<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>Web Wiz Support and Community Forums : About RSS Topic &amp; Post Feeds</title>
  <link>https://forums.webwiz.net/</link>
  <description><![CDATA[This is an XML content feed of; Web Wiz Support and Community Forums : Web Wiz Forums : About RSS Topic &amp; Post Feeds]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Sat, 11 Apr 2026 13:23:26 +0000</pubDate>
  <lastBuildDate>Mon, 19 Jun 2006 10:17:51 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.08</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forums.webwiz.net/RSS_post_feed.asp?TID=19986</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Web Wiz Support and Community Forums]]></title>
   <url>https://forums.webwiz.net/forum_images/web_wiz_forums.png</url>
   <link>https://forums.webwiz.net/</link>
  </image>
  <item>
   <title><![CDATA[About RSS Topic &amp; Post Feeds : I don&amp;#039;t know your code, but...]]></title>
   <link>https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109255.html#109255</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 19986<br /><strong>Posted:</strong> 19&nbsp;June&nbsp;2006 at 10:17am<br /><br />I don't know your code, but to me just adding a 4 characters to a querystring will not take very long at all for a hacker to find an exploit in this and publish the results so that anyone can view posts they shouldn't do in forums.<br><br>If all you are doing is having 1 link for Guests and having a different link for Registered users then you have no security at all, all it needs is for someone to give out the link they shouldn't and anyone has access to posts they shouldn't.<br>]]>
   </description>
   <pubDate>Mon, 19 Jun 2006 10:17:51 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109255.html#109255</guid>
  </item> 
  <item>
   <title><![CDATA[About RSS Topic &amp; Post Feeds : Hi Borg, I try an implement for...]]></title>
   <link>https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109229.html#109229</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=18438">superlative</a><br /><strong>Subject:</strong> 19986<br /><strong>Posted:</strong> 17&nbsp;June&nbsp;2006 at 9:24pm<br /><br /><P>Hi Borg,</P><DIV>I try an implement for RSS security, this is very simple and easy.&nbsp;Please check my implement for securty holes :</DIV><DIV>&nbsp;</DIV><DIV>This link for guests :</DIV><DIV>&nbsp;</DIV><DIV><a href="http://www.knowhow.gen.tr/forum/RSS_topic_feed.asp?hVQ=F" target="_blank">http://www.knowhow.gen.tr/forum/RSS_topic_feed.asp?hVQ=F</A></DIV><DIV>&nbsp;</DIV><DIV>This link automatically generating for who didnt logon to forum.</DIV><DIV>&nbsp;</DIV><DIV>This link for my a new user :</DIV><DIV>&nbsp;</DIV><DIV><a href="http://www.knowhow.gen.tr/forum/RSS_topic_feed.asp?hVQ=HGFL" target="_blank">http://www.knowhow.gen.tr/forum/RSS_topic_feed.asp?hVQ=HGFL</A></DIV><DIV>&nbsp;</DIV><DIV>All RSS topic feed links&nbsp;generate automatically and for user. Checking permissions. If Borg's answer safely, I publish my code to Modification Forum.</DIV><DIV>&nbsp;</DIV>]]>
   </description>
   <pubDate>Sat, 17 Jun 2006 21:24:38 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109229.html#109229</guid>
  </item> 
  <item>
   <title><![CDATA[About RSS Topic &amp; Post Feeds : I think alternate way for check...]]></title>
   <link>https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109167.html#109167</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=18438">superlative</a><br /><strong>Subject:</strong> 19986<br /><strong>Posted:</strong> 16&nbsp;June&nbsp;2006 at 10:23am<br /><br />I think alternate way for check RSS System.<DIV>&nbsp;</DIV><DIV>For this way using ticket system. Tickets update each week. And user must obtain new RSS link.