<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Rough Sea Games &#187; Friends</title>
	<atom:link href="http://blog.rough-sea.com/category/friends/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.rough-sea.com</link>
	<description>Indie game development</description>
	<lastBuildDate>Sun, 29 Jan 2012 12:19:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<image>
			<title>Rough Sea Games</title>
			<url>/wp-content/uploads/2008/10/rsg_rss-feed.jpg</url>
			<link>http://blog.rough-sea.com</link>
			<width>144</width>
			<height>95</height>
			<description>Indie game development</description>
		</image>		<item>
		<title>Jaques Roque</title>
		<link>http://blog.rough-sea.com/2011/05/jaques-roque/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=jaques-roque</link>
		<comments>http://blog.rough-sea.com/2011/05/jaques-roque/#comments</comments>
		<pubDate>Wed, 04 May 2011 19:03:24 +0000</pubDate>
		<dc:creator>Joe Cool</dc:creator>
				<category><![CDATA[Friends]]></category>

		<guid isPermaLink="false">http://blog.rough-sea.com/?p=1552</guid>
		<description><![CDATA[<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.rough-sea.com%2F2011%2F05%2Fjaques-roque%2F"> <img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.rough-sea.com%2F2011%2F05%2Fjaques-roque%2F&#38;style=compact&#38;b=2" height="61" width="50" /> </a> <p>Hi there,</p> <p>three friends of mine have lately released a great indie game called <a href="http://www.jaquesroque.com/">Jaques Roque</a>. While the name of this puzzle game is a little hard to spell, the game has a very nice appeal with 100 handmade compelling levels of pure fun.</p> <p>Stockpile your &#8230; </p><p><a class="more-link block-button" href="http://blog.rough-sea.com/2011/05/jaques-roque/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.rough-sea.com%2F2011%2F05%2Fjaques-roque%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.rough-sea.com%2F2011%2F05%2Fjaques-roque%2F&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Hi there,</p>
<p>three friends of mine have lately released a great indie game called <a href="http://www.jaquesroque.com/">Jaques Roque</a>.<br />
While the name of this puzzle game is a little hard to spell, the game has a very nice appeal with 100 handmade compelling levels of pure fun.</p>
<p>Stockpile your treasure while experiencing tombs of the great pharaos and the mystic islands of Atlantis. Try the demo at <a href="http://www.jaquesroque.com/">the official website!</a> (and please buy the game if you like it <img src='http://blog.rough-sea.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  )</p>
<p><object style="height: 390px; width: 640px;"><param name="movie" value="http://www.youtube.com/v/tILiTOKwQKo?version=3" /><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><embed type="application/x-shockwave-flash" width="640" height="390" src="http://www.youtube.com/v/tILiTOKwQKo?version=3" allowfullscreen="true" allowscriptaccess="always"></embed></object></p>
<img src="http://blog.rough-sea.com/?ak_action=api_record_view&id=1552&type=feed" alt="" /><p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.rough-sea.com%2F2011%2F05%2Fjaques-roque%2F&amp;title=Jaques%20Roque" id="wpa2a_2">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.rough-sea.com/2011/05/jaques-roque/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Happy Halloween!</title>
		<link>http://blog.rough-sea.com/2009/10/happy-halloween/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=happy-halloween</link>
		<comments>http://blog.rough-sea.com/2009/10/happy-halloween/#comments</comments>
		<pubDate>Sat, 31 Oct 2009 11:16:00 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Company]]></category>
		<category><![CDATA[Friends]]></category>
		<category><![CDATA[blood]]></category>
		<category><![CDATA[gore]]></category>
		<category><![CDATA[Halloween]]></category>
		<category><![CDATA[horror]]></category>
		<category><![CDATA[horrormovie]]></category>
		<category><![CDATA[Jack O'Lantern]]></category>
		<category><![CDATA[monster]]></category>

		<guid isPermaLink="false">http://blog.rough-sea.com/?p=1143</guid>
		<description><![CDATA[<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.rough-sea.com%2F2009%2F10%2Fhappy-halloween%2F"> <img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.rough-sea.com%2F2009%2F10%2Fhappy-halloween%2F&#38;style=compact&#38;b=2" height="61" width="50" /> </a> <p><img title="Happy Halloween!" src="http://www.chrisnoeth.de/RoughSeaGames/Rough_Sea_Games_HappyHalloween_2009.jpg" border="0" alt="Happy Halloween!" hspace="4" vspace="1" align="center" />The Rough Sea Games team wishes you a Happy Halloween 2009!</p>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.rough-sea.com%2F2009%2F10%2Fhappy-halloween%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.rough-sea.com%2F2009%2F10%2Fhappy-halloween%2F&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><img title="Happy Halloween!" src="http://www.chrisnoeth.de/RoughSeaGames/Rough_Sea_Games_HappyHalloween_2009.jpg" border="0" alt="Happy Halloween!" hspace="4" vspace="1" align="center" />The Rough Sea Games team wishes you a Happy Halloween 2009!</p>
