<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Silver bullets or magic beans?</title>
	<atom:link href="http://www.mikeandrews.com/2008/01/14/silver-bullets-or-magic-beans/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mikeandrews.com/2008/01/14/silver-bullets-or-magic-beans/</link>
	<description></description>
	<lastBuildDate>Fri, 09 Apr 2010 12:01:55 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: BlueHat review &#124; Mike Andrews</title>
		<link>http://www.mikeandrews.com/2008/01/14/silver-bullets-or-magic-beans/comment-page-1/#comment-248</link>
		<dc:creator>BlueHat review &#124; Mike Andrews</dc:creator>
		<pubDate>Mon, 20 Oct 2008 04:08:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.mikeandrews.com/2008/01/14/silver-bullets-or-magic-beans/#comment-248</guid>
		<description>[...] remember all of the answers or points that each of us raised (although I did pull out the &quot;silver bullet and Jack and the Beanstalk&quot; allegory at one point).&#160; I hope there&#8217;s some audio somewhere as there was some [...]</description>
		<content:encoded><![CDATA[<p>[...] remember all of the answers or points that each of us raised (although I did pull out the &quot;silver bullet and Jack and the Beanstalk&quot; allegory at one point).&#160; I hope there&#8217;s some audio somewhere as there was some [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: VA+WAF: that&#8217;s hot! &#124; Mike Andrews</title>
		<link>http://www.mikeandrews.com/2008/01/14/silver-bullets-or-magic-beans/comment-page-1/#comment-196</link>
		<dc:creator>VA+WAF: that&#8217;s hot! &#124; Mike Andrews</dc:creator>
		<pubDate>Fri, 20 Jun 2008 05:57:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.mikeandrews.com/2008/01/14/silver-bullets-or-magic-beans/#comment-196</guid>
		<description>[...] However, just because it&#8217;s not a magic bullet, doesn&#8217;t mean that there&#8217;s not at least some worth behind the [...]</description>
		<content:encoded><![CDATA[<p>[...] However, just because it&#8217;s not a magic bullet, doesn&#8217;t mean that there&#8217;s not at least some worth behind the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Crystal ball 2008 &#124; Mike Andrews</title>
		<link>http://www.mikeandrews.com/2008/01/14/silver-bullets-or-magic-beans/comment-page-1/#comment-9</link>
		<dc:creator>Crystal ball 2008 &#124; Mike Andrews</dc:creator>
		<pubDate>Wed, 23 Jan 2008 03:45:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.mikeandrews.com/2008/01/14/silver-bullets-or-magic-beans/#comment-9</guid>
		<description>[...] they can be used in catching certain attacks like SQL injection and XSS in their basic form, and therefore are of some use, but after these attacks are gone what is left are business logic flaws, authorization flaws, and [...]</description>
		<content:encoded><![CDATA[<p>[...] they can be used in catching certain attacks like SQL injection and XSS in their basic form, and therefore are of some use, but after these attacks are gone what is left are business logic flaws, authorization flaws, and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wanted: More Penn &#38; Teller&#8217;s &#124; Mike Andrews</title>
		<link>http://www.mikeandrews.com/2008/01/14/silver-bullets-or-magic-beans/comment-page-1/#comment-2</link>
		<dc:creator>Wanted: More Penn &#38; Teller&#8217;s &#124; Mike Andrews</dc:creator>
		<pubDate>Wed, 16 Jan 2008 07:09:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.mikeandrews.com/2008/01/14/silver-bullets-or-magic-beans/#comment-2</guid>
		<description>[...] So, this is a call out for more Penn and Teller&#8217;s of the security world.  Share the knowledge as far and wide as you can.  Let other testers, developers, consultants, clients, management, etc, etc, etc, know about the &#8220;tricks&#8221; you&#8217;ve found, describe how they work, and make the attackers (who no-doubt already have this information, and use their own knowledge networks much like the magic castle/magic circle) work harder - you&#8217;ve seen the slight of hand, and it no longer fools you. Over time we&#8217;ll expose how the &#8220;John the Magnificent&#8221;, script-kiddie-esq, tricks work leaving just the &#8220;master magicians&#8221;.  It&#8217;s debatable how much this will help, but I think moving the bar, education and knowledge is one of the remaining silver bullets. [...]</description>
		<content:encoded><![CDATA[<p>[...] So, this is a call out for more Penn and Teller&#8217;s of the security world.  Share the knowledge as far and wide as you can.  Let other testers, developers, consultants, clients, management, etc, etc, etc, know about the &#8220;tricks&#8221; you&#8217;ve found, describe how they work, and make the attackers (who no-doubt already have this information, and use their own knowledge networks much like the magic castle/magic circle) work harder &#8211; you&#8217;ve seen the slight of hand, and it no longer fools you. Over time we&#8217;ll expose how the &#8220;John the Magnificent&#8221;, script-kiddie-esq, tricks work leaving just the &#8220;master magicians&#8221;.  It&#8217;s debatable how much this will help, but I think moving the bar, education and knowledge is one of the remaining silver bullets. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
