<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: New XSS vector</title>
	<atom:link href="http://www.thespanner.co.uk/2008/08/26/new-xss-vector/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Wed, 08 Sep 2010 00:33:14 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Милан</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1356</link>
		<dc:creator>Милан</dc:creator>
		<pubDate>Mon, 10 Nov 2008 11:53:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1356</guid>
		<description>Also works in IE8. thx</description>
		<content:encoded><![CDATA[<p>Also works in IE8. thx</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: naughty.spanky.boy</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1294</link>
		<dc:creator>naughty.spanky.boy</dc:creator>
		<pubDate>Fri, 29 Aug 2008 07:51:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1294</guid>
		<description>Hi,

I have an idea, for protecting websites against XSS attacks. Why not ban all the tags, and allow only predefined ones with 'special' care. Like, allow img only with src that starts with a http://, or allow a href but only if http https is found.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I have an idea, for protecting websites against XSS attacks. Why not ban all the tags, and allow only predefined ones with &#8217;special&#8217; care. Like, allow img only with src that starts with a <a href="http://" rel="nofollow">http://</a>, or allow a href but only if http https is found.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1293</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 28 Aug 2008 10:48:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1293</guid>
		<description>@jim

Hey jim thanks, why don't you put a online demo of ESAPI like &lt;a href="http://demo.phpids.org/" rel="nofollow"&gt;Mario's smoketest&lt;/a&gt;? Then we'll see how good it is :)</description>
		<content:encoded><![CDATA[<p>@jim</p>
<p>Hey jim thanks, why don&#8217;t you put a online demo of ESAPI like <a href="http://demo.phpids.org/" rel="nofollow">Mario&#8217;s smoketest</a>? Then we&#8217;ll see how good it is <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Manico</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1292</link>
		<dc:creator>Jim Manico</dc:creator>
		<pubDate>Wed, 27 Aug 2008 22:56:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1292</guid>
		<description>If only everyone had the power of

ESAPI.encoder().encodeForHTMLAttribute(String userData);

Great find, good job!</description>
		<content:encoded><![CDATA[<p>If only everyone had the power of</p>
<p>ESAPI.encoder().encodeForHTMLAttribute(String userData);</p>
<p>Great find, good job!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: superhei</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1290</link>
		<dc:creator>superhei</dc:creator>
		<pubDate>Wed, 27 Aug 2008 05:17:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1290</guid>
		<description>hi Gareth Heyes

good job 
it work in ie6/7/8</description>
		<content:encoded><![CDATA[<p>hi Gareth Heyes</p>
<p>good job<br />
it work in ie6/7/8</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1289</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 26 Aug 2008 21:54:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1289</guid>
		<description>Emailed rsnake but they won't be added to the cheat sheet because there is no new event handler and javascript: is already mentioned</description>
		<content:encoded><![CDATA[<p>Emailed rsnake but they won&#8217;t be added to the cheat sheet because there is no new event handler and javascript: is already mentioned</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1288</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 26 Aug 2008 21:25:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1288</guid>
		<description>Also works in IE8

I'll email him</description>
		<content:encoded><![CDATA[<p>Also works in IE8</p>
<p>I&#8217;ll email him</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: x-tense</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1287</link>
		<dc:creator>x-tense</dc:creator>
		<pubDate>Tue, 26 Aug 2008 21:16:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1287</guid>
		<description>You can remove the value of src attribute:

&#60;isindex type=image onerror=alert(1) src=&#62;

(only tested on IE6)

Did you ask to rsnake to add this vector ?</description>
		<content:encoded><![CDATA[<p>You can remove the value of src attribute:</p>
<p>&lt;isindex type=image onerror=alert(1) src=&gt;</p>
<p>(only tested on IE6)</p>
<p>Did you ask to rsnake to add this vector ?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
