<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for RedTeam</title>
	<atom:link href="http://blogs.23.nu/RedTeam/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.23.nu/RedTeam</link>
	<description>Seeing your network from the attacker&#039;s perspective</description>
	<lastBuildDate>Mon, 22 Mar 2010 16:12:44 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Reading the fine manual by RedTeam : The Documentation Is Always Right. Right?</title>
		<link>http://blogs.23.nu/RedTeam/2006/06/antville-12189/comment-page-1/#comment-1140</link>
		<dc:creator>RedTeam : The Documentation Is Always Right. Right?</dc:creator>
		<pubDate>Mon, 22 Mar 2010 16:12:44 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/RedTeam/2006/06/antville-12189/#comment-1140</guid>
		<description>[...] wrote a similar blog post way back in 2006 titled &#8220;Reading the fine Manual&#8221;, where we saw that the PHP ereg*() functions are not binary safe. In that case however, the [...]</description>
		<content:encoded><![CDATA[<p>[...] wrote a similar blog post way back in 2006 titled &#8220;Reading the fine Manual&#8221;, where we saw that the PHP ereg*() functions are not binary safe. In that case however, the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Rent a Hacker by RedTeam : Security Policy Gone Wrong</title>
		<link>http://blogs.23.nu/RedTeam/2009/05/rent-a-hacker/comment-page-1/#comment-1045</link>
		<dc:creator>RedTeam : Security Policy Gone Wrong</dc:creator>
		<pubDate>Fri, 12 Mar 2010 15:43:35 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=620#comment-1045</guid>
		<description>[...] listed on our homepage, something you usually do not see with other companies. You may want to read this older blog post about pentesting as a me-too-business too, a topic also relevant when thinking about trust.   Posted by phof on Friday, March 12, 2010, [...]</description>
		<content:encoded><![CDATA[<p>[...] listed on our homepage, something you usually do not see with other companies. You may want to read this older blog post about pentesting as a me-too-business too, a topic also relevant when thinking about trust.   Posted by phof on Friday, March 12, 2010, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scanning JBoss AS for open Invokers by Patrick Hof</title>
		<link>http://blogs.23.nu/RedTeam/2010/02/scanning-jboss-as-for-open-invokers/comment-page-1/#comment-822</link>
		<dc:creator>Patrick Hof</dc:creator>
		<pubDate>Wed, 03 Feb 2010 09:48:50 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=938#comment-822</guid>
		<description>BTW: If anyone of you owns a JBoss Community account, the english JBoss Wiki page at

http://community.jboss.org/wiki/SecureJboss

still links the German and not the English version of the paper. The English paper is at

http://www.redteam-pentesting.de/publications/2009-11-30-Whitepaper_Whos-the-JBoss-now_RedTeam-Pentesting_EN.pdf</description>
		<content:encoded><![CDATA[<p>BTW: If anyone of you owns a JBoss Community account, the english JBoss Wiki page at</p>
<p><a href="http://community.jboss.org/wiki/SecureJboss" rel="nofollow">http://community.jboss.org/wiki/SecureJboss</a></p>
<p>still links the German and not the English version of the paper. The English paper is at</p>
<p><a href="http://www.redteam-pentesting.de/publications/2009-11-30-Whitepaper_Whos-the-JBoss-now_RedTeam-Pentesting_EN.pdf" rel="nofollow">http://www.redteam-pentesting.de/publications/2009-11-30-Whitepaper_Whos-the-JBoss-now_RedTeam-Pentesting_EN.pdf</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SSL Man-in-the-Middle PoC to come by Week 51 in Review &#124; Infosec Events</title>
		<link>http://blogs.23.nu/RedTeam/2009/12/ssl-man-in-the-middle-poc-to-come/comment-page-1/#comment-731</link>
		<dc:creator>Week 51 in Review &#124; Infosec Events</dc:creator>
		<pubDate>Mon, 28 Dec 2009 10:13:53 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=877#comment-731</guid>
		<description>[...] SSL Man-in-the-Middle PoC to come &#8211; blogs.23.nu/RedTeam Red Team to release a SSL/TLS authentication man-in-the-middle attack [...]</description>
