} span.EmailStyle15 	{mso-style-type:personal; 	mso-style-noshow:yes; 	mso-style-unhide:no; 	mso-ansi-font-size:11.0pt; 	mso-bidi-font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi; 	color:windowtext;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --></p>
<p class="MsoNormal"><strong><span><a href="http://www.kraasecurity.com/"><span style="color: blue;">http://www.kraasecurity.com</span></a></span></strong></p>
<p class="MsoNormal"><strong><span><a href="http://blog.kraasecurity.com">http://blog.kraasecurity.com</a></span></strong></p>
<p class="MsoNormal"><strong><span><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></span></strong></p>
<p class="MsoNormal"><span style="color: #c00000;">*Managed Security Services</span></p>
<p class="MsoNormal"><span style="color: #c00000;">*Vulnerability Management</span></p>
<p class="MsoNormal"><span style="color: #c00000;">*Compliance &amp; Policy Development</span></p>
<p class="MsoNormal"><span style="color: #c00000;">*PGP Security</span></p>
<p class="MsoNormal"><span style="color: #c00000;">*FREE Website Security Test</span></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/07/12/hipaa-assessments-are-the-next-wave/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vanguard Security Conference &#8211; Supplier Security</title>
		<link>http://blog.kraasecurity.com/2009/06/02/supplier-security/</link>
		<comments>http://blog.kraasecurity.com/2009/06/02/supplier-security/#comments</comments>
		<pubDate>Tue, 02 Jun 2009 15:44:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Supplier Security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Code review]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[Managed Vulnerability Scanning]]></category>
		<category><![CDATA[web security]]></category>
		<category><![CDATA[Website security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=48</guid>
		<description><![CDATA[I spoke yesterday at the Vanguard Security Conference (http://www.go2vanguard.com) Vanguard has been doing this conference for a number of years. The focus is on Mainframe security. Most security professionals these days have never worked on MF security. I am proud to say I have back in the mid-90&#8217;s. We perhaps I shouldnt be do happy, [...]]]></description>
			<content:encoded><![CDATA[<p>I spoke yesterday at the Vanguard Security Conference (<a href="http://www.go2vanguard.com">http://www.go2vanguard.com</a>) Vanguard has been doing this conference for a number of years. The focus is on Mainframe security. Most security professionals these days have never worked on MF security. I am proud to say I have back in the mid-90&#8217;s. We perhaps I shouldnt be do happy, it was over a decade ago.</p>
<p>The point being, that there are so many areas of security out there that most of us will never touch yet there is a dire need for professionals. The conference was less attended, as are most conferences this year, but I found the folks here are REALLY interested in learning and excited about the classes.</p>
<p>My topic was on <strong>Supplier Risk Management</strong> processe. You are asking yourself, what is that? I asked myself that same question in coming up with some good processes to target Supplier security. We have to go way beyond a SAS70 if you want real security over the hundreds or thousands of vendors that a large company may work with.</p>
<p>The Problem:</p>
<ol>
<li>No framework for managing <strong>vendor risk</strong></li>
<li>Inconsistent processes for tracking vendors</li>
<li>Lack of enforcement capabilities</li>
</ol>
<p>The Opportunity:</p>
<ol>
<li>Provide practical steps to manage vendor access/management</li>
<li>Provide cost effective solution for risk mitigation</li>
<li>Provide numerical risk analysis of vendor/partner security issues</li>
<li>Risk reduction or risk acceptance</li>
<li>Documented exposure</li>
<li>Iterative process for <strong>risk management</strong></li>
<li>Happy CIO</li>
</ol>
<p>So a Supplier Security assessment follow 4 main steps:</p>
<ol>
<li>Analyze current vendor database, catageorize each</li>
<li>determine risk of each supplier, determine threats posed by each supplier</li>
<li>Perform assessment tests of each supplier, their processes of interaction, and data access</li>
<li>develop risk mitigation plan, update processed, monitoring processes</li>
</ol>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">Gary Bahadur</span></span></span></p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p>*Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*PGP Security</p>
<p>*FREE Website Security Test</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/06/02/supplier-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ways to Maintain Website Security</title>
		<link>http://blog.kraasecurity.com/2009/04/10/website-security/</link>
		<comments>http://blog.kraasecurity.com/2009/04/10/website-security/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 14:33:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Could Computing]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Application security]]></category>
		<category><![CDATA[Code review]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[firewall management]]></category>
		<category><![CDATA[Intrusion detection system]]></category>
		<category><![CDATA[Intrusion prevention system]]></category>
		<category><![CDATA[Managed Vulnerability Scanning]]></category>
		<category><![CDATA[Website security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=3</guid>
