<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: XSS is art</title>
	<atom:link href="http://www.thespanner.co.uk/2008/09/11/xss-is-art/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2008/09/11/xss-is-art/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Thu, 11 Mar 2010 17:59:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: thornmaker</title>
		<link>http://www.thespanner.co.uk/2008/09/11/xss-is-art/#comment-1327</link>
		<dc:creator>thornmaker</dc:creator>
		<pubDate>Thu, 02 Oct 2008 00:22:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=224#comment-1327</guid>
		<description>true, but i liked the string of dots for aesthetic reasons.  i've looked around for some other built in functions that work like this but haven't found anything yet.  you?</description>
		<content:encoded><![CDATA[<p>true, but i liked the string of dots for aesthetic reasons.  i&#8217;ve looked around for some other built in functions that work like this but haven&#8217;t found anything yet.  you?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/09/11/xss-is-art/#comment-1326</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 01 Oct 2008 07:07:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=224#comment-1326</guid>
		<description>Nice! :)

Can be shortened too
'xalert(0)x'.replace(/[^x]+/,eval)</description>
		<content:encoded><![CDATA[<p>Nice! <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Can be shortened too<br />
&#8216;xalert(0)x&#8217;.replace(/[^x]+/,eval)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: thornmaker</title>
		<link>http://www.thespanner.co.uk/2008/09/11/xss-is-art/#comment-1325</link>
		<dc:creator>thornmaker</dc:creator>
		<pubDate>Tue, 30 Sep 2008 23:10:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=224#comment-1325</guid>
		<description>The opera trick you showed me earlier today also works in FF3 provided you use eval:

'xalert(0)x'.replace(/a......./,eval)</description>
		<content:encoded><![CDATA[<p>The opera trick you showed me earlier today also works in FF3 provided you use eval:</p>
<p>&#8216;xalert(0)x&#8217;.replace(/a&#8230;&#8230;./,eval)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spletno gostovanje</title>
		<link>http://www.thespanner.co.uk/2008/09/11/xss-is-art/#comment-1320</link>
		<dc:creator>Spletno gostovanje</dc:creator>
		<pubDate>Wed, 24 Sep 2008 11:09:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=224#comment-1320</guid>
		<description>XSS... it really is an art...

I agree :)</description>
		<content:encoded><![CDATA[<p>XSS&#8230; it really is an art&#8230;</p>
<p>I agree <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erik</title>
		<link>http://www.thespanner.co.uk/2008/09/11/xss-is-art/#comment-1311</link>
		<dc:creator>Erik</dc:creator>
		<pubDate>Mon, 15 Sep 2008 14:09:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=224#comment-1311</guid>
		<description>i think xss it's art too :xD</description>
		<content:encoded><![CDATA[<p>i think xss it&#8217;s art too :xD</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DoctorDan</title>
		<link>http://www.thespanner.co.uk/2008/09/11/xss-is-art/#comment-1309</link>
		<dc:creator>DoctorDan</dc:creator>
		<pubDate>Fri, 12 Sep 2008 22:10:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=224#comment-1309</guid>
		<description>Oh, you tricky, tricky man.
XSS is art, and in this case is certainly beauty as well :P</description>
		<content:encoded><![CDATA[<p>Oh, you tricky, tricky man.<br />
XSS is art, and in this case is certainly beauty as well <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gilzow</title>
		<link>http://www.thespanner.co.uk/2008/09/11/xss-is-art/#comment-1308</link>
		<dc:creator>Gilzow</dc:creator>
		<pubDate>Fri, 12 Sep 2008 20:59:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=224#comment-1308</guid>
		<description>ok, NOW it makes more sense.  I noticed that the smoke-screen was saying that it had detected an injection.  Thanks for the clarification.

*Very* interesting stuff that you are coming up with.  Let's hope the REAL bad guys are two steps behind you.</description>
		<content:encoded><![CDATA[<p>ok, NOW it makes more sense.  I noticed that the smoke-screen was saying that it had detected an injection.  Thanks for the clarification.</p>
<p>*Very* interesting stuff that you are coming up with.  Let&#8217;s hope the REAL bad guys are two steps behind you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/09/11/xss-is-art/#comment-1307</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 12 Sep 2008 18:25:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=224#comment-1307</guid>
		<description>Yeah that's because Mario already fixed it ;)

Here's a demo of how it did work:-
&lt;a href="http://www.businessinfo.co.uk/labs/hackvertor/hackvertor.php?input=Ly9IaXQgdGhlICJleGVjdXRlIG91dHB1dCBidXR0b24KbmFtZT0nYWxlcnQoMSknOwpkZWZhdWx0IHhtbCBuYW1lc3BhY2U9dG9vbGJhcixiPTEmJnRoaXMuYXRvYgpkZWZhdWx0IHhtbCBuYW1lc3BhY2U9dG9vbGJhcixlMj1iKCdaWFpoYkEnKQpkZWZhdWx0IHhtbCBuYW1lc3BhY2U9dG9vbGJhcixlPXRoaXNbdG9vbGJhcixlMl0KZGVmYXVsdCB4bWwgbmFtZXNwYWNlPXRvb2xiYXIseT0xJiZuYW1lCmRlZmF1bHQgeG1sIG5hbWVzcGFjZT10b29sYmFyCmRlZmF1bHQgeG1sIG5hbWVzcGFjZT1lKHkp" rel="nofollow"&gt;demo&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Yeah that&#8217;s because Mario already fixed it <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Here&#8217;s a demo of how it did work:-<br />
<a href="http://www.businessinfo.co.uk/labs/hackvertor/hackvertor.php?input=Ly9IaXQgdGhlICJleGVjdXRlIG91dHB1dCBidXR0b24KbmFtZT0nYWxlcnQoMSknOwpkZWZhdWx0IHhtbCBuYW1lc3BhY2U9dG9vbGJhcixiPTEmJnRoaXMuYXRvYgpkZWZhdWx0IHhtbCBuYW1lc3BhY2U9dG9vbGJhcixlMj1iKCdaWFpoYkEnKQpkZWZhdWx0IHhtbCBuYW1lc3BhY2U9dG9vbGJhcixlPXRoaXNbdG9vbGJhcixlMl0KZGVmYXVsdCB4bWwgbmFtZXNwYWNlPXRvb2xiYXIseT0xJiZuYW1lCmRlZmF1bHQgeG1sIG5hbWVzcGFjZT10b29sYmFyCmRlZmF1bHQgeG1sIG5hbWVzcGFjZT1lKHkp" rel="nofollow">demo</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gilzow</title>
		<link>http://www.thespanner.co.uk/2008/09/11/xss-is-art/#comment-1306</link>
		<dc:creator>Gilzow</dc:creator>
		<pubDate>Fri, 12 Sep 2008 17:01:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=224#comment-1306</guid>
		<description>ok, i see now where name comes into play, but the link to the payload, in firefox, doesnt fire off the alert.   So i'm still a bit confused...</description>
		<content:encoded><![CDATA[<p>ok, i see now where name comes into play, but the link to the payload, in firefox, doesnt fire off the alert.   So i&#8217;m still a bit confused&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/09/11/xss-is-art/#comment-1305</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 12 Sep 2008 15:41:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=224#comment-1305</guid>
		<description>@Gilzow 

:) thanks

I didn't include the actual payload until later which uses window.name. It can be passed from site to site so it's a good way of passing a XSS payload.

Line 5 does nothing it is there to get round phpids centrifuge detection. Centrifuge detects vectors when they look like previous ones. The toolbar reference is window.toolbar in Firefox and is used to again bypass centrifuge, any global object/function can be called on one line like this.

Look at comment 4 to see how window.name can be passed as a payload.</description>
		<content:encoded><![CDATA[<p>@Gilzow </p>
<p> <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> thanks</p>
<p>I didn&#8217;t include the actual payload until later which uses window.name. It can be passed from site to site so it&#8217;s a good way of passing a XSS payload.</p>
<p>Line 5 does nothing it is there to get round phpids centrifuge detection. Centrifuge detects vectors when they look like previous ones. The toolbar reference is window.toolbar in Firefox and is used to again bypass centrifuge, any global object/function can be called on one line like this.</p>
<p>Look at comment 4 to see how window.name can be passed as a payload.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
