<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Google Ratproxy</title>
	<atom:link href="http://www.webadminblog.com/index.php/2008/07/22/google-ratproxy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webadminblog.com/index.php/2008/07/22/google-ratproxy/</link>
	<description>Real Web Admins.  Real World Experience.</description>
	<lastBuildDate>Thu, 22 Jul 2010 22:44:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Josh</title>
		<link>http://www.webadminblog.com/index.php/2008/07/22/google-ratproxy/comment-page-1/#comment-515</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Mon, 11 May 2009 21:32:34 +0000</pubDate>
		<guid isPermaLink="false">http://webadminblog.com/?p=30#comment-515</guid>
		<description>Sure, feel free to quote me in your report for school and please let me know if you have any questions.</description>
		<content:encoded><![CDATA[<p>Sure, feel free to quote me in your report for school and please let me know if you have any questions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Proxy Guy</title>
		<link>http://www.webadminblog.com/index.php/2008/07/22/google-ratproxy/comment-page-1/#comment-512</link>
		<dc:creator>Proxy Guy</dc:creator>
		<pubDate>Mon, 11 May 2009 05:22:33 +0000</pubDate>
		<guid isPermaLink="false">http://webadminblog.com/?p=30#comment-512</guid>
		<description>Can I quote you in my report for school?</description>
		<content:encoded><![CDATA[<p>Can I quote you in my report for school?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh</title>
		<link>http://www.webadminblog.com/index.php/2008/07/22/google-ratproxy/comment-page-1/#comment-74</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Sun, 27 Jul 2008 16:41:10 +0000</pubDate>
		<guid isPermaLink="false">http://webadminblog.com/?p=30#comment-74</guid>
		<description>Good point, Victor.  There are actually some very good Firefox plugins that you can use to test the security of your web applications.  These includes &quot;Add N Edit Cookies&quot; (to modify your cookie info), HackBar (HTML encoding, XSS, SQL Injection), Tamper Data (modify POST parameters), and Live HTTP Headers (view HTTP headers).  As Ernest said, the problem with these tools is that while they allow you to test web application security, the user using them has to actually know what they are doing.  If you don&#039;t know what you are looking for, then a proxy tool like RatProxy helps to fill in those knowledge gaps.</description>
		<content:encoded><![CDATA[<p>Good point, Victor.  There are actually some very good Firefox plugins that you can use to test the security of your web applications.  These includes &#8220;Add N Edit Cookies&#8221; (to modify your cookie info), HackBar (HTML encoding, XSS, SQL Injection), Tamper Data (modify POST parameters), and Live HTTP Headers (view HTTP headers).  As Ernest said, the problem with these tools is that while they allow you to test web application security, the user using them has to actually know what they are doing.  If you don&#8217;t know what you are looking for, then a proxy tool like RatProxy helps to fill in those knowledge gaps.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ernest</title>
		<link>http://www.webadminblog.com/index.php/2008/07/22/google-ratproxy/comment-page-1/#comment-72</link>
		<dc:creator>Ernest</dc:creator>
		<pubDate>Thu, 24 Jul 2008 21:07:48 +0000</pubDate>
		<guid isPermaLink="false">http://webadminblog.com/?p=30#comment-72</guid>
		<description>I think the deal with ratproxy is it&#039;s good for less advanced users.  You just set up a proxy and browse and then it gives you lovely reports on what&#039;s wrong.  If you &quot;know what you&#039;re doing&quot; you can use WebScarab or any number of other tools, but unfortunately the number of developers that &quot;know what they&#039;re doing&quot; in a security sense is low.</description>
		<content:encoded><![CDATA[<p>I think the deal with ratproxy is it&#8217;s good for less advanced users.  You just set up a proxy and browse and then it gives you lovely reports on what&#8217;s wrong.  If you &#8220;know what you&#8217;re doing&#8221; you can use WebScarab or any number of other tools, but unfortunately the number of developers that &#8220;know what they&#8217;re doing&#8221; in a security sense is low.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Victor Trac</title>
		<link>http://www.webadminblog.com/index.php/2008/07/22/google-ratproxy/comment-page-1/#comment-71</link>
		<dc:creator>Victor Trac</dc:creator>
		<pubDate>Wed, 23 Jul 2008 07:21:11 +0000</pubDate>
		<guid isPermaLink="false">http://webadminblog.com/?p=30#comment-71</guid>
		<description>Thanks for posting about Ratproxy.  It seems like it could be a useful tool, especially if you&#039;re managing a network and trying to figure out the vulnerabilities of your users.

For a single user though, it seems to me like a simple browser-side extension could work just as well.  Firebug probably has the capability of doing this, although the plugins I&#039;ve seen are generally geared for web development.  It would at least save you the trouble of running a proxy and reconfiguring your browser to use it.</description>
		<content:encoded><![CDATA[<p>Thanks for posting about Ratproxy.  It seems like it could be a useful tool, especially if you&#8217;re managing a network and trying to figure out the vulnerabilities of your users.</p>
<p>For a single user though, it seems to me like a simple browser-side extension could work just as well.  Firebug probably has the capability of doing this, although the plugins I&#8217;ve seen are generally geared for web development.  It would at least save you the trouble of running a proxy and reconfiguring your browser to use it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
