<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Window name trick</title>
	<atom:link href="http://www.thespanner.co.uk/2007/09/06/window-name-trick/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Fri, 25 Jul 2008 14:10:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-561</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 07 Sep 2007 23:54:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-561</guid>
		<description>The PHPIDS has since fixed the problem, I haven't tested the window.name exploit but I'm sure it works.</description>
		<content:encoded><![CDATA[<p>The PHPIDS has since fixed the problem, I haven&#8217;t tested the window.name exploit but I&#8217;m sure it works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-560</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 07 Sep 2007 23:52:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-560</guid>
		<description>Mario nice! Good tool!</description>
		<content:encoded><![CDATA[<p>Mario nice! Good tool!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-559</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Fri, 07 Sep 2007 22:18:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-559</guid>
		<description>I've recently updated the PHP Charset Encoder with some new candy - including an easy 'name' tool. It's not as powerful as Giorgio's hackademix redirector but might be quite useful in combination with the other features. Use responsible ;)

http://h4k.in/encoding/</description>
		<content:encoded><![CDATA[<p>I&#8217;ve recently updated the PHP Charset Encoder with some new candy - including an easy &#8216;name&#8217; tool. It&#8217;s not as powerful as Giorgio&#8217;s hackademix redirector but might be quite useful in combination with the other features. Use responsible <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><a href="http://h4k.in/encoding/" rel="nofollow">http://h4k.in/encoding/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: raaka</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-558</link>
		<dc:creator>raaka</dc:creator>
		<pubDate>Fri, 07 Sep 2007 17:30:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-558</guid>
		<description>hi Gareth 
window.name="javascript:alert((window.opener&#124;&#124;window).document.cookie);";
is this working on IE7 ?
my browserint responding..</description>
		<content:encoded><![CDATA[<p>hi Gareth<br />
window.name=&#8221;javascript:alert((window.opener||window).document.cookie);&#8221;;<br />
is this working on IE7 ?<br />
my browserint responding..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-548</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 07 Sep 2007 10:38:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-548</guid>
		<description>Regards to the spam protection, I have recently updated my plugin so you should now be able to post in IE7, sorry about that.</description>
		<content:encoded><![CDATA[<p>Regards to the spam protection, I have recently updated my plugin so you should now be able to post in IE7, sorry about that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-543</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 07 Sep 2007 00:28:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-543</guid>
		<description>My mistake I thought Giorgio Maone because he was mentioned as the inventor on Sirdarckcat's blog.

I don't really care how old it is though, I didn't know about it and I'm sure a few others didn't either. You shouldn't be able to inject javascript on one site and read it from another, so regardless if it is being used anywhere to maintain state it should be fixed.

Sorry to hear about the spam issue, please could you give me more details on your configuration so I can look into it. Thanks.</description>
		<content:encoded><![CDATA[<p>My mistake I thought Giorgio Maone because he was mentioned as the inventor on Sirdarckcat&#8217;s blog.</p>
<p>I don&#8217;t really care how old it is though, I didn&#8217;t know about it and I&#8217;m sure a few others didn&#8217;t either. You shouldn&#8217;t be able to inject javascript on one site and read it from another, so regardless if it is being used anywhere to maintain state it should be fixed.</p>
<p>Sorry to hear about the spam issue, please could you give me more details on your configuration so I can look into it. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: digi7al64</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-542</link>
		<dc:creator>digi7al64</dc:creator>
		<pubDate>Fri, 07 Sep 2007 00:20:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-542</guid>
		<description>... this is old, really old. Also you would suprised at the number of places that use it to maintain browser state on cookieless connections.

Also Giorgio Maone certainly didn't invent it.

http://www.criticalsecurity.net/lofiversion/index.php/t5089.html (read second post from the bottom [I was testing it as an attack storage space back in 2005])

http://www.securitytracker.com/alerts/2005/May/1013914.html [back in 2005 - used as a operator to determine if hack should occur])


[-BTW: IF THIS POST APPEARS PLEASE FIX YOUR ANTI SPAM STUFF - IT WON'T LET ME POST WITH IE7... WITH JAVASCRIPT TURNED ON -]</description>
		<content:encoded><![CDATA[<p>&#8230; this is old, really old. Also you would suprised at the number of places that use it to maintain browser state on cookieless connections.</p>
<p>Also Giorgio Maone certainly didn&#8217;t invent it.</p>
<p><a href="http://www.criticalsecurity.net/lofiversion/index.php/t5089.html" rel="nofollow">http://www.criticalsecurity.net/lofiversion/index.php/t5089.html</a> (read second post from the bottom [I was testing it as an attack storage space back in 2005])</p>
<p><a href="http://www.securitytracker.com/alerts/2005/May/1013914.html" rel="nofollow">http://www.securitytracker.com/alerts/2005/May/1013914.html</a> [back in 2005 - used as a operator to determine if hack should occur])</p>
<p>[-BTW: IF THIS POST APPEARS PLEASE FIX YOUR ANTI SPAM STUFF - IT WON'T LET ME POST WITH IE7... WITH JAVASCRIPT TURNED ON -]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-535</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 06 Sep 2007 14:13:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-535</guid>
		<description>Hi raaka

Which item are you referring to? window.name or URL=name?</description>
		<content:encoded><![CDATA[<p>Hi raaka</p>
<p>Which item are you referring to? window.name or URL=name?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: raaka</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-534</link>
		<dc:creator>raaka</dc:creator>
		<pubDate>Thu, 06 Sep 2007 14:08:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-534</guid>
		<description>not working on IE7
anyone tried ?</description>
		<content:encoded><![CDATA[<p>not working on IE7<br />
anyone tried ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-533</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 06 Sep 2007 12:56:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-533</guid>
		<description>Nope it's daft, they should prevent it.

If that made your head hurt.....sorry Mario:-
URL=name

I've no idea how you'll prevent that one. Maybe it's not your problem but rather a browser security issue.</description>
		<content:encoded><![CDATA[<p>Nope it&#8217;s daft, they should prevent it.</p>
<p>If that made your head hurt&#8230;..sorry Mario:-<br />
URL=name</p>
<p>I&#8217;ve no idea how you&#8217;ll prevent that one. Maybe it&#8217;s not your problem but rather a browser security issue.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
