<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: About logical security flaws</title>
	<atom:link href="http://antisnatchor.com/2009/07/19/about-logical-security-flaws/feed/" rel="self" type="application/rss+xml" />
	<link>http://antisnatchor.com/2009/07/19/about-logical-security-flaws/</link>
	<description>Keeping You Informed on the latest and coolest AntiSnatchOr security researches...</description>
	<lastBuildDate>Tue, 27 Jul 2010 02:01:34 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: teapartylatest</title>
		<link>http://antisnatchor.com/2009/07/19/about-logical-security-flaws/comment-page-1/#comment-34</link>
		<dc:creator>teapartylatest</dc:creator>
		<pubDate>Mon, 12 Apr 2010 02:20:58 +0000</pubDate>
		<guid isPermaLink="false">http://antisnatchor.com/?p=70#comment-34</guid>
		<description>appreciated this post!</description>
		<content:encoded><![CDATA[<p>appreciated this post!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: antisnatchor</title>
		<link>http://antisnatchor.com/2009/07/19/about-logical-security-flaws/comment-page-1/#comment-21</link>
		<dc:creator>antisnatchor</dc:creator>
		<pubDate>Mon, 20 Jul 2009 17:11:41 +0000</pubDate>
		<guid isPermaLink="false">http://antisnatchor.com/?p=70#comment-21</guid>
		<description>That&#039;s right.
I&#039;m glad you like my point of view.
I will look deeper on it in these days.</description>
		<content:encoded><![CDATA[<p>That&#8217;s right.<br />
I&#8217;m glad you like my point of view.<br />
I will look deeper on it in these days.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Si Chen</title>
		<link>http://antisnatchor.com/2009/07/19/about-logical-security-flaws/comment-page-1/#comment-20</link>
		<dc:creator>Si Chen</dc:creator>
		<pubDate>Mon, 20 Jul 2009 17:04:01 +0000</pubDate>
		<guid isPermaLink="false">http://antisnatchor.com/?p=70#comment-20</guid>
		<description>I think you bring up some good points, in addition to what we&#039;ve discussed already. We should probably always require that the user enter the old password before changing it, even if the user is the owner of the password. We should probably also require that the admin user always enter his own password before being able to change somebody else&#039;s password.

 These kind of logical flaws can be exploited by more ways than just XSRF.   For example, somebody could just walk over to the admin user&#039;s terminal while he is out for a coffee break and start changing passwords, if we don&#039;t require the admin password to be checked first.</description>
		<content:encoded><![CDATA[<p>I think you bring up some good points, in addition to what we&#8217;ve discussed already. We should probably always require that the user enter the old password before changing it, even if the user is the owner of the password. We should probably also require that the admin user always enter his own password before being able to change somebody else&#8217;s password.</p>
<p> These kind of logical flaws can be exploited by more ways than just XSRF.   For example, somebody could just walk over to the admin user&#8217;s terminal while he is out for a coffee break and start changing passwords, if we don&#8217;t require the admin password to be checked first.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: About logical security flaws &#171; crm like soft</title>
		<link>http://antisnatchor.com/2009/07/19/about-logical-security-flaws/comment-page-1/#comment-19</link>
		<dc:creator>About logical security flaws &#171; crm like soft</dc:creator>
		<pubDate>Sun, 19 Jul 2009 12:33:06 +0000</pubDate>
		<guid isPermaLink="false">http://antisnatchor.com/?p=70#comment-19</guid>
		<description>[...] here to see the original:  About logical security flaws   19 Jul 09 &#124; [...]</description>
		<content:encoded><![CDATA[<p>[...] here to see the original:  About logical security flaws   19 Jul 09 | [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
