<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:copyright="http://blogs.law.harvard.edu/tech/rss" xmlns:image="http://purl.org/rss/1.0/modules/image/">
    <channel>
        <title>idunno.org</title>
        <link>http://idunno.org/Default.aspx</link>
        <description>now with extra subtext goodness</description>
        <language>en-GB</language>
        <copyright>Barry Dorrans</copyright>
        <generator>Subtext Version 2.1.0.5</generator>
        <image>
            <title>idunno.org</title>
            <url>http://idunno.org/images/RSS2Image.gif</url>
            <link>http://idunno.org/Default.aspx</link>
            <width>77</width>
            <height>60</height>
        </image>
        <item>
            <title>Vista Squad: OWASP Top 10 Security Vulnerabilities Video</title>
            <category>Usergroups</category>
            <category>Security</category>
            <category>ASP.NET</category>
            <link>http://idunno.org/archive/2009/06/20/vista-squad-owasp-top-10-security-vulnerabilities-video.aspx</link>
            <description>&lt;p&gt;I gave my OSWAP presentation to Vista Squad last Wednesday, where &lt;a href="http://www.irascian.com/"&gt;Ian Smith&lt;/a&gt; kindly (?) videoed it. The other speaker for that evening dropped out, meaning the poor attendees had just me to listen to as I stretched it out to about 100 minutes. The length meant that the video is in two halves.&lt;/p&gt; &lt;object width="640" height="368"&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=5237762&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=00adef&amp;amp;fullscreen=1" /&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=5237762&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=00adef&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="640" height="368" /&gt;&lt;/object&gt;  &lt;p&gt;&lt;a href="http://vimeo.com/5237762"&gt;Part 1&lt;/a&gt; from &lt;a href="http://vimeo.com/vistasquad"&gt;Vista Squad&lt;/a&gt; on &lt;a href="http://vimeo.com"&gt;Vimeo&lt;/a&gt;.&lt;/p&gt; &lt;object width="640" height="368"&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=5253895&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=00adef&amp;amp;fullscreen=1" /&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=5253895&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=00adef&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="640" height="368" /&gt;&lt;/object&gt;  &lt;p&gt;&lt;a href="http://vimeo.com/5253895"&gt;Part 2&lt;/a&gt; from &lt;a href="http://vimeo.com/vistasquad"&gt;Vista Squad&lt;/a&gt; on &lt;a href="http://vimeo.com"&gt;Vimeo&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;The presentation is the same one I gave at &lt;a href="http://idunno.org/archive/2009/04/18/donrsquot-get-stung-ndash-an-introduction-to-the-owasp-top.aspx"&gt;WebDD&lt;/a&gt; so the slides and code are the same.&lt;/p&gt;  &lt;p&gt;The feedback on twitter was amusing;&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td&gt;         &lt;p&gt;&lt;a href="http://search.twitter.com/search?q=%23VistaSquad"&gt;#VistaSquad&lt;/a&gt; enjoyed the talk by @&lt;a href="http://twitter.com/blowdart"&gt;blowdart&lt;/a&gt; made me think (oh ***t) fix that            &lt;br /&gt;&lt;i&gt;Thu, Jun 18 09:25:04 from &lt;a href="http://www.tweetdeck.com/"&gt;TweetDeck&lt;/a&gt; &lt;/i&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:72428e00-4ea6-4c70-8b1a-544d79b1ce6d" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Vista+Squad" rel="tag"&gt;Vista Squad&lt;/a&gt;,&lt;a href="http://technorati.com/tags/OWASP" rel="tag"&gt;OWASP&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Security" rel="tag"&gt;Security&lt;/a&gt;&lt;/div&gt;&lt;img src="http://idunno.org/aggbug/487.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Barry Dorrans</dc:creator>
            <guid>http://idunno.org/archive/2009/06/20/vista-squad-owasp-top-10-security-vulnerabilities-video.aspx</guid>
            <pubDate>Sat, 20 Jun 2009 08:02:14 GMT</pubDate>
            <wfw:comment>http://idunno.org/comments/487.aspx</wfw:comment>
            <comments>http://idunno.org/archive/2009/06/20/vista-squad-owasp-top-10-security-vulnerabilities-video.aspx#feedback</comments>
            <wfw:commentRss>http://idunno.org/comments/commentRss/487.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Fancy a free 3 month trail of TechNet?</title>
            <link>http://idunno.org/archive/2009/06/03/fancy-a-free-3-month-trail-of-technet.aspx</link>
