<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-6836909.post6995562014381255284..comments</id><updated>2011-08-22T17:27:12.170+05:30</updated><category term='ruby'/><category term='pics'/><category term='tech'/><category term='weblog'/><category term='bad'/><category term='web'/><category term='gyaan'/><category term='good'/><category term='etl'/><category term='random'/><category term='mumbai'/><category term='thailand'/><category term='marketing experiments'/><category term='cleartrip'/><category term='spotted'/><category term='every trip has a purpose'/><category term='music'/><category term='rainbow'/><category term='opinions'/><category term='hadoop'/><category term='dlvr.all'/><category term='my purpose'/><category term='cool quotient'/><category term='cynical'/><category term='clickstream'/><category term='movie'/><category term='bashing'/><category term='zapak'/><category term='userscript'/><category term='dlvr.fb'/><category term='android'/><category term='ab testing'/><category term='online marketing'/><category term='travel'/><category term='dlvr.tw'/><category term='airdeccan'/><category term='software'/><category term='food'/><category term='play'/><category term='fm'/><category term='simplymarry'/><category term='hive'/><category term='email marketing'/><category term='arbit'/><category term='review'/><category term='greasemonkey'/><category term='mypurpose'/><title type='text'>Comments on Digital Daaroo - by Saurabh Nanda: CCAvenue hack: What can developers &amp; businesses le...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.saurabhnanda.com/feeds/6995562014381255284/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default'/><link rel='alternate' type='text/html' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html'/><author><name>Saurabh Nanda</name><uri>http://www.blogger.com/profile/00867453089820169282</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://photos1.blogger.com/img/158/980/640/myself-bw.1.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>7</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6836909.post-1676366308540083036</id><published>2011-08-22T17:27:12.170+05:30</published><updated>2011-08-22T17:27:12.170+05:30</updated><title type='text'>sa they say that no hack were done bt this is to i...</title><content type='html'>sa they say that no hack were done bt this is to inform you tat paytm.com&lt;br /&gt;&lt;br /&gt;latest hack yesterday</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/1676366308540083036'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/1676366308540083036'/><link rel='alternate' type='text/html' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html?showComment=1314014232170#c1676366308540083036' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html' ref='tag:blogger.com,1999:blog-6836909.post-6995562014381255284' source='http://www.blogger.com/feeds/6836909/posts/default/6995562014381255284' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-15004823'/></entry><entry><id>tag:blogger.com,1999:blog-6836909.post-2163865971628866095</id><published>2011-08-22T17:24:17.848+05:30</published><updated>2011-08-22T17:24:17.848+05:30</updated><title type='text'>ccaevenue has low security

anyone should tell the...</title><content type='html'>ccaevenue has low security&lt;br /&gt;&lt;br /&gt;anyone should tell them to upgrade&lt;br /&gt;&lt;br /&gt;now hackers are very sharp ,like me and childrens like age of 17 hacking it</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/2163865971628866095'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/2163865971628866095'/><link rel='alternate' type='text/html' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html?showComment=1314014057848#c2163865971628866095' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html' ref='tag:blogger.com,1999:blog-6836909.post-6995562014381255284' source='http://www.blogger.com/feeds/6836909/posts/default/6995562014381255284' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-15004823'/></entry><entry><id>tag:blogger.com,1999:blog-6836909.post-6897613608077896011</id><published>2011-08-22T17:22:14.371+05:30</published><updated>2011-08-22T17:22:14.371+05:30</updated><title type='text'>ccavenue is a payment gateway website tat gateways...</title><content type='html'>ccavenue is a payment gateway website tat gateways the bank and the website&amp;quot;S&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;it got hacked many times</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/6897613608077896011'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/6897613608077896011'/><link rel='alternate' type='text/html' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html?showComment=1314013934371#c6897613608077896011' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html' ref='tag:blogger.com,1999:blog-6836909.post-6995562014381255284' source='http://www.blogger.com/feeds/6836909/posts/default/6995562014381255284' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-15004823'/></entry><entry><id>tag:blogger.com,1999:blog-6836909.post-5033387467722902129</id><published>2011-06-10T17:49:35.160+05:30</published><updated>2011-06-10T17:49:35.160+05:30</updated><title type='text'>I&amp;#39;m glad that my gyaan helped. Where have you ...</title><content type='html'>I&amp;#39;m glad that my gyaan helped. Where have you used bcrypt, Srikanth?