<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url><loc>https://blog.javan.de/</loc></url>
  <url><loc>https://blog.javan.de/archive/</loc></url>
  <url><loc>https://blog.javan.de/page/2/</loc></url>
  <url><loc>https://blog.javan.de/page/3/</loc></url>
  <url><loc>https://blog.javan.de/page/4/</loc></url>
  <url><loc>https://blog.javan.de/page/5/</loc></url>
  <url><loc>https://blog.javan.de/page/6/</loc></url>
  <url><loc>https://blog.javan.de/page/7/</loc></url>
  <url><loc>https://blog.javan.de/the-future-security-engineer/</loc></url>
  <url><loc>https://blog.javan.de/reality-shift-in-vulnerability-management/</loc></url>
  <url><loc>https://blog.javan.de/inside-my-black-hat-usa-trainings-full-agenda-hands-on-labs/</loc></url>
  <url><loc>https://blog.javan.de/announcing-my-new-courses-for-black-hat-usa-2026/</loc></url>
  <url><loc>https://blog.javan.de/2025-a-year-of-growth-gratitude-and-perspective/</loc></url>
  <url><loc>https://blog.javan.de/from-conference-energy-to-reality-the-story-of-alex-security-culture-and-why-it-resonated/</loc></url>
  <url><loc>https://blog.javan.de/coming-full-circle-teaching-ethical-hacking-at-aalen-university/</loc></url>
  <url><loc>https://blog.javan.de/recap-of-hacker-summer-camp-2025/</loc></url>
  <url><loc>https://blog.javan.de/my-password-vault-was-hacked-but-2fa-saved-my-ass-ongoing-bitwarden-incident/</loc></url>
  <url><loc>https://blog.javan.de/from-firefighting-to-prevention-taking-browser-native-defences-to-hacker-summer-camp/</loc></url>
  <url><loc>https://blog.javan.de/ai-tools-in-the-classroom-what-i-learned-from-12-student-projects-on-secure-coding/</loc></url>
  <url><loc>https://blog.javan.de/how-to-send-http-requests-from-cloudflares-ip-range/</loc></url>
  <url><loc>https://blog.javan.de/how-to-prevent-cloudflare-proxy-bypasses/</loc></url>
  <url><loc>https://blog.javan.de/hacking-the-fireplace/</loc></url>
  <url><loc>https://blog.javan.de/weve-normalised-ai-but-not-secure-code/</loc></url>
  <url><loc>https://blog.javan.de/is-it-just-me-or-is-2025-the-year-of-scale/</loc></url>
  <url><loc>https://blog.javan.de/prompt-inj-ai-firewalls-waf/</loc></url>
  <url><loc>https://blog.javan.de/scaling-appsec-in-high-velocity-engineering-my-take/</loc></url>
  <url><loc>https://blog.javan.de/hacking-your-not-so-smart-doorbell-home-assistant-and-gemini-ai/</loc></url>
  <url><loc>https://blog.javan.de/appsec-team-topologies/</loc></url>
  <url><loc>https://blog.javan.de/rethinking-shift-left-more-than-just-eliminating-vulnerabilities/</loc></url>
  <url><loc>https://blog.javan.de/relying-solely-on-ip-allowlisting-with-cloudflare-is-wrong/</loc></url>
  <url><loc>https://blog.javan.de/10-practices-to-secure-a-wordpress-site-updated-2024/</loc></url>
  <url><loc>https://blog.javan.de/owasp-frankfurt-chapter-meetup-63-recap/</loc></url>
  <url><loc>https://blog.javan.de/recap-of-sector-security-conference/</loc></url>
  <url><loc>https://blog.javan.de/secure-coding-workshop-at-dhbw-cas-university/</loc></url>
  <url><loc>https://blog.javan.de/the-dark-side-of-large-language-models-uncovering-and-overcoming-of-code-vulnerabilities/</loc></url>
  <url><loc>https://blog.javan.de/the-ticking-time-bomb-when-features-turn-into-unexpected-vulnerabilities/</loc></url>
  <url><loc>https://blog.javan.de/security-concerns-with-github-copilot/</loc></url>
  <url><loc>https://blog.javan.de/privacy-engineering-the-missing-piece-in-application-security/</loc></url>
  <url><loc>https://blog.javan.de/re-cap-of-owasp-appsec-san-fran-conference-2022/</loc></url>
  <url><loc>https://blog.javan.de/my-talk-at-ekoparty-security-conference-2022/</loc></url>
  <url><loc>https://blog.javan.de/software-quality-engineering-vorlesung-am-dhbw-cas/</loc></url>