            <description>&lt;p&gt;OK so it’s not MSDN, but &lt;a href="http://technet.microsoft.com/"&gt;TechNet&lt;/a&gt; gives you full versions of MS software, betas, bundled support incidents, a reference library, courses and other gubbins IT pros will love. It costs though. Well, it did. MS are now giving away a 3 month subscription for free to folks in the &lt;a href="https://om2.one.microsoft.com/offer/technet_emea.aspx"&gt;UK&lt;/a&gt;, &lt;a href="https://om2.one.microsoft.com/offer/technet_can.aspx"&gt;Canada&lt;/a&gt; and the &lt;a href="https://om2.one.microsoft.com/offer/technet_na.aspx"&gt;US&lt;/a&gt;. Yes, I’m as shocked that it’s a UK thing as you are. ArsTechnica has &lt;a href="http://arstechnica.com/microsoft/news/2009/06/free-one-year-technet-plus-subscription.ars"&gt;all the details&lt;/a&gt;.&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:cd33eb42-5627-4370-a01a-2a174eeb304a" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/TechNet" rel="tag"&gt;TechNet&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Microsoft" rel="tag"&gt;Microsoft&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Freebie" rel="tag"&gt;Freebie&lt;/a&gt;&lt;/div&gt;&lt;img src="http://idunno.org/aggbug/486.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Barry Dorrans</dc:creator>
            <guid>http://idunno.org/archive/2009/06/03/fancy-a-free-3-month-trail-of-technet.aspx</guid>
            <pubDate>Wed, 03 Jun 2009 07:20:25 GMT</pubDate>
            <wfw:comment>http://idunno.org/comments/486.aspx</wfw:comment>
            <comments>http://idunno.org/archive/2009/06/03/fancy-a-free-3-month-trail-of-technet.aspx#feedback</comments>
            <slash:comments>2</slash:comments>
            <wfw:commentRss>http://idunno.org/comments/commentRss/486.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Fun with Bing DNS</title>
            <link>http://idunno.org/archive/2009/06/01/fun-with-bing-dns.aspx</link>
            <description>&lt;p&gt;It appears bing is live. I’m not that impressed as a &lt;a href="http://www.bing.com/search?q=barry+dorrans&amp;amp;form=QBLH&amp;amp;filt=all"&gt;vanity search&lt;/a&gt; has my blog on the second page, twitter as the first hit, and a bunch of very old content on other sites taking up the rest of the first page.&lt;/p&gt;  &lt;p&gt;However it appears Microsoft are using a wildcard DNS entry for the site – what does this mean? Well &lt;em&gt;anything&lt;/em&gt;.bing.com will resolve, including &lt;a href="http://chandler.bing.com/"&gt;chandler.bing.com&lt;/a&gt; and &lt;a href="http://monica.bing.com"&gt;monica.bing.com&lt;/a&gt; … could that be any more silly? (although interestingly subdomains revert to using Live Search.&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:6f6afca1-e6d5-44a0-ae0b-33af9fa3cdc8" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/bing" rel="tag"&gt;bing&lt;/a&gt;,&lt;a href="http://technorati.com/tags/dns" rel="tag"&gt;dns&lt;/a&gt;&lt;/div&gt;&lt;img src="http://idunno.org/aggbug/485.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Barry Dorrans</dc:creator>
            <guid>http://idunno.org/archive/2009/06/01/fun-with-bing-dns.aspx</guid>
            <pubDate>Mon, 01 Jun 2009 07:47:26 GMT</pubDate>
            <wfw:comment>http://idunno.org/comments/485.aspx</wfw:comment>
            <comments>http://idunno.org/archive/2009/06/01/fun-with-bing-dns.aspx#feedback</comments>
            <wfw:commentRss>http://idunno.org/comments/commentRss/485.aspx</wfw:commentRss>
        </item>
        <item>
            <title>A week&amp;rsquo;s worth of Microsoft desserts.</title>
            <link>http://idunno.org/archive/2009/05/11/a-weekrsquos-worth-of-microsoft-desserts.aspx</link>
            <description>&lt;p&gt;I’m at Microsoft doing a Proof of Concept with Geneva, building a custom STS for a Microsoft customer. I can’t talk about the POC but I can present you with yet another week’s worth of desserts…&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="400"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top"&gt;         &lt;p align="center"&gt;&lt;a href="http://idunno.org/images/idunno_org/WindowsLiveWriter/AweeksworthofMicrosoftdesserts_B239/IMAG0027_2.jpg" rel="lightbox"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="IMAG0027" border="0" alt="IMAG0027" src="http://idunno.org/images/idunno_org/WindowsLiveWriter/AweeksworthofMicrosoftdesserts_B239/IMAG0027_thumb.jpg" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;            &lt;p align="center"&gt;Eton Mess&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top"&gt;         &lt;p align="center"&gt;&lt;a href="http://idunno.org/images/idunno_org/WindowsLiveWriter/AweeksworthofMicrosoftdesserts_B239/IMAG0028_2.jpg" rel="lightbox"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="IMAG0028" border="0" alt="IMAG0028" src="http://idunno.org/images/idunno_org/WindowsLiveWriter/AweeksworthofMicrosoftdesserts_B239/IMAG0028_thumb.jpg" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;          &lt;p align="center"&gt;Brandy snap basket with summer fruits&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top"&gt;         &lt;p align="center"&gt;&lt;a