<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet href='http://feeds.feedsky.com/styles/temp01.xsl' type='text/xsl' ?><!--这是一个由Feedsy提供技术支持的Feed，为了提高读者阅读的体验，以及满足用户美化自己Feed的需要，我们设计了多种精美的Feed模板，提供给大家选择，所有最终呈现出来的样式，皆由用户自愿选择使用，未经许可，任何团体和个人，请不要擅自修改样式或者盗用，这是对于用户选择权的尊重。--><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:fs="http://www.feedsky.com/namespace/feed" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><atom:link href="http://feeds.feedsky.com/csdn.net/chengyun_chu" type="application/rss+xml" rel="self"></atom:link><fs:self_link href="http://feeds.feedsky.com/csdn.net/chengyun_chu" type="application/rss+xml"></fs:self_link><lastBuildDate>Thu, 25 Jun 2009 01:20:00 GMT</lastBuildDate><title>信息安全专栏 -- 褚诚云</title><description>希望能在这里和大家交流讨论信息安全领域的技术。</description><link>http://blog.csdn.net/chengyun_chu/</link><item><title>跨站脚本XSS</title><link>http://blog.csdn.net/chengyun_chu/archive/2009/06/25/4296262.aspx</link><wfw:comment>http://blog.csdn.net/chengyun_chu/comments/4296262.aspx</wfw:comment><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/chengyun_chu/comments/commentRss/4296262.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=4296262</trackback:ping><description>跨站脚本Cross-Site Scripting（XSS）是最为流行的Web安全漏洞之一。据统计，2007年，跨站脚本类的安全漏洞的数目已经远远超出传统类型的安全漏洞【1】。那么，什么是跨站脚本？它的危害性是什么？Web开发人员如何在开发过程中避免这类的安全漏洞？就是我们这篇文章要讨论的内容。&lt;img src =&quot;http://blog.csdn.net/chengyun_chu/aggbug/4296262.aspx&quot; width = &quot;1&quot; height = &quot;1&quot; /&gt;&lt;img src=&quot;http://www1.feedsky.com/t1/236815331/chengyun_chu/csdn.net/s.gif?r=http://blog.csdn.net/chengyun_chu/archive/2009/06/25/4296262.aspx&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/csdn.net/chengyun_chu/236815331/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/csdn.net/chengyun_chu/236815331/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><pubDate>Thu, 25 Jun 2009 09:20:00 +0800</pubDate><author>褚诚云</author><comments>http://blog.csdn.net/chengyun_chu/archive/2009/06/25/4296262.aspx#Feedback</comments><guid isPermaLink="false">http://blog.csdn.net/chengyun_chu/archive/2009/06/25/4296262.aspx</guid><dc:creator>褚诚云</dc:creator><fs:srclink>http://blog.csdn.net/chengyun_chu/archive/2009/06/25/4296262.aspx</fs:srclink><fs:srcfeed>http://blog.csdn.net/chengyun_chu/rss.aspx</fs:srcfeed><fs:itemid>csdn.net/chengyun_chu/~1295556/236815331/1298450</fs:itemid></item><item><title>安全：操作系统和浏览器的关系</title><link>http://blog.csdn.net/chengyun_chu/archive/2009/03/21/4010068.aspx</link><wfw:comment>http://blog.csdn.net/chengyun_chu/comments/4010068.aspx</wfw:comment><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/chengyun_chu/comments/commentRss/4010068.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=4010068</trackback:ping><description>Ryan对Charlie Miller的采访。这位老兄刚刚在CanSecWest上的黑客大赛上攻陷了Safari浏览器。
&lt;img src =&quot;http://blog.csdn.net/chengyun_chu/aggbug/4010068.aspx&quot; width = &quot;1&quot; height = &quot;1&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/csdn.net/chengyun_chu/236815332/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/csdn.net/chengyun_chu/236815332/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><pubDate>Sat, 21 Mar 2009 13:07:00 +0800</pubDate><author>褚诚云</author><comments>http://blog.csdn.net/chengyun_chu/archive/2009/03/21/4010068.aspx#Feedback</comments><guid isPermaLink="false">http://blog.csdn.net/chengyun_chu/archive/2009/03/21/4010068.aspx</guid><dc:creator>褚诚云</dc:creator><fs:srclink>http://blog.csdn.net/chengyun_chu/archive/2009/03/21/4010068.aspx</fs:srclink><fs:srcfeed>http://blog.csdn.net/chengyun_chu/rss.aspx</fs:srcfeed><fs:itemid>csdn.net/chengyun_chu/~1295556/236815332/1298450</fs:itemid></item><item><title>IE 8 RC 发布 附:IE 8 安全特性一文</title><link>http://blog.csdn.net/chengyun_chu/archive/2009/01/29/3854255.aspx</link><wfw:comment>http://blog.csdn.net/chengyun_chu/comments/3854255.aspx</wfw:comment><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/chengyun_chu/comments/commentRss/3854255.