<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Dinesh Mistry:</title>
	<atom:link href="http://www.dman.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dman.com</link>
	<description>Search Engine Optimization, InfoSec and Ethical Hacking</description>
	<lastBuildDate>Tue, 08 Nov 2011 07:42:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Tracking Google Instant Partial Queries in Google Analytics by MCA Suman</title>
		<link>http://www.dman.com/tracking-google-instant-partial-queries-in-google-analytics/#comment-284</link>
		<dc:creator>MCA Suman</dc:creator>
		<pubDate>Tue, 08 Nov 2011 07:42:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=354#comment-284</guid>
		<description>Field B -&gt; Extract B: Medium:^organic$


I am not getting this (Medium) option in Field B, Google has been remove it or make other option...

Please tell me the same...</description>
		<content:encoded><![CDATA[<p>Field B -&gt; Extract B: Medium:^organic$</p>
<p>I am not getting this (Medium) option in Field B, Google has been remove it or make other option&#8230;</p>
<p>Please tell me the same&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Google Launches New Algorithm Update to Target Link Farms by Tweets that mention Google Launches New Algorithm Update to Target Link Farms -- Topsy.com</title>
		<link>http://www.dman.com/google-launches-farmer-algorithm-updat/#comment-112</link>
		<dc:creator>Tweets that mention Google Launches New Algorithm Update to Target Link Farms -- Topsy.com</dc:creator>
		<pubDate>Fri, 25 Feb 2011 05:00:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=556#comment-112</guid>
		<description>[...] This post was mentioned on Twitter by Jason Stultz and Kelly Mistry, Dinesh Mistry. Dinesh Mistry said: New Post: Google Launches New Algorithm Update to Target Link Farms http://bit.ly/evYAcK [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Jason Stultz and Kelly Mistry, Dinesh Mistry. Dinesh Mistry said: New Post: Google Launches New Algorithm Update to Target Link Farms <a href="http://bit.ly/evYAcK" rel="nofollow">http://bit.ly/evYAcK</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cloud Computing &#8211; Multi-Tenancy and Application Security by Tweets that mention Cloud Computing - Multi-Tenancy and Application Security -- Topsy.com</title>
		<link>http://www.dman.com/cloud-computing-multi-tenancy-and-application-security/#comment-109</link>
		<dc:creator>Tweets that mention Cloud Computing - Multi-Tenancy and Application Security -- Topsy.com</dc:creator>
		<pubDate>Thu, 24 Feb 2011 02:50:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=548#comment-109</guid>
		<description>[...] This post was mentioned on Twitter by Trevor Hinson and Kelly Mistry, Dinesh Mistry. Dinesh Mistry said: New Post: Cloud Computing - Multi-Tenancy and Application Security http://bit.ly/hXRSMh [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Trevor Hinson and Kelly Mistry, Dinesh Mistry. Dinesh Mistry said: New Post: Cloud Computing &#8211; Multi-Tenancy and Application Security <a href="http://bit.ly/hXRSMh" rel="nofollow">http://bit.ly/hXRSMh</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Steal iPhone passwords in six minutes by Tweets that mention Steal iPhone passwords in six minutes -- Topsy.com</title>
		<link>http://www.dman.com/steal-iphone-passwords-in-six-minutes/#comment-98</link>
		<dc:creator>Tweets that mention Steal iPhone passwords in six minutes -- Topsy.com</dc:creator>
		<pubDate>Fri, 11 Feb 2011 04:57:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=514#comment-98</guid>
		<description>[...] This post was mentioned on Twitter by Defcon 201 and Kelly Mistry, Dinesh Mistry. Dinesh Mistry said: New Post: Steal iPhone passwords in six minutes http://bit.ly/eIcAi4 [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Defcon 201 and Kelly Mistry, Dinesh Mistry. Dinesh Mistry said: New Post: Steal iPhone passwords in six minutes <a href="http://bit.ly/eIcAi4" rel="nofollow">http://bit.ly/eIcAi4</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Experiment &#8211; How Twitter Links Effect Search Engine Ranking by Tweets that mention Experiment - How Twitter Links Effect Search Engine Ranking -- Topsy.com</title>
