<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-8503755746105415394</id><updated>2010-01-07T21:09:11.942Z</updated><title type='text'>PortSwigger.net - web application security</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.portswigger.net/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default?start-index=26&amp;max-results=25'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>98</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-4573797607172565342</id><published>2010-01-07T16:56:00.009Z</published><updated>2010-01-07T17:19:30.013Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='burp'/><title type='text'>Burp Suite v1.3 released</title><summary type='text'>Burp Suite v1.3 is now available to download. This is a major upgrade with a host of new features.New features in Burp Suite free edition include:A new message editor/viewer optimised for HTTP requests and responses, with colourised syntax, mouse-over decoding, and quick conversion functions.Facility to add comments and highlights to the proxy history and site map.Support for AMF-encoded </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/4573797607172565342/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=4573797607172565342' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/4573797607172565342'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/4573797607172565342'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2010/01/burp-suite-v13-released.html' title='Burp Suite v1.3 released'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_lHJDdiLYLFc/S0YTBFWcKII/AAAAAAAAAdw/5VlmiWqfC3s/s72-c/woohoo.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-8674264634800116487</id><published>2009-12-14T22:03:00.004Z</published><updated>2009-12-14T22:10:19.292Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='2.0'/><title type='text'>MilkSwigger</title><summary type='text'>This little chap showed up a couple of weeks ago, somewhat earlier than expected. Needless to say, this event has thrown my meticulous plans for the final release of Burp v1.3 into disarray. Many thanks to everyone who has emailed with bugs and suggestions from the beta release, and apologies for the lack of responses. Normal service will be resumed in January.</summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/8674264634800116487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=8674264634800116487' title='14 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8674264634800116487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8674264634800116487'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/12/milkswigger.html' title='MilkSwigger'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_lHJDdiLYLFc/Sya2jARKtlI/AAAAAAAAAdg/1QrWaaKNM-Q/s72-c/MilkSwigger+and+PortSwigger.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>14</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-6225778599190657826</id><published>2009-11-30T10:15:00.001Z</published><updated>2009-11-30T10:19:18.338Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] Pro beta version now available</title><summary type='text'>A beta version of the new release of Burp is now available for Professional users. The free edition will be available in two or three weeks time. If you don't have a Pro license and are eager to try out the new features, why not treat yourself here?As always, any help flushing out bugs will be much appreciated. Please email these directly, so that I can easily get back to you for more details if </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/6225778599190657826/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=6225778599190657826' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/6225778599190657826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/6225778599190657826'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-pro-beta-version-now-available.html' title='[V13P] Pro beta version now available'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_lHJDdiLYLFc/Sw5CmLQr6FI/AAAAAAAAAdQ/QYeypI4on8o/s72-c/bojo.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-106881407277420498</id><published>2009-11-29T09:06:00.000Z</published><updated>2009-11-29T09:06:00.636Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] Other bits and pieces</title><summary type='text'>I've described most of the major additions to Burp's functionality that are arriving in v1.3. There are a few other smaller tweaks that are worth drawing attention to:The tables in the site map and search results now include a timestamp column. Sorting the results on this column lets you easily see when new items are added. This is handy when you are running spidering or content discovery </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/106881407277420498/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=106881407277420498' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/106881407277420498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/106881407277420498'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-other-bits-and-pieces.html' title='[V13P] Other bits and pieces'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-3417236661635561953</id><published>2009-11-27T13:41:00.000Z</published><updated>2009-11-27T13:41:00.440Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] Target analyser</title><summary type='text'>For Pro users, Burp now includes a function to analyse a target web application and tell you how many static and dynamic URLs it contains, and how many parameters each URL takes. This can help you assess how much effort a penetration testing engagement is likely to involve, and can help you decide where to focus your attention during the test itself. To access this feature, you select one or more</summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/3417236661635561953/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=3417236661635561953' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/3417236661635561953'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/3417236661635561953'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-target-analyser.html' title='[V13P] Target analyser'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_lHJDdiLYLFc/SwzwaFmhiDI/AAAAAAAAAdI/AzPtbg5wSkI/s72-c/analyser1.