<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Commenti a: Guida al Cross Site Scripting (XSS)</title>
	<atom:link href="http://www.lucamarchi.com/2008/01/26/guida-al-cross-site-scripting-xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lucamarchi.com/2008/01/26/guida-al-cross-site-scripting-xss/</link>
	<description>Software is like sex, better when is free</description>
	<pubDate>Tue, 06 Jan 2009 06:15:03 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Di: fatmatt</title>
		<link>http://www.lucamarchi.com/2008/01/26/guida-al-cross-site-scripting-xss/comment-page-1/#comment-229</link>
		<dc:creator>fatmatt</dc:creator>
		<pubDate>Mon, 03 Mar 2008 19:43:41 +0000</pubDate>
		<guid isPermaLink="false">http://lucamarchi.wordpress.com/?p=142#comment-229</guid>
		<description>oppure un semplice filtro che strippa i tags? ^^
prova con la funzione String.fromCharCode(), gli dai in pasto una sequenza di decimali e te li converte in ASCII... così ti toglie lcuni problemi di quoting ;)</description>
		<content:encoded><![CDATA[<p>oppure un semplice filtro che strippa i tags? ^^<br />
prova con la funzione String.fromCharCode(), gli dai in pasto una sequenza di decimali e te li converte in ASCII&#8230; così ti toglie lcuni problemi di quoting <img src='http://www.lucamarchi.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: Agokill</title>
		<link>http://www.lucamarchi.com/2008/01/26/guida-al-cross-site-scripting-xss/comment-page-1/#comment-228</link>
		<dc:creator>Agokill</dc:creator>
		<pubDate>Tue, 29 Jan 2008 18:23:53 +0000</pubDate>
		<guid isPermaLink="false">http://lucamarchi.wordpress.com/?p=142#comment-228</guid>
		<description>nn mi fa inserire il codice js ....ci sara un sentinel...</description>
		<content:encoded><![CDATA[<p>nn mi fa inserire il codice js &#8230;.ci sara un sentinel&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: Agokill</title>
		<link>http://www.lucamarchi.com/2008/01/26/guida-al-cross-site-scripting-xss/comment-page-1/#comment-227</link>
		<dc:creator>Agokill</dc:creator>
		<pubDate>Tue, 29 Jan 2008 18:23:10 +0000</pubDate>
		<guid isPermaLink="false">http://lucamarchi.wordpress.com/?p=142#comment-227</guid>
		<description>www.juventus.it

nel search inserire "&#62;alert('_Agokill_ r0x4')

xss trovata nnt cookie stealing

ormai le xss le piazzo ovunque</description>
		<content:encoded><![CDATA[<p><a href="http://www.juventus.it" onclick="javascript:pageTracker._trackPageview('/outbound/comment/www.juventus.it');" rel="nofollow">http://www.juventus.it</a></p>
<p>nel search inserire &#8220;&gt;alert(&#8217;_Agokill_ r0&#215;4&#8242;)</p>
<p>xss trovata nnt cookie stealing</p>
<p>ormai le xss le piazzo ovunque</p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: lucamarchi</title>
		<link>http://www.lucamarchi.com/2008/01/26/guida-al-cross-site-scripting-xss/comment-page-1/#comment-226</link>
		<dc:creator>lucamarchi</dc:creator>
		<pubDate>Sun, 27 Jan 2008 19:59:15 +0000</pubDate>
		<guid isPermaLink="false">http://lucamarchi.wordpress.com/?p=142#comment-226</guid>
		<description>Famosissima :)</description>
		<content:encoded><![CDATA[<p>Famosissima <img src='http://www.lucamarchi.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: elmirco</title>
		<link>http://www.lucamarchi.com/2008/01/26/guida-al-cross-site-scripting-xss/comment-page-1/#comment-225</link>
		<dc:creator>elmirco</dc:creator>
		<pubDate>Sun, 27 Jan 2008 18:20:54 +0000</pubDate>
		<guid isPermaLink="false">http://lucamarchi.wordpress.com/?p=142#comment-225</guid>
		<description>uhmmm &#62;_&#62; come hai fatto ad indovinare?</description>
		<content:encoded><![CDATA[<p>uhmmm &gt;_&gt; come hai fatto ad indovinare?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: lucamarchi</title>
		<link>http://www.lucamarchi.com/2008/01/26/guida-al-cross-site-scripting-xss/comment-page-1/#comment-224</link>
		<dc:creator>lucamarchi</dc:creator>
		<pubDate>Sun, 27 Jan 2008 17:26:12 +0000</pubDate>
		<guid isPermaLink="false">http://lucamarchi.wordpress.com/?p=142#comment-224</guid>
		<description>dici Extremelot?</description>
		<content:encoded><![CDATA[<p>dici Extremelot?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: elmirco</title>
		<link>http://www.lucamarchi.com/2008/01/26/guida-al-cross-site-scripting-xss/comment-page-1/#comment-223</link>
		<dc:creator>elmirco</dc:creator>
		<pubDate>Sun, 27 Jan 2008 16:18:37 +0000</pubDate>
		<guid isPermaLink="false">http://lucamarchi.wordpress.com/?p=142#comment-223</guid>
		<description>ottimo metodo. Ho usato l'XSS su un gdr online (preferisco non dichiararne il nome, ovviamente) e in pratica l'ho smontato :D hihi ma potevo fare di peggio...</description>
		<content:encoded><![CDATA[<p>ottimo metodo. Ho usato l&#8217;XSS su un gdr online (preferisco non dichiararne il nome, ovviamente) e in pratica l&#8217;ho smontato <img src='http://www.lucamarchi.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> hihi ma potevo fare di peggio&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
