<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Language Model Generated Injection Attacks: Cool/Disturbing LingPipe Application</title>
	<atom:link href="http://lingpipe-blog.com/2010/03/09/language-model-generated-injection-attacks-cooldisturbing-lingpipe-application/feed/" rel="self" type="application/rss+xml" />
	<link>http://lingpipe-blog.com/2010/03/09/language-model-generated-injection-attacks-cooldisturbing-lingpipe-application/</link>
	<description>Natural Language Processing and Text Analytics</description>
	<lastBuildDate>Wed, 08 Feb 2012 17:47:08 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Breck</title>
		<link>http://lingpipe-blog.com/2010/03/09/language-model-generated-injection-attacks-cooldisturbing-lingpipe-application/#comment-6524</link>
		<dc:creator><![CDATA[Breck]]></dc:creator>
		<pubDate>Wed, 10 Mar 2010 21:03:31 +0000</pubDate>
		<guid isPermaLink="false">http://lingpipe-blog.com/?p=3820#comment-6524</guid>
		<description><![CDATA[The key to the high quality of the output is that there is a bunch of conditional jump n-bytes commands in ASCII (p through z). Josh said in an email that he would not have even tried the approach without that flexibility. About 40% of the English attack text is being executed.

Josh also said that the filters for the unsophisticated version do not exist currently so there is no reason to go to the English generation step. That is depressing, At least I know if a firewall vendor comes calling about filtering for the simpler attack that more will need to be done.

Cool paper in any case.]]></description>
		<content:encoded><![CDATA[<p>The key to the high quality of the output is that there is a bunch of conditional jump n-bytes commands in ASCII (p through z). Josh said in an email that he would not have even tried the approach without that flexibility. About 40% of the English attack text is being executed.</p>
<p>Josh also said that the filters for the unsophisticated version do not exist currently so there is no reason to go to the English generation step. That is depressing, At least I know if a firewall vendor comes calling about filtering for the simpler attack that more will need to be done.</p>
<p>Cool paper in any case.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Lewis</title>
		<link>http://lingpipe-blog.com/2010/03/09/language-model-generated-injection-attacks-cooldisturbing-lingpipe-application/#comment-6519</link>
		<dc:creator><![CDATA[Dave Lewis]]></dc:creator>
		<pubDate>Tue, 09 Mar 2010 21:58:01 +0000</pubDate>
		<guid isPermaLink="false">http://lingpipe-blog.com/?p=3820#comment-6519</guid>
		<description><![CDATA[I too wouldn&#039;t have guessed that it was possible to make code look this English-like.   The authors suggest that considering syntactic or semantic information might help, but I&#039;m inclined to think that any advances in that direction would be more useful for generating attacks than preventing them.   They do finish by saying that the real need is to avoid externally controlled inputs from being executed in the first place.  Indeed!]]></description>
		<content:encoded><![CDATA[<p>I too wouldn&#8217;t have guessed that it was possible to make code look this English-like.   The authors suggest that considering syntactic or semantic information might help, but I&#8217;m inclined to think that any advances in that direction would be more useful for generating attacks than preventing them.   They do finish by saying that the real need is to avoid externally controlled inputs from being executed in the first place.  Indeed!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

