<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: JSCK</title>
	<atom:link href="http://www.thespanner.co.uk/2007/10/19/jsck/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/10/19/jsck/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Fri, 25 Jul 2008 14:23:38 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Surendran</title>
		<link>http://www.thespanner.co.uk/2007/10/19/jsck/#comment-1149</link>
		<dc:creator>Surendran</dc:creator>
		<pubDate>Wed, 27 Feb 2008 10:15:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/19/jsck/#comment-1149</guid>
		<description>Hi guys,

Thanks for your information.

i am also looking forward to get source code of the current version and the related version. 

Have a great day! :)</description>
		<content:encoded><![CDATA[<p>Hi guys,</p>
<p>Thanks for your information.</p>
<p>i am also looking forward to get source code of the current version and the related version. </p>
<p>Have a great day! <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anshuk</title>
		<link>http://www.thespanner.co.uk/2007/10/19/jsck/#comment-976</link>
		<dc:creator>Anshuk</dc:creator>
		<pubDate>Tue, 04 Dec 2007 12:10:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/19/jsck/#comment-976</guid>
		<description>Hi Gareth,

Thanks for your quick reply.
I would definitely like to have a look in the code and try to understand the issues and fix it.
Can you please send across the source code of the current version and also the released version (which I suppose is not the current one)

Thanks.

/
Anshuk</description>
		<content:encoded><![CDATA[<p>Hi Gareth,</p>
<p>Thanks for your quick reply.<br />
I would definitely like to have a look in the code and try to understand the issues and fix it.<br />
Can you please send across the source code of the current version and also the released version (which I suppose is not the current one)</p>
<p>Thanks.</p>
<p>/<br />
Anshuk</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/10/19/jsck/#comment-975</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 04 Dec 2007 11:53:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/19/jsck/#comment-975</guid>
		<description>Hi Anshuk

Yes I've released the current version however it isn't final yet as there are still some issues I need to fix. There are a couple of vulnerabilities like multiple urls and external source inclusion.

I wouldn't recommend using this version and as soon as I find time I'll sort it out. If you want to work on the code let me know and I'll supply you with the current source and provide you with credit if you fix it. 

Thanks</description>
		<content:encoded><![CDATA[<p>Hi Anshuk</p>
<p>Yes I&#8217;ve released the current version however it isn&#8217;t final yet as there are still some issues I need to fix. There are a couple of vulnerabilities like multiple urls and external source inclusion.</p>
<p>I wouldn&#8217;t recommend using this version and as soon as I find time I&#8217;ll sort it out. If you want to work on the code let me know and I&#8217;ll supply you with the current source and provide you with credit if you fix it. </p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anshuk</title>
		<link>http://www.thespanner.co.uk/2007/10/19/jsck/#comment-974</link>
		<dc:creator>Anshuk</dc:creator>
		<pubDate>Tue, 04 Dec 2007 11:48:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/19/jsck/#comment-974</guid>
		<description>Hi Gareth,

Have you released the code for the JSCK?

/
Anhsuk</description>
		<content:encoded><![CDATA[<p>Hi Gareth,</p>
<p>Have you released the code for the JSCK?</p>
<p>/<br />
Anhsuk</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sally, translator</title>
		<link>http://www.thespanner.co.uk/2007/10/19/jsck/#comment-939</link>
		<dc:creator>Sally, translator</dc:creator>
		<pubDate>Tue, 27 Nov 2007 17:40:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/19/jsck/#comment-939</guid>
		<description>It's really cool! But it is not so perfect you see. According to the comments.</description>
		<content:encoded><![CDATA[<p>It&#8217;s really cool! But it is not so perfect you see. According to the comments.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/10/19/jsck/#comment-746</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sun, 21 Oct 2007 09:34:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/19/jsck/#comment-746</guid>
		<description>@Iehrepus

Oh yeah no doubt they could get the key with XSS but why bother? If they have found XSS then they have complete control anyway.</description>
		<content:encoded><![CDATA[<p>@Iehrepus</p>
<p>Oh yeah no doubt they could get the key with XSS but why bother? If they have found XSS then they have complete control anyway.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Iehrepus</title>
		<link>http://www.thespanner.co.uk/2007/10/19/jsck/#comment-745</link>
		<dc:creator>Iehrepus</dc:creator>
		<pubDate>Sun, 21 Oct 2007 02:41:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/19/jsck/#comment-745</guid>
		<description>kuza55's meaning is 'mstorage and transfer the random key is dangerous' 

so only inserts a hidden field,it will solve this problem?