		<description><![CDATA[With the advancement in technology comes the heavy responsibility of monitoring an organization&#8217;s sensitive and valuable information. The use of the Internet has become a necessity in organizations to exchange their data and various other business details with their business partners, vendors and clients. In many cases, during transmission of datahackers compromise a network or [...]]]></description>
			<content:encoded><![CDATA[<p>With the advancement in technology comes the heavy responsibility of monitoring an organization&#8217;s sensitive and valuable information. The use of the <a class="zem_slink freebase/guid/9202a8c04000641f800000000001de59" title="Internet" rel="wikipedia" href="http://en.wikipedia.org/wiki/Internet">Internet</a> has become a necessity in organizations to exchange their data and various other business details with their business partners, vendors and clients. In many cases, during transmission of datahackers compromise a network or transmission medium and illegally gain the data. It maligns not only the market value of the company but also the number of clients that place trust in the company and the company’s infrastructure or website.</p>
<p>There are preventive measures that every company can adopt to maintain the value of the company as well as the client base. It is very important for any company to maintain the data securityase and safeguard the internal information of the company. The clients and business partners share their data only after confirming that the partner company will keep it safe and intact under the safety norms of the company.</p>
<p>By taking a few cautionary measures, one can easily secure the sensitive information of the company. Installing a <a href="http://www.kraasecurity.com/managed-services/intrusion-defense/firewall">firewall </a>in the network system keeps the security intact and safe. Earlier, this was a bit expensive for companies but with the advent of technology, this has become an easily accessible tool for the organization. Affordable monthly subscriptiuons are available for <a class="zem_slink freebase/en/firewall" title="Firewall" rel="wikipedia" href="http://en.wikipedia.org/wiki/Firewall">firewalls</a>, <a class="zem_slink freebase/en/intrusion-detection_system" title="Intrusion detection system" rel="wikipedia" href="http://en.wikipedia.org/wiki/Intrusion_detection_system">Intrusion detection systems</a> and host <a href="http://www.kraasecurity.com/managed-services/intrusion-defense/intrusion-detection">intrusion prevention systems</a>. hey need not spend a lot of money in availing these services now.</p>
<p>A firewall is the main defense. A firewall carries out routine security checks and blocking techniques at particular time intervals and this helps stop attacks. It will sound an alert in case of any threat posed to the data and will automatically start blocking and reporting.  on it. It never compromises on your company&#8217;s security and safety and always keeps the information safe. Firewall protection can be easily availed from various online sources at quite reasonable rates but one must always cross-check the credentials of the source company as well and only then purchase it from experts in the field.</p>
<p>Other than installing these tools to maintain web security, companies are also hiring third parties to review the policies and procedures of the organization and also to keep track of the online process of distribution of data of the company. These third parties install web applications that thoroughly review the codes installed in the process and provide valuable feedback to update and upgrade the quality of network systems. hough it is somewhat expensive to employ third-parties but they really keep a detailed track of the security system of their clients&#8217; information.</p>
<p>Many network systems of very renowned companies are getting hacked and misused these days by the hackers. It is high time that the companies take proper action against such activities and thefts as the number of incidents are growing day-by-day. Otherwise, people will start losing their trust in sharing their personal information through web sites.</p>
<p>A web security expert of <a href="http://kraasecurity.com/">application security risk assessment</a> has written this article.</p>
<p>Gary Bahadur<br />
baha@kraasecurity.com<br />
<a href="http://www.kraasecurity.com">http://www.kraasecurity.com</a></p>
<p><a href="http://blog.kraasecurity.com">http://blog.kraasecurity.com</a></p>
<p><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
Managed Security Services<br />
Managed Firewall<br />
Managed Vulnerability Scanning</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.schneier.com/blog/archives/2010/03/electronic_heal.html">Electronic Health Record Security Analysis</a> (schneier.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.channelweb.co.uk/crn/news/2260643/saas-demand-fuel-growth">SaaS demand to fuel growth in security services</a> (channelweb.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://go.theregister.com/feed/www.theregister.co.uk/2010/03/19/gartner_virt_server_security/">Fake servers even less secure than real ones</a> (go.theregister.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/aa33117b-3a26-49b8-afd8-63a851e3d98f/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=aa33117b-3a26-49b8-afd8-63a851e3d98f" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/04/10/website-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
