<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for John Melton&#039;s Weblog</title>
	<atom:link href="http://www.jtmelton.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jtmelton.com</link>
	<description>Java, Security and Technology</description>
	<lastBuildDate>Wed, 25 Jan 2012 05:18:23 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on Year Of Security for Java &#8211; Week 3 &#8211; Session Cookie Secure Flag by Year Of Security for Java &#8211; Week 4 &#8211; Session Cookie HttpOnly Flag : John Melton&#039;s Weblog</title>
		<link>http://www.jtmelton.com/2012/01/17/year-of-security-for-java-week-3-session-cookie-secure-flag/comment-page-1/#comment-45047</link>
		<dc:creator>Year Of Security for Java &#8211; Week 4 &#8211; Session Cookie HttpOnly Flag : John Melton&#039;s Weblog</dc:creator>
		<pubDate>Wed, 25 Jan 2012 05:18:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/?p=218#comment-45047</guid>
		<description>[...] if you were following along from last week, with both the secure and HttpOnly [...]</description>
		<content:encoded><![CDATA[<p>[...] if you were following along from last week, with both the secure and HttpOnly [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Year Of Security for Java &#8211; Week 1 &#8211; Session Fixation Prevention by Dominik Schadow</title>
		<link>http://www.jtmelton.com/2012/01/02/year-of-security-for-java-week-1-session-fixation-prevention/comment-page-1/#comment-45046</link>
		<dc:creator>Dominik Schadow</dc:creator>
		<pubDate>Thu, 12 Jan 2012 21:24:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/?p=203#comment-45046</guid>
		<description>&lt;strong&gt;Java security updates - January 2012...&lt;/strong&gt;