href="http://idunno.org/images/idunno_org/WindowsLiveWriter/AweeksworthofMicrosoftdesserts_B239/IMAG0029_2.jpg" rel="lightbox"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="IMAG0029" border="0" alt="IMAG0029" src="http://idunno.org/images/idunno_org/WindowsLiveWriter/AweeksworthofMicrosoftdesserts_B239/IMAG0029_thumb.jpg" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;          &lt;p align="center"&gt;Banoffee cheesecake&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top"&gt;         &lt;p align="center"&gt;&lt;a href="http://idunno.org/images/idunno_org/WindowsLiveWriter/AweeksworthofMicrosoftdesserts_B239/IMAG0030_2.jpg" rel="lightbox"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="IMAG0030" border="0" alt="IMAG0030" src="http://idunno.org/images/idunno_org/WindowsLiveWriter/AweeksworthofMicrosoftdesserts_B239/IMAG0030_thumb.jpg" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;          &lt;p align="center"&gt;Fruit kebabs with coconut rice pudding&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top"&gt;         &lt;p align="center"&gt;&lt;a href="http://idunno.org/images/idunno_org/WindowsLiveWriter/AweeksworthofMicrosoftdesserts_B239/IMAG0031_2.jpg" rel="lightbox"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="IMAG0031" border="0" alt="IMAG0031" src="http://idunno.org/images/idunno_org/WindowsLiveWriter/AweeksworthofMicrosoftdesserts_B239/IMAG0031_thumb.jpg" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;          &lt;p align="center"&gt;Fresh fruit vacharins&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top"&gt; &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;That’s far more important than discussing CardSpace. Now excuse me while I take my afternoon snooze …&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:09910f13-0307-4e76-96a8-96968be0a42b" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Microsoft" rel="tag"&gt;Microsoft&lt;/a&gt;&lt;/div&gt;&lt;img src="http://idunno.org/aggbug/484.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Barry Dorrans</dc:creator>
            <guid>http://idunno.org/archive/2009/05/11/a-weekrsquos-worth-of-microsoft-desserts.aspx</guid>
            <pubDate>Mon, 11 May 2009 11:51:24 GMT</pubDate>
            <wfw:comment>http://idunno.org/comments/484.aspx</wfw:comment>
            <comments>http://idunno.org/archive/2009/05/11/a-weekrsquos-worth-of-microsoft-desserts.aspx#feedback</comments>
            <slash:comments>4</slash:comments>
            <wfw:commentRss>http://idunno.org/comments/commentRss/484.aspx</wfw:commentRss>
        </item>
        <item>
            <title>The ID Element &amp;ndash; a new C9 show on identity</title>
            <category>CardSpace</category>
            <category>Security</category>
            <link>http://idunno.org/archive/2009/04/20/the-id-element-ndash-a-new-c9-show-on-identity.aspx</link>
            <description>&lt;p&gt;&lt;a href="http://blogs.msdn.com/vbertocci/"&gt;Vittorio&lt;/a&gt; has a new starring role in &lt;strike&gt;a shampoo and conditioner commercial&lt;/strike&gt; Channel9 show, &lt;a href="http://channel9.msdn.com/identity/"&gt;The ID Element&lt;/a&gt;. The first episode has Stuart Kwan, the Federated Identity PM talking about Geneva in all its glory, server, framework and client. &lt;/p&gt;  &lt;p&gt;I know, none of you aside from Dominick and Travis will care, but you should. Honestly. (because it’ll give me another presentation to do at DDDs if nothing else!)&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:15109eca-c86e-493c-bdef-275ed1bfb54e" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Geneva" rel="tag"&gt;Geneva&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Federated+Identity" rel="tag"&gt;Federated Identity&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Big+Hair" rel="tag"&gt;Big Hair&lt;/a&gt;&lt;/div&gt;&lt;img src="http://idunno.org/aggbug/483.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Barry Dorrans</dc:creator>
            <guid>http://idunno.org/archive/2009/04/20/the-id-element-ndash-a-new-c9-show-on-identity.aspx</guid>
            <pubDate>Mon, 20 Apr 2009 11:43:52 GMT</pubDate>
            <wfw:comment>http://idunno.org/comments/483.aspx</wfw:comment>
            <comments>http://idunno.org/archive/2009/04/20/the-id-element-ndash-a-new-c9-show-on-identity.aspx#feedback</comments>
            <slash:comments>1</slash:comments>
            <wfw:commentRss>http://idunno.org/comments/commentRss/483.aspx</wfw:commentRss>
        </item>
        <item>
            <title>LINQ and SQL Injection</title>
            <category>C#</category>
            <category>Security</category>
            <link>http://idunno.org/archive/2009/04/20/linq-and-sql-injection.aspx</link>