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/5033387467722902129'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/5033387467722902129'/><link rel='alternate' type='text/html' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html?showComment=1307708375160#c5033387467722902129' title=''/><author><name>Saurabh Nanda</name><uri>http://www.blogger.com/profile/00867453089820169282</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='18331976337516182080'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://photos1.blogger.com/img/158/980/640/myself-bw.1.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html' ref='tag:blogger.com,1999:blog-6836909.post-6995562014381255284' source='http://www.blogger.com/feeds/6836909/posts/default/6995562014381255284' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1460659616'/></entry><entry><id>tag:blogger.com,1999:blog-6836909.post-3321090340361987909</id><published>2011-06-10T17:41:20.727+05:30</published><updated>2011-06-10T17:41:20.727+05:30</updated><title type='text'>Thanks for the bcrypt thing Saurabh.</title><content type='html'>Thanks for the bcrypt thing Saurabh.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/3321090340361987909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/3321090340361987909'/><link rel='alternate' type='text/html' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html?showComment=1307707880727#c3321090340361987909' title=''/><author><name>srikanth</name><uri>http://www.blogger.com/profile/15900742782134100536</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://1.bp.blogspot.com/_-JCXTZFI9Eo/TIsujvfp7UI/AAAAAAAABxs/djeXldVRE4Y/S220/IMG_3549new.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html' ref='tag:blogger.com,1999:blog-6836909.post-6995562014381255284' source='http://www.blogger.com/feeds/6836909/posts/default/6995562014381255284' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-904773587'/></entry><entry><id>tag:blogger.com,1999:blog-6836909.post-3269766550207808647</id><published>2011-05-08T10:46:37.921+05:30</published><updated>2011-05-08T10:46:37.921+05:30</updated><title type='text'>Hmm, probably you&amp;#39;re right about the upgrade d...</title><content type='html'>Hmm, probably you&amp;#39;re right about the upgrade date, but it could be that the hacker got lazy and looked-up the server ID string on netcraft on 4th may just before publishing the hack. Possible?&lt;br /&gt;&lt;br /&gt;And yeah, hiding server identification is security 101. Not sure whether that&amp;#39;s part of PCI-DSS or not.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/3269766550207808647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/3269766550207808647'/><link rel='alternate' type='text/html' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html?showComment=1304831797921#c3269766550207808647' title=''/><author><name>Saurabh Nanda</name><uri>http://www.blogger.com/profile/00867453089820169282</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='18331976337516182080'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://photos1.blogger.com/img/158/980/640/myself-bw.1.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html' ref='tag:blogger.com,1999:blog-6836909.post-6995562014381255284' source='http://www.blogger.com/feeds/6836909/posts/default/6995562014381255284' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1460659616'/></entry><entry><id>tag:blogger.com,1999:blog-6836909.post-3574371730241423588</id><published>2011-05-08T08:08:45.979+05:30</published><updated>2011-05-08T08:08:45.979+05:30</updated><title type='text'>Good point about MD5 and SHA.

The CCAvenue respon...</title><content type='html'>Good point about MD5 and SHA.&lt;br /&gt;&lt;br /&gt;The CCAvenue response is preciously what one would have expected. We are like our politicians - always blaming the opposition party for the &amp;quot;mischief&amp;quot;. However I don&amp;#39;t think the interpretation of Netcraft report is correct. Since the last 2 pings are at a difference of 1 year, upgrade could have happened anytime in between. Also have a look at this: http://toolbar.netcraft.com/site_report?url=http://ccavenue.com which shows that Apache was indeed upgraded on another server.&lt;br /&gt;&lt;br /&gt;Also isn&amp;#39;t it also suggested as part of basic hardening of site that you turn off detailed server headers giving the version of Apache and other installed modules? :)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/3574371730241423588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6836909/6995562014381255284/comments/default/3574371730241423588'/><link rel='alternate' type='text/html' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html?showComment=1304822325979#c3574371730241423588' title=''/><author><name>abhaya</name><uri>http://www.blogger.com/profile/02584059046263945740</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://3.bp.blogspot.com/_XDg8KAwnHt4/SOdorfucBoI/AAAAAAAAB9E/qJAAgG8czbc/S220/IMG_0337-1.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.saurabhnanda.com/2011/05/ccavenue-hack-what-can-developers.html' ref='tag:blogger.com,1999:blog-6836909.post-6995562014381255284' source='http://www.blogger.com/feeds/6836909/posts/default/6995562014381255284' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-861112212'/></entry></feed>
