<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Google Adsense CSRF hole</title>
	<atom:link href="http://www.thespanner.co.uk/2007/09/27/google-adsense-csrf-hole/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/09/27/google-adsense-csrf-hole/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Fri, 12 Mar 2010 05:04:18 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: s c tan</title>
		<link>http://www.thespanner.co.uk/2007/09/27/google-adsense-csrf-hole/#comment-1000</link>
		<dc:creator>s c tan</dc:creator>
		<pubDate>Tue, 18 Dec 2007 12:12:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/27/google-adsense-csrf-hole/#comment-1000</guid>
		<description>great blog!</description>
		<content:encoded><![CDATA[<p>great blog!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 0kn0ck</title>
		<link>http://www.thespanner.co.uk/2007/09/27/google-adsense-csrf-hole/#comment-631</link>
		<dc:creator>0kn0ck</dc:creator>
		<pubDate>Fri, 28 Sep 2007 07:08:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/27/google-adsense-csrf-hole/#comment-631</guid>
		<description>Good Stroke Gareth</description>
		<content:encoded><![CDATA[<p>Good Stroke Gareth</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/27/google-adsense-csrf-hole/#comment-628</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 27 Sep 2007 16:59:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/27/google-adsense-csrf-hole/#comment-628</guid>
		<description>Hi Ronald

I'm sorry I didn't realise you had released the same exploit, I just wanted to point out how easy it was to find a hole.

My comment about a security researcher was in jest :) of course I don't think I need to find one in Google, I just thought it would be funny.</description>
		<content:encoded><![CDATA[<p>Hi Ronald</p>
<p>I&#8217;m sorry I didn&#8217;t realise you had released the same exploit, I just wanted to point out how easy it was to find a hole.</p>
<p>My comment about a security researcher was in jest <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> of course I don&#8217;t think I need to find one in Google, I just thought it would be funny.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.thespanner.co.uk/2007/09/27/google-adsense-csrf-hole/#comment-627</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 27 Sep 2007 16:42:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/27/google-adsense-csrf-hole/#comment-627</guid>
		<description>rock on!</description>
		<content:encoded><![CDATA[<p>rock on!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronald</title>
		<link>http://www.thespanner.co.uk/2007/09/27/google-adsense-csrf-hole/#comment-626</link>
		<dc:creator>Ronald</dc:creator>
		<pubDate>Thu, 27 Sep 2007 16:30:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/27/google-adsense-csrf-hole/#comment-626</guid>
		<description>How is that one different from mine Gareth?
I did exactly the same 6 months ago, only I used GET.

I don't think it has something to do with releasing Google holes to be a researcher. 
All of Google is vulnerable, unlike PDP I found more, but I don't feel like spending a single second on their site anymore. Okay it gets a ton of media attention, but it isn't hard to find one. For me, I don't want all this media hyping around me anymore, cause first off it doesn't do a thing for you only that you'll become a sort of side-show, some kind of carnivale, you knwo like: see the bearded lady! IMHO thats how I look at it.

lol :D</description>
		<content:encoded><![CDATA[<p>How is that one different from mine Gareth?<br />
I did exactly the same 6 months ago, only I used GET.</p>
<p>I don&#8217;t think it has something to do with releasing Google holes to be a researcher.<br />
All of Google is vulnerable, unlike PDP I found more, but I don&#8217;t feel like spending a single second on their site anymore. Okay it gets a ton of media attention, but it isn&#8217;t hard to find one. For me, I don&#8217;t want all this media hyping around me anymore, cause first off it doesn&#8217;t do a thing for you only that you&#8217;ll become a sort of side-show, some kind of carnivale, you knwo like: see the bearded lady! IMHO thats how I look at it.</p>
<p>lol <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
</channel>
</rss>