            <description>&lt;p&gt;In my &lt;a href="http://idunno.org/archive/2009/04/18/donrsquot-get-stung-ndash-an-introduction-to-the-owasp-top.aspx"&gt;WebDD09 talk&lt;/a&gt; on Saturday I mentioned SQL injection and LINQ. I’ve had a query about what exactly is the problem with LINQ as I was constrained by time and only mentioned it in passing.&lt;/p&gt;  &lt;p&gt;Microsoft &lt;a href="http://msdn.microsoft.com/en-us/library/bb386929.aspx"&gt;asserts&lt;/a&gt; that LINQ stops SQL injection attacks:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;LINQ to SQL avoids such injection by using &lt;a href="http://msdn.microsoft.com/en-us/library/system.data.sqlclient.sqlparameter.aspx"&gt;SqlParameter&lt;/a&gt; in queries. User input is turned into parameter values. This approach prevents malicious commands from being used from customer input.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;This is generally true, however LINQ has a problem method – &lt;a href="http://msdn.microsoft.com/en-us/library/system.data.linq.datacontext.executequery.aspx"&gt;ExecuteQuery&lt;/a&gt;. This methodexecutes queries directly on the server which can lead to injection. Now ExecuteQuery does support parameters:&lt;/p&gt;  &lt;pre class="code"&gt;&lt;span style="color: #2b91af"&gt;IEnumerable&lt;/span&gt;&amp;lt;&lt;span style="color: #2b91af"&gt;Customer&lt;/span&gt;&amp;gt; results = db.ExecuteQuery&amp;lt;&lt;span style="color: #2b91af"&gt;Customer&lt;/span&gt;&amp;gt;(
    &lt;span style="color: #a31515"&gt;"SELECT contactname FROM customers WHERE city = {0}"&lt;/span&gt;,
    &lt;span style="color: #a31515"&gt;"London"&lt;/span&gt;);&lt;/pre&gt;

&lt;p&gt;However if you don't know about SQL parameters already it's going to be all to tempting to build a command string up with concatenation and then bang, there’s SQL Injection. I’ve seen ExecuteQuery recommended for optimisation and performance with scant or no warnings given about parameterisation.&lt;/p&gt;

&lt;p&gt;In summary LINQ avoids SQL Injection - if you use it properly – but the same thing can be said about the ADO.NET classes… and we know people still slip up using those.&lt;/p&gt;

&lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:186937ef-bb30-4f8b-9989-6e9cc6d0e26f" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/LINQ" rel="tag"&gt;LINQ&lt;/a&gt;,&lt;a href="http://technorati.com/tags/SQL+Injection" rel="tag"&gt;SQL Injection&lt;/a&gt;&lt;/div&gt;&lt;img src="http://idunno.org/aggbug/482.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Barry Dorrans</dc:creator>
            <guid>http://idunno.org/archive/2009/04/20/linq-and-sql-injection.aspx</guid>
            <pubDate>Mon, 20 Apr 2009 08:58:20 GMT</pubDate>
            <wfw:comment>http://idunno.org/comments/482.aspx</wfw:comment>
            <comments>http://idunno.org/archive/2009/04/20/linq-and-sql-injection.aspx#feedback</comments>
            <wfw:commentRss>http://idunno.org/comments/commentRss/482.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Don&amp;rsquo;t Get Stung &amp;ndash; An introduction to the OWASP Top Ten</title>
            <category>ASP.NET</category>
            <category>Conferences</category>
            <category>Security</category>
            <link>http://idunno.org/archive/2009/04/18/donrsquot-get-stung-ndash-an-introduction-to-the-owasp-top.aspx</link>
            <description>&lt;p&gt;After DDD Belfast came &lt;a href="http://www.developerdeveloperdeveloper.com/webdd09"&gt;WebDD09&lt;/a&gt; where I was presenting on the &lt;a href="http://www.owasp.org/index.php/OWASP_Top_Ten_Project"&gt;OWASP Top Ten Project&lt;/a&gt; (well I could hardly present at DDD Belfast, I was organising, that seems just a little too egotistical *grin*). You can download the &lt;a href="/presentations/webdd09/Dontgetstung.pptx"&gt;PowerPoint&lt;/a&gt; [905kb] and the &lt;a href="/presentations/webdd09/DontgetstungSamples.zip"&gt;sample code&lt;/a&gt; [432k].&lt;/p&gt;  &lt;p&gt;For the person who asked you can download Fritz Onion’s &lt;a href="http://www.pluralsight.com/community/media/p/51688.aspx"&gt;ViewState Decoder&lt;/a&gt;. For further reading on XSS Russ McRee republishes his &lt;a href="http://holisticinfosec.org/content/view/69/1/"&gt;Anatomy of an XSS attack&lt;/a&gt; article from the ISSA journal and NG Software have two PDFs, &lt;a href="http://www.ngssoftware.com/papers/advanced_sql_injection.pdf"&gt;Advanced SQL Injection&lt;/a&gt; and &lt;a href="http://www.ngssoftware.com/papers/more_advanced_sql_injection.pdf"&gt;More Advanced SQL Injection&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;With the added bonus of discovering coffee beans in my rucksack and a Windows Azure sticker on the back of my car all in all it was a fun day and if you attended I hope you got a lot out of it… and will pre-order my book *cough*&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:2df1fbd5-4797-458f-9172-2dbf3d74ca0d" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/WebDD09" rel="tag"&gt;WebDD09&lt;/a&gt;,&lt;a href="http://technorati.com/tags/WebDD" rel="tag"&gt;WebDD&lt;/a&gt;,&lt;a href="http://technorati.com/tags/OWASP" rel="tag"&gt;OWASP&lt;/a&gt;&lt;/div&gt;&lt;img src="http://idunno.org/aggbug/481.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Barry Dorrans</dc:creator>
