<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Michael Gracie &#187; XSS</title>
	<atom:link href="http://michaelgracie.com/tag/xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://michaelgracie.com</link>
	<description>Technology, Finance, Fly-Fishing, and vain attempts to merge the three</description>
	<lastBuildDate>Mon, 06 Sep 2010 04:28:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<cloud domain='michaelgracie.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Google search box opens up XSS vulnerability</title>
		<link>http://michaelgracie.com/2006/11/29/google-search-box-opens-up-xss-vulnerability/</link>
		<comments>http://michaelgracie.com/2006/11/29/google-search-box-opens-up-xss-vulnerability/#comments</comments>
		<pubDate>Wed, 29 Nov 2006 16:30:04 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
				<category><![CDATA[Spamroll]]></category>
		<category><![CDATA[google search appliance]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/google-search-box-opens-up-xss-vulnerability/</guid>
		<description><![CDATA[Couldn&#8217;t think of a sarcastic title for this post, and I don&#8217;t think it makes a heck of a lot of difference anyway &#8211; it&#8217;s just news, and not much to worry about. The Google Search Appliance, that box companies throw on the rack to help them weed through data on their own networks, opens [...]]]></description>
			<content:encoded><![CDATA[<p>Couldn&#8217;t think of a sarcastic title for this post, and I don&#8217;t think it makes a heck of a lot of difference anyway &#8211; it&#8217;s just news, and not much to worry about.  The Google Search Appliance, that box companies throw on the rack to help them weed through data on their own networks, <a title="News - IT Security News - SC Magazine UK" href="http://www.scmagazine.com/uk/news/article/606941/google-search-device-flaw-leaves-sites-open-phishing-attacks/">opens up a cross-site scripting vulnerability</a> that can allow phishers to promote their own scams.</p>
<p>Google has already issued a fix, and if the organizations using the system don&#8217;t want to pay attention, it becomes their problem alone.</p>
<hr style="border-top:black solid 1px" /><strong>©2004-10 <a href="http://michaelgracie.com">Michael Gracie</a> - Technology, Finance, Fly-Fishing, and vain attempts to merge the three.</strong> Use of this feed is for personal non-commercial use only - any and all other uses may be subject to court-ordered asylum commitment.<br />]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/11/29/google-search-box-opens-up-xss-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cross-site scripting goes primetime</title>
		<link>http://michaelgracie.com/2006/09/25/cross-site-scripting-goes-primetime/</link>
		<comments>http://michaelgracie.com/2006/09/25/cross-site-scripting-goes-primetime/#comments</comments>
		<pubDate>Mon, 25 Sep 2006 16:40:05 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
				<category><![CDATA[Spamroll]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/cross-site-scripting-goes-primetime/</guid>
		<description><![CDATA[Cross-site scripting attacks are hitting major websites, including MySpace, YouTube, and even venerable oldies like MSN, Dell, and Apple. XSS attacks were long a tool of cute little script kiddies who malformed sites for the joy of their cute little friends. As a result, some still question how big the threat really is. Just when [...]]]></description>
			<content:encoded><![CDATA[<p>Cross-site scripting attacks are <a title="Slashdot | Cross-Site Scripting Hits Major Sites" href="http://it.slashdot.org/article.pl?sid=06/09/25/1440220&#038;from=rss" target="">hitting major websites</a>, including MySpace, YouTube, and even venerable oldies like MSN, Dell, and Apple.</p>
<p>XSS attacks were long a tool of cute little script kiddies who malformed sites for the joy of their cute little friends.  As a result, some <a title="XSS flaws jump to top of CVE rankings, but is the threat overblown? - IT Security News - SC Magazine US" href="http://www.scmagazine.com/us/news/article/594339/xss-flaws-jump-top-cve-rankings-threat-overblown/" target="">still question</a> how big the threat really is.</p>
<p>Just when you get complacent, someone is going to figure out how to make money from a vulnerability.  Then shit hits the fan, and a bunch of overpriced consultants run in to save the day while someone&#8217;s multi-million a year ecommerce site flails, frames displaying Winnie-the-Pooh notwithstanding.</p>
<p>XSS, welcome to the corporate world.</p>
<hr style="border-top:black solid 1px" /><strong>©2004-10 <a href="http://michaelgracie.com">Michael Gracie</a> - Technology, Finance, Fly-Fishing, and vain attempts to merge the three.</strong> Use of this feed is for personal non-commercial use only - any and all other uses may be subject to court-ordered asylum commitment.<br />]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/09/25/cross-site-scripting-goes-primetime/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Script Kiddie Cookbook</title>
		<link>http://michaelgracie.com/2006/08/15/the-script-kiddie-cookbook/</link>
		<comments>http://michaelgracie.com/2006/08/15/the-script-kiddie-cookbook/#comments</comments>
		<pubDate>Tue, 15 Aug 2006 13:42:32 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
				<category><![CDATA[Spamroll]]></category>
		<category><![CDATA[cross site scripting]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/the-script-kiddie-cookbook/</guid>
		<description><![CDATA[When a script kiddie injects a chunk of javascript or a frame into a website, it generally gets fixed pretty quickly and everyone laughs about it. Maybe developers should think twice &#8211; those XSS exploits can cause a lot of harm, as detailed here. I just got though jumping through hoops, getting special characters stripped [...]]]></description>
			<content:encoded><![CDATA[<p>When a script kiddie injects a chunk of javascript or a frame into a website, it generally gets fixed pretty quickly and everyone laughs about it.  Maybe developers should think twice &#8211; those XSS exploits can cause a lot of harm, <a title="XSS, Cookies, and Session ID Authentication Three Ingredients for a Successful Hack The XSS Vulnerability" href="http://www.informit.com/articles/article.asp?p=603037&#038;rl=1" target="">as detailed here</a>.</p>
<p>I just got though jumping through hoops, getting special characters stripped from forms galore in an app.  It was a pain in the butt, and the whole time I was thinking &#8220;who cares&#8221; if someone sticks a random reference to some other site, or a smiley faced pop-up.  I did the work anyway, but I certainly won&#8217;t be shrugging off the risks anymore.</p>
<p>***UPDATE***</p>
<p>Brian Krebs has <a title="Cross-Site Scripting Flaws Abound - Security Fix" href="http://blog.washingtonpost.com/securityfix/2006/08/crosssite_scripting_flaws_abou.html?referrer=email&#038;referrer=email&#038;referrer=email" target="">uncovered</a> a few big sites that are affected by XSS.  The NSA?  Heh.</p>
<hr style="border-top:black solid 1px" /><strong>©2004-10 <a href="http://michaelgracie.com">Michael Gracie</a> - Technology, Finance, Fly-Fishing, and vain attempts to merge the three.</strong> Use of this feed is for personal non-commercial use only - any and all other uses may be subject to court-ordered asylum commitment.<br />]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/08/15/the-script-kiddie-cookbook/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