		<link>http://www.dman.com/experiment-how-twitter-links-effect-search-engine-ranking/#comment-90</link>
		<dc:creator>Tweets that mention Experiment - How Twitter Links Effect Search Engine Ranking -- Topsy.com</dc:creator>
		<pubDate>Fri, 10 Dec 2010 22:13:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=431#comment-90</guid>
		<description>[...] This post was mentioned on Twitter by MyFairyTaleBooks, Dinesh Mistry. Dinesh Mistry said: New Post: Experiment - How Twitter Links Effect Search Engine Ranking http://bit.ly/eyAa8s [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by MyFairyTaleBooks, Dinesh Mistry. Dinesh Mistry said: New Post: Experiment &#8211; How Twitter Links Effect Search Engine Ranking <a href="http://bit.ly/eyAa8s" rel="nofollow">http://bit.ly/eyAa8s</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hacking With Copier Machines by Tweets that mention Hacking With Copier Machines -- Topsy.com</title>
		<link>http://www.dman.com/hacking-with-copier-machine/#comment-86</link>
		<dc:creator>Tweets that mention Hacking With Copier Machines -- Topsy.com</dc:creator>
		<pubDate>Mon, 08 Nov 2010 03:41:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=411#comment-86</guid>
		<description>[...] This post was mentioned on Twitter by Defcon 201, Dinesh Mistry. Dinesh Mistry said: New Post: Hacking With Copier Machines http://bit.ly/9L6wpg [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Defcon 201, Dinesh Mistry. Dinesh Mistry said: New Post: Hacking With Copier Machines <a href="http://bit.ly/9L6wpg" rel="nofollow">http://bit.ly/9L6wpg</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Peek-a-boooooooo – Default web pages, and why you should care to change or eliminate them by Jason</title>
		<link>http://www.dman.com/default-web-pages-and-why-you-should-change-them/#comment-72</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Fri, 15 Oct 2010 15:59:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=144#comment-72</guid>
		<description>Also, note that you can find more sensitive information with even more basic queries.  For example, searching for &lt;a href=&quot;http://www.google.com/search?hl=en&amp;lr=&amp;ie=UTF-8&amp;q=filetype%3AQDF+QDF&quot; rel=&quot;nofollow&quot;&gt;filetype:QDF QDF&lt;/a&gt; will yield a slough of interesting details from folks who have allowed Quicken detail to be crawled.</description>
		<content:encoded><![CDATA[<p>Also, note that you can find more sensitive information with even more basic queries.  For example, searching for <a href="http://www.google.com/search?hl=en&amp;lr=&amp;ie=UTF-8&amp;q=filetype%3AQDF+QDF" rel="nofollow">filetype:QDF QDF</a> will yield a slough of interesting details from folks who have allowed Quicken detail to be crawled.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Google Instant Expands &#8211; Adds Keyboard Navigation by Tweets that mention Google Instant Expands - Adds Keyboard Navigation -- Topsy.com</title>
		<link>http://www.dman.com/google-instant-expands-adds-keyboard-navigation/#comment-49</link>
		<dc:creator>Tweets that mention Google Instant Expands - Adds Keyboard Navigation -- Topsy.com</dc:creator>
		<pubDate>Thu, 30 Sep 2010 00:54:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=390#comment-49</guid>
		<description>[...] This post was mentioned on Twitter by HomePCTechnician, Dinesh Mistry. Dinesh Mistry said: New Post: Google Instant Expands - Adds Keyboard Navigation http://bit.ly/cRKe2K [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by HomePCTechnician, Dinesh Mistry. Dinesh Mistry said: New Post: Google Instant Expands &#8211; Adds Keyboard Navigation <a href="http://bit.ly/cRKe2K" rel="nofollow">http://bit.ly/cRKe2K</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Twitter Hacked &#8211; onMouseover Bug by Dinesh Mistry</title>