            <guid>http://idunno.org/archive/2009/04/18/donrsquot-get-stung-ndash-an-introduction-to-the-owasp-top.aspx</guid>
            <pubDate>Sat, 18 Apr 2009 17:45:50 GMT</pubDate>
            <wfw:comment>http://idunno.org/comments/481.aspx</wfw:comment>
            <comments>http://idunno.org/archive/2009/04/18/donrsquot-get-stung-ndash-an-introduction-to-the-owasp-top.aspx#feedback</comments>
            <slash:comments>4</slash:comments>
            <wfw:commentRss>http://idunno.org/comments/commentRss/481.aspx</wfw:commentRss>
        </item>
        <item>
            <title>Beginning ASP.NET Security is available for pre-order</title>
            <category>Security</category>
            <category>Books</category>
            <link>http://idunno.org/archive/2009/04/14/beginning-asp.net-security-is-available-for-pre-order.aspx</link>
            <description>&lt;p&gt;Alex Mackey tweeted yesterday that his book was available for pre-order on Amazon so vanity got the best of me – so I checked and mine is available too. It grows ever more real and scary, although not as scary as the cover (which is now on its third iteration but I still can't convince them to use Oliver's &lt;a href="http://www.sturmnet.org/blog/2009/03/10/improvements-to-barry-s-book-cover"&gt;alternative version&lt;/a&gt;) …&lt;/p&gt;  &lt;p&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Beginning ASP.NET Security" border="0" alt="Beginning ASP.NET Security" src="http://idunno.org/images/idunno_org/WindowsLiveWriter/Beginn.NETSecurityisavailableforpreorder_A823/cover_3.png" width="190" height="240" /&gt;     &lt;br /&gt;&lt;a href="http://www.amazon.co.uk/gp/product/0470743654?ie=UTF8&amp;amp;tag=httpidunnorg-21&amp;amp;linkCode=as2&amp;amp;camp=1634&amp;amp;creative=6738&amp;amp;creativeASIN=0470743654"&gt;Pre-order from Amazon UK&lt;/a&gt;&lt;img style="border-bottom-style: none !important; border-right-style: none !important; margin: 0px; border-top-style: none !important; border-left-style: none !important" border="0" alt="" src="http://www.assoc-amazon.co.uk/e/ir?t=httpidunnorg-21&amp;amp;l=as2&amp;amp;o=2&amp;amp;a=0470743654" width="1" height="1" /&gt;     &lt;br /&gt;&lt;a href="http://www.amazon.com/gp/product/0470743654?ie=UTF8&amp;amp;tag=barrdorr-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0470743654"&gt;Pre-order from Amazon US&lt;/a&gt;     &lt;br /&gt;    &lt;br /&gt;&lt;/p&gt; &lt;img style="border-bottom-style: none !important; border-right-style: none !important; margin: 0px; border-top-style: none !important; border-left-style: none !important" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:18f9e59a-6825-474b-9159-0db73cbd6518" class="wlWriterEditableSmartContent" border="0" alt="" src="http://www.assoc-amazon.com/e/ir?t=barrdorr-&amp;lt;br /&amp;gt;&amp;lt;div style=" 0px?="0px?" padding-top:="padding-top:" none;="none;" float:="float:" inline;="inline;" display:="display:" 0px;="0px;" padding-right:="padding-right:" padding-left:="padding-left:" margin:="margin:" padding-bottom:="padding-bottom:" /&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/ASP.NET" rel="tag"&gt;ASP.NET&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Wrox" rel="tag"&gt;Wrox&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Vanity" rel="tag"&gt;Vanity&lt;/a&gt;&lt;img src="http://idunno.org/aggbug/480.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Barry Dorrans</dc:creator>
            <guid>http://idunno.org/archive/2009/04/14/beginning-asp.net-security-is-available-for-pre-order.aspx</guid>
            <pubDate>Tue, 14 Apr 2009 11:09:32 GMT</pubDate>
            <wfw:comment>http://idunno.org/comments/480.aspx</wfw:comment>
            <comments>http://idunno.org/archive/2009/04/14/beginning-asp.net-security-is-available-for-pre-order.aspx#feedback</comments>
            <slash:comments>4</slash:comments>
            <wfw:commentRss>http://idunno.org/comments/commentRss/480.aspx</wfw:commentRss>
        </item>
        <item>
            <title>I know! Lets use a proven flawed network for a national identity card system</title>
            <category>Security</category>
            <link>http://idunno.org/archive/2009/04/07/i-know-lets-use-a-proven-flawed-network-for-a.aspx</link>
