<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Open source security tools</title>
	<atom:link href="http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Tue, 14 Oct 2008 01:37:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/#comment-391</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 15 Aug 2007 22:27:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/#comment-391</guid>
		<description>Hi Ascii

Yeah I forgot to remove the inc file because it was originally hosted on my site but I figured people would know to remove it anyway. Same with the styles and images. 

There's been a few instances of interesting javascript execution reported. The plan is to log them in the fuzz database, and the address variable is used to report the fuzz results back to my server using dynamic images. It's up to you, you can choose to report the results or not.</description>
		<content:encoded><![CDATA[<p>Hi Ascii</p>
<p>Yeah I forgot to remove the inc file because it was originally hosted on my site but I figured people would know to remove it anyway. Same with the styles and images. </p>
<p>There&#8217;s been a few instances of interesting javascript execution reported. The plan is to log them in the fuzz database, and the address variable is used to report the fuzz results back to my server using dynamic images. It&#8217;s up to you, you can choose to report the results or not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ascii</title>
		<link>http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/#comment-390</link>
		<dc:creator>ascii</dc:creator>
		<pubDate>Wed, 15 Aug 2007 21:59:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/#comment-390</guid>
		<description>did executedJavascript turned to 1 in any cool way so far? are there already notable results? (just curious, i can understand if you refuse to publish results details since you already opensourced the fuzzer)

the only glitches i found are:

include ads.inc.php that could be removed (or make the path absolute and go evil)

var address that still points to your server (dunno if wanted or not :P)

some missing external stuff that is not directly involved in the fuzzing mechanism (styles, images, etc)

just an idea: the user agent string could be added to the reporting</description>
		<content:encoded><![CDATA[<p>did executedJavascript turned to 1 in any cool way so far? are there already notable results? (just curious, i can understand if you refuse to publish results details since you already opensourced the fuzzer)</p>
<p>the only glitches i found are:</p>
<p>include ads.inc.php that could be removed (or make the path absolute and go evil)</p>
<p>var address that still points to your server (dunno if wanted or not :P)</p>
<p>some missing external stuff that is not directly involved in the fuzzing mechanism (styles, images, etc)</p>
<p>just an idea: the user agent string could be added to the reporting</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/#comment-389</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 15 Aug 2007 21:00:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/#comment-389</guid>
		<description>No probs I'm glad you like the code :) If you improve it or use it anywhere let me know and get involved with the Google group, I'm hoping we can all share ideas, learn and improve the code.</description>
		<content:encoded><![CDATA[<p>No probs I&#8217;m glad you like the code <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> If you improve it or use it anywhere let me know and get involved with the Google group, I&#8217;m hoping we can all share ideas, learn and improve the code.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ascii</title>
		<link>http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/#comment-388</link>
		<dc:creator>ascii</dc:creator>
		<pubDate>Wed, 15 Aug 2007 20:51:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/#comment-388</guid>
		<description>i'm still reading the sources but it seems really good stuff, thanks!</description>
		<content:encoded><![CDATA[<p>i&#8217;m still reading the sources but it seems really good stuff, thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pF ;)</title>
		<link>http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/#comment-375</link>
		<dc:creator>pF ;)</dc:creator>
		<pubDate>Wed, 15 Aug 2007 07:36:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/#comment-375</guid>
		<description>Cool!</description>
		<content:encoded><![CDATA[<p>Cool!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/#comment-374</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Wed, 15 Aug 2007 06:36:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/14/open-source-security-tools/#comment-374</guid>
		<description>sweet</description>
		<content:encoded><![CDATA[<p>sweet</p>
]]></content:encoded>
	</item>
</channel>
</rss>
