<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Someone else actually likes NTOSpider?</title>
	<atom:link href="http://anautonomouszone.com/blog/archives/16/feed" rel="self" type="application/rss+xml" />
	<link>http://anautonomouszone.com/blog/archives/16</link>
	<description>An autonomous zone to promote an exchange of ideas, skills, and experiences with computer (in)security.</description>
	<lastBuildDate>Tue, 15 Sep 2009 22:49:34 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Ehsan</title>
		<link>http://anautonomouszone.com/blog/archives/16/comment-page-1#comment-8596</link>
		<dc:creator>Ehsan</dc:creator>
		<pubDate>Tue, 15 Sep 2009 22:49:34 +0000</pubDate>
		<guid isPermaLink="false">http://anautonomouszone.com/blog/?p=16#comment-8596</guid>
		<description>Great post. But with the sky high pricing for commercial version , it is hardly affordable to use multiple scanners.</description>
		<content:encoded><![CDATA[<p>Great post. But with the sky high pricing for commercial version , it is hardly affordable to use multiple scanners.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kristian Erik Hermansen</title>
		<link>http://anautonomouszone.com/blog/archives/16/comment-page-1#comment-5609</link>
		<dc:creator>Kristian Erik Hermansen</dc:creator>
		<pubDate>Fri, 19 Jun 2009 00:07:58 +0000</pubDate>
		<guid isPermaLink="false">http://anautonomouszone.com/blog/?p=16#comment-5609</guid>
		<description>Chuck/Caleb,

Excellent comments!  I think both sides of the issue have been presented well.  Now it&#039;s time for me to write that automated webapp scanner ;-P</description>
		<content:encoded><![CDATA[<p>Chuck/Caleb,</p>
<p>Excellent comments!  I think both sides of the issue have been presented well.  Now it&#8217;s time for me to write that automated webapp scanner ;-P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Caleb Sima</title>
		<link>http://anautonomouszone.com/blog/archives/16/comment-page-1#comment-5</link>
		<dc:creator>Caleb Sima</dc:creator>
		<pubDate>Mon, 07 Jul 2008 01:59:11 +0000</pubDate>
		<guid isPermaLink="false">http://anautonomouszone.com/blog/?p=16#comment-5</guid>
		<description>Ran across your blog due to my google alert (gotta love it). I pretty much agree with most of what you have said here except for one key issue. Your quote: &quot;I mean to build a web app scanner generally isn’t rocket science&quot;. 
I have to say - being the founder and CTO of SPI Dynamics(now HP) at the surface it may seem like that but there is nothing farther from the truth.
It is one of the most complicated pieces of technology I have ever had to deal with. Its not as simple as parsing out HREFs and sticking single quotes in params. Start adding in that nobody follows HTTP or HTML specs and you add some trouble. Start throwing in the huge complex state management mechanisms in applications that are custom coded from app to app then top it off with the flood of client side code(flash,ajax,silverlight.. blah blah). You have yourself quite a project.  Sure you say - I will just use mozilla&#039;s engine and be done. Good luck :) Of course I have just barely touched the surface into the complications of building one.
There is a reason we can&#039;t seem to really get it right and there are not that many players in this game.. at the end of the day building a good robust and comprehensive web app scanner that works from basic asp website to bank of america is a royal PIA! Try it :)
btw - nice blog!</description>
		<content:encoded><![CDATA[<p>Ran across your blog due to my google alert (gotta love it). I pretty much agree with most of what you have said here except for one key issue. Your quote: &#8220;I mean to build a web app scanner generally isn’t rocket science&#8221;.<br />
I have to say &#8211; being the founder and CTO of SPI Dynamics(now HP) at the surface it may seem like that but there is nothing farther from the truth.<br />
It is one of the most complicated pieces of technology I have ever had to deal with. Its not as simple as parsing out HREFs and sticking single quotes in params. Start adding in that nobody follows HTTP or HTML specs and you add some trouble. Start throwing in the huge complex state management mechanisms in applications that are custom coded from app to app then top it off with the flood of client side code(flash,ajax,silverlight.. blah blah). You have yourself quite a project.  Sure you say &#8211; I will just use mozilla&#8217;s engine and be done. Good luck <img src='http://anautonomouszone.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Of course I have just barely touched the surface into the complications of building one.<br />
There is a reason we can&#8217;t seem to really get it right and there are not that many players in this game.. at the end of the day building a good robust and comprehensive web app scanner that works from basic asp website to bank of america is a royal PIA! Try it <img src='http://anautonomouszone.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
btw &#8211; nice blog!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Wakling</title>
		<link>http://anautonomouszone.com/blog/archives/16/comment-page-1#comment-3</link>
		<dc:creator>Aaron Wakling</dc:creator>
		<pubDate>Mon, 07 Jul 2008 01:15:18 +0000</pubDate>
		<guid isPermaLink="false">http://anautonomouszone.com/blog/?p=16#comment-3</guid>
		<description>I found your blog on google and read a few of your other posts.  I just added you to my Google News Reader. Keep up the good work.  Look forward to reading more from you in the future.</description>
		<content:encoded><![CDATA[<p>I found your blog on google and read a few of your other posts.  I just added you to my Google News Reader. Keep up the good work.  Look forward to reading more from you in the future.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