The Oracle Secure Coding Guidelines for the Java Programming Language are available in version 4.0 (probably already for a couple of days, couldn’t find any announcement). This version includes some hints for the latest Java 7 SDK. And John Melton anno...</description>
		<content:encoded><![CDATA[<p><strong>Java security updates &#8211; January 2012&#8230;</strong></p>
<p>The Oracle Secure Coding Guidelines for the Java Programming Language are available in version 4.0 (probably already for a couple of days, couldn’t find any announcement). This version includes some hints for the latest Java 7 SDK. And John Melton anno&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 6 &#8211; Information Leakage and Improper Error Handling by Year Of Security for Java &#8211; Week 2 &#8211; Error Handling in web.xml : John Melton&#039;s Weblog</title>
		<link>http://www.jtmelton.com/2010/06/02/the-owasp-top-ten-and-esapi-part-7-information-leakage-and-improper-error-handling/comment-page-1/#comment-44988</link>
		<dc:creator>Year Of Security for Java &#8211; Week 2 &#8211; Error Handling in web.xml : John Melton&#039;s Weblog</dc:creator>
		<pubDate>Wed, 11 Jan 2012 04:20:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/?p=117#comment-44988</guid>
		<description>[...] in more detail as it&#8217;s part of the OWASP Top 10, so you can find more detail here &#8211; http://www.jtmelton.com/2010/06/02/the-owasp-top-ten-and-esapi-part-7-information-leakage-and-improp.... In this article, I&#8217;ll just cover the important [...]</description>
		<content:encoded><![CDATA[<p>[...] in more detail as it&#8217;s part of the OWASP Top 10, so you can find more detail here &#8211; <a href="http://www.jtmelton.com/2010/06/02/the-owasp-top-ten-and-esapi-part-7-information-leakage-and-improp..." rel="nofollow">http://www.jtmelton.com/2010/06/02/the-owasp-top-ten-and-esapi-part-7-information-leakage-and-improp&#8230;</a>. In this article, I&#8217;ll just cover the important [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Final Summary by Year Of Security for Java &#8211; Introduction : John Melton&#039;s Weblog</title>
		<link>http://www.jtmelton.com/2010/08/17/the-owasp-top-ten-and-esapi-final-summary/comment-page-1/#comment-44805</link>
		<dc:creator>Year Of Security for Java &#8211; Introduction : John Melton&#039;s Weblog</dc:creator>
		<pubDate>Tue, 03 Jan 2012 03:50:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/?p=145#comment-44805</guid>
		<description>[...] will have roughly 1 article per week for a year. This series will be different from my last series (OWASP Top Ten &#8211; Java) in that each article will be pretty short and focused. There are several motivations for this [...]</description>
		<content:encoded><![CDATA[<p>[...] will have roughly 1 article per week for a year. This series will be different from my last series (OWASP Top Ten &#8211; Java) in that each article will be pretty short and focused. There are several motivations for this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 9 &#8211; Insecure Communications by john</title>
		<link>http://www.jtmelton.com/2010/08/04/the-owasp-top-ten-and-esapi-part-10-insecure-communications/comment-page-1/#comment-42839</link>
		<dc:creator>john</dc:creator>
		<pubDate>Wed, 21 Sep 2011 15:13:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/?p=129#comment-42839</guid>
		<description>@Charles, 
I honestly don&#039;t remember if there is a config option in the ESAPI.properties file (though that&#039;s where you need to check) related to https. However, you can always override the check (probably search for assertSecure in the ESAPI code) in your own implementation.</description>
		<content:encoded><![CDATA[<p>@Charles,<br />
I honestly don&#8217;t remember if there is a config option in the ESAPI.properties file (though that&#8217;s where you need to check) related to https. However, you can always override the check (probably search for assertSecure in the ESAPI code) in your own implementation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 9 &#8211; Insecure Communications by Charles</title>
		<link>http://www.jtmelton.com/2010/08/04/the-owasp-top-ten-and-esapi-part-10-insecure-communications/comment-page-1/#comment-42838</link>
		<dc:creator>Charles</dc:creator>
		<pubDate>Wed, 21 Sep 2011 14:26:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/?p=129#comment-42838</guid>
		<description>Okay... but what if you WANT to use HTTP? The Swingset demo and apache server are HTTP, and none of the pages in the demo work because of that. How do I disable the HTTPS requirement in ESAPI so I can run these samples?</description>
		<content:encoded><![CDATA[<p>Okay&#8230; but what if you WANT to use HTTP? The Swingset demo and apache server are HTTP, and none of the pages in the demo work because of that. How do I disable the HTTPS requirement in ESAPI so I can run these samples?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 1 &#8211; Cross Site Scripting (XSS) by john</title>
		<link>http://www.jtmelton.com/2009/01/12/the-owasp-top-ten-and-esapi-part-2-cross-site-scripting-xss/comment-page-1/#comment-42823</link>
		<dc:creator>john</dc:creator>
		<pubDate>Wed, 21 Sep 2011 01:02:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/2009/11/12/the-owasp-top-ten-and-esapi-part-2-cross-site-scripting-xss/#comment-42823</guid>
		<description>@Charles, 
Yes you can look at the esapi-dev and esapi-user mailing lists (and their archives). Thought it&#039;s not a standard forum, it&#039;s the mechanism you can use to get info. I&#039;d start w/ the user list first.</description>
		<content:encoded><![CDATA[<p>@Charles,<br />
Yes you can look at the esapi-dev and esapi-user mailing lists (and their archives). Thought it&#8217;s not a standard forum, it&#8217;s the mechanism you can use to get info. I&#8217;d start w/ the user list first.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 1 &#8211; Cross Site Scripting (XSS) by Charles</title>
		<link>http://www.jtmelton.com/2009/01/12/the-owasp-top-ten-and-esapi-part-2-cross-site-scripting-xss/comment-page-1/#comment-42816</link>
		<dc:creator>Charles</dc:creator>
		<pubDate>Tue, 20 Sep 2011 20:10:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/2009/11/12/the-owasp-top-ten-and-esapi-part-2-cross-site-scripting-xss/#comment-42816</guid>
		<description>Is there a forum for ESAPI? I need to disable strong password checks, and the complete lack of documentation is daunting.</description>
		<content:encoded><![CDATA[<p>Is there a forum for ESAPI? I need to disable strong password checks, and the complete lack of documentation is daunting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on A Simple Multi-Threaded Java HTTP Proxy Server by João Cortela</title>
		<link>http://www.jtmelton.com/2007/11/27/a-simple-multi-threaded-java-http-proxy-server/comment-page-1/#comment-42147</link>
		<dc:creator>João Cortela</dc:creator>
		<pubDate>Thu, 25 Aug 2011 20:32:01 +0000</pubDate>
		<guid isPermaLink="false">http://uncc.dyndns.org/2007/11/27/a-simple-multi-threaded-java-http-proxy-server/#comment-42147</guid>
		<description>Thanks man!

Now it&#039;s working... =)

It helped me a lot!</description>
		<content:encoded><![CDATA[<p>Thanks man!</p>
<p>Now it&#8217;s working&#8230; =)</p>
<p>It helped me a lot!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on A Simple Multi-Threaded Java HTTP Proxy Server by john</title>
		<link>http://www.jtmelton.com/2007/11/27/a-simple-multi-threaded-java-http-proxy-server/comment-page-1/#comment-42146</link>
		<dc:creator>john</dc:creator>
		<pubDate>Thu, 25 Aug 2011 20:21:59 +0000</pubDate>
		<guid isPermaLink="false">http://uncc.dyndns.org/2007/11/27/a-simple-multi-threaded-java-http-proxy-server/#comment-42146</guid>
		<description>@Joao, 
Looks like you might not have the java command right. You might want to try &quot;java -cp . proxy.ProxyServer&quot;</description>
		<content:encoded><![CDATA[<p>@Joao,<br />
Looks like you might not have the java command right. You might want to try &#8220;java -cp . proxy.ProxyServer&#8221;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 1/20 queries in 0.012 seconds using disk: basic
Object Caching 338/350 objects using disk: basic

Served from: www.jtmelton.com @ 2012-02-04 21:27:21 -->