            <description>&lt;p&gt;It’s been &lt;a href="http://news.bbc.co.uk/1/hi/uk/7986618.stm"&gt;reported&lt;/a&gt; that Labour would like the proposed UK ID cards to plug into the Chip and Pin network. This is a commercial network that has security that has never been verified, and a bunch of folks at Cambridge reverse engineered and showed &lt;a href="http://www.cl.cam.ac.uk/~sjm217/papers/fc09optimised.pdf"&gt;massive cryptographic flaws&lt;/a&gt; in it, such as reusing authentication tokens, overloading data semantics, and failing to ensure freshness of responses.&lt;/p&gt;  &lt;p&gt;This is the same network that a &lt;a href="http://cryptome.org/UK-Chip-PIN-07.pdf"&gt;leaked report&lt;/a&gt; showed had higher instances of fraud associated with it that were expected. This was a system designed, not for security, but for moving the consequences of fraud onto the retailer, a system where with a paperclip and some weak card readers caused &lt;a href="http://news.bbc.co.uk/1/hi/england/4980190.stm"&gt;card cloning&lt;/a&gt;  and was &lt;a href=" http://www.silicon.com/research/specialreports/idmanagement/0,3800011361,39158743,00.htm"&gt;over £1m in fraudulent transactions&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;So anyone with a suitable weak reader would have the ability to copy and reproduce ID cards. This is supposed to protect us? A network which cannot be checked because it belongs to a corporate entity?&lt;/p&gt;  &lt;p&gt;There are ways to do it – the Estonia government has an identity card which uses proven, open standards to validate identity to government and banks. The Estonian identity card holds two X509 certificates, one for identity and one for signing documents and can be used for encryption when communicating with government or any other web site that cares to opt-in to the scheme, and there’s no need for specialised code, it’s just X509 after all. In addition the UK Government Gateway optionally uses X509 for company identification, so not much extra code needed there.&lt;/p&gt;  &lt;p&gt;Of course I have my doubts about the purpose of the UK identity card anyway, it points more to monitoring and control through easily joined databases than anything to do with protecting citizens, but even so, if it’s going to be forced on us then lets do it right ok?&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:3a6cedba-f4f4-4fc6-a2e6-cfb1fed2d04c" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Identity+Cards" rel="tag"&gt;Identity Cards&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Chip+and+Pin" rel="tag"&gt;Chip and Pin&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Fraud" rel="tag"&gt;Fraud&lt;/a&gt;,&lt;a href="http://technorati.com/tags/UK+egovernment" rel="tag"&gt;UK egovernment&lt;/a&gt;&lt;/div&gt;&lt;img src="http://idunno.org/aggbug/479.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Barry Dorrans</dc:creator>
            <guid>http://idunno.org/archive/2009/04/07/i-know-lets-use-a-proven-flawed-network-for-a.aspx</guid>
            <pubDate>Tue, 07 Apr 2009 07:26:44 GMT</pubDate>
            <wfw:comment>http://idunno.org/comments/479.aspx</wfw:comment>
            <comments>http://idunno.org/archive/2009/04/07/i-know-lets-use-a-proven-flawed-network-for-a.aspx#feedback</comments>
            <wfw:commentRss>http://idunno.org/comments/commentRss/479.aspx</wfw:commentRss>
        </item>
        <item>
            <title>DDD Belfast is over. And relax&amp;hellip;</title>
            <category>Conferences</category>
            <link>http://idunno.org/archive/2009/04/05/ddd-belfast-is-over.-and-relaxhellip.aspx</link>
            <description>&lt;p&gt;Well that was fun :) 150 people, 15 speakers, 3 organisers, 2 Microsoft folks and swag from Wrox, TechSmith, DevExpress, RedGate, Jetbrains and a special offer from Innerworkings for &lt;a href="https://www.innerworkings.com/promotions/5b5be94d-48ec-42cf-a926-9f45c127052f/ddd-mvc-promotion"&gt;free ASP.NET MVC training&lt;/a&gt;. And then there was the Wrox lollipops…&lt;/p&gt;  &lt;p&gt;I have my pictures up on &lt;a href="http://www.flickr.com/photos/blowdart/sets/72157616245440689/"&gt;flickr&lt;/a&gt;; here is just a small sample.&lt;/p&gt;  &lt;p&gt;&lt;a title="DSCF1502" href="http://www.flickr.com/photos/77049614@N00/3410791781/"&gt;&lt;img border="0" alt="DSCF1502" src="http://farm4.static.flickr.com/3638/3410791781_7411dd7082_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1504" href="http://www.flickr.com/photos/77049614@N00/3410792263/"&gt;&lt;img border="0" alt="DSCF1504" src="http://farm4.static.flickr.com/3339/3410792263_dfbda1279e_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1505" href="http://www.flickr.com/photos/77049614@N00/3411602718/"&gt;&lt;img border="0" alt="DSCF1505" src="http://farm4.static.flickr.com/3390/3411602718_35dba0ab88_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1507" href="http://www.flickr.com/photos/77049614@N00/3410793133/"&gt;&lt;img border="0" alt="DSCF1507" src="http://farm4.static.flickr.com/3621/3410793133_bbac285f70_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1508" href="http://www.flickr.com/photos/77049614@N00/3411603444/"&gt;&lt;img border="0" alt="DSCF1508" src="http://farm4.static.flickr.com/3636/3411603444_caf8310921_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1513" href="http://www.flickr.com/photos/77049614@N00/3410794317/"&gt;&lt;img border="0" alt="DSCF1513" src="http://farm4.static.flickr.com/3332/3410794317_7bc0d4651a_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1515" href="http://www.flickr.com/photos/77049614@N00/3411604958/"&gt;&lt;img