		<content:encoded><![CDATA[<p>[...] SSL Man-in-the-Middle PoC to come &#8211; blogs.23.nu/RedTeam Red Team to release a SSL/TLS authentication man-in-the-middle attack [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SSL Man-in-the-Middle PoC to come by RedTeam : TLS Renegotiation Vulnerability: Proof of Concept Code Released</title>
		<link>http://blogs.23.nu/RedTeam/2009/12/ssl-man-in-the-middle-poc-to-come/comment-page-1/#comment-713</link>
		<dc:creator>RedTeam : TLS Renegotiation Vulnerability: Proof of Concept Code Released</dc:creator>
		<pubDate>Mon, 21 Dec 2009 12:48:49 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=877#comment-713</guid>
		<description>[...] As promised, the TLS Renegotiation vulnerability Python PoC is now publicly available on our websites: [...]</description>
		<content:encoded><![CDATA[<p>[...] As promised, the TLS Renegotiation vulnerability Python PoC is now publicly available on our websites: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SSL Man-in-the-Middle PoC to come by Sn0rkY</title>
		<link>http://blogs.23.nu/RedTeam/2009/12/ssl-man-in-the-middle-poc-to-come/comment-page-1/#comment-690</link>
		<dc:creator>Sn0rkY</dc:creator>
		<pubDate>Mon, 14 Dec 2009 21:11:25 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=877#comment-690</guid>
		<description>Cool, I am eager to test it in a VoIP environment ;-)
 Inform me when it will published...

Health &amp; Happiness :-D
Sn0rkY</description>
		<content:encoded><![CDATA[<p>Cool, I am eager to test it in a VoIP environment ;-)<br />
 Inform me when it will published&#8230;</p>
<p>Health &amp; Happiness :-D<br />
Sn0rkY</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ATM weirdness by Logan Buchanan</title>
		<link>http://blogs.23.nu/RedTeam/2008/08/antville-18652/comment-page-1/#comment-652</link>
		<dc:creator>Logan Buchanan</dc:creator>
		<pubDate>Wed, 02 Dec 2009 14:31:30 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/RedTeam/2008/08/antville-18652/#comment-652</guid>
		<description>what one is write</description>
		<content:encoded><![CDATA[<p>what one is write</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on JBoss Paper: English version released by Lutz Böhne</title>
		<link>http://blogs.23.nu/RedTeam/2009/12/jboss-paper-english-version-released/comment-page-1/#comment-649</link>
		<dc:creator>Lutz Böhne</dc:creator>
		<pubDate>Tue, 01 Dec 2009 09:09:39 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=721#comment-649</guid>
		<description>Oh, sorry, next time I&#039;ll insert TODOs for you :P</description>
		<content:encoded><![CDATA[<p>Oh, sorry, next time I&#8217;ll insert TODOs for you :P</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on &#8220;Who&#8217;s the JBoss now?&#8221; Whitepaper released by RedTeam : JBoss Paper: English version released</title>
		<link>http://blogs.23.nu/RedTeam/2009/06/whos-the-jboss-now-whitepaper-released/comment-page-1/#comment-648</link>
		<dc:creator>RedTeam : JBoss Paper: English version released</dc:creator>
		<pubDate>Tue, 01 Dec 2009 08:50:35 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=650#comment-648</guid>
		<description>[...] finally came around to translate and release the 27+ pages of our JBoss paper (see also this post). That was quite some work, the first versions of my translations always read like a one-to-one [...]</description>
		<content:encoded><![CDATA[<p>[...] finally came around to translate and release the 27+ pages of our JBoss paper (see also this post). That was quite some work, the first versions of my translations always read like a one-to-one [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RedTeam@TV: Dangerous Online Banking by RedTeam : Man-in-the-Middle Attacks against the chipTAN comfort Online Banking System</title>
		<link>http://blogs.23.nu/RedTeam/2009/11/redteamtv-dangerous-online-banking/comment-page-1/#comment-632</link>
		<dc:creator>RedTeam : Man-in-the-Middle Attacks against the chipTAN comfort Online Banking System</dc:creator>
		<pubDate>Mon, 23 Nov 2009 09:16:48 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=826#comment-632</guid>
		<description>[...] As promised, we have released information about the attacks we developed against chipTAN comfort today. Have a look at our website: [...]</description>