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-7208742856822728059</id><published>2009-11-26T16:10:00.000Z</published><updated>2009-11-26T16:14:21.667Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] Exporting of request information</title><summary type='text'>In the new release, Burp lets you export full details of interesting requests and responses in XML format, including all relevant metadata such as response length, HTTP status code and MIME type. For example:If you have annotated any of the exported items, your comments will also be included within the XML.You can access this feature via the context menu anywhere in Burp that you see requests and</summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/7208742856822728059/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=7208742856822728059' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/7208742856822728059'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/7208742856822728059'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-exporting-of-request-information.html' title='[V13P] Exporting of request information'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_lHJDdiLYLFc/Sww0l-o3lUI/AAAAAAAAAcw/Ludqjut106Q/s72-c/export.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-4096559240133725129</id><published>2009-11-25T17:20:00.000Z</published><updated>2009-11-25T17:20:36.877Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] Manual testing simulator</title><summary type='text'>This feature won't exactly enhance your productivity, but you may sometimes find it useful nonetheless. In the new release, lazy Pro users can make Burp simulate manual testing activities, by sending common test payloads to random URLs and parameters within a target application, at irregular intervals. Burp doesn't do anything with the responses, so you won't find out about any bugs in this way. </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/4096559240133725129/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=4096559240133725129' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/4096559240133725129'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/4096559240133725129'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-manual-testing-simulator.html' title='[V13P] Manual testing simulator'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_lHJDdiLYLFc/Sww-HUt5C8I/AAAAAAAAAc4/oNKCKZo3uRQ/s72-c/simulator.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-8152673915469090012</id><published>2009-11-25T12:39:00.001Z</published><updated>2009-11-25T13:28:09.443Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] Laser-guided scanning</title><summary type='text'>To my great pride, nearly everyone who has tried out Burp Scanner absolutely loves it. But people still helpfully come back with tons of feature requests for it.One of the biggest complaints is the relatively crude way in which Burp lets you send items for active scanning from the site map. For example, when you have mapped out all of the content and functionality within your target application, </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/8152673915469090012/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=8152673915469090012' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8152673915469090012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8152673915469090012'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-laser-guided-scanning.html' title='[V13P] Laser-guided scanning'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_lHJDdiLYLFc/Swwu-pGpAhI/AAAAAAAAAco/OLiQw70LxvQ/s72-c/scanwizard1.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-7511439357751646466</id><published>2009-11-24T18:24:00.003Z</published><updated>2009-11-24T18:36:46.705Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] New display filters</title><summary type='text'>The display filters used in the proxy history and site map are now more powerful, and allow you to filter on:Simple and regex search terms (Pro version only) - this is often handier than using the suite-wide search function.File extension - this supplements the MIME type filter, and is useful for unusual content types, and when HTTP 304 responses do not contain any content.Annotations made by the</summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/7511439357751646466/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=7511439357751646466' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/7511439357751646466'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/7511439357751646466'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-new-display-filters.html' title='[V13P] New display filters'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_lHJDdiLYLFc/SwwmWN-PkcI/AAAAAAAAAcY/LJfBURmRK1c/s72-c/displayfilters.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-8005645696334064143</id><published>2009-11-24T12:21:00.000Z</published><updated>2009-11-24T14:00:31.606Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] Scripts and comments search</title><summary type='text'>Pro users can now search part or all of the site map for scripts and comments. This feature is accessed by selecting relevant branches within the site map, and using the context menu.The search results window shows responses from all Burp tools containing either scripts or comments. Selecting an individual item shows the full request and response in a preview pane, with relevant items </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/8005645696334064143/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=8005645696334064143' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8005645696334064143'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8005645696334064143'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-scripts-and-comments-search.html' title='[V13P] Scripts and comments search'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_lHJDdiLYLFc/SwfcmQX8dnI/AAAAAAAAAcA/RNd38lnsg-0/s72-c/scriptssearch.