</DIV><DIV>&nbsp;</DIV><DIV>Tickets use same way, for example</DIV><DIV>&nbsp;</DIV><DIV><FONT size=2><a href="http://forums.webwiz.net/RSS_topic_feed.asp?FID=18&amp;ticket=sdf787cvxcv547s8dfs8d7fwe4r564" target="_blank">http://forums.webwiz.net/RSS_topic_feed.asp?FID=18&amp;ticket=sdf787cvxcv547s8dfs8d7fwe4r564</A></FONT></DIV><DIV><FONT size=2></FONT>&nbsp;</DIV><DIV><FONT size=2>Then RSS page read ticket. Tickets contain user id and date but do not understandin (Ex:asd787a8d78a7s87d244f) Check ticket date (expired?) and user permission for this forum. If ok only publish XML content.</FONT></DIV><DIV><FONT size=2></FONT>&nbsp;</DIV><DIV><FONT size=2>This way guarantee user will&nbsp;not hack. If somebody learn this RSS link who will access via RSS reader (not forum). And after 1 week, ticket expire. Only user must obtain new RSS link. RSS link automaticly generating when user browse to forum. Each user's RSS link is different. If user dont access to some forum (permission denied) user can not obtain RSS link.</FONT></DIV><DIV><FONT size=2></FONT>&nbsp;</DIV><DIV><FONT size=2>Ticket expire date is last logon time + 7 days</FONT></DIV><DIV><FONT size=2></FONT>&nbsp;</DIV><DIV><FONT size=2>What do you think this way&nbsp;borg ? Any security bug ?</FONT></DIV>]]>
   </description>
   <pubDate>Fri, 16 Jun 2006 10:23:23 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109167.html#109167</guid>
  </item> 
  <item>
   <title><![CDATA[About RSS Topic &amp; Post Feeds : You right Borg, I didnt think...]]></title>
   <link>https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109165.html#109165</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=18438">superlative</a><br /><strong>Subject:</strong> 19986<br /><strong>Posted:</strong> 16&nbsp;June&nbsp;2006 at 10:02am<br /><br />You right Borg, I didnt think this. But be must a way for accomplish for RSS. I dont want to open our forums to public and I want to our members can follow forum via RSS.&nbsp;How&nbsp;how how ? I start our brain <IMG height=17 alt=Smile src="http://forums.webwiz.net/smileys/smiley1.gif" width=17 align=absMiddle border="0">. I created&nbsp;any security system for our articles. (Prevent copying,stole or etc.) Check it :<DIV>&nbsp;</DIV><DIV><a href="http://www.knowhow.gen.tr/makaleler/article.asp?id=264" target="_blank">http://www.knowhow.gen.tr/makaleler/article.asp?id=264</A></DIV><DIV>&nbsp;</DIV><DIV>May be I find a way how to accomplish this.&nbsp;</DIV>]]>
   </description>
   <pubDate>Fri, 16 Jun 2006 10:02:33 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109165.html#109165</guid>
  </item> 
  <item>
   <title><![CDATA[About RSS Topic &amp; Post Feeds :   Using the encrypted password...]]></title>
   <link>https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109164.html#109164</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 19986<br /><strong>Posted:</strong> 16&nbsp;June&nbsp;2006 at 9:52am<br /><br />Using the encrypted password in the querystring is also a a BIG security hole and not something I would want to use.<br><br>For security reasons the database encrypted passwords, security codes, etc. are updated periodically to add extra security to the system.<br><br>There is no permanent way to ID a user and any permanent solution through the use of querystrings and/or cookies would open a huge security hole in the software.<br><br>Cookies, querystrings, etc. are cached and can be got by hackers very easily, if a hacker gets hold of any permanent way of ID'ing a member they can use this to gain control of that users account.<br><br>Using the system you mention a hacker can very easily get hold of encrypted password, forum tracking codes, etc. then append this to an RSS Feed to view posts that they are not permitted to.<br><br>I have done allot of work in securing web wiz forums with white hat hackers and spent allot of time following security sites on hacking, and know that if such a system were implemented it would be only weeks, if not days, before hackers were announcing this as a big security hole in the software, and people demanding it be patched.<br><span style="font-size:10px"><br /><br />Edited by -boRg- - 16&nbsp;June&nbsp;2006 at 9:56am</span>]]>
