<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Javascript for hackers part 2</title>
	<atom:link href="http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Thu, 20 Nov 2008 22:21:19 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-1223</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 14 May 2008 21:22:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-1223</guid>
		<description>@k 

Unicode and html entities would be the best cross platform solution:-
&lt;a href="http://www.businessinfo.co.uk/labs/hackvertor/hackvertor.php?input=PEBjX2xpbmtfMD48QGhleF9lbnRfNCgpPjxAY19qc18xPjxAdW5pXzMoXHUpPjxAY19hbGVydF8yPigxKTxAL2NfYWxlcnRfMj48QC91bmlfMz48QC9jX2pzXzE%2BPEAvaGV4X2VudF80PjxAL2NfbGlua18wPg%3D%3D" rel="nofollow"&gt;Example&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>@k </p>
<p>Unicode and html entities would be the best cross platform solution:-<br />
<a href="http://www.businessinfo.co.uk/labs/hackvertor/hackvertor.php?input=PEBjX2xpbmtfMD48QGhleF9lbnRfNCgpPjxAY19qc18xPjxAdW5pXzMoXHUpPjxAY19hbGVydF8yPigxKTxAL2NfYWxlcnRfMj48QC91bmlfMz48QC9jX2pzXzE%2BPEAvaGV4X2VudF80PjxAL2NfbGlua18wPg%3D%3D" rel="nofollow">Example</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: k</title>
		<link>http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-1222</link>
		<dc:creator>k</dc:creator>
		<pubDate>Mon, 12 May 2008 04:06:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-1222</guid>
		<description>This seems to work only on Firefox. No IE, Opera, Safari. 

Gareth, if you had to encode it so that it would work on most browsers, what code would you use?</description>
		<content:encoded><![CDATA[<p>This seems to work only on Firefox. No IE, Opera, Safari. </p>
<p>Gareth, if you had to encode it so that it would work on most browsers, what code would you use?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-1174</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 18 Mar 2008 02:05:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-1174</guid>
		<description>@loveshell

It does work in IE but in certain circumstances and certain chars, yes I'm pretty sure it's defined in ecmascript.</description>
		<content:encoded><![CDATA[<p>@loveshell</p>
<p>It does work in IE but in certain circumstances and certain chars, yes I&#8217;m pretty sure it&#8217;s defined in ecmascript.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: loveshell</title>
		<link>http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-1173</link>
		<dc:creator>loveshell</dc:creator>
		<pubDate>Tue, 18 Mar 2008 01:57:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-1173</guid>
		<description>To take our vector a stage further we can also add backslash escapes, in javascript when a character is escaped that doesn’t have special meaning it is returned as normal.

is it defined in ecmascript?
it doesn't work in IE....</description>
		<content:encoded><![CDATA[<p>To take our vector a stage further we can also add backslash escapes, in javascript when a character is escaped that doesn’t have special meaning it is returned as normal.</p>
<p>is it defined in ecmascript?<br />
it doesn&#8217;t work in IE&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-1144</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 18 Feb 2008 10:32:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-1144</guid>
		<description>@josh

&#60;script&#62;alert(/LOL/)&#60;/script&#62;</description>
		<content:encoded><![CDATA[<p>@josh</p>
<p>&lt;script&gt;alert(/LOL/)&lt;/script&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh</title>
		<link>http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-1142</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Mon, 18 Feb 2008 09:41:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-1142</guid>
		<description>&#60;script&#62;alert("hi");&#60;/script&#62;</description>
		<content:encoded><![CDATA[<p>&lt;script&gt;alert(&#8221;hi&#8221;);&lt;/script&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-999</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 12 Dec 2007 14:10:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-999</guid>
		<description>Check this out :D 
0/alert(1)</description>
		<content:encoded><![CDATA[<p>Check this out <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /><br />
0/alert(1)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-998</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 12 Dec 2007 09:19:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-998</guid>
		<description>@Marco @Master Ternary Li 

Glad you enjoyed them :) I'll do some more write ups if I find any new vectors

@pdp

Nice :) got anymore?</description>
		<content:encoded><![CDATA[<p>@Marco @Master Ternary Li </p>
<p>Glad you enjoyed them <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> I&#8217;ll do some more write ups if I find any new vectors</p>
<p>@pdp</p>
<p>Nice <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> got anymore?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-995</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 12 Dec 2007 05:43:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-995</guid>
		<description>too long for my taste

0..eval('alert(1)')

works as well :) a few chars less</description>
		<content:encoded><![CDATA[<p>too long for my taste</p>
<p>0..eval(&#8217;alert(1)&#8217;)</p>
<p>works as well <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> a few chars less</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Master Ternary Li</title>
		<link>http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-993</link>
		<dc:creator>Master Ternary Li</dc:creator>
		<pubDate>Wed, 12 Dec 2007 03:17:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/12/12/javascript-for-hackers-part-2/#comment-993</guid>
		<description>good writeup.  it's nice having all of these vectors in place along with the explanatory text.  All the recent bypasses to the PHPIDS have used these techniques (as i'm sure you know since you found them)  :)</description>
		<content:encoded><![CDATA[<p>good writeup.  it&#8217;s nice having all of these vectors in place along with the explanatory text.  All the recent bypasses to the PHPIDS have used these techniques (as i&#8217;m sure you know since you found them)  <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
</channel>
</rss>
