<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Yahoo! epic fail &#8211; permanent xss unleashed</title>
	<atom:link href="http://blog.rstcenter.com/2009/02/10/yahoo-epic-fail-permanent-xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.rstcenter.com/2009/02/10/yahoo-epic-fail-permanent-xss/</link>
	<description></description>
	<lastBuildDate>Sat, 17 Sep 2011 10:00:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: MD6</title>
		<link>http://blog.rstcenter.com/2009/02/10/yahoo-epic-fail-permanent-xss/comment-page-1/#comment-1556</link>
		<dc:creator>MD6</dc:creator>
		<pubDate>Fri, 13 Mar 2009 22:14:55 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1213#comment-1556</guid>
		<description>Se pare ca nu mai merge linku http://timetags.research.yahoo.com</description>
		<content:encoded><![CDATA[<p>Se pare ca nu mai merge linku <a href="http://timetags.research.yahoo.com" rel="nofollow">http://timetags.research.yahoo.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Claudel</title>
		<link>http://blog.rstcenter.com/2009/02/10/yahoo-epic-fail-permanent-xss/comment-page-1/#comment-1322</link>
		<dc:creator>Claudel</dc:creator>
		<pubDate>Sun, 01 Mar 2009 13:29:32 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1213#comment-1322</guid>
		<description>is neamuri de rRomi:)))</description>
		<content:encoded><![CDATA[<p>is neamuri de rRomi:)))</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mrjuki</title>
		<link>http://blog.rstcenter.com/2009/02/10/yahoo-epic-fail-permanent-xss/comment-page-1/#comment-1321</link>
		<dc:creator>Mrjuki</dc:creator>
		<pubDate>Sun, 01 Mar 2009 02:44:34 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1213#comment-1321</guid>
		<description>http://www.kaskus.us/showthread.php?t=1428092

someone steal your post

use google translate if you don&#039;t understand</description>
		<content:encoded><![CDATA[<p><a href="http://www.kaskus.us/showthread.php?t=1428092" rel="nofollow">http://www.kaskus.us/showthread.php?t=1428092</a></p>
<p>someone steal your post</p>
<p>use google translate if you don&#8217;t understand</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: black_death</title>
		<link>http://blog.rstcenter.com/2009/02/10/yahoo-epic-fail-permanent-xss/comment-page-1/#comment-944</link>
		<dc:creator>black_death</dc:creator>
		<pubDate>Thu, 12 Feb 2009 12:56:32 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1213#comment-944</guid>
		<description>my ass :( , kenpachi l-o facut , ii dau la ciocatu lu pax.</description>
		<content:encoded><![CDATA[<p>my ass <img src='http://blog.rstcenter.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  , kenpachi l-o facut , ii dau la ciocatu lu pax.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CODEX</title>
		<link>http://blog.rstcenter.com/2009/02/10/yahoo-epic-fail-permanent-xss/comment-page-1/#comment-942</link>
		<dc:creator>CODEX</dc:creator>
		<pubDate>Thu, 12 Feb 2009 12:26:49 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1213#comment-942</guid>
		<description>bine pax :)))</description>
		<content:encoded><![CDATA[<p>bine pax <img src='http://blog.rstcenter.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ))</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nab</title>
		<link>http://blog.rstcenter.com/2009/02/10/yahoo-epic-fail-permanent-xss/comment-page-1/#comment-895</link>
		<dc:creator>Nab</dc:creator>
		<pubDate>Wed, 11 Feb 2009 22:25:35 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1213#comment-895</guid>
		<description>aiurea că l-ai făcut public. mai bine îl vindeai</description>
		<content:encoded><![CDATA[<p>aiurea că l-ai făcut public. mai bine îl vindeai</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Broken</title>
		<link>http://blog.rstcenter.com/2009/02/10/yahoo-epic-fail-permanent-xss/comment-page-1/#comment-801</link>
		<dc:creator>Broken</dc:creator>
		<pubDate>Tue, 10 Feb 2009 19:53:56 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1213#comment-801</guid>
		<description>super tare frate :&#124;, si yahoo si gugal au avut articole cu titlu epic fail =))</description>
		<content:encoded><![CDATA[<p>super tare frate <img src='http://blog.rstcenter.com/wp-includes/images/smilies/icon_neutral.gif' alt=':|' class='wp-smiley' /> , si yahoo si gugal au avut articole cu titlu epic fail =))</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrei Rine</title>
		<link>http://blog.rstcenter.com/2009/02/10/yahoo-epic-fail-permanent-xss/comment-page-1/#comment-800</link>
		<dc:creator>Andrei Rine</dc:creator>
		<pubDate>Tue, 10 Feb 2009 19:53:27 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1213#comment-800</guid>
		<description>Bineinteles ca validarea inputului si encodarea corecta a outputului sunt lucruri sfinte in functionarea unei aplicatii software. HttpOnly este nesuportat corect de cam nici un browser momentan si are statut de leucoplast. Totusi consideram oportun sa il mentionez. :D</description>
		<content:encoded><![CDATA[<p>Bineinteles ca validarea inputului si encodarea corecta a outputului sunt lucruri sfinte in functionarea unei aplicatii software. HttpOnly este nesuportat corect de cam nici un browser momentan si are statut de leucoplast. Totusi consideram oportun sa il mentionez. <img src='http://blog.rstcenter.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shocker</title>
		<link>http://blog.rstcenter.com/2009/02/10/yahoo-epic-fail-permanent-xss/comment-page-1/#comment-798</link>
		<dc:creator>Shocker</dc:creator>
		<pubDate>Tue, 10 Feb 2009 19:50:57 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1213#comment-798</guid>
		<description>@Andrei: In primul rand, la Yahoo nu sunt HttpOnly. In al doilea rand, cum HttpOnly nu e un standard, nu toate browserele tin cont de acel atribut (Opera spre exemplu), in consecinta nu e indicat sa te bazezi pe HttpOnly. Mai bine iti securizezi site-ul.</description>
		<content:encoded><![CDATA[<p>@Andrei: In primul rand, la Yahoo nu sunt HttpOnly. In al doilea rand, cum HttpOnly nu e un standard, nu toate browserele tin cont de acel atribut (Opera spre exemplu), in consecinta nu e indicat sa te bazezi pe HttpOnly. Mai bine iti securizezi site-ul.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrei Rine</title>
		<link>http://blog.rstcenter.com/2009/02/10/yahoo-epic-fail-permanent-xss/comment-page-1/#comment-789</link>
		<dc:creator>Andrei Rine</dc:creator>
		<pubDate>Tue, 10 Feb 2009 19:18:50 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1213#comment-789</guid>
		<description>Si nu, XMLHttpRequest nu va merge ca o alternativa decat la platformele de cacat. Dupa cum scriam aici -&gt; http://ha.ckers.org/blog/20070719/firefox-implements-httponly-and-is-vulnerable-to-xmlhttprequest/#comment-85043 numai platformele foarte maro ce emit cookie-ul de sesiune la fiecare raspuns HTTP sunt vulnerabile.</description>
		<content:encoded><![CDATA[<p>Si nu, XMLHttpRequest nu va merge ca o alternativa decat la platformele de cacat. Dupa cum scriam aici -&gt; <a href="http://ha.ckers.org/blog/20070719/firefox-implements-httponly-and-is-vulnerable-to-xmlhttprequest/#comment-85043" rel="nofollow">http://ha.ckers.org/blog/20070719/firefox-implements-httponly-and-is-vulnerable-to-xmlhttprequest/#comment-85043</a> numai platformele foarte maro ce emit cookie-ul de sesiune la fiecare raspuns HTTP sunt vulnerabile.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

