<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for John Melton&#039;s Weblog</title>
	<atom:link href="http://www.jtmelton.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jtmelton.com</link>
	<description>Java, Security and Technology</description>
	<lastBuildDate>Wed, 14 Jul 2010 12:23:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 2 &#8211; Cross Site Scripting (XSS) by Mostafa Siraj</title>
		<link>http://www.jtmelton.com/2009/01/12/the-owasp-top-ten-and-esapi-part-2-cross-site-scripting-xss/comment-page-1/#comment-8125</link>
		<dc:creator>Mostafa Siraj</dc:creator>
		<pubDate>Wed, 14 Jul 2010 12:23:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/2009/11/12/the-owasp-top-ten-and-esapi-part-2-cross-site-scripting-xss/#comment-8125</guid>
		<description>John, the article is great, I would suggestion renaming the titles of posts to start from zero, like that the posts part numbers will match those on  owasp top 10 vulnerabilities.</description>
		<content:encoded><![CDATA[<p>John, the article is great, I would suggestion renaming the titles of posts to start from zero, like that the posts part numbers will match those on  owasp top 10 vulnerabilities.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 8 &#8211; Broken Authentication and Session Management by Owen</title>
		<link>http://www.jtmelton.com/2010/06/16/the-owasp-top-ten-and-esapi-part-8-broken-authentication-and-session-management/comment-page-1/#comment-5907</link>
		<dc:creator>Owen</dc:creator>
		<pubDate>Sat, 26 Jun 2010 00:25:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/?p=123#comment-5907</guid>
		<description>Cool, thank you, working on it now. Will likely take me longer than a day though!</description>
		<content:encoded><![CDATA[<p>Cool, thank you, working on it now. Will likely take me longer than a day though!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 8 &#8211; Broken Authentication and Session Management by john</title>
		<link>http://www.jtmelton.com/2010/06/16/the-owasp-top-ten-and-esapi-part-8-broken-authentication-and-session-management/comment-page-1/#comment-5834</link>
		<dc:creator>john</dc:creator>
		<pubDate>Fri, 25 Jun 2010 04:32:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/?p=123#comment-5834</guid>
		<description>@Owen, 
There is currently no database-backed implementation of the authenticator in ESAPI, and that may or may not change.  I suspect (though I can&#039;t speak for the dev team) that the reason for not including one is that a database driven implementation is going to levy a specific schema requirement on an application.  This might be fine for some applications that are likely a)very small and b)using ESAPI from day one, but it&#039;s unlikely that&#039;s an acceptable requirement outside of those 2 situations.  
However, having said that, much of the code in the FileBasedAuthenticator does not need to be changed in order to use a database.  Simply look for the places where data goes in or out of the datastore, and make your modifications.  Much of the code can likely be reused.  If it helps, it took me a day or two to do that work, and I believe I remember Jim Manico (ESAPI dev lead) saying a similar conversion to Hibernate took him about 2 days as well.  Good luck!</description>
		<content:encoded><![CDATA[<p>@Owen,<br />
There is currently no database-backed implementation of the authenticator in ESAPI, and that may or may not change.  I suspect (though I can&#8217;t speak for the dev team) that the reason for not including one is that a database driven implementation is going to levy a specific schema requirement on an application.  This might be fine for some applications that are likely a)very small and b)using ESAPI from day one, but it&#8217;s unlikely that&#8217;s an acceptable requirement outside of those 2 situations.<br />
However, having said that, much of the code in the FileBasedAuthenticator does not need to be changed in order to use a database.  Simply look for the places where data goes in or out of the datastore, and make your modifications.  Much of the code can likely be reused.  If it helps, it took me a day or two to do that work, and I believe I remember Jim Manico (ESAPI dev lead) saying a similar conversion to Hibernate took him about 2 days as well.  Good luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 8 &#8211; Broken Authentication and Session Management by Owen</title>
		<link>http://www.jtmelton.com/2010/06/16/the-owasp-top-ten-and-esapi-part-8-broken-authentication-and-session-management/comment-page-1/#comment-5833</link>
		<dc:creator>Owen</dc:creator>
		<pubDate>Fri, 25 Jun 2010 04:23:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/?p=123#comment-5833</guid>
		<description>Mr. Melton,
I have been attempting to adapt a website I am working on to use the principles (and of course the library) of ESAPI, but there is no User to Database interaction that I can find.  Are there any examples you are aware of for a DatabaseBasedAuthenticator, rather than the FileBasedAuthenticator that they use as the default authenticator? Thank you for any help.</description>
		<content:encoded><![CDATA[<p>Mr. Melton,<br />
I have been attempting to adapt a website I am working on to use the principles (and of course the library) of ESAPI, but there is no User to Database interaction that I can find.  Are there any examples you are aware of for a DatabaseBasedAuthenticator, rather than the FileBasedAuthenticator that they use as the default authenticator? Thank you for any help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 8 &#8211; Broken Authentication and Session Management by Tweets that mention The OWASP Top Ten and ESAPI – Part 8 – Broken Authentication and Session Management : John Melton's Weblog -- Topsy.com</title>
		<link>http://www.jtmelton.com/2010/06/16/the-owasp-top-ten-and-esapi-part-8-broken-authentication-and-session-management/comment-page-1/#comment-5097</link>
		<dc:creator>Tweets that mention The OWASP Top Ten and ESAPI – Part 8 – Broken Authentication and Session Management : John Melton's Weblog -- Topsy.com</dc:creator>
		<pubDate>Thu, 17 Jun 2010 09:18:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/?p=123#comment-5097</guid>
		<description>[...] This post was mentioned on Twitter by Roberto Martinez, Open Foundstone. Open Foundstone said: The OWASP Top Ten and ESAPI – Part 8 – Broken Authentication and Session Management: This article will describe ho... http://bit.ly/dj41JD [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Roberto Martinez, Open Foundstone. Open Foundstone said: The OWASP Top Ten and ESAPI – Part 8 – Broken Authentication and Session Management: This article will describe ho&#8230; <a href="http://bit.ly/dj41JD" rel="nofollow">http://bit.ly/dj41JD</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 6 &#8211; Cross Site Request Forgery (CSRF) by Owen</title>
		<link>http://www.jtmelton.com/2010/05/16/the-owasp-top-ten-and-esapi-part-6-cross-site-request-forgery-csrf/comment-page-1/#comment-4427</link>
		<dc:creator>Owen</dc:creator>
		<pubDate>Fri, 11 Jun 2010 05:49:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/?p=87#comment-4427</guid>
		<description>I love this series!  I tried to implement the randomizer for a Session Credential on one of my projects, rather than my own hacked version, and it stated that DefaultEncoder.CHAR_ALPHANUMERICS is deprecated and to use EncoderConstants instead.  Thank you again and keep up the good work.</description>
		<content:encoded><![CDATA[<p>I love this series!  I tried to implement the randomizer for a Session Credential on one of my projects, rather than my own hacked version, and it stated that DefaultEncoder.CHAR_ALPHANUMERICS is deprecated and to use EncoderConstants instead.  Thank you again and keep up the good work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 4 &#8211; Malicious File Execution by Tweets that mention The OWASP Top Ten and ESAPI – Part 4 – Malicious File Execution : John Melton's Weblog -- Topsy.com</title>
		<link>http://www.jtmelton.com/2010/05/02/the-owasp-top-ten-and-esapi-part-4-malicious-file-execution/comment-page-1/#comment-1548</link>
		<dc:creator>Tweets that mention The OWASP Top Ten and ESAPI – Part 4 – Malicious File Execution : John Melton's Weblog -- Topsy.com</dc:creator>
		<pubDate>Mon, 03 May 2010 14:48:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/?p=81#comment-1548</guid>
		<description>[...] This post was mentioned on Twitter by d3v1l, Open Foundstone. Open Foundstone said: The OWASP Top Ten and ESAPI – Part 4 – Malicious File Execution: This article will describe how to protect your J2... http://bit.ly/aFJ8E6 [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by d3v1l, Open Foundstone. Open Foundstone said: The OWASP Top Ten and ESAPI – Part 4 – Malicious File Execution: This article will describe how to protect your J2&#8230; <a href="http://bit.ly/aFJ8E6" rel="nofollow">http://bit.ly/aFJ8E6</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 3 &#8211; Injection Flaws by jose</title>
		<link>http://www.jtmelton.com/2009/12/01/the-owasp-top-ten-and-esapi-part-3-injection-flaws/comment-page-1/#comment-1102</link>
		<dc:creator>jose</dc:creator>
		<pubDate>Tue, 13 Apr 2010 15:01:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/2009/12/01/the-owasp-top-ten-and-esapi-part-3-injection-flaws/#comment-1102</guid>
		<description>Excellents articles!