		<content:encoded><![CDATA[<p>[...] As promised, we have released information about the attacks we developed against chipTAN comfort today. Have a look at our website: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Security quote of the day by wlet</title>
		<link>http://blogs.23.nu/RedTeam/2009/10/security-quote-of-the-day/comment-page-1/#comment-562</link>
		<dc:creator>wlet</dc:creator>
		<pubDate>Mon, 12 Oct 2009 07:30:02 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=445#comment-562</guid>
		<description>awesome :P...</description>
		<content:encoded><![CDATA[<p>awesome :P&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Tidy up! Your web app looks like a hog house! by RedTeam : Why Teamwork Matters</title>
		<link>http://blogs.23.nu/RedTeam/2009/06/tidy-up-your-web-app-looks-like-a-hog-house/comment-page-1/#comment-526</link>
		<dc:creator>RedTeam : Why Teamwork Matters</dc:creator>
		<pubDate>Tue, 15 Sep 2009 14:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=679#comment-526</guid>
		<description>[...] have already mentioned in this blog post that there&#8217;s always standard stuff you have to do in a pentest. Finding all the standard [...]</description>
		<content:encoded><![CDATA[<p>[...] have already mentioned in this blog post that there&#8217;s always standard stuff you have to do in a pentest. Finding all the standard [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Advisory: 0wning with Gimp by bob</title>
		<link>http://blogs.23.nu/RedTeam/2009/08/new-advisory-0wning-with-gimp/comment-page-1/#comment-412</link>
		<dc:creator>bob</dc:creator>
		<pubDate>Fri, 14 Aug 2009 16:19:17 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=708#comment-412</guid>
		<description>HD, you have it backwards.
a.php.gif will not process as php.
a.gif.php will.</description>
		<content:encoded><![CDATA[<p>HD, you have it backwards.<br />
a.php.gif will not process as php.<br />
a.gif.php will.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Advisory: 0wning with Gimp by Daily Digs &#8211; 08.10.2009 &#171; Security Stallions Blog</title>
		<link>http://blogs.23.nu/RedTeam/2009/08/new-advisory-0wning-with-gimp/comment-page-1/#comment-407</link>
		<dc:creator>Daily Digs &#8211; 08.10.2009 &#171; Security Stallions Blog</dc:creator>
		<pubDate>Tue, 11 Aug 2009 01:01:43 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=708#comment-407</guid>
		<description>[...] I happened to post this one earlier in the day and it got quite a bit more attention than I had expected.  The RedTeam blog has some Gimp pwnage fun that shows you how to embed some sneaky PHP in a GIF.  That and @hdmoore pointed out to me some extra fun to go along with the &#8217;sploit. Double whammy! [0wning with Gimp] [...]</description>
		<content:encoded><![CDATA[<p>[...] I happened to post this one earlier in the day and it got quite a bit more attention than I had expected.  The RedTeam blog has some Gimp pwnage fun that shows you how to embed some sneaky PHP in a GIF.  That and @hdmoore pointed out to me some extra fun to go along with the &#8217;sploit. Double whammy! [0wning with Gimp] [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Advisory: 0wning with Gimp by HD</title>
		<link>http://blogs.23.nu/RedTeam/2009/08/new-advisory-0wning-with-gimp/comment-page-1/#comment-406</link>
		<dc:creator>HD</dc:creator>
		<pubDate>Mon, 10 Aug 2009 15:29:05 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=708#comment-406</guid>
		<description>Keep in mind apache will process the first extension in the file, not the last, so just checking for ending &quot;.gif&quot; doesn&#039;t work if the file is called &quot;exploit.php.gif&quot; -- the PHP extension is detected and the file is processed as PHP instead of GIF.</description>
		<content:encoded><![CDATA[<p>Keep in mind apache will process the first extension in the file, not the last, so just checking for ending &#8220;.gif&#8221; doesn&#8217;t work if the file is called &#8220;exploit.php.gif&#8221; &#8212; the PHP extension is detected and the file is processed as PHP instead of GIF.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FrOSCon 2009 by Conference &#124; FrOSCon 2009 &#124; Conference calling</title>