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=3854255</trackback:ping><description>IE 8 安全特性&lt;img src =&quot;http://blog.csdn.net/chengyun_chu/aggbug/3854255.aspx&quot; width = &quot;1&quot; height = &quot;1&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/csdn.net/chengyun_chu/236815333/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/csdn.net/chengyun_chu/236815333/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><pubDate>Thu, 29 Jan 2009 14:30:00 +0800</pubDate><author>褚诚云</author><comments>http://blog.csdn.net/chengyun_chu/archive/2009/01/29/3854255.aspx#Feedback</comments><guid isPermaLink="false">http://blog.csdn.net/chengyun_chu/archive/2009/01/29/3854255.aspx</guid><dc:creator>褚诚云</dc:creator><fs:srclink>http://blog.csdn.net/chengyun_chu/archive/2009/01/29/3854255.aspx</fs:srclink><fs:srcfeed>http://blog.csdn.net/chengyun_chu/rss.aspx</fs:srcfeed><fs:itemid>csdn.net/chengyun_chu/~1295556/236815333/1298450</fs:itemid></item><item><title>祝大家牛年快乐</title><link>http://blog.csdn.net/chengyun_chu/archive/2009/01/29/3854254.aspx</link><wfw:comment>http://blog.csdn.net/chengyun_chu/comments/3854254.aspx</wfw:comment><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/chengyun_chu/comments/commentRss/3854254.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=3854254</trackback:ping><description>祝大家牛年快乐，万事如意&lt;img src =&quot;http://blog.csdn.net/chengyun_chu/aggbug/3854254.aspx&quot; width = &quot;1&quot; height = &quot;1&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/csdn.net/chengyun_chu/236815334/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/csdn.net/chengyun_chu/236815334/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><pubDate>Thu, 29 Jan 2009 14:26:00 +0800</pubDate><author>褚诚云</author><comments>http://blog.csdn.net/chengyun_chu/archive/2009/01/29/3854254.aspx#Feedback</comments><guid isPermaLink="false">http://blog.csdn.net/chengyun_chu/archive/2009/01/29/3854254.aspx</guid><dc:creator>褚诚云</dc:creator><fs:srclink>http://blog.csdn.net/chengyun_chu/archive/2009/01/29/3854254.aspx</fs:srclink><fs:srcfeed>http://blog.csdn.net/chengyun_chu/rss.aspx</fs:srcfeed><fs:itemid>csdn.net/chengyun_chu/~1295556/236815334/1298450</fs:itemid></item><item><title>推荐大牛蛙的博客</title><link>http://blog.csdn.net/chengyun_chu/archive/2008/12/06/3458613.aspx</link><wfw:comment>http://blog.csdn.net/chengyun_chu/comments/3458613.aspx</wfw:comment><slash:comments>2</slash:comments><wfw:commentRss>http://blog.csdn.net/chengyun_chu/comments/commentRss/3458613.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=3458613</trackback:ping><description>&lt;br /&gt;大牛蛙的博客，对微软安全漏洞感兴趣的可不要错过哦！有时候还有小道消息提供。:)&lt;br /&gt;&lt;br /&gt;http://blogs.technet.com/secure/default.aspx&lt;br /&gt;&lt;img src =&quot;http://blog.csdn.net/chengyun_chu/aggbug/3458613.aspx&quot; width = &quot;1&quot; height = &quot;1&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/csdn.net/chengyun_chu/236815335/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/csdn.net/chengyun_chu/236815335/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><pubDate>Sat, 06 Dec 2008 17:15:00 +0800</pubDate><author>褚诚云</author><comments>http://blog.csdn.net/chengyun_chu/archive/2008/12/06/3458613.aspx#Feedback</comments><guid isPermaLink="false">http://blog.csdn.net/chengyun_chu/archive/2008/12/06/3458613.aspx</guid><dc:creator>褚诚云</dc:creator><fs:srclink>http://blog.csdn.net/chengyun_chu/archive/2008/12/06/3458613.aspx</fs:srclink><fs:srcfeed>http://blog.csdn.net/chengyun_chu/rss.aspx</fs:srcfeed><fs:itemid>csdn.net/chengyun_chu/~1295556/236815335/1298450</fs:itemid></item><item><title>中国软件安全峰会 -  个人笔记</title><link>http://blog.csdn.net/chengyun_chu/archive/2008/12/06/3458584.aspx</link><wfw:comment>http://blog.csdn.net/chengyun_chu/comments/3458584.aspx</wfw:comment><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/chengyun_chu/comments/commentRss/3458584.