<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments for The Spanner</title>
	<atom:link href="http://www.thespanner.co.uk/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Tue, 16 Mar 2010 17:45:45 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>Comment on Inline UTF-7 E4X javascript hijacking by Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/02/24/inline-utf-7-e4x-javascript-hijacking/#comment-1705</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 02 Mar 2010 22:00:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=361#comment-1705</guid>
		<description>@Eli

Interesting the E4X spec says this shouldn't be possible, have you got a POC? 

Anyway it's possible to get the rest of the doc using setTimeout and assigning the remaining HTML to a E4X variable</description>
		<content:encoded><![CDATA[<p>@Eli</p>
<p>Interesting the E4X spec says this shouldn&#8217;t be possible, have you got a POC? </p>
<p>Anyway it&#8217;s possible to get the rest of the doc using setTimeout and assigning the remaining HTML to a E4X variable</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Inline UTF-7 E4X javascript hijacking by Eli Grey</title>
		<link>http://www.thespanner.co.uk/2009/02/24/inline-utf-7-e4x-javascript-hijacking/#comment-1704</link>
		<dc:creator>Eli Grey</dc:creator>
		<pubDate>Tue, 02 Mar 2010 21:50:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=361#comment-1704</guid>
		<description>You can hijack the rest of the XML by defining a setter on XML.prototype. Then you could do xml.function::hijack = rest-of-the-xml.</description>
		<content:encoded><![CDATA[<p>You can hijack the rest of the XML by defining a setter on XML.prototype. Then you could do xml.function::hijack = rest-of-the-xml.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SpamBam! by بلياردو</title>
		<link>http://www.thespanner.co.uk/2007/02/12/spambam/#comment-1700</link>
		<dc:creator>بلياردو</dc:creator>
		<pubDate>Fri, 19 Feb 2010 23:24:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/02/12/spambam/#comment-1700</guid>
		<description>WordPress оченьхорошо защищает от спама, за что ему огромное спасибо</description>
		<content:encoded><![CDATA[<p>WordPress оченьхорошо защищает от спама, за что ему огромное спасибо</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Detecting browsers javascript hacks by Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/01/29/detecting-browsers-javascript-hacks/#comment-1698</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 18 Feb 2010 22:09:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=340#comment-1698</guid>
		<description>@noob

Yeah probably a typo nobody is perfect :)</description>
		<content:encoded><![CDATA[<p>@noob</p>
<p>Yeah probably a typo nobody is perfect <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Detecting browsers javascript hacks by noob</title>
		<link>http://www.thespanner.co.uk/2009/01/29/detecting-browsers-javascript-hacks/#comment-1697</link>
		<dc:creator>noob</dc:creator>
		<pubDate>Thu, 18 Feb 2010 17:53:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=340#comment-1697</guid>
		<description>i was wondering why are you using ((/a/.toString+'')) instead of (/a/.toString+'') ?</description>
		<content:encoded><![CDATA[<p>i was wondering why are you using ((/a/.toString+&#8221;)) instead of (/a/.toString+&#8221;) ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The safety net by Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2010/02/04/the-safety-net/#comment-1695</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 15 Feb 2010 08:07:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=586#comment-1695</guid>
		<description>@Robert

The idea would be to only enable the SN when a specific action is taken like clicking on a link that takes you to a external web site, the SN is decided depending on the meta or http header of the parent site. For example twitter should have a meta identify as Social Network. 

This would allow sites to function as normal but prevent exploitation by limiting the user's "first click"</description>
		<content:encoded><![CDATA[<p>@Robert</p>
<p>The idea would be to only enable the SN when a specific action is taken like clicking on a link that takes you to a external web site, the SN is decided depending on the meta or http header of the parent site. For example twitter should have a meta identify as Social Network. </p>
<p>This would allow sites to function as normal but prevent exploitation by limiting the user&#8217;s &#8220;first click&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The safety net by Robert Jakobson</title>
		<link>http://www.thespanner.co.uk/2010/02/04/the-safety-net/#comment-1694</link>
		<dc:creator>Robert Jakobson</dc:creator>
		<pubDate>Mon, 15 Feb 2010 05:32:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=586#comment-1694</guid>
		<description>This is exactly what the web needs, I dare say I have thought of something of this kind  myself, however there is the question of how this would fit the kind of old "new trend" of having the user manipulating their own data ( or data of their friends / etc .. ) from one application inside another ? 

Therefore, there should be an ability to have a list of outside inputs or URL-s which are "trusted" and "accepted" sources in the context of any concrete safety net.</description>
		<content:encoded><![CDATA[<p>This is exactly what the web needs, I dare say I have thought of something of this kind  myself, however there is the question of how this would fit the kind of old &#8220;new trend&#8221; of having the user manipulating their own data ( or data of their friends / etc .. ) from one application inside another ? </p>
<p>Therefore, there should be an ability to have a list of outside inputs or URL-s which are &#8220;trusted&#8221; and &#8220;accepted&#8221; sources in the context of any concrete safety net.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Detecting browsers javascript hacks by Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2009/01/29/detecting-browsers-javascript-hacks/#comment-1691</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 09 Feb 2010 14:13:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=340#comment-1691</guid>
		<description>@superhei 

Yep Mozilla decided this was a security issue when I reported it so these techniques can no longer be expected to work in later versions of Firefox</description>
		<content:encoded><![CDATA[<p>@superhei </p>
<p>Yep Mozilla decided this was a security issue when I reported it so these techniques can no longer be expected to work in later versions of Firefox</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Detecting browsers javascript hacks by superhei</title>
		<link>http://www.thespanner.co.uk/2009/01/29/detecting-browsers-javascript-hacks/#comment-1690</link>
		<dc:creator>superhei</dc:creator>
		<pubDate>Tue, 09 Feb 2010 14:10:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=340#comment-1690</guid>
		<description>/a/[-1]=='a' isn't work on firefox3.6</description>
		<content:encoded><![CDATA[<p>/a/[-1]==&#8217;a&#8217; isn&#8217;t work on firefox3.6</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook sandbox escape by gfy</title>
		<link>http://www.thespanner.co.uk/2010/01/29/facebook-sandbox-escape/#comment-1688</link>
		<dc:creator>gfy</dc:creator>
		<pubDate>Sat, 30 Jan 2010 12:01:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=580#comment-1688</guid>
		<description>"The vector has now been fixed by Facebook."

RAT</description>
		<content:encoded><![CDATA[<p>&#8220;The vector has now been fixed by Facebook.&#8221;</p>
<p>RAT</p>
]]></content:encoded>
	</item>
</channel>
</rss>