border="0" alt="DSCF1515" src="http://farm4.static.flickr.com/3547/3411604958_f1ce155559_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1517" href="http://www.flickr.com/photos/77049614@N00/3411605538/"&gt;&lt;img border="0" alt="DSCF1517" src="http://farm4.static.flickr.com/3626/3411605538_65143467e1_t.jpg" /&gt;&lt;/a&gt;&lt;a title="Paul is a little teapot" href="http://www.flickr.com/photos/77049614@N00/3410796357/"&gt;&lt;img border="0" alt="Paul is a little teapot" src="http://farm4.static.flickr.com/3341/3410796357_4979cafd96_t.jpg" /&gt;&lt;/a&gt;&lt;a title="Attendees look happy with TechSmith CDs" href="http://www.flickr.com/photos/77049614@N00/3411606948/"&gt;&lt;img border="0" alt="Attendees look happy with TechSmith CDs" src="http://farm4.static.flickr.com/3362/3411606948_9a4882ec9f_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1526" href="http://www.flickr.com/photos/77049614@N00/3410796939/"&gt;&lt;img border="0" alt="DSCF1526" src="http://farm4.static.flickr.com/3387/3410796939_b3bbe6b304_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1531" href="http://www.flickr.com/photos/77049614@N00/3411608156/"&gt;&lt;img border="0" alt="DSCF1531" src="http://farm4.static.flickr.com/3644/3411608156_df11519a02_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1534" href="http://www.flickr.com/photos/77049614@N00/3410798675/"&gt;&lt;img border="0" alt="DSCF1534" src="http://farm4.static.flickr.com/3416/3410798675_8e08dfaf6a_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1536" href="http://www.flickr.com/photos/77049614@N00/3410799269/"&gt;&lt;img border="0" alt="DSCF1536" src="http://farm4.static.flickr.com/3313/3410799269_f26973c503_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1545" href="http://www.flickr.com/photos/77049614@N00/3410800909/"&gt;&lt;img border="0" alt="DSCF1545" src="http://farm4.static.flickr.com/3545/3410800909_fcc1488b4d_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1549" href="http://www.flickr.com/photos/77049614@N00/3410801655/"&gt;&lt;img border="0" alt="DSCF1549" src="http://farm4.static.flickr.com/3082/3410801655_a4823ac1bd_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1551" href="http://www.flickr.com/photos/77049614@N00/3411612542/"&gt;&lt;img border="0" alt="DSCF1551" src="http://farm4.static.flickr.com/3553/3411612542_db20a577a1_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1552" href="http://www.flickr.com/photos/77049614@N00/3411612782/"&gt;&lt;img border="0" alt="DSCF1552" src="http://farm4.static.flickr.com/3312/3411612782_6ca81cc08d_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1553" href="http://www.flickr.com/photos/77049614@N00/3411613114/"&gt;&lt;img border="0" alt="DSCF1553" src="http://farm4.static.flickr.com/3553/3411613114_0664f111ca_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1554" href="http://www.flickr.com/photos/77049614@N00/3410802973/"&gt;&lt;img border="0" alt="DSCF1554" src="http://farm4.static.flickr.com/3361/3410802973_80620f067b_t.jpg" /&gt;&lt;/a&gt;&lt;a title="Udi demonstrates the latest dance moves." href="http://www.flickr.com/photos/77049614@N00/3411614658/"&gt;&lt;img border="0" alt="Udi demonstrates the latest dance moves." src="http://farm4.static.flickr.com/3541/3411614658_c1b7059ddd_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1573" href="http://www.flickr.com/photos/77049614@N00/3411616622/"&gt;&lt;img border="0" alt="DSCF1573" src="http://farm4.static.flickr.com/3644/3411616622_c0af05bd49_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1576" href="http://www.flickr.com/photos/77049614@N00/3410875457/"&gt;&lt;img border="0" alt="DSCF1576" src="http://farm4.static.flickr.com/3345/3410875457_4abe22ab13_t.jpg" /&gt;&lt;/a&gt;&lt;a title="Dave Sussman wants these curtains for his boudoir." href="http://www.flickr.com/photos/77049614@N00/3411686902/"&gt;&lt;img border="0" alt="Dave Sussman wants these curtains for his boudoir." src="http://farm4.static.flickr.com/3319/3411686902_239b597581_t.jpg" /&gt;&lt;/a&gt;&lt;a title="Colin is awake. For a change." href="http://www.flickr.com/photos/77049614@N00/3410876793/"&gt;&lt;img border="0" alt="Colin is awake. For a change." src="http://farm4.static.flickr.com/3072/3410876793_78f9bbf299_t.jpg" /&gt;&lt;/a&gt;&lt;a title="Come to DDD, get Wrox lollipops" href="http://www.flickr.com/photos/77049614@N00/3410877137/"&gt;&lt;img border="0" alt="Come to DDD, get Wrox lollipops" src="http://farm4.static.flickr.com/3407/3410877137_bafbc099d5_t.jpg" /&gt;&lt;/a&gt;&lt;a title="Chris Canal starts his presentation" href="http://www.flickr.com/photos/77049614@N00/3410877347/"&gt;&lt;img border="0" alt="Chris Canal starts his presentation" src="http://farm4.static.flickr.com/3415/3410877347_c456e1eed0_t.jpg" /&gt;&lt;/a&gt;&lt;a title="Alex exhorts his audience to take the ring to Mordor" href="http://www.flickr.com/photos/77049614@N00/3411689158/"&gt;&lt;img border="0" alt="Alex