<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Window name trick</title>
	<atom:link href="http://www.thespanner.co.uk/2007/09/06/window-name-trick/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Tue, 16 Mar 2010 17:27:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-1346</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 29 Oct 2008 23:02:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-1346</guid>
		<description>name is a string like any other variable string but is passed between windows. So if you assign something to name in one site or window and then move to another site you can still get the contents of name.</description>
		<content:encoded><![CDATA[<p>name is a string like any other variable string but is passed between windows. So if you assign something to name in one site or window and then move to another site you can still get the contents of name.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bender</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-1345</link>
		<dc:creator>bender</dc:creator>
		<pubDate>Wed, 29 Oct 2008 22:15:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-1345</guid>
		<description>i dont see how javascript is executed using the javascript can be executed in window.name..can you explain please?</description>
		<content:encoded><![CDATA[<p>i dont see how javascript is executed using the javascript can be executed in window.name..can you explain please?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-561</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 07 Sep 2007 23:54:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-561</guid>
		<description>The PHPIDS has since fixed the problem, I haven't tested the window.name exploit but I'm sure it works.</description>
		<content:encoded><![CDATA[<p>The PHPIDS has since fixed the problem, I haven&#8217;t tested the window.name exploit but I&#8217;m sure it works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-560</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 07 Sep 2007 23:52:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-560</guid>
		<description>Mario nice! Good tool!</description>
		<content:encoded><![CDATA[<p>Mario nice! Good tool!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-559</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Fri, 07 Sep 2007 22:18:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-559</guid>
		<description>I've recently updated the PHP Charset Encoder with some new candy - including an easy 'name' tool. It's not as powerful as Giorgio's hackademix redirector but might be quite useful in combination with the other features. Use responsible ;)

http://h4k.in/encoding/</description>
		<content:encoded><![CDATA[<p>I&#8217;ve recently updated the PHP Charset Encoder with some new candy - including an easy &#8216;name&#8217; tool. It&#8217;s not as powerful as Giorgio&#8217;s hackademix redirector but might be quite useful in combination with the other features. Use responsible <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><a href="http://h4k.in/encoding/" rel="nofollow">http://h4k.in/encoding/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: raaka</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-558</link>
		<dc:creator>raaka</dc:creator>
		<pubDate>Fri, 07 Sep 2007 17:30:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-558</guid>
		<description>hi Gareth 
window.name="javascript:alert((window.opener&#124;&#124;window).document.cookie);";
is this working on IE7 ?
my browserint responding..</description>
		<content:encoded><![CDATA[<p>hi Gareth<br />
window.name=&#8221;javascript:alert((window.opener||window).document.cookie);&#8221;;<br />
is this working on IE7 ?<br />
my browserint responding..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-548</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 07 Sep 2007 10:38:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-548</guid>
		<description>Regards to the spam protection, I have recently updated my plugin so you should now be able to post in IE7, sorry about that.</description>
		<content:encoded><![CDATA[<p>Regards to the spam protection, I have recently updated my plugin so you should now be able to post in IE7, sorry about that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-543</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 07 Sep 2007 00:28:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-543</guid>
		<description>My mistake I thought Giorgio Maone because he was mentioned as the inventor on Sirdarckcat's blog.

I don't really care how old it is though, I didn't know about it and I'm sure a few others didn't either. You shouldn't be able to inject javascript on one site and read it from another, so regardless if it is being used anywhere to maintain state it should be fixed.

Sorry to hear about the spam issue, please could you give me more details on your configuration so I can look into it. Thanks.</description>
		<content:encoded><![CDATA[<p>My mistake I thought Giorgio Maone because he was mentioned as the inventor on Sirdarckcat&#8217;s blog.</p>
<p>I don&#8217;t really care how old it is though, I didn&#8217;t know about it and I&#8217;m sure a few others didn&#8217;t either. You shouldn&#8217;t be able to inject javascript on one site and read it from another, so regardless if it is being used anywhere to maintain state it should be fixed.</p>
<p>Sorry to hear about the spam issue, please could you give me more details on your configuration so I can look into it. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: digi7al64</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-542</link>
		<dc:creator>digi7al64</dc:creator>
		<pubDate>Fri, 07 Sep 2007 00:20:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-542</guid>
		<description>... this is old, really old. Also you would suprised at the number of places that use it to maintain browser state on cookieless connections.

Also Giorgio Maone certainly didn't invent it.

http://www.criticalsecurity.net/lofiversion/index.php/t5089.html (read second post from the bottom [I was testing it as an attack storage space back in 2005])

http://www.securitytracker.com/alerts/2005/May/1013914.html [back in 2005 - used as a operator to determine if hack should occur])


[-BTW: IF THIS POST APPEARS PLEASE FIX YOUR ANTI SPAM STUFF - IT WON'T LET ME POST WITH IE7... WITH JAVASCRIPT TURNED ON -]</description>
		<content:encoded><![CDATA[<p>&#8230; this is old, really old. Also you would suprised at the number of places that use it to maintain browser state on cookieless connections.</p>
<p>Also Giorgio Maone certainly didn&#8217;t invent it.</p>
<p><a href="http://www.criticalsecurity.net/lofiversion/index.php/t5089.html" rel="nofollow">http://www.criticalsecurity.net/lofiversion/index.php/t5089.html</a> (read second post from the bottom [I was testing it as an attack storage space back in 2005])</p>
<p><a href="http://www.securitytracker.com/alerts/2005/May/1013914.html" rel="nofollow">http://www.securitytracker.com/alerts/2005/May/1013914.html</a> [back in 2005 - used as a operator to determine if hack should occur])</p>
<p>[-BTW: IF THIS POST APPEARS PLEASE FIX YOUR ANTI SPAM STUFF - IT WON'T LET ME POST WITH IE7... WITH JAVASCRIPT TURNED ON -]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-535</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 06 Sep 2007 14:13:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/06/window-name-trick/#comment-535</guid>
		<description>Hi raaka

Which item are you referring to? window.name or URL=name?</description>
		<content:encoded><![CDATA[<p>Hi raaka</p>
<p>Which item are you referring to? window.name or URL=name?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