<img src="http://blog.rough-sea.com/?ak_action=api_record_view&id=1143&type=feed" alt="" /><p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.rough-sea.com%2F2009%2F10%2Fhappy-halloween%2F&amp;title=Happy%20Halloween%21" id="wpa2a_4">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.rough-sea.com/2009/10/happy-halloween/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Security &#8211; How to keep HTTP Variables secure</title>
		<link>http://blog.rough-sea.com/2008/09/web-security-how-to-keep-http-variables-secure/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=web-security-how-to-keep-http-variables-secure</link>
		<comments>http://blog.rough-sea.com/2008/09/web-security-how-to-keep-http-variables-secure/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 20:25:12 +0000</pubDate>
		<dc:creator>Dirk</dc:creator>
				<category><![CDATA[Friends]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Web security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[server]]></category>

		<guid isPermaLink="false">http://www.rough-sea.com/wordpress/?p=45</guid>
		<description><![CDATA[<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.rough-sea.com%2F2008%2F09%2Fweb-security-how-to-keep-http-variables-secure%2F"> <img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.rough-sea.com%2F2008%2F09%2Fweb-security-how-to-keep-http-variables-secure%2F&#38;style=compact&#38;b=2" height="61" width="50" /> </a> <p>When I am surfing, I often see websites that have big security leaks in the communication between Server and Client. I know to avoid this, and will describe it here.</p> <p>The most common way for a web server and client to communication is through HTTP Variables. This &#8230; </p><p><a class="more-link block-button" href="http://blog.rough-sea.com/2008/09/web-security-how-to-keep-http-variables-secure/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.rough-sea.com%2F2008%2F09%2Fweb-security-how-to-keep-http-variables-secure%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.rough-sea.com%2F2008%2F09%2Fweb-security-how-to-keep-http-variables-secure%2F&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>When I am surfing, I often see websites that have big security leaks in the communication between Server and Client. I know to avoid this, and will describe it here.</p>
<p>The most common way for a web server and client to communication is through HTTP Variables. This means that values are stored in the URL (GET) or in the header of the request (POST).<br />
I will give an example for a GET parameter: news.php?id=4. The GET variable &#8220;id&#8221; has the value 4. This is not a random example; I deliberately used one with the keyword ID.<br />
Databases usually identify records through a number. If a new data record is added, the number is incremented.<br />
If you change the value of the variable &#8220;id&#8221; to 3 or 2, the website will display the contents of the article with the id 3 or 2. Many websites are built in this way. This is a small security leak and not really dangerous. But think about a message system or a community where somebody can read the messages of another. This would be a really delicate issue. Luckily, it can be avoided in several ways.</p>
<p>Modifying the GET or POST data of an http request can also cause a issue called SQL injection. Hackers can concatenate your variable with an SQL query, executing the query when the request is sent. For example, they could change the GET parameter to &#8220;site.php?id=3; DROP DATABASE mydatabase&#8221;. Boing! Data is gone.</p>
<p>Here are some tips to avoid this problems:</p>
<ol>
<li>Newer database systems support GUIDs (global unique identifiers). These are 128 bit keys, and hence &#8220;more unique&#8221; as an id. They can be generated simply by counting, beginning with 000000-000000-00000&#8230; . But the big size of the data type will increase the size of your database.</li>
<li>Create a user which only has read privileges. Web pages often only need to output data, not to modify it.</li>