		<link>http://www.dman.com/twitter-hacked-onmouseover-bug/#comment-36</link>
		<dc:creator>Dinesh Mistry</dc:creator>
		<pubDate>Wed, 22 Sep 2010 02:36:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=382#comment-36</guid>
		<description>Good question, from what I gather it only seemed to hold true for the older interface.</description>
		<content:encoded><![CDATA[<p>Good question, from what I gather it only seemed to hold true for the older interface.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Twitter Hacked &#8211; onMouseover Bug by HudsonValleyTec</title>
		<link>http://www.dman.com/twitter-hacked-onmouseover-bug/#comment-35</link>
		<dc:creator>HudsonValleyTec</dc:creator>
		<pubDate>Wed, 22 Sep 2010 02:35:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=382#comment-35</guid>
		<description>Did this hold true for the new twitter.com interface or just the old one?</description>
		<content:encoded><![CDATA[<p>Did this hold true for the new twitter.com interface or just the old one?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Twitter Hacked &#8211; onMouseover Bug by Tweets that mention Twitter Hacked - onMouseover Bug -- Topsy.com</title>
		<link>http://www.dman.com/twitter-hacked-onmouseover-bug/#comment-34</link>
		<dc:creator>Tweets that mention Twitter Hacked - onMouseover Bug -- Topsy.com</dc:creator>
		<pubDate>Wed, 22 Sep 2010 00:17:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=382#comment-34</guid>
		<description>[...] This post was mentioned on Twitter by Jason Stultz and HomePCTechnician, Dinesh Mistry. Dinesh Mistry said: New Post: Twitter Hacked - onMouseover Bug http://bit.ly/95DeBK [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Jason Stultz and HomePCTechnician, Dinesh Mistry. Dinesh Mistry said: New Post: Twitter Hacked &#8211; onMouseover Bug <a href="http://bit.ly/95DeBK" rel="nofollow">http://bit.ly/95DeBK</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Stack-based buffer overflow &#8211; Adobe Reader and Acrobat 9.3.4 by Tweets that mention Stack-based buffer overflow - Adobe Reader and Acrobat 9.3.4 -- Topsy.com</title>
		<link>http://www.dman.com/stack-based-buffer-overflow-adobe-reader-and-acrobat-9-3-4/#comment-26</link>
		<dc:creator>Tweets that mention Stack-based buffer overflow - Adobe Reader and Acrobat 9.3.4 -- Topsy.com</dc:creator>
		<pubDate>Wed, 15 Sep 2010 05:52:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=365#comment-26</guid>
		<description>[...] This post was mentioned on Twitter by Ganesh babu, Dinesh Mistry. Dinesh Mistry said: New Post: Stack-based buffer overflow - Adobe Reader and Acrobat 9.3.4 http://bit.ly/9IG1ES [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Ganesh babu, Dinesh Mistry. Dinesh Mistry said: New Post: Stack-based buffer overflow &#8211; Adobe Reader and Acrobat 9.3.4 <a href="http://bit.ly/9IG1ES" rel="nofollow">http://bit.ly/9IG1ES</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Google Instant &#8211; New Search Enhancement by Tracking Google Instant Partial Queries in Google Analytics</title>
		<link>http://www.dman.com/google-instant-new-search-enhancement/#comment-18</link>
		<dc:creator>Tracking Google Instant Partial Queries in Google Analytics</dc:creator>
		<pubDate>Thu, 09 Sep 2010 02:55:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=339#comment-18</guid>
		<description>[...] previous post describes Google Instant and the new search results user interface. Now that folks have had several hours to play certain [...]</description>
		<content:encoded><![CDATA[<p>[...] previous post describes Google Instant and the new search results user interface. Now that folks have had several hours to play certain [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Internet Explorer 8 &#124; Arbitrary Sites allowed to tweet by J</title>
		<link>http://www.dman.com/internet-explorer-8-arbitrary-sites-allowed-to-tweet/#comment-12</link>
		<dc:creator>J</dc:creator>
		<pubDate>Sat, 04 Sep 2010 17:27:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=316#comment-12</guid>
