<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Ping pong obfuscation</title>
	<atom:link href="http://www.thespanner.co.uk/2009/11/23/ping-pong-obfuscation/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2009/11/23/ping-pong-obfuscation/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Mon, 15 Mar 2010 22:24:50 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/11/23/ping-pong-obfuscation/#comment-1640</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 24 Nov 2009 08:43:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=561#comment-1640</guid>
		<description>@Holyfield 

LOL I XSS sites now without trying</description>
		<content:encoded><![CDATA[<p>@Holyfield </p>
<p>LOL I XSS sites now without trying</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Holyfield</title>
		<link>http://www.thespanner.co.uk/2009/11/23/ping-pong-obfuscation/#comment-1639</link>
		<dc:creator>Holyfield</dc:creator>
		<pubDate>Tue, 24 Nov 2009 07:12:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=561#comment-1639</guid>
		<description>The RSS feed they publish on the OWASP homepage is executing VBScript popups in IE from your post.  LOL.  http://www.owasp.org/index.php/Main_Page</description>
		<content:encoded><![CDATA[<p>The RSS feed they publish on the OWASP homepage is executing VBScript popups in IE from your post.  LOL.  <a href="http://www.owasp.org/index.php/Main_Page" rel="nofollow">http://www.owasp.org/index.php/Main_Page</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/11/23/ping-pong-obfuscation/#comment-1637</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 23 Nov 2009 14:17:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=561#comment-1637</guid>
		<description>@Wladimir

Ah yeah you're right I forgot to encode the last step but it worked anyway heh. Personally I love obscure features and I think every browser should add their own javascript and css features oh wait... they do :)</description>
		<content:encoded><![CDATA[<p>@Wladimir</p>
<p>Ah yeah you&#8217;re right I forgot to encode the last step but it worked anyway heh. Personally I love obscure features and I think every browser should add their own javascript and css features oh wait&#8230; they do <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wladimir Palant</title>
		<link>http://www.thespanner.co.uk/2009/11/23/ping-pong-obfuscation/#comment-1636</link>
		<dc:creator>Wladimir Palant</dc:creator>
		<pubDate>Mon, 23 Nov 2009 14:08:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=561#comment-1636</guid>
		<description>If http://www.greymagic.com/security/tools/decoder/ isn't lying to me you encoded only twice. Still - oh my, will MS ever throw this crap away? And by "crap" I mean both VBS in a browser and this useless JScript.Encode. But I guess, even with the web moving away from proprietary technologies there are still applications using the IE engine that use VBS. Who knows, I wouldn't be surprised if those even use VBScript.Encode to "protect" their application "source code".</description>
		<content:encoded><![CDATA[<p>If <a href="http://www.greymagic.com/security/tools/decoder/" rel="nofollow">http://www.greymagic.com/security/tools/decoder/</a> isn&#8217;t lying to me you encoded only twice. Still - oh my, will MS ever throw this crap away? And by &#8220;crap&#8221; I mean both VBS in a browser and this useless JScript.Encode. But I guess, even with the web moving away from proprietary technologies there are still applications using the IE engine that use VBS. Who knows, I wouldn&#8217;t be surprised if those even use VBScript.Encode to &#8220;protect&#8221; their application &#8220;source code&#8221;.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