<li>Have your code validate http vars before using them. Checking string or enum values will increase the source code size, so use a checksum for this. A lot of server side application languages support some kind of checksum function, like a MD5 hash.  This works as follows: create a keyword, like &#8220;MM3banana13&#8243;.  Now take your variables id, id2 and id3 and concatenate them with the keyword as prefix or suffix (note that the order is important). Use this string to generate the md5. The destination site receives the GET variables &#8220;id&#8221;,&#8221;id2&#8243;,&#8221;id3&#8243; and &#8220;check&#8221; which includes the generated hash. The destination site now also concatenates the id&#8217; s and the keyword in the same way. After that the destination site compares the generated and the received hash. If the data was modified the generated hash will differ. You can improve security by changing the keyword every day. This is a established method for communication with an e-payment service.</li>
<li>Use SSL connections for sensitive data. This will keep your data private and inaccessible to third parties.</li>
</ol>
<p>I think these four things will help to keep a website secure (on the software side).</p>
<p style="text-align: center;"><strong>The basic idea is to expect data that you don&#8217;t expect.</strong></p>
<p style="text-align: center;">
<img src="http://blog.rough-sea.com/?ak_action=api_record_view&id=45&type=feed" alt="" /><p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.rough-sea.com%2F2008%2F09%2Fweb-security-how-to-keep-http-variables-secure%2F&amp;title=Web%20Security%20%26%238211%3B%20How%20to%20keep%20HTTP%20Variables%20secure" id="wpa2a_6">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.rough-sea.com/2008/09/web-security-how-to-keep-http-variables-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dirk Schreiter &#8211; Friend of Rough Sea</title>
		<link>http://blog.rough-sea.com/2008/09/dirk-schreiter/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dirk-schreiter</link>
		<comments>http://blog.rough-sea.com/2008/09/dirk-schreiter/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 20:21:12 +0000</pubDate>
		<dc:creator>Dirk</dc:creator>
				<category><![CDATA[Friends]]></category>
		<category><![CDATA[People]]></category>
		<category><![CDATA[billing]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[introductions]]></category>
		<category><![CDATA[payment]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.rough-sea.com/wordpress/?p=43</guid>
		<description><![CDATA[<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.rough-sea.com%2F2008%2F09%2Fdirk-schreiter%2F"> <img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.rough-sea.com%2F2008%2F09%2Fdirk-schreiter%2F&#38;style=compact&#38;b=2" height="61" width="50" /> </a> <p>Hello! I am a programmer from Augsburg (Germany). I have worked in the software industry since 1998. My knowledge includes several programming language like C#, C++, Visual Basic, and Delphi. I have a lot of experience in PHP, ASP, JS, CSS, HTML and several other web technologies. I &#8230; </p><p><a class="more-link block-button" href="http://blog.rough-sea.com/2008/09/dirk-schreiter/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.rough-sea.com%2F2008%2F09%2Fdirk-schreiter%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.rough-sea.com%2F2008%2F09%2Fdirk-schreiter%2F&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Hello! I am a programmer from Augsburg (Germany). I have worked in the software industry since 1998. My knowledge includes several programming language like C#, C++, Visual Basic, and Delphi. I have a lot of experience in PHP, ASP, JS, CSS, HTML and several other web technologies. I also have experience in creating company websites, e-commerce/e-payment systems, Web security, handling huge data masses and optimizing databases.</p>
<p>Beside my job as C#/database programmer in a financial management company, I am very interested in computer games. Most of my free time was, is and will be invested in playing and creating computer games. I worked for one year in a game studio in Darmstadt, and learned a lot about game programming. I learned how to create well-though-out, consistent, reusable, secure and efficient code. Currently, I am developing a commercial casual game in my free time with a small team. We want to release it this year.</p>
<img src="http://blog.rough-sea.com/?ak_action=api_record_view&id=43&type=feed" alt="" /><p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.rough-sea.com%2F2008%2F09%2Fdirk-schreiter%2F&amp;title=Dirk%20Schreiter%20%26%238211%3B%20Friend%20of%20Rough%20Sea" id="wpa2a_8">Share/Bookmark</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.rough-sea.com/2008/09/dirk-schreiter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