		<description>Very interesting article, yay for session-hijacking.</description>
		<content:encoded><![CDATA[<p>Very interesting article, yay for session-hijacking.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Internet Explorer 8 &#124; Arbitrary Sites allowed to tweet by Tweets that mention Internet Explorer 8 &#124; Arbitrary Sites allowed to tweet -- Topsy.com</title>
		<link>http://www.dman.com/internet-explorer-8-arbitrary-sites-allowed-to-tweet/#comment-11</link>
		<dc:creator>Tweets that mention Internet Explorer 8 &#124; Arbitrary Sites allowed to tweet -- Topsy.com</dc:creator>
		<pubDate>Sat, 04 Sep 2010 03:12:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=316#comment-11</guid>
		<description>[...] This post was mentioned on Twitter by Kelly Mistry, Dinesh Mistry. Dinesh Mistry said: New Post: Internet Explorer 8 &#124; Arbitrary Sites allowed to tweet http://bit.ly/9tydR7 [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Kelly Mistry, Dinesh Mistry. Dinesh Mistry said: New Post: Internet Explorer 8 | Arbitrary Sites allowed to tweet <a href="http://bit.ly/9tydR7" rel="nofollow">http://bit.ly/9tydR7</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Crazy Egg  &#8211; A Must Have Analytics Tool by Dinesh</title>
		<link>http://www.dman.com/crazy-egg-is-a-must-have-too/#comment-10</link>
		<dc:creator>Dinesh</dc:creator>
		<pubDate>Fri, 27 Aug 2010 12:57:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=236#comment-10</guid>
		<description>Alex,

Sure. So just to be clear this was for another site not this one. What I learned was that most all of the visitors clicked links on the left hand side of the screen; I initially had 2 navigation areas (left &amp; right). I was able to notice that 80% of clicks occurred on the left side which meant my navigation (and ultimately content/pages) on the right was only seen by a few visitors. Switching the navigation 100% to the left, increased my click thru, which lead to an increase in conversation rate. Visitors were able to actually find the products they were looking for!</description>
		<content:encoded><![CDATA[<p>Alex,</p>
<p>Sure. So just to be clear this was for another site not this one. What I learned was that most all of the visitors clicked links on the left hand side of the screen; I initially had 2 navigation areas (left &amp; right). I was able to notice that 80% of clicks occurred on the left side which meant my navigation (and ultimately content/pages) on the right was only seen by a few visitors. Switching the navigation 100% to the left, increased my click thru, which lead to an increase in conversation rate. Visitors were able to actually find the products they were looking for!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Crazy Egg  &#8211; A Must Have Analytics Tool by Alex</title>
		<link>http://www.dman.com/crazy-egg-is-a-must-have-too/#comment-9</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Thu, 26 Aug 2010 17:20:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=236#comment-9</guid>
		<description>I just started using Crazy Egg as well.  I picked it up from SumoApp, fantastic deal.  The app is awesome.  Easy to use and very visual.

Can you explain what kind of changes and adjustments you made after using Crazy Egg?</description>
		<content:encoded><![CDATA[<p>I just started using Crazy Egg as well.  I picked it up from SumoApp, fantastic deal.  The app is awesome.  Easy to use and very visual.</p>
<p>Can you explain what kind of changes and adjustments you made after using Crazy Egg?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on .htaccess 101: how to password protect a directory by Jay</title>
		<link>http://www.dman.com/htaccess-101-how-to-password-protect-a-directory/#comment-3</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Wed, 23 Jun 2010 01:59:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=120#comment-3</guid>
		<description>Good advice; far too few small-shop webpages have proper access control in place, this is definitely a step (out of many) in the right direction.