  <url><loc>https://blog.javan.de/my-upcoming-talks-at-eko2022-and-globalappsecsanfran/</loc></url>
  <url><loc>https://blog.javan.de/my-keynote-on-beekeeping-and-technology-at-plcnext-technology-community-summit/</loc></url>
  <url><loc>https://blog.javan.de/my-talk-on-exploiting-race-condition-vulnerabilities-in-web-applications-at-hitb2022sin-conference/</loc></url>
  <url><loc>https://blog.javan.de/secure-coding-vorlesung-an-der-hochschule/</loc></url>
  <url><loc>https://blog.javan.de/scraping-is-not-a-crime/</loc></url>
  <url><loc>https://blog.javan.de/race-condition-leads-to-ms-account-takeover/</loc></url>
  <url><loc>https://blog.javan.de/review-my-path-to-certified-secure-software-lifecycle-professional-csslp/</loc></url>
  <url><loc>https://blog.javan.de/review-sec660-giac-exploit-researcher-and-advanced-penetration-tester-gxpn/</loc></url>
  <url><loc>https://blog.javan.de/install-kali-linux-subsystem-on-windows/</loc></url>
  <url><loc>https://blog.javan.de/monitoring-your-wordpress-blog-with-sqreen/</loc></url>
  <url><loc>https://blog.javan.de/wordpress-security-7-schritte-zur-absicherung-eines-wordpress-blogs/</loc></url>
  <url><loc>https://blog.javan.de/hacking-lotto-%f0%9f%98%88-mein-fazit-nach-einem-jahr-lotto-data-mining-data-tampering/</loc></url>
  <url><loc>https://blog.javan.de/securing-typo3-cms-new-security-scanner/</loc></url>
  <url><loc>https://blog.javan.de/pihole-dns-blocklists-adlists-auto-updater/</loc></url>
  <url><loc>https://blog.javan.de/firefox-bug-1608687/</loc></url>
  <url><loc>https://blog.javan.de/raspbian-images-selbst-bauen/</loc></url>
  <url><loc>https://blog.javan.de/condition-injection/</loc></url>
  <url><loc>https://blog.javan.de/wie-auf-einen-spear-phishing-angriff-reagieren/</loc></url>
  <url><loc>https://blog.javan.de/open-source-pricetracker-fuer-amazon-artikel-php-mysql-jquery/</loc></url>
  <url><loc>https://blog.javan.de/bienenstand-monitoring-%f0%9f%90%9d-%f0%9f%94%8d-mit-r/</loc></url>
  <url><loc>https://blog.javan.de/automatische-vulnerability-scans-mit-owasp-zap-in-sonarqube-und-jenkins-ci-devsecops/</loc></url>
  <url><loc>https://blog.javan.de/owasp-appsensor-detect-and-respond-to-attacks-on-application-level/</loc></url>
  <url><loc>https://blog.javan.de/trainingsanwendung-sql-injection-innerhalb-eines-node-js-projekts/</loc></url>
  <url><loc>https://blog.javan.de/dynamische-analyse-mit-owasp-zed-attack-proxy-zap/</loc></url>
  <url><loc>https://blog.javan.de/esp32-bme680-sensor-in-webinterface-visualisieren/</loc></url>
  <url><loc>https://blog.javan.de/naturathon-2018-wir-haben-gewonnen-%f0%9f%8e%89/</loc></url>
  <url><loc>https://blog.javan.de/rich-internet-application-vs-single-page-application/</loc></url>
  <url><loc>https://blog.javan.de/angriffsvektoren-durch-iot-devices-internet-of-insecure-things/</loc></url>
  <url><loc>https://blog.javan.de/greasemonkey-keylogger-mit-steuerungs-interface/</loc></url>
  <url><loc>https://blog.javan.de/it-sicherheit-code-injection-grundsaetzliches-prinzip-und-beispiele-fuer-sql-und-html/</loc></url>
  <url><loc>https://blog.javan.de/archive/2026/</loc></url>
  <url><loc>https://blog.javan.de/archive/2025/</loc></url>
  <url><loc>https://blog.javan.de/archive/2024/</loc></url>
  <url><loc>https://blog.javan.de/archive/2023/</loc></url>
  <url><loc>https://blog.javan.de/archive/2022/</loc></url>
  <url><loc>https://blog.javan.de/archive/2021/</loc></url>
  <url><loc>https://blog.javan.de/archive/2020/</loc></url>
  <url><loc>https://blog.javan.de/archive/2019/</loc></url>
  <url><loc>https://blog.javan.de/archive/2018/</loc></url>
  <url><loc>https://blog.javan.de/archive/2015/</loc></url>
</urlset>
