<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New XSS vector</title>
	<atom:link href="http://www.thespanner.co.uk/2008/08/26/new-xss-vector/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/</link>
	<description>Javascript blog with messed up syntax inside</description>
	<lastBuildDate>Thu, 26 Jan 2012 01:38:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: ÐœÐ¸Ð»Ð°Ð½</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1356</link>
		<dc:creator>ÐœÐ¸Ð»Ð°Ð½</dc:creator>
		<pubDate>Mon, 10 Nov 2008 11:53:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1356</guid>
		<description>Also works in IE8. thx</description>
		<content:encoded><![CDATA[<p>Also works in IE8. thx</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: naughty.spanky.boy</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1294</link>
		<dc:creator>naughty.spanky.boy</dc:creator>
		<pubDate>Fri, 29 Aug 2008 07:51:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1294</guid>
		<description>Hi,

I have an idea, for protecting websites against XSS attacks. Why not ban all the tags, and allow only predefined ones with &#039;special&#039; care. Like, allow img only with src that starts with a http://, or allow a href but only if http https is found.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I have an idea, for protecting websites against XSS attacks. Why not ban all the tags, and allow only predefined ones with &#8216;special&#8217; care. Like, allow img only with src that starts with a http://, or allow a href but only if http https is found.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1293</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 28 Aug 2008 10:48:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1293</guid>
		<description>@jim

Hey jim thanks, why don&#039;t you put a online demo of ESAPI like &lt;a href=&quot;http://demo.phpids.org/&quot; rel=&quot;nofollow&quot;&gt;Mario&#039;s smoketest&lt;/a&gt;? Then we&#039;ll see how good it is :)</description>
		<content:encoded><![CDATA[<p>@jim</p>
<p>Hey jim thanks, why don&#8217;t you put a online demo of ESAPI like <a href="http://demo.phpids.org/" rel="nofollow">Mario&#8217;s smoketest</a>? Then we&#8217;ll see how good it is <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Manico</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1292</link>
		<dc:creator>Jim Manico</dc:creator>
		<pubDate>Wed, 27 Aug 2008 22:56:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1292</guid>
		<description>If only everyone had the power of

ESAPI.encoder().encodeForHTMLAttribute(String userData);

Great find, good job!</description>
		<content:encoded><![CDATA[<p>If only everyone had the power of</p>
<p>ESAPI.encoder().encodeForHTMLAttribute(String userData);</p>
<p>Great find, good job!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: superhei</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1290</link>
		<dc:creator>superhei</dc:creator>
		<pubDate>Wed, 27 Aug 2008 05:17:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1290</guid>
		<description>hi Gareth Heyes

good job 
it work in ie6/7/8</description>
		<content:encoded><![CDATA[<p>hi Gareth Heyes</p>
<p>good job<br />
it work in ie6/7/8</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1289</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 26 Aug 2008 21:54:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1289</guid>
		<description>Emailed rsnake but they won&#039;t be added to the cheat sheet because there is no new event handler and javascript: is already mentioned</description>
		<content:encoded><![CDATA[<p>Emailed rsnake but they won&#8217;t be added to the cheat sheet because there is no new event handler and javascript: is already mentioned</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1288</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 26 Aug 2008 21:25:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1288</guid>
		<description>Also works in IE8

I&#039;ll email him</description>
		<content:encoded><![CDATA[<p>Also works in IE8</p>
<p>I&#8217;ll email him</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: x-tense</title>
		<link>http://www.thespanner.co.uk/2008/08/26/new-xss-vector/#comment-1287</link>
		<dc:creator>x-tense</dc:creator>
		<pubDate>Tue, 26 Aug 2008 21:16:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=221#comment-1287</guid>
		<description>You can remove the value of src attribute:

&lt;isindex type=image onerror=alert(1) src=&gt;

(only tested on IE6)

Did you ask to rsnake to add this vector ?</description>
		<content:encoded><![CDATA[<p>You can remove the value of src attribute:</p>
<p>&lt;isindex type=image onerror=alert(1) src=&gt;</p>
<p>(only tested on IE6)</p>
<p>Did you ask to rsnake to add this vector ?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

