<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Blog</title>
	<atom:link href="http://www.securityninja.co.uk/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securityninja.co.uk</link>
	<description>Security research, news and guidance</description>
	<lastBuildDate>Mon, 23 Jan 2012 08:29:38 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Hack In Paris 2011 &#124; Segmentation fault</title>
		<link>http://www.securityninja.co.uk/blog/comment-page-1/#comment-11422</link>
		<dc:creator>Hack In Paris 2011 &#124; Segmentation fault</dc:creator>
		<pubDate>Fri, 24 Jun 2011 09:26:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.securityninja.co.uk/?page_id=1898#comment-11422</guid>
		<description>[...] the security code review Swiss army knife. David Rook expose sa vision de la revue de code : il ne s&#8217;agit pas de lire le maximum de lignes de code [...]</description>
		<content:encoded><![CDATA[<p>[...] the security code review Swiss army knife. David Rook expose sa vision de la revue de code : il ne s&#8217;agit pas de lire le maximum de lignes de code [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BSidesLondon Wrap Up &#171; /dev/random</title>
		<link>http://www.securityninja.co.uk/blog/comment-page-1/#comment-11029</link>
		<dc:creator>BSidesLondon Wrap Up &#171; /dev/random</dc:creator>
		<pubDate>Thu, 21 Apr 2011 00:31:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.securityninja.co.uk/?page_id=1898#comment-11029</guid>
		<description>[...] David Rook presented his tool: “Agnitio: its static analysis, but not as we know it”. He introduced the concept of static analysis: review applications security without executing it. It can be performed manually or via tools (automated). Classic error: security issues are fixed too late in the SDLC process and cost a huge amount of money! A nice comparison was done between developers and drivers: What if we taught drivers in the same way as developers? Instructors will tell driver about the different ways to crash and inevitably the driver will crash! Then David switched to a deeper presentation of his tool &#8220;Agnitio&#8220;: [...]</description>
		<content:encoded><![CDATA[<p>[...] David Rook presented his tool: “Agnitio: its static analysis, but not as we know it”. He introduced the concept of static analysis: review applications security without executing it. It can be performed manually or via tools (automated). Classic error: security issues are fixed too late in the SDLC process and cost a huge amount of money! A nice comparison was done between developers and drivers: What if we taught drivers in the same way as developers? Instructors will tell driver about the different ways to crash and inevitably the driver will crash! Then David switched to a deeper presentation of his tool &#8220;Agnitio&#8220;: [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

