<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Online form Security</title>
	<atom:link href="http://chiunam.net/blog/archives/85/feed" rel="self" type="application/rss+xml" />
	<link>http://chiunam.net/blog/archives/85</link>
	<description>Every little thing counts</description>
	<pubDate>Fri, 30 Jul 2010 18:09:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: sluis9</title>
		<link>http://chiunam.net/blog/archives/85#comment-51853</link>
		<dc:creator>sluis9</dc:creator>
		<pubDate>Thu, 01 Apr 2010 11:09:26 +0000</pubDate>
		<guid isPermaLink="false">http://chiunam.net/blog/archives/85#comment-51853</guid>
		<description>Good
 I understand that you want a previous user's feedback on this one but with your question, I just have to reiterate that even if you may get a feedback that the one-time dose is better (or the other), treatment options vary on a case to case basis. substitute
 Pa!!!
____________________________
&lt;a href="http://buy-vigra.edpills-online.info/index.html"&gt; discount online&lt;/a&gt; :)</description>
		<content:encoded><![CDATA[<p>Good<br />
 I understand that you want a previous user&#8217;s feedback on this one but with your question, I just have to reiterate that even if you may get a feedback that the one-time dose is better (or the other), treatment options vary on a case to case basis. substitute<br />
 Pa!!!<br />
____________________________<br />
<a href="http://buy-vigra.edpills-online.info/index.html" class="external"> discount online</a> <img src='http://chiunam.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bwoqpcyx</title>
		<link>http://chiunam.net/blog/archives/85#comment-21350</link>
		<dc:creator>Bwoqpcyx</dc:creator>
		<pubDate>Sat, 13 Dec 2008 19:32:28 +0000</pubDate>
		<guid isPermaLink="false">http://chiunam.net/blog/archives/85#comment-21350</guid>
		<description>Thanks!,</description>
		<content:encoded><![CDATA[<p>Thanks!,</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mk</title>
		<link>http://chiunam.net/blog/archives/85#comment-3003</link>
		<dc:creator>mk</dc:creator>
		<pubDate>Mon, 16 Apr 2007 18:12:29 +0000</pubDate>
		<guid isPermaLink="false">http://chiunam.net/blog/archives/85#comment-3003</guid>
		<description>那要看 Malicious usage 究竟是怎樣。保護使用者的話會將密碼放進資料庫前變成雜湊值(Hash)，而 form to mail 盡量不用(不經 HTTP)，因為統統會變成 clear text...(除非你還會附一條 public key... 不過這樣的話使用 HTTPS 對使用者會更為方便)
SSL... 設定起來也不太麻煩，不過如果只是普通資料有點殺雞用牛刀的感覺。
保護網站方面，會檢查 user input 是必然的啦，原因也不用多說。同理，網頁一定不可以直接顯示用家輸入值。
Captcha 不會用，一來不方便使用者(歧視)，二來繞過這種東西實在簡單得很(有人甚至想過把認 captcha 的工作 outsource 給印度人)
還有這個，很值得一看：http://isc.sans.org/diary.html?storyid=1836</description>
		<content:encoded><![CDATA[<p>那要看 Malicious usage 究竟是怎樣。保護使用者的話會將密碼放進資料庫前變成雜湊值(Hash)，而 form to mail 盡量不用(不經 HTTP)，因為統統會變成 clear text&#8230;(除非你還會附一條 public key&#8230; 不過這樣的話使用 HTTPS 對使用者會更為方便)<br />
SSL&#8230; 設定起來也不太麻煩，不過如果只是普通資料有點殺雞用牛刀的感覺。<br />
保護網站方面，會檢查 user input 是必然的啦，原因也不用多說。同理，網頁一定不可以直接顯示用家輸入值。<br />
Captcha 不會用，一來不方便使用者(歧視)，二來繞過這種東西實在簡單得很(有人甚至想過把認 captcha 的工作 outsource 給印度人)<br />
還有這個，很值得一看：http://isc.sans.org/diary.html?storyid=1836</p>
]]></content:encoded>
	</item>
</channel>
</rss>
