<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Unusual XSS vectors</title>
	<atom:link href="http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Tue, 30 Sep 2008 23:29:23 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: xss2root</title>
		<link>http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-1284</link>
		<dc:creator>xss2root</dc:creator>
		<pubDate>Fri, 15 Aug 2008 08:23:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-1284</guid>
		<description>some filter is based on the HTML syntax,it will remove all attributs like on*,remove some unsafe tags and so on.
the filter just like a browser,and it's safe much more.</description>
		<content:encoded><![CDATA[<p>some filter is based on the HTML syntax,it will remove all attributs like on*,remove some unsafe tags and so on.<br />
the filter just like a browser,and it&#8217;s safe much more.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-1274</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 04 Aug 2008 13:30:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-1274</guid>
		<description>@Reelix 

1. You'd be getting a XSS on wordpress and not me.
2. You didn't get XSS
3. This is boring</description>
		<content:encoded><![CDATA[<p>@Reelix </p>
<p>1. You&#8217;d be getting a XSS on wordpress and not me.<br />
2. You didn&#8217;t get XSS<br />
3. This is boring</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Reelix</title>
		<link>http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-1273</link>
		<dc:creator>Reelix</dc:creator>
		<pubDate>Mon, 04 Aug 2008 12:37:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-1273</guid>
		<description>'&#62;"&#62;&#60;script&#62;alert(0)&#60;/script&#62;</description>
		<content:encoded><![CDATA[<p>&#8216;&gt;&#8221;&gt;&lt;script&gt;alert(0)&lt;/script&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Reelix</title>
		<link>http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-1272</link>
		<dc:creator>Reelix</dc:creator>
		<pubDate>Mon, 04 Aug 2008 12:37:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-1272</guid>
		<description>An XSS attempt :)

&#60;script&#62;window.location = 'http://www.reelic.za.net/'&#62;&#60;/script&#62;</description>
		<content:encoded><![CDATA[<p>An XSS attempt <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>&lt;script&gt;window.location = &#8216;http://www.reelic.za.net/&#8217;&gt;&lt;/script&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-891</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 22 Nov 2007 12:13:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-891</guid>
		<description>@Domber

He should update his cheatsheet then :)</description>
		<content:encoded><![CDATA[<p>@Domber</p>
<p>He should update his cheatsheet then <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Domber</title>
		<link>http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-890</link>
		<dc:creator>Domber</dc:creator>
		<pubDate>Thu, 22 Nov 2007 11:51:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-890</guid>
		<description>&#62; It’s not in RSnake’s cheatsheet after a quick check.

But in his Book ;-)
“Cross Site Scripting Attacks: Xss Exploits and Defense” 

HTH</description>
		<content:encoded><![CDATA[<p>&gt; It’s not in RSnake’s cheatsheet after a quick check.</p>
<p>But in his Book <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /><br />
“Cross Site Scripting Attacks: Xss Exploits and Defense” </p>
<p>HTH</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-871</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Mon, 19 Nov 2007 17:11:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-871</guid>
		<description>onwhatever :)

http://www.w3schools.com/dhtml/dhtml_events.asp

MSIE even features dozens of additional ones...</description>
		<content:encoded><![CDATA[<p>onwhatever <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://www.w3schools.com/dhtml/dhtml_events.asp" rel="nofollow">http://www.w3schools.com/dhtml/dhtml_events.asp</a></p>
<p>MSIE even features dozens of additional ones&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marcin</title>
		<link>http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-870</link>
		<dc:creator>Marcin</dc:creator>
		<pubDate>Mon, 19 Nov 2007 16:31:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-870</guid>
		<description>Cool! I wrote a http://www.tssci-security.com/archives/2007/11/15/blacklisting-xss-filter-evasion-and-other-resources/ a couple days ago about using &#60;img src="" onerror=alert(/xss/)&#62; in a site review..  Didn't even realize there was an &#60;image&#62; element that works the same.

I'm going to have to try the onmouseover attribute next time around.

Mario's is a nice one too... I'm building up my own little cheat sheet as I go along. Perhaps XSS Cheat Sheet could use an update.

:)</description>
		<content:encoded><![CDATA[<p>Cool! I wrote a <a href="http://www.tssci-security.com/archives/2007/11/15/blacklisting-xss-filter-evasion-and-other-resources/" rel="nofollow">http://www.tssci-security.com/archives/2007/11/15/blacklisting-xss-filter-evasion-and-other-resources/</a> a couple days ago about using &lt;img src=&#8221;" onerror=alert(/xss/)&gt; in a site review..  Didn&#8217;t even realize there was an &lt;image&gt; element that works the same.</p>
<p>I&#8217;m going to have to try the onmouseover attribute next time around.</p>
<p>Mario&#8217;s is a nice one too&#8230; I&#8217;m building up my own little cheat sheet as I go along. Perhaps XSS Cheat Sheet could use an update.</p>
<p> <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-866</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 19 Nov 2007 12:35:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-866</guid>
		<description>Thanks Mario :) I've registered a domain for Hackvertor and once I've finished the look behind matching and completed the fuzzing features I'll start work on a API, which should be cool :D</description>
		<content:encoded><![CDATA[<p>Thanks Mario <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> I&#8217;ve registered a domain for Hackvertor and once I&#8217;ve finished the look behind matching and completed the fuzzing features I&#8217;ll start work on a API, which should be cool <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-865</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Mon, 19 Nov 2007 12:30:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/19/unusual-xss-vectors/#comment-865</guid>
		<description>Wow - the &#60;image&#62; issue is new indeed. The rest is just plain browser madness - Firefox in particular.

&#60;image/src onerror=alert(1)&#62;

Incredible... Nice find :) I await the day when Hackvertor hs an API with itching fingers ;)</description>
		<content:encoded><![CDATA[<p>Wow - the &lt;image&gt; issue is new indeed. The rest is just plain browser madness - Firefox in particular.</p>
<p>&lt;image/src onerror=alert(1)&gt;</p>
<p>Incredible&#8230; Nice find <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> I await the day when Hackvertor hs an API with itching fingers <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
</channel>
</rss>