I cannot emphasize enough the significance of ensuring that the password file is stored &lt;b&gt;outside&lt;/b&gt; of the web directory.  Even if it only contains hashes, a well-equipped novice hacker could easily use a brute force tool such as &lt;i&gt;John&lt;/i&gt; to enumerate the keys to your web server &quot;castle&quot;.  Additionally, ensure that access to these files is strictly locked down (&lt;i&gt;man chmod&lt;/i&gt; may very well be your best friend), especially if the server resides within a shared environment.</description>
		<content:encoded><![CDATA[<p>Good advice; far too few small-shop webpages have proper access control in place, this is definitely a step (out of many) in the right direction.</p>
<p>I cannot emphasize enough the significance of ensuring that the password file is stored <b>outside</b> of the web directory.  Even if it only contains hashes, a well-equipped novice hacker could easily use a brute force tool such as <i>John</i> to enumerate the keys to your web server &#8220;castle&#8221;.  Additionally, ensure that access to these files is strictly locked down (<i>man chmod</i> may very well be your best friend), especially if the server resides within a shared environment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cross Site Scripting (XSS) Attack by Jay</title>
		<link>http://www.dman.com/cross-site-scripting-xss-attack/#comment-4</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Wed, 23 Jun 2010 01:36:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=131#comment-4</guid>
		<description>I&#039;m guessing the &quot;auto-attack&quot; he&#039;s referring to in said post is actually what&#039;s referred to as &lt;i&gt;Persistent&lt;/i&gt; XSS, in which a user enters a strategically-crafted string (possibly including JS, VBS, ActiveX, etc) into a form that serves as database input via a web application.  That database input may potentially be called by the web frontend as part of a dynamically-produced page (in the context of a SELECT statement made by the application), serving the script to the browser as parsed HTML.  The script may contain a malicious payload, and can potentially compromise the browsing system (e.g. The newest version of the ASPRox botnet propagation tool features a form injector that allows this method to be exploited) This can be prevented by using one (or more) of the below tactics, which are listed in order of feasibility and effectiveness from greater to lesser:
- Validate form input within the web application code - there are libraries to make this reasonably easy.

- Validate database output to avoid dynamically producing a webpage that includes unexpected script content.

- Run a script to audit the contents of the database for unexpected special characters (primarily things like &#039;&lt;&#039;).  This is time and resource consuming, though periodic integrity checks are always a good idea.

As a web user, I highly recommend utilizing an addon such as &lt;i&gt;noscript&lt;/i&gt; as a precautionary measure against Persistent Cross-Site Scripting.</description>
		<content:encoded><![CDATA[<p>I&#8217;m guessing the &#8220;auto-attack&#8221; he&#8217;s referring to in said post is actually what&#8217;s referred to as <i>Persistent</i> XSS, in which a user enters a strategically-crafted string (possibly including JS, VBS, ActiveX, etc) into a form that serves as database input via a web application.  That database input may potentially be called by the web frontend as part of a dynamically-produced page (in the context of a SELECT statement made by the application), serving the script to the browser as parsed HTML.  The script may contain a malicious payload, and can potentially compromise the browsing system (e.g. The newest version of the ASPRox botnet propagation tool features a form injector that allows this method to be exploited) This can be prevented by using one (or more) of the below tactics, which are listed in order of feasibility and effectiveness from greater to lesser:<br />
- Validate form input within the web application code &#8211; there are libraries to make this reasonably easy.</p>
<p>- Validate database output to avoid dynamically producing a webpage that includes unexpected script content.</p>
<p>- Run a script to audit the contents of the database for unexpected special characters (primarily things like &#8216;&lt;&#039;).  This is time and resource consuming, though periodic integrity checks are always a good idea.</p>
<p>As a web user, I highly recommend utilizing an addon such as <i>noscript</i> as a precautionary measure against Persistent Cross-Site Scripting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Wireless Network Security vs Wired Security by Kelly</title>
		<link>http://www.dman.com/wireless-network-security-vs-wired-security/#comment-2</link>
		<dc:creator>Kelly</dc:creator>
		<pubDate>Fri, 01 Jan 2010 02:21:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.dman.com/?p=29#comment-2</guid>
		<description>This was very helpful!</description>
		<content:encoded><![CDATA[<p>This was very helpful!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