I hope that you&#039;ll  still continue writting about that, because is a issue than there&#039;re not so much information about how can we used it. 

Good for you! and thank u</description>
		<content:encoded><![CDATA[<p>Excellents articles!</p>
<p>I hope that you&#8217;ll  still continue writting about that, because is a issue than there&#8217;re not so much information about how can we used it. </p>
<p>Good for you! and thank u</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI by Nodo54 &#187; Blog Archive &#187; The OWASP Top Ten and ESAPI &#8211; Part 3 &#8211; Injection Flaws</title>
		<link>http://www.jtmelton.com/2009/01/03/the-owasp-top-ten-and-esapi/comment-page-1/#comment-33</link>
		<dc:creator>Nodo54 &#187; Blog Archive &#187; The OWASP Top Ten and ESAPI &#8211; Part 3 &#8211; Injection Flaws</dc:creator>
		<pubDate>Mon, 04 Jan 2010 09:04:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/2009/11/03/the-owasp-top-ten-and-esapi/#comment-33</guid>
		<description>[...] This article will describe how to protect your J2EE application from injection (SQL and others) attacks using ESAPI. As with all of the detail articles in this series, if you need a refresher on OWASP or ESAPI, please see the intro article The OWASP Top Ten and ESAPI. [...]</description>
		<content:encoded><![CDATA[<p>[...] This article will describe how to protect your J2EE application from injection (SQL and others) attacks using ESAPI. As with all of the detail articles in this series, if you need a refresher on OWASP or ESAPI, please see the intro article The OWASP Top Ten and ESAPI. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The OWASP Top Ten and ESAPI &#8211; Part 3 &#8211; Injection Flaws by KRvW</title>
		<link>http://www.jtmelton.com/2009/12/01/the-owasp-top-ten-and-esapi-part-3-injection-flaws/comment-page-1/#comment-14</link>
		<dc:creator>KRvW</dc:creator>
		<pubDate>Wed, 02 Dec 2009 13:13:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.jtmelton.com/2009/12/01/the-owasp-top-ten-and-esapi-part-3-injection-flaws/#comment-14</guid>
		<description>Excellent series of articles--thanks for taking the time to write and post them.

Cheers,

Ken van Wyk</description>
		<content:encoded><![CDATA[<p>Excellent series of articles&#8211;thanks for taking the time to write and post them.</p>
<p>Cheers,</p>
<p>Ken van Wyk</p>
]]></content:encoded>
	</item>
</channel>
</rss>