And if the site have a xss hole, attacker coulde get the random key,like this:

	xmlhttp.get(Turl+"admincp.php?action=members",function(s) {
		var reg = /name=\"formhash\" value=\"([\w\d]+)\"&#62;/i;
        var arr=reg.exec(s);
        var formhash=arr[1];</description>
		<content:encoded><![CDATA[<p>kuza55&#8217;s meaning is &#8216;mstorage and transfer the random key is dangerous&#8217; </p>
<p>so only inserts a hidden field,it will solve this problem?</p>
<p>And if the site have a xss hole, attacker coulde get the random key,like this:</p>
<p>	xmlhttp.get(Turl+&#8221;admincp.php?action=members&#8221;,function(s) {<br />
		var reg = /name=\&#8221;formhash\&#8221; value=\&#8221;([\w\d]+)\&#8221;&gt;/i;<br />
        var arr=reg.exec(s);<br />
        var formhash=arr[1];</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/10/19/jsck/#comment-743</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sat, 20 Oct 2007 11:02:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/19/jsck/#comment-743</guid>
		<description>Good points Kuza55 I shall consider those when working on the next version thanks.</description>
		<content:encoded><![CDATA[<p>Good points Kuza55 I shall consider those when working on the next version thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kuza55</title>
		<link>http://www.thespanner.co.uk/2007/10/19/jsck/#comment-742</link>
		<dc:creator>kuza55</dc:creator>
		<pubDate>Fri, 19 Oct 2007 22:47:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/19/jsck/#comment-742</guid>
		<description>Its nice, but it would fail where an attacker can add their own link to the page and then entice a user to click on it, e.g. forums &#38; blogs since every link has the same token, and you aren't doing anything to make sure you do not add the token to external links.

Furthermore, due to the fact that the same token is used for every URL, no two links can be clicked from the same page without reloading it, which isn't a very good solution at all IMO.</description>
		<content:encoded><![CDATA[<p>Its nice, but it would fail where an attacker can add their own link to the page and then entice a user to click on it, e.g. forums &amp; blogs since every link has the same token, and you aren&#8217;t doing anything to make sure you do not add the token to external links.</p>
<p>Furthermore, due to the fact that the same token is used for every URL, no two links can be clicked from the same page without reloading it, which isn&#8217;t a very good solution at all IMO.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Iehrepus</title>
		<link>http://www.thespanner.co.uk/2007/10/19/jsck/#comment-738</link>
		<dc:creator>Iehrepus</dc:creator>
		<pubDate>Fri, 19 Oct 2007 15:25:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/19/jsck/#comment-738</guid>
		<description>THX Gareth Heyes,Sorry my bad English,you can translation by 
http://translate.google.com/translate?u=http%3A%2F%2Fsuperhei.blogbus.com&#38;langpair=zh%7Cen&#38;complete=1&#38;hl=en&#38;newwindow=1&#38;ie=UTF-8&#38;oe=UTF-8&#38;prev=%2Flanguage_tools

but it look so.... :)</description>
		<content:encoded><![CDATA[<p>THX Gareth Heyes,Sorry my bad English,you can translation by<br />
<a href="http://translate.google.com/translate?u=http%3A%2F%2Fsuperhei.blogbus.com&amp;langpair=zh%7Cen&amp;complete=1&amp;hl=en&amp;newwindow=1&amp;ie=UTF-8&amp;oe=UTF-8&amp;prev=%2Flanguage_tools" rel="nofollow">http://translate.google.com/translate?u=http%3A%2F%2Fsuperhei.blogbus.com&amp;langpair=zh%7Cen&amp;complete=1&amp;hl=en&amp;newwindow=1&amp;ie=UTF-8&amp;oe=UTF-8&amp;prev=%2Flanguage_tools</a></p>
<p>but it look so&#8230;. <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
</channel>
</rss>
