<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CodeBlog &#187; Site Security</title>
	<atom:link href="http://www.codeblog.co.uk/tag/site-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.codeblog.co.uk</link>
	<description></description>
	<lastBuildDate>Tue, 24 Jan 2012 21:02:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Preventing HTTP TRACE Method Cross Site Scripting Attacks</title>
		<link>http://www.codeblog.co.uk/2007/12/19/web-platforms/preventing-http-trace-method-cross-site-scripting-attacks/</link>
		<comments>http://www.codeblog.co.uk/2007/12/19/web-platforms/preventing-http-trace-method-cross-site-scripting-attacks/#comments</comments>
		<pubDate>Wed, 19 Dec 2007 12:03:46 +0000</pubDate>
		<dc:creator>Oliver</dc:creator>
				<category><![CDATA[Web Platforms]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Site Security]]></category>

		<guid isPermaLink="false">http://www.codeblog.co.uk/2007/12/19/tips-tricks/preventing-http-trace-method-cross-site-scripting-attacks/</guid>
		<description><![CDATA[What is a cross site scripting attack?: &#8220;Cross-site scripting (XSS) is a simple idea at heart: the attacker loads exploitative HTML, including a client-side script, into a web site, typically one which allows public submissions and which does not properly quote HTML tags. Any user of the site who reads the story loads the exploit into their browser. The script uses the client browser&#8217;s rights to cause mischief &#8212; typically to access information and send it to the attacker.&#8221; Quote provided by LWN.NET How to prevent the TRACE method using Apache config, insert the following code into each virtual host &#8230;]]></description>
		<wfw:commentRss>http://www.codeblog.co.uk/2007/12/19/web-platforms/preventing-http-trace-method-cross-site-scripting-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