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-8200585723031918197</id><published>2009-11-23T09:49:00.001Z</published><updated>2009-11-23T14:15:03.302Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] Content discovery</title><summary type='text'>Burp now includes a content discovery function, similar in concept to OWASP's DirtBuster. You can access this feature by selecting a request or URL anywhere within Burp, and using the context menu to start content discovery. Burp uses various techniques to discover content, including name guessing, web spidering, and extrapolation from naming conventions observed in use within the application. </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/8200585723031918197/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=8200585723031918197' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8200585723031918197'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8200585723031918197'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-content-discovery.html' title='[V13P] Content discovery'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_lHJDdiLYLFc/SwZqARWciXI/AAAAAAAAAbw/hqN1mueordg/s72-c/discovery.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-5616318758832177973</id><published>2009-11-22T10:02:00.005Z</published><updated>2009-11-22T10:34:33.467Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] SSL pain relief</title><summary type='text'>In v1.2.11, Burp introduced a new method of generating the server SSL certificates which are presented to your browser when you connect via Burp Proxy. This involved creating a root CA certificate (per user), which you can install into your browser, and using this to sign each host certificate, thus enabling you to eliminate SSL certificate errors. Read more here. Unfortunately, in v3.5 Firefox </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/5616318758832177973/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=5616318758832177973' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/5616318758832177973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/5616318758832177973'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-ssl-pain-relief.html' title='[V13P] SSL pain relief'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_lHJDdiLYLFc/SwkS9_9A2YI/AAAAAAAAAcQ/VzargR1GJmA/s72-c/cacert.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-8292384336449245919</id><published>2009-11-21T11:55:00.003Z</published><updated>2009-11-21T12:03:28.796Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] Upstream proxy rules</title><summary type='text'>If I had a beer for every time someone has requested this feature, I'd have been way too wasted to implement it.Burp already supports upstream web proxies, but only as a global configuration which affects all outgoing traffic. In the new release, Burp allows you to configure rules specifying different proxy settings for different (ranges of) destination hosts.The following configuration will make</summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/8292384336449245919/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=8292384336449245919' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8292384336449245919'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8292384336449245919'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-upstream-proxy-rules.html' title='[V13P] Upstream proxy rules'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_lHJDdiLYLFc/SwfWb6KJUII/AAAAAAAAAb4/GE9K9cWGkNU/s72-c/proxyoptions.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-6907171041981619663</id><published>2009-11-20T08:36:00.006Z</published><updated>2009-11-20T15:10:31.723Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] Request annotation</title><summary type='text'>You can now add comments and coloured highlights to items in the site map and proxy history:You can highlight individual items using a drop-down menu on the left-most table column:And you can comment individual items in-place by double-clicking and editing the table cell:Alternatively, if you want to annotate several items at once, you select the relevant items and use the context menu to add </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/6907171041981619663/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=6907171041981619663' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/6907171041981619663'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/6907171041981619663'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-request-annotation.html' title='[V13P] Request annotation'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_lHJDdiLYLFc/SwZajhtuuYI/AAAAAAAAAbY/dVUwkkJlI6c/s72-c/annotation.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-1617878352053990068</id><published>2009-11-20T08:12:00.005Z</published><updated>2009-11-20T08:34:07.888Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>[V13P] Improved search</title><summary type='text'>The suite-wide search function has had a revamp, with a number of useful features added:regex mode;optional restriction to target scope;optional dynamic updating of existing search results as new requests are made;ability to search selected hosts/branches within the site map, via the site map context menu.Here's an example of using a regex search term with dynamic updating, to monitor all </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/1617878352053990068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=1617878352053990068' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/1617878352053990068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/1617878352053990068'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/v13p-improved-search.html' title='[V13P] Improved search'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_lHJDdiLYLFc/SwZSsW7q_AI/AAAAAAAAAa4/nlgpQMFE8Z4/s72-c/search.