		<link>http://blogs.23.nu/RedTeam/2009/07/froscon-2009/comment-page-1/#comment-391</link>
		<dc:creator>Conference &#124; FrOSCon 2009 &#124; Conference calling</dc:creator>
		<pubDate>Tue, 28 Jul 2009 17:26:16 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=692#comment-391</guid>
		<description>[...] more: FrOSCon 2009 Tags: are-currently, Conference, excuse-the-lack, jboss, lack, please-excuse, post-more, program, [...]</description>
		<content:encoded><![CDATA[<p>[...] more: FrOSCon 2009 Tags: are-currently, Conference, excuse-the-lack, jboss, lack, please-excuse, post-more, program, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DEFCON 17 CTF Qualifiers by Lexi</title>
		<link>http://blogs.23.nu/RedTeam/2009/06/defcon-17-ctf-qualifiers/comment-page-1/#comment-314</link>
		<dc:creator>Lexi</dc:creator>
		<pubDate>Wed, 10 Jun 2009 13:55:21 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=668#comment-314</guid>
		<description>Congrats :-)</description>
		<content:encoded><![CDATA[<p>Congrats :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Better be Safe by Lutz Böhne</title>
		<link>http://blogs.23.nu/RedTeam/2009/05/better-be-safe/comment-page-1/#comment-284</link>
		<dc:creator>Lutz Böhne</dc:creator>
		<pubDate>Mon, 25 May 2009 08:24:13 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=637#comment-284</guid>
		<description>What you forgot to mention is that the next paragraph tells the user to happily click &quot;Yes&quot; to establish the connection and enter their username and password  ;)</description>
		<content:encoded><![CDATA[<p>What you forgot to mention is that the next paragraph tells the user to happily click &#8220;Yes&#8221; to establish the connection and enter their username and password  ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on JBoss Talk at the RWTH Aachen University by Lexi</title>
		<link>http://blogs.23.nu/RedTeam/2009/05/jboss-talk-at-the-rwth-aachen-university/comment-page-1/#comment-271</link>
		<dc:creator>Lexi</dc:creator>
		<pubDate>Tue, 05 May 2009 06:57:08 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=591#comment-271</guid>
		<description>Ich wuerde ja gerne kommen, aber der Vortrag ist mir etwas zu frueh :-/</description>
		<content:encoded><![CDATA[<p>Ich wuerde ja gerne kommen, aber der Vortrag ist mir etwas zu frueh :-/</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 16th DFN Workshop by RedTeam : JBoss Talk at the RWTH Aachen University</title>
		<link>http://blogs.23.nu/RedTeam/2009/03/16th-dfn-workshop/comment-page-1/#comment-270</link>
		<dc:creator>RedTeam : JBoss Talk at the RWTH Aachen University</dc:creator>
		<pubDate>Mon, 04 May 2009 11:53:32 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=430#comment-270</guid>
		<description>[...] Center for Computing and Communication of RWTH Aachen University. As we have more time than at the DFN CERT, we will be able to demonstrate all attacks live and generally go into a little bit more detail. [...]</description>
		<content:encoded><![CDATA[<p>[...] Center for Computing and Communication of RWTH Aachen University. As we have more time than at the DFN CERT, we will be able to demonstrate all attacks live and generally go into a little bit more detail. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on EiPSI Opening by RedTeam : EiPSI 1st Anniversary</title>
		<link>http://blogs.23.nu/RedTeam/2008/04/antville-17930/comment-page-1/#comment-266</link>
		<dc:creator>RedTeam : EiPSI 1st Anniversary</dc:creator>
		<pubDate>Mon, 27 Apr 2009 14:22:52 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/RedTeam/2008/04/antville-17930/#comment-266</guid>
		<description>[...] the Protection of Systems and Information (EiPSI) celebrated its first anniversary last Friday. The opening in 2008 was already a very nice event, and I was looking forward to the announced talks for the [...]</description>
		<content:encoded><![CDATA[<p>[...] the Protection of Systems and Information (EiPSI) celebrated its first anniversary last Friday. The opening in