   </description>
   <pubDate>Fri, 16 Jun 2006 09:52:18 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109164.html#109164</guid>
  </item> 
  <item>
   <title><![CDATA[About RSS Topic &amp; Post Feeds : SUJO, I like your supermarket...]]></title>
   <link>https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109086.html#109086</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=18438">superlative</a><br /><strong>Subject:</strong> 19986<br /><strong>Posted:</strong> 15&nbsp;June&nbsp;2006 at 10:15am<br /><br />SUJO, I like your supermarket imitation. But this is not interested in our case. <DIV>&nbsp;</DIV><DIV>By providing the RSS feed to others, they just might get interested enough to go to your page and register </DIV><DIV>&nbsp;</DIV><DIV>You wrote this, If you dont give access permission &nbsp;to guest, anybody follow content via RSS Feed. But guests register and be member and read content&nbsp;via forum (Not RSS)</DIV><DIV>&nbsp;</DIV><DIV>RSS Feeds is not&nbsp;only for computer users. Visitors read content via mobile phone. Many software exist for smartphones.</DIV><DIV>&nbsp;</DIV><DIV>RSS Feeds nice feature. Some members want to follow forums, blogs via RSS. If you want to reply they will go to forum. In this case we don't discussion RSS benefits/injuries. We discussion&nbsp;:</DIV><DIV>&nbsp;</DIV><DIV><strong><U>How to give to RSS access permission to our members without any security hole. isn't it ?</U></strong>&nbsp;</DIV>]]>
   </description>
   <pubDate>Thu, 15 Jun 2006 10:15:52 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109086.html#109086</guid>
  </item> 
  <item>
   <title><![CDATA[About RSS Topic &amp; Post Feeds : I agree with -boRg- here. The...]]></title>
   <link>https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109083.html#109083</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=21212">SUJO</a><br /><strong>Subject:</strong> 19986<br /><strong>Posted:</strong> 15&nbsp;June&nbsp;2006 at 9:54am<br /><br />I agree with <strong>-boRg-</strong> here. The RSS itself was designed to be available to everyone who wants to use it. It's like going into a supermarket - everybody can go in, and everybody can buy anything (except the things they keep in stock <IMG height=17 alt=Smile src="http://forums.webwiz.net/smileys/smiley1.gif" width=17 align=absMiddle border="0">). It is also encouraging. By providing the RSS feed to others, they just might get interested enough to go to your page and register -&nbsp;for more, or just to keep up. You have no idea how many feeds can/are being read...(you could be gaining people by not even knowing of it).&nbsp;Also, RSS does not include topics/threads/pages that you do not want to - eg. the permissions for forums you set. So - why would you want to complicate things where/when they are not necessary?]]>
   </description>
   <pubDate>Thu, 15 Jun 2006 09:54:26 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109083.html#109083</guid>
  </item> 
  <item>
   <title><![CDATA[About RSS Topic &amp; Post Feeds : Borg I explained as wrong, ID...]]></title>
   <link>https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109080.html#109080</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=18438">superlative</a><br /><strong>Subject:</strong> 19986<br /><strong>Posted:</strong> 15&nbsp;June&nbsp;2006 at 9:08am<br /><br />Borg I explained as wrong, ID is not permanent. Hackers can forund AID (Author ID) but can not find PW. Because PW is encryted user password. RSS links different for each user. For example :<DIV>&nbsp;</DIV><DIV>User 1 : </DIV><DIV>&nbsp;</DIV><DIV>User name : &nbsp;<strong>Borg</strong>, AID (Author ID) : <strong>1</strong>, Real PW : <strong>1234</strong>, Encrypted PW : <strong>sdfs545d4f5645s</strong>, Permission for WWF 8x Support : <strong>Access</strong>, RSS Link :</DIV><DIV>&nbsp;</DIV><DIV><a href="http://forums.webwiz.net/RSS_topic_feed.asp?FID=18&amp;AID=1&amp;PW=sdfs545d4f5645s" target="_blank">http://forums.webwiz.net/RSS_topic_feed.asp?FID=18&amp;AID=1&amp;PW=sdfs545d4f5645s</A></DIV><DIV>&nbsp;</DIV><DIV><DIV>User&nbsp;2 : </DIV><DIV>&nbsp;</DIV><DIV>User name :&nbsp;&nbsp;<strong>superlative</strong>, AID (Author ID) : <strong>18438</strong>, Real PW : <strong>369874</strong>, Encrypted PW : <strong>sdfsuyuewrjhss</strong>, Permission for WWF 8x Support : <strong>No Access</strong>, RSS Link : N/A (Because No Access forum)</DIV><DIV>&nbsp;</DIV><DIV>In This case, User 1 copy his own RSS link to RSS Reader software and RSS asp page decrypt to PW and check the user permission. If OK publish content.</DIV><DIV>&nbsp;</DIV><DIV>User 2 do not access the same forum. I am not hacker but this way very secure for RSS. RSS links generate for each member who have got access right. If guest access OK, bypass this security system for improve performance.</DIV><DIV>&nbsp;</DIV><DIV>&nbsp;</DIV></DIV><DIV>&nbsp;</DIV><DIV>&nbsp;</DIV>]]>
   </description>
   <pubDate>Thu, 15 Jun 2006 09:08:15 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109080.html#109080</guid>
  </item> 
  <item>
   <title><![CDATA[About RSS Topic &amp; Post Feeds :  By using the method you mention...]]></title>
   <link>https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109077.html#109077</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 19986<br /><strong>Posted:</strong> 15&nbsp;June&nbsp;2006 at 8:25am<br /><br />By using the method you mention using permanent ID within a URL would open a huge security hole that hackers could easily use to hack the forum and gain access to information that they shouldn't be allowed to view.<br><br>Cookies to do the same thing also would not be secure, and most RSS Readers do not support cookies.<br><span style="font-size:10px"><br /><br />Edited by -boRg- - 15&nbsp;June&nbsp;2006 at 8:26am</span>]]>
   </description>
   <pubDate>Thu, 15 Jun 2006 08:25:50 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109077.html#109077</guid>
  </item> 
  <item>
   <title><![CDATA[About RSS Topic &amp; Post Feeds : Hi Again Borg;  Can you use...]]></title>
   <link>https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109061.html#109061</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=18438">superlative</a><br /><strong>Subject:</strong> 19986<br /><strong>Posted:</strong> 14&nbsp;June&nbsp;2006 at 11:51pm<br /><br />Hi Again Borg;<DIV>&nbsp;</DIV><DIV>Can you use cookie authentication&nbsp;for&nbsp;RSS News Reader ? For special reasons we close our forum to guests. Only members can display. For this reason members can not follow our forum&nbsp;via RSS. If cookies support this maybe work. Or simple auth system may be add&nbsp;to RSS asp pages.</DIV><DIV>&nbsp;</DIV><DIV>For Example : </DIV><DIV>&nbsp;</DIV><DIV>Author ID and excrypted password send to RSS pages and simple check user permissions.</DIV><DIV>&nbsp;</DIV><DIV><a href="http://www.knowhow.gen.tr/forum/RSS_topic_feed.asp?FID=28" target="_blank">http://www.knowhow.gen.tr/forum/RSS_topic_feed.asp?FID=28</A></DIV><DIV>&nbsp;</DIV><DIV>insted of</DIV><DIV>&nbsp;</DIV><DIV><a href="http://www.knowhow.gen.tr/forum/RSS_topic_feed.asp?FID=28&amp;AID=blahblah&amp;pw=asjdhkajsd76678a5sdhhh" target="_blank">http://www.knowhow.gen.tr/forum/RSS_topic_feed.asp?FID=28&amp;AID=blahblah&amp;pw=asjdhkajsd76678a5sdhhh</A></DIV><DIV>&nbsp;</DIV><DIV>Then RSS page check AID (Author ID) and encyrpted PW, then appyle user permissions. Also, members can follow forum via RSS. Sory for my bad english grammar. Borg I hope you understand me :)</DIV>]]>
   </description>
   <pubDate>Wed, 14 Jun 2006 23:51:20 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/about-rss-topic-post-feeds_topic19986_post109061.html#109061</guid>
  </item> 
 </channel>
</rss>