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=3458584</trackback:ping><description>中国软件安全峰会部分讲座的个人笔记&lt;img src =&quot;http://blog.csdn.net/chengyun_chu/aggbug/3458584.aspx&quot; width = &quot;1&quot; height = &quot;1&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/csdn.net/chengyun_chu/236815336/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/csdn.net/chengyun_chu/236815336/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><pubDate>Sat, 06 Dec 2008 16:26:00 +0800</pubDate><author>褚诚云</author><comments>http://blog.csdn.net/chengyun_chu/archive/2008/12/06/3458584.aspx#Feedback</comments><guid isPermaLink="false">http://blog.csdn.net/chengyun_chu/archive/2008/12/06/3458584.aspx</guid><dc:creator>褚诚云</dc:creator><fs:srclink>http://blog.csdn.net/chengyun_chu/archive/2008/12/06/3458584.aspx</fs:srclink><fs:srcfeed>http://blog.csdn.net/chengyun_chu/rss.aspx</fs:srcfeed><fs:itemid>csdn.net/chengyun_chu/~1295556/236815336/1298450</fs:itemid></item><item><title>禁用危险的API: banned.h</title><link>http://blog.csdn.net/chengyun_chu/archive/2008/11/05/3230088.aspx</link><wfw:comment>http://blog.csdn.net/chengyun_chu/comments/3230088.aspx</wfw:comment><slash:comments>1</slash:comments><wfw:commentRss>http://blog.csdn.net/chengyun_chu/comments/commentRss/3230088.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=3230088</trackback:ping><description>&lt;br /&gt;上一篇有关C/C++禁用危险的API的一文里面没有提到：如果在编译中禁止使用这些危险的API。&lt;br /&gt;&lt;br /&gt;很简单，&lt;br /&gt;&lt;br /&gt;#include &quot;banned.h&quot;&lt;br /&gt;&lt;br /&gt;即可。&lt;br /&gt;&lt;br /&gt;用户可以从以下链接中直接下载http://download.microsoft.com/download/2/e/b/2ebac853-63b7-49b4-b66f-9fd85f37c0f5/banned.h&lt;br /&gt;&lt;br /&gt;如果打开banner.h，可以看到，里面有&lt;br /&gt;&lt;br /&gt;#       pragma deprecated (strlen, wcslen, _mbslen, _mbstrlen, StrLen, lstrlen)&lt;br /&gt;&lt;br /&gt;通过这种方法，就可以通知编译器对调用危险API报告错误信息。&lt;img src =&quot;http://blog.csdn.net/chengyun_chu/aggbug/3230088.aspx&quot; width = &quot;1&quot; height = &quot;1&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/csdn.net/chengyun_chu/236815337/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/csdn.net/chengyun_chu/236815337/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><pubDate>Thu, 06 Nov 2008 06:37:00 +0800</pubDate><author>褚诚云</author><comments>http://blog.csdn.net/chengyun_chu/archive/2008/11/05/3230088.aspx#Feedback</comments><guid isPermaLink="false">http://blog.csdn.net/chengyun_chu/archive/2008/11/05/3230088.aspx</guid><dc:creator>褚诚云</dc:creator><fs:srclink>http://blog.csdn.net/chengyun_chu/archive/2008/11/05/3230088.aspx</fs:srclink><fs:srcfeed>http://blog.csdn.net/chengyun_chu/rss.aspx</fs:srcfeed><fs:itemid>csdn.net/chengyun_chu/~1295556/236815337/1298450</fs:itemid></item><item><title>微软今天发布的紧急安全公告 MS08-067</title><link>http://blog.csdn.net/chengyun_chu/archive/2008/10/24/3134568.aspx</link><wfw:comment>http://blog.csdn.net/chengyun_chu/comments/3134568.aspx</wfw:comment><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/chengyun_chu/comments/commentRss/3134568.