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-2081680365868260389</id><published>2009-11-20T08:03:00.002Z</published><updated>2009-11-20T08:09:19.295Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='V13P'/><title type='text'>Burp Suite v1.3 preview</title><summary type='text'>Work on the next release of Burp is inching forwards, and over the next two weeks I'll be posting regularly with previews of some of the cool new features to look forward to. Then I'll release a beta version for Pro users to play with. Everyone with a current license will receive an automatic upgrade to v1.3.Many thanks to everyone who has submitted feature requests. A lot of these have been </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/2081680365868260389/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=2081680365868260389' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/2081680365868260389'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/2081680365868260389'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/burp-suite-v13-preview.html' title='Burp Suite v1.3 preview'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-8741080124258596801</id><published>2009-11-02T11:21:00.001Z</published><updated>2009-11-02T11:24:34.792Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='burp'/><title type='text'>Burp Suite - feature requests please</title><summary type='text'>It's getting to that time of year again when all the hastily made promises about the next release of Burp need to be made good. So I'm pleased to announce that release 1.3 of Burp Suite will be available before Christmas*.The free edition of Burp will get a roll-up of some of the new stuff that has been added to the pro edition over the past year. And the pro edition will get a bunch of cool new </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/8741080124258596801/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=8741080124258596801' title='54 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8741080124258596801'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8741080124258596801'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/burp-suite-feature-requests-please.html' title='Burp Suite - feature requests please'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>54</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-8796275138034780270</id><published>2009-11-02T11:06:00.000Z</published><updated>2009-11-02T11:21:40.879Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='nonsense'/><title type='text'>If politicians were HTTP status codes</title><summary type='text'>401 Not AuthorizedGeorge W. Bush416 Not SatisfiableBill Clinton417 Expectation FailedBarack Obama302 FoundSaddam Hussein404 Not FoundOsama Bin Laden410 GoneJohn F Kennedy500 Internal ErrorDonald Rumsfeld415 Unsupported Media TypeTony Blair203 Non-Authoritative InformationSarah Palin306 UnusedAl Gore408 TimeoutJohn McCain303 See OtherNicolas Sarkozy100 ContinueVladimir Putin405 Method Not </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/8796275138034780270/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=8796275138034780270' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8796275138034780270'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8796275138034780270'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/if-politicians-were-http-status-codes.html' title='If politicians were HTTP status codes'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_lHJDdiLYLFc/Su6whIye1II/AAAAAAAAAao/pr7fCDQHTnE/s72-c/George+W.+Bush.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-6806743423404912617</id><published>2009-11-02T10:56:00.004Z</published><updated>2009-11-02T11:13:36.023Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='burp intruder'/><title type='text'>GIAC paper on Burp Intruder</title><summary type='text'>Karl Dawson has written a nice paper about using Burp Intruder for discovering login credentials, and how you can use various tricks to reveal other useful information and anomalies, as well as actually guessing valid passwords. Download it here.</summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/6806743423404912617/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=6806743423404912617' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/6806743423404912617'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/6806743423404912617'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/11/giac-paper-on-burp-intruder.html' title='GIAC paper on Burp Intruder'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-2380477660426565986</id><published>2009-04-11T10:25:00.000Z</published><updated>2009-04-11T09:26:54.590Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='burp'/><title type='text'>New release notes feed</title><summary type='text'>I've been releasing updates to the Pro version of Burp pretty frequently recently. Some of these are fairly minor so you won't always see alerts that a new version is available. To help people who do want to follow the latest updates, you can now subscribe to a listing of release notes. The latest update gives Burp a new editor for raw HTTP messages, which can handle much larger messages </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/2380477660426565986/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=2380477660426565986' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/2380477660426565986'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/2380477660426565986'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/04/new-release-notes-feed.html' title='New release notes feed'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_lHJDdiLYLFc/Sd3stwLhhuI/AAAAAAAAAUg/ALt0fp0hTOM/s72-c/neweditor.