exhorts his audience to take the ring to Mordor" src="http://farm4.static.flickr.com/3390/3411689158_019b5e9819_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1597" href="http://www.flickr.com/photos/77049614@N00/3410879129/"&gt;&lt;img border="0" alt="DSCF1597" src="http://farm4.static.flickr.com/3639/3410879129_ca2e3164a9_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1602" href="http://www.flickr.com/photos/77049614@N00/3410880303/"&gt;&lt;img border="0" alt="DSCF1602" src="http://farm4.static.flickr.com/3548/3410880303_0c82a1f944_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1604" href="http://www.flickr.com/photos/77049614@N00/3411211409/"&gt;&lt;img border="0" alt="DSCF1604" src="http://farm4.static.flickr.com/3607/3411211409_c298c5bcbe_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1605" href="http://www.flickr.com/photos/77049614@N00/3411211875/"&gt;&lt;img border="0" alt="DSCF1605" src="http://farm4.static.flickr.com/3552/3411211875_a2423feebe_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1607" href="http://www.flickr.com/photos/77049614@N00/3411212643/"&gt;&lt;img border="0" alt="DSCF1607" src="http://farm4.static.flickr.com/3329/3411212643_7de4e4484e_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1611" href="http://www.flickr.com/photos/77049614@N00/3412022526/"&gt;&lt;img border="0" alt="DSCF1611" src="http://farm4.static.flickr.com/3367/3412022526_efbf315821_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1625" href="http://www.flickr.com/photos/77049614@N00/3411221395/"&gt;&lt;img border="0" alt="DSCF1625" src="http://farm4.static.flickr.com/3319/3411221395_ecddd5903a_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1630" href="http://www.flickr.com/photos/77049614@N00/3411222403/"&gt;&lt;img border="0" alt="DSCF1630" src="http://farm4.static.flickr.com/3407/3411222403_b25d07372a_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1632" href="http://www.flickr.com/photos/77049614@N00/3411223479/"&gt;&lt;img border="0" alt="DSCF1632" src="http://farm4.static.flickr.com/3352/3411223479_2ac06b23ef_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1634" href="http://www.flickr.com/photos/77049614@N00/3411224341/"&gt;&lt;img border="0" alt="DSCF1634" src="http://farm4.static.flickr.com/3556/3411224341_dfa10bdf71_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1636" href="http://www.flickr.com/photos/77049614@N00/3411225155/"&gt;&lt;img border="0" alt="DSCF1636" src="http://farm4.static.flickr.com/3549/3411225155_d7a9d55a47_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1641" href="http://www.flickr.com/photos/77049614@N00/3411226597/"&gt;&lt;img border="0" alt="DSCF1641" src="http://farm4.static.flickr.com/3572/3411226597_0a0f10a78a_t.jpg" /&gt;&lt;/a&gt;&lt;a title="DSCF1648" href="http://www.flickr.com/photos/77049614@N00/3411230585/"&gt;&lt;img border="0" alt="DSCF1648" src="http://farm4.static.flickr.com/3645/3411230585_b2576b1e1f_t.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Obviously I’d like to thank all our speakers, our sponsors, the venue folks and of course Microsoft Ireland.&lt;/p&gt;  &lt;p&gt;And I’d like to thank our attendees, I hope you all got something out of it. You’ll be receiving details of the feedback web page early next week – please leave feedback for us and the speakers, it’s the only way we know how we did!&lt;/p&gt;  &lt;p&gt;If you were one of the 60+ that dropped out – we’d love to know why too – leave a comment, or email me through my contact page here.&lt;/p&gt;  &lt;p&gt;(We won’t mention the gossip – who wasn’t allowed into a pub because of his trainers, who was turned away from a nightclub for being too drunk on Saturday evening, who refused to come down for breakfast Sunday morning because he couldn’t face food … no, mentioning that would be wrong.)&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:097d57e5-bd6b-4c28-a0b4-bd2ea8e33b0f" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/DDD" rel="tag"&gt;DDD&lt;/a&gt;,&lt;a href="http://technorati.com/tags/DDD+Belfast" rel="tag"&gt;DDD Belfast&lt;/a&gt;,&lt;a href="http://technorati.com/tags/DDDBelfast" rel="tag"&gt;DDDBelfast&lt;/a&gt;,&lt;a href="http://technorati.com/tags/dddBFST" rel="tag"&gt;dddBFST&lt;/a&gt;&lt;/div&gt;&lt;img src="http://idunno.org/aggbug/478.aspx" width="1" height="1" /&gt;</description>
            <dc:creator>Barry Dorrans</dc:creator>
            <guid>http://idunno.org/archive/2009/04/05/ddd-belfast-is-over.-and-relaxhellip.aspx</guid>
            <pubDate>Sun, 05 Apr 2009 20:13:01 GMT</pubDate>
            <wfw:comment>http://idunno.org/comments/478.aspx</wfw:comment>
            <comments>http://idunno.org/archive/2009/04/05/ddd-belfast-is-over.-and-relaxhellip.aspx#feedback</comments>
            <slash:comments>3</slash:comments>
            <wfw:commentRss>http://idunno.org/comments/commentRss/478.aspx</wfw:commentRss>
        </item>
    </channel>
</rss>