<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: HTML5 XSS</title>
	<atom:link href="http://www.thespanner.co.uk/2009/03/20/html5-xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2009/03/20/html5-xss/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Wed, 08 Sep 2010 00:47:50 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: eric su</title>
		<link>http://www.thespanner.co.uk/2009/03/20/html5-xss/#comment-1546</link>
		<dc:creator>eric su</dc:creator>
		<pubDate>Wed, 29 Apr 2009 02:47:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=372#comment-1546</guid>
		<description>@cosine
thanks for the Chinese version lol</description>
		<content:encoded><![CDATA[<p>@cosine<br />
thanks for the Chinese version lol</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anne van Kesteren</title>
		<link>http://www.thespanner.co.uk/2009/03/20/html5-xss/#comment-1507</link>
		<dc:creator>Anne van Kesteren</dc:creator>
		<pubDate>Fri, 27 Mar 2009 12:03:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=372#comment-1507</guid>
		<description>Both seem to rely on blacklists being used, which are a pretty bad idea for exactly this reason.</description>
		<content:encoded><![CDATA[<p>Both seem to rely on blacklists being used, which are a pretty bad idea for exactly this reason.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/03/20/html5-xss/#comment-1485</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 23 Mar 2009 09:34:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=372#comment-1485</guid>
		<description>@Ian

It's a new tag to execute automatically, this could be XSS filters that use a blacklist of HTML tags but even so there are new event handlers pointed out by cosine:-

&#60;video src="somevalidvideo" onloadedmetadata="alert(document.cookie);" ondurationchanged="alert(/XSS2/);" ontimeupdate="alert(/XSS1/);"&#62;&#60;/video&#62;</description>
		<content:encoded><![CDATA[<p>@Ian</p>
<p>It&#8217;s a new tag to execute automatically, this could be XSS filters that use a blacklist of HTML tags but even so there are new event handlers pointed out by cosine:-</p>
<p>&lt;video src=&#8221;somevalidvideo&#8221; onloadedmetadata=&#8221;alert(document.cookie);&#8221; ondurationchanged=&#8221;alert(/XSS2/);&#8221; ontimeupdate=&#8221;alert(/XSS1/);&#8221;&gt;&lt;/video&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian Hickson</title>
		<link>http://www.thespanner.co.uk/2009/03/20/html5-xss/#comment-1484</link>
		<dc:creator>Ian Hickson</dc:creator>
		<pubDate>Mon, 23 Mar 2009 03:12:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=372#comment-1484</guid>
		<description>Isn't that the same as:

   &#60;img src=1 onerror=alert(1)&#62;

...?</description>
		<content:encoded><![CDATA[<p>Isn&#8217;t that the same as:</p>
<p>   &lt;img src=1 onerror=alert(1)&gt;</p>
<p>&#8230;?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/03/20/html5-xss/#comment-1483</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sat, 21 Mar 2009 15:26:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=372#comment-1483</guid>
		<description>@cosine

cool thanks!</description>
		<content:encoded><![CDATA[<p>@cosine</p>
<p>cool thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cosine</title>
		<link>http://www.thespanner.co.uk/2009/03/20/html5-xss/#comment-1482</link>
		<dc:creator>cosine</dc:creator>
		<pubDate>Sat, 21 Mar 2009 14:14:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=372#comment-1482</guid>
		<description>it is nice.
and, you can have a look,here:)
http://hi.baidu.com/aullik5/blog/item/0a4af8f3431ab21bb07ec57a.html</description>
		<content:encoded><![CDATA[<p>it is nice.<br />
and, you can have a look,here:)<br />
<a href="http://hi.baidu.com/aullik5/blog/item/0a4af8f3431ab21bb07ec57a.html" rel="nofollow">http://hi.baidu.com/aullik5/blog/item/0a4af8f3431ab21bb07ec57a.html</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