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-3413211736867047080</id><published>2009-04-10T14:00:00.000Z</published><updated>2009-04-10T13:34:45.572Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='burp'/><category scheme='http://www.blogger.com/atom/ns#' term='thick clients'/><title type='text'>Intercepting thick client communications</title><summary type='text'>I've written before about how Burp's invisible proxying mode can help you intercept requests from non-proxy-aware thick clients. Burp Suite Pro now contains a new feature which makes this task even easier.If you are using a thick client component which cannot be configured to use a proxy, you can force it to talk to Burp Proxy instead of the actual destination host by performing the following </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/3413211736867047080/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=3413211736867047080' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/3413211736867047080'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/3413211736867047080'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html' title='Intercepting thick client communications'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_lHJDdiLYLFc/Sdy1bzrtc9I/AAAAAAAAAUY/KMBxEsHUEec/s72-c/hostresolution.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-4675657230005318786</id><published>2009-04-09T19:18:00.000Z</published><updated>2009-04-09T15:10:37.771Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='burp'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><title type='text'>Burp problems after Windows update</title><summary type='text'>If you use Windows, you may have encountered a problem following March's security update, in that Burp Proxy listeners running on the loopback interface stopped working. This was caused by Microsoft changing the "localhost" entry in the Windows hosts file from:127.0.0.1 localhostto:::1 localhostManually reverting to the old entry fixes the problem for a while, but Windows will silently update to </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/4675657230005318786/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=4675657230005318786' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/4675657230005318786'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/4675657230005318786'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/04/burp-problems-after-windows-update.html' title='Burp problems after Windows update'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-4997133539657116342</id><published>2009-04-08T19:08:00.000Z</published><updated>2009-04-08T18:14:39.244Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='burp extender'/><title type='text'>Using Burp Extender</title><summary type='text'>From time to time, people ask me for help getting their code working with Burp Extender, so here is a quick worked example of how to do this. The example is based on a plugin written by Daniele Costa, which extracts HTML comments from HTTP responses, and writes these to file and to the command line.The core of the plugin code is simple. It implements the processProxyMessage method in </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/4997133539657116342/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=4997133539657116342' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/4997133539657116342'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/4997133539657116342'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/04/using-burp-extender.html' title='Using Burp Extender'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_lHJDdiLYLFc/SdyrnRhVYFI/AAAAAAAAAUQ/sGy-I2k-_Eg/s72-c/alerts.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-8874707003934087528</id><published>2008-12-14T14:00:00.000Z</published><updated>2008-12-14T14:11:15.007Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='burp'/><title type='text'>Burp Suite v1.2 released</title><summary type='text'> Burp Suite v1.2 is now available to download. This is a major upgrade with a host of new features, including:Site map showing information accumulated about target applications in tree and table formSuite-level target scope configuration, driving numerous individual tool actionsDisplay filters on site map and Proxy request historySuite-wide search functionSupport for invisible proxyingFully </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/8874707003934087528/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=8874707003934087528' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8874707003934087528'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/8874707003934087528'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2008/12/burp-suite-v12-released.html' title='Burp Suite v1.2 released'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_lHJDdiLYLFc/SUJ6ytQCC6I/AAAAAAAAAT0/9qJBGoY2ZUg/s72-c/santa.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-4159519539263466853</id><published>2008-11-30T15:29:00.003Z</published><updated>2008-11-30T15:47:57.198Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MoBP'/><category scheme='http://www.blogger.com/atom/ns#' term='burp'/><title type='text'>[MoBP] Pro beta version now available</title><summary type='text'> A beta version of the new release of Burp Suite Professional is now available to licensed users. The free edition will be made available in two or three weeks time. If you just can't wait that long to get your hands on the new Burp, there is an easy solution!If you bought or renewed your Burp license within the last year, you should today have received the new beta. If you think you have missed </summary><link rel='replies' type='application/atom+xml' href='http://blog.portswigger.net/feeds/4159519539263466853/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8503755746105415394&amp;postID=4159519539263466853' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/4159519539263466853'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/posts/default/4159519539263466853'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2008/11/mobp-pro-beta-version-now-available.html' title='[MoBP] Pro beta version now available'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17119005656566588951'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_lHJDdiLYLFc/STK0IyluuvI/AAAAAAAAATs/D-VwPb0OJiU/s72-c/rabbit.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>6</thr:total></entry></feed>