<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: XSS Rays</title>
	<atom:link href="http://www.thespanner.co.uk/2009/03/25/xss-rays/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Wed, 08 Sep 2010 00:41:47 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1667</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 18 Dec 2009 10:04:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1667</guid>
		<description>Working on a fix for this, there is a bug on firefox but the vectors are intentionally duplicated as there are path injections. A temporary workaround is either comment out the path injections or disable the path option in the vectors.

I should have a fix soon when I get chance to look at the code.</description>
		<content:encoded><![CDATA[<p>Working on a fix for this, there is a bug on firefox but the vectors are intentionally duplicated as there are path injections. A temporary workaround is either comment out the path injections or disable the path option in the vectors.</p>
<p>I should have a fix soon when I get chance to look at the code.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mindsparc</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1663</link>
		<dc:creator>mindsparc</dc:creator>
		<pubDate>Wed, 16 Dec 2009 11:40:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1663</guid>
		<description>Can you please send the details for me too,
it is not working for me</description>
		<content:encoded><![CDATA[<p>Can you please send the details for me too,<br />
it is not working for me</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jagstyle</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1660</link>
		<dc:creator>jagstyle</dc:creator>
		<pubDate>Sat, 12 Dec 2009 01:44:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1660</guid>
		<description>Firefox 3.5.5

I sent an email with full details. Hopefully it's helpful.</description>
		<content:encoded><![CDATA[<p>Firefox 3.5.5</p>
<p>I sent an email with full details. Hopefully it&#8217;s helpful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1658</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 10 Dec 2009 18:32:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1658</guid>
		<description>@jagstyle 

Please can you tell me which browser you are using? It could be a bug in the way it gets the path</description>
		<content:encoded><![CDATA[<p>@jagstyle </p>
<p>Please can you tell me which browser you are using? It could be a bug in the way it gets the path</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jagstyle</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1657</link>
		<dc:creator>jagstyle</dc:creator>
		<pubDate>Thu, 10 Dec 2009 17:17:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1657</guid>
		<description>without it my test hangs at that point with the linkStatus field displaying "url: undefined"</description>
		<content:encoded><![CDATA[<p>without it my test hangs at that point with the linkStatus field displaying &#8220;url: undefined&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1656</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 10 Dec 2009 07:08:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1656</guid>
		<description>@jagstyle 

Nope this is intentional, I scan the path name of the url</description>
		<content:encoded><![CDATA[<p>@jagstyle </p>
<p>Nope this is intentional, I scan the path name of the url</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jagstyle</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1652</link>
		<dc:creator>jagstyle</dc:creator>
		<pubDate>Wed, 09 Dec 2009 21:39:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1652</guid>
		<description>isnt the xss function call on Line 175 (scanLinks function) of XSS_RAYS.js missing the href parameter?

observed:
this.xss({pathname:location.pathname,search:location.search, type: 'url'});//scan originating url

expected:
this.xss({href:location.href,pathname:location.pathname,search:location.search, type: 'url'});//scan originating url</description>
		<content:encoded><![CDATA[<p>isnt the xss function call on Line 175 (scanLinks function) of XSS_RAYS.js missing the href parameter?</p>
<p>observed:<br />
this.xss({pathname:location.pathname,search:location.search, type: &#8216;url&#8217;});//scan originating url</p>
<p>expected:<br />
this.xss({href:location.href,pathname:location.pathname,search:location.search, type: &#8216;url&#8217;});//scan originating url</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HTD</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1627</link>
		<dc:creator>HTD</dc:creator>
		<pubDate>Thu, 17 Sep 2009 18:56:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1627</guid>
		<description>Hi,

i liked your article very much,
and i would also like to point out another article on this blog -&#62;
&lt;a href="http://hackerthedude.blogspot.com/2009/09/xss-phishing.html" rel="nofollow"&gt;XSS Phishing&lt;/a&gt;

Thanks</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>i liked your article very much,<br />
and i would also like to point out another article on this blog -&gt;<br />
<a href="http://hackerthedude.blogspot.com/2009/09/xss-phishing.html" rel="nofollow">XSS Phishing</a></p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1511</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 30 Mar 2009 08:18:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1511</guid>
		<description>Latest version is now 0.5.5</description>
		<content:encoded><![CDATA[<p>Latest version is now 0.5.5</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Balaji D Loganathan</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1510</link>
		<dc:creator>Balaji D Loganathan</dc:creator>
		<pubDate>Sat, 28 Mar 2009 18:01:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1510</guid>
		<description>so nice.</description>
		<content:encoded><![CDATA[<p>so nice.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
