<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: XSS Rays</title>
	<atom:link href="http://www.thespanner.co.uk/2009/03/25/xss-rays/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/</link>
	<description>Javascript blog with messed up syntax inside</description>
	<lastBuildDate>Thu, 26 Jan 2012 01:38:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1850</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 01 Nov 2010 10:38:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1850</guid>
		<description>@jyoti @3p1C

I plan to update the XSS Rays code and release a new version which will hopefully make it more user friendly. In the meantime try editing the XSS_Rays.js file to execute automatically</description>
		<content:encoded><![CDATA[<p>@jyoti @3p1C</p>
<p>I plan to update the XSS Rays code and release a new version which will hopefully make it more user friendly. In the meantime try editing the XSS_Rays.js file to execute automatically</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jyoti bajoria</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1849</link>
		<dc:creator>jyoti bajoria</dc:creator>
		<pubDate>Sun, 31 Oct 2010 06:40:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1849</guid>
		<description>Hi , i tried to use this tool , but nt able  to activate. Clicked on the link in my favourites also &amp; then pressed the combination of keys also as mentioned. Help me in giving detailed steps to start this.</description>
		<content:encoded><![CDATA[<p>Hi , i tried to use this tool , but nt able  to activate. Clicked on the link in my favourites also &amp; then pressed the combination of keys also as mentioned. Help me in giving detailed steps to start this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 3p1C</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1841</link>
		<dc:creator>3p1C</dc:creator>
		<pubDate>Sun, 03 Oct 2010 07:53:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1841</guid>
		<description>I can&#039;t scan something except on 127.0.0.1 despite I changed the xss_rays.js and bookmarklet.php files. When scan start is clicked nothing happens.</description>
		<content:encoded><![CDATA[<p>I can&#8217;t scan something except on 127.0.0.1 despite I changed the xss_rays.js and bookmarklet.php files. When scan start is clicked nothing happens.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1667</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 18 Dec 2009 10:04:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1667</guid>
		<description>Working on a fix for this, there is a bug on firefox but the vectors are intentionally duplicated as there are path injections. A temporary workaround is either comment out the path injections or disable the path option in the vectors.

I should have a fix soon when I get chance to look at the code.</description>
		<content:encoded><![CDATA[<p>Working on a fix for this, there is a bug on firefox but the vectors are intentionally duplicated as there are path injections. A temporary workaround is either comment out the path injections or disable the path option in the vectors.</p>
<p>I should have a fix soon when I get chance to look at the code.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mindsparc</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1663</link>
		<dc:creator>mindsparc</dc:creator>
		<pubDate>Wed, 16 Dec 2009 11:40:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1663</guid>
		<description>Can you please send the details for me too,
it is not working for me</description>
		<content:encoded><![CDATA[<p>Can you please send the details for me too,<br />
it is not working for me</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jagstyle</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1660</link>
		<dc:creator>jagstyle</dc:creator>
		<pubDate>Sat, 12 Dec 2009 01:44:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1660</guid>
		<description>Firefox 3.5.5

I sent an email with full details. Hopefully it&#039;s helpful.</description>
		<content:encoded><![CDATA[<p>Firefox 3.5.5</p>
<p>I sent an email with full details. Hopefully it&#8217;s helpful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1658</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 10 Dec 2009 18:32:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1658</guid>
		<description>@jagstyle 

Please can you tell me which browser you are using? It could be a bug in the way it gets the path</description>
		<content:encoded><![CDATA[<p>@jagstyle </p>
<p>Please can you tell me which browser you are using? It could be a bug in the way it gets the path</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jagstyle</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1657</link>
		<dc:creator>jagstyle</dc:creator>
		<pubDate>Thu, 10 Dec 2009 17:17:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1657</guid>
		<description>without it my test hangs at that point with the linkStatus field displaying &quot;url: undefined&quot;</description>
		<content:encoded><![CDATA[<p>without it my test hangs at that point with the linkStatus field displaying &#8220;url: undefined&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1656</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 10 Dec 2009 07:08:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1656</guid>
		<description>@jagstyle 

Nope this is intentional, I scan the path name of the url</description>
		<content:encoded><![CDATA[<p>@jagstyle </p>
<p>Nope this is intentional, I scan the path name of the url</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jagstyle</title>
		<link>http://www.thespanner.co.uk/2009/03/25/xss-rays/#comment-1652</link>
		<dc:creator>jagstyle</dc:creator>
		<pubDate>Wed, 09 Dec 2009 21:39:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=378#comment-1652</guid>
		<description>isnt the xss function call on Line 175 (scanLinks function) of XSS_RAYS.js missing the href parameter?

observed:
this.xss({pathname:location.pathname,search:location.search, type: &#039;url&#039;});//scan originating url

expected:
this.xss({href:location.href,pathname:location.pathname,search:location.search, type: &#039;url&#039;});//scan originating url</description>
		<content:encoded><![CDATA[<p>isnt the xss function call on Line 175 (scanLinks function) of XSS_RAYS.js missing the href parameter?</p>
<p>observed:<br />
this.xss({pathname:location.pathname,search:location.search, type: &#8216;url&#8217;});//scan originating url</p>
<p>expected:<br />
this.xss({href:location.href,pathname:location.pathname,search:location.search, type: &#8216;url&#8217;});//scan originating url</p>
]]></content:encoded>
	</item>
</channel>
</rss>