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=3134568</trackback:ping><description>今天早上微软发布了一个紧急安全公告 MS08-067&lt;img src =&quot;http://blog.csdn.net/chengyun_chu/aggbug/3134568.aspx&quot; width = &quot;1&quot; height = &quot;1&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/csdn.net/chengyun_chu/236815338/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/csdn.net/chengyun_chu/236815338/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><pubDate>Fri, 24 Oct 2008 15:18:00 +0800</pubDate><author>褚诚云</author><comments>http://blog.csdn.net/chengyun_chu/archive/2008/10/24/3134568.aspx#Feedback</comments><guid isPermaLink="false">http://blog.csdn.net/chengyun_chu/archive/2008/10/24/3134568.aspx</guid><dc:creator>褚诚云</dc:creator><fs:srclink>http://blog.csdn.net/chengyun_chu/archive/2008/10/24/3134568.aspx</fs:srclink><fs:srcfeed>http://blog.csdn.net/chengyun_chu/rss.aspx</fs:srcfeed><fs:itemid>csdn.net/chengyun_chu/~1295556/236815338/1298450</fs:itemid></item><item><title>11月份的若干安全会议</title><link>http://blog.csdn.net/chengyun_chu/archive/2008/10/23/3127845.aspx</link><wfw:comment>http://blog.csdn.net/chengyun_chu/comments/3127845.aspx</wfw:comment><slash:comments>4</slash:comments><wfw:commentRss>http://blog.csdn.net/chengyun_chu/comments/commentRss/3127845.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=3127845</trackback:ping><description>11月份的三个和计算机安全有关的会议。&lt;img src =&quot;http://blog.csdn.net/chengyun_chu/aggbug/3127845.aspx&quot; width = &quot;1&quot; height = &quot;1&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/csdn.net/chengyun_chu/236815339/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/csdn.net/chengyun_chu/236815339/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><pubDate>Thu, 23 Oct 2008 14:49:00 +0800</pubDate><author>褚诚云</author><comments>http://blog.csdn.net/chengyun_chu/archive/2008/10/23/3127845.aspx#Feedback</comments><guid isPermaLink="false">http://blog.csdn.net/chengyun_chu/archive/2008/10/23/3127845.aspx</guid><dc:creator>褚诚云</dc:creator><fs:srclink>http://blog.csdn.net/chengyun_chu/archive/2008/10/23/3127845.aspx</fs:srclink><fs:srcfeed>http://blog.csdn.net/chengyun_chu/rss.aspx</fs:srcfeed><fs:itemid>csdn.net/chengyun_chu/~1295556/236815339/1298450</fs:itemid></item><item><title>安全编码实践四：C/C++中禁用危险API</title><link>http://blog.csdn.net/chengyun_chu/archive/2008/10/23/3127844.aspx</link><wfw:comment>http://blog.csdn.net/chengyun_chu/comments/3127844.aspx</wfw:comment><slash:comments>16</slash:comments><wfw:commentRss>http://blog.csdn.net/chengyun_chu/comments/commentRss/3127844.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=3127844</trackback:ping><description>C/C++代码中禁用危险的API，其主要目的是为了减少代码中引入安全漏洞的可能性。&lt;img src =&quot;http://blog.csdn.net/chengyun_chu/aggbug/3127844.aspx&quot; width = &quot;1&quot; height = &quot;1&quot; /&gt;&lt;p class=&quot;fswww1&quot;&gt;&lt;a href=&quot;http://www1.feedsky.com/r/l/csdn.net/chengyun_chu/236815340/art01.html&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; ismap=&quot;ismap&quot; src=&quot;http://www1.feedsky.com/r/i/csdn.net/chengyun_chu/236815340/art01.gif&quot; onerror=&quot;this.style.display='none'&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description><pubDate>Thu, 23 Oct 2008 14:47:00 +0800</pubDate><author>褚诚云</author><comments>http://blog.csdn.net/chengyun_chu/archive/2008/10/23/3127844.aspx#Feedback</comments><guid isPermaLink="false">http://blog.csdn.net/chengyun_chu/archive/2008/10/23/3127844.aspx</guid><dc:creator>褚诚云</dc:creator><fs:srclink>http://blog.csdn.net/chengyun_chu/archive/2008/10/23/3127844.aspx</fs:srclink><fs:srcfeed>http://blog.csdn.net/chengyun_chu/rss.aspx</fs:srcfeed><fs:itemid>csdn.net/chengyun_chu/~1295556/236815340/1298450</fs:itemid></item></channel></rss>