<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: I know what your friends did last summer</title>
	<atom:link href="http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Wed, 08 Sep 2010 00:31:30 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/#comment-1673</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 22 Dec 2009 10:44:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=299#comment-1673</guid>
		<description>@carstein

I do follow honest but if you used poisoned UTF-7 data with a json request then you can get most of the data by manipulating the javascript. See my CSP hack.

http://www.thespanner.co.uk/2009/11/23/bypassing-csp-for-fun-no-profit/</description>
		<content:encoded><![CDATA[<p>@carstein</p>
<p>I do follow honest but if you used poisoned UTF-7 data with a json request then you can get most of the data by manipulating the javascript. See my CSP hack.</p>
<p><a href="http://www.thespanner.co.uk/2009/11/23/bypassing-csp-for-fun-no-profit/" rel="nofollow">http://www.thespanner.co.uk/2009/11/23/bypassing-csp-for-fun-no-profit/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: carstein</title>
		<link>http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/#comment-1672</link>
		<dc:creator>carstein</dc:creator>
		<pubDate>Mon, 21 Dec 2009 13:42:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=299#comment-1672</guid>
		<description>@Gareth:
I don't think I follow you. UTF-7 where?

The problem is, that in FF3 you can define Setter for an Object.prototype which gets invoked when you recived JSON object (as a JS, so Object() is being initialized). However, due to tweaks in FF3.5 setters are only called when the value is begin set to an existing object, but not during initialization (so it spoils all the joy of JSON hijack).</description>
		<content:encoded><![CDATA[<p>@Gareth:<br />
I don&#8217;t think I follow you. UTF-7 where?</p>
<p>The problem is, that in FF3 you can define Setter for an Object.prototype which gets invoked when you recived JSON object (as a JS, so Object() is being initialized). However, due to tweaks in FF3.5 setters are only called when the value is begin set to an existing object, but not during initialization (so it spoils all the joy of JSON hijack).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/#comment-1671</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 21 Dec 2009 13:13:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=299#comment-1671</guid>
		<description>@carstein

UTF-7 should work until they fix it</description>
		<content:encoded><![CDATA[<p>@carstein</p>
<p>UTF-7 should work until they fix it</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: carstein</title>
		<link>http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/#comment-1670</link>
		<dc:creator>carstein</dc:creator>
		<pubDate>Mon, 21 Dec 2009 11:45:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=299#comment-1670</guid>
		<description>It seems that doesn't work in ff 3.5 because setters are ignored when initializing object. Any ideas how to evade that?</description>
		<content:encoded><![CDATA[<p>It seems that doesn&#8217;t work in ff 3.5 because setters are ignored when initializing object. Any ideas how to evade that?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frank Polenose</title>
		<link>http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/#comment-1558</link>
		<dc:creator>Frank Polenose</dc:creator>
		<pubDate>Thu, 21 May 2009 16:23:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=299#comment-1558</guid>
		<description>I had to have a chuckle at Petes comment! Cheered me right up!</description>
		<content:encoded><![CDATA[<p>I had to have a chuckle at Petes comment! Cheered me right up!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/#comment-1471</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 26 Feb 2009 09:52:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=299#comment-1471</guid>
		<description>@Pete

I think you misunderstood what I actually do. I'm a security researcher.</description>
		<content:encoded><![CDATA[<p>@Pete</p>
<p>I think you misunderstood what I actually do. I&#8217;m a security researcher.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/#comment-1470</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Thu, 26 Feb 2009 09:29:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=299#comment-1470</guid>
		<description>Hi Gareth
I found your name and information on the Security Planet website. Can you help me, or do you know someone who can help me, to crack a gmail password?
Thanks
Pete</description>
		<content:encoded><![CDATA[<p>Hi Gareth<br />
I found your name and information on the Security Planet website. Can you help me, or do you know someone who can help me, to crack a gmail password?<br />
Thanks<br />
Pete</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Maone</title>
		<link>http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/#comment-1408</link>
		<dc:creator>Giorgio Maone</dc:creator>
		<pubDate>Tue, 13 Jan 2009 10:34:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=299#comment-1408</guid>
		<description>Get NoScript 1.8.8.95 from http://noscript.net/getit#devel :)

http://hackademix.net/2009/01/13/you-dont-know-what-my-twitter-leaks/

http://hackademix.net/2009/01/13/twitter-json-hijacking-updates/</description>
		<content:encoded><![CDATA[<p>Get NoScript 1.8.8.95 from <a href="http://noscript.net/getit#devel" rel="nofollow">http://noscript.net/getit#devel</a> <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://hackademix.net/2009/01/13/you-dont-know-what-my-twitter-leaks/" rel="nofollow">http://hackademix.net/2009/01/13/you-dont-know-what-my-twitter-leaks/</a></p>
<p><a href="http://hackademix.net/2009/01/13/twitter-json-hijacking-updates/" rel="nofollow">http://hackademix.net/2009/01/13/twitter-json-hijacking-updates/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/#comment-1407</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 13 Jan 2009 09:19:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=299#comment-1407</guid>
		<description>Twitter has now fixed the problem whoo hoo</description>
		<content:encoded><![CDATA[<p>Twitter has now fixed the problem whoo hoo</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/#comment-1396</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 07 Jan 2009 17:38:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=299#comment-1396</guid>
		<description>* Note You need to be logged into twitter using https in order for the POC to work correct</description>
		<content:encoded><![CDATA[<p>* Note You need to be logged into twitter using https in order for the POC to work correct</p>
]]></content:encoded>
	</item>
</channel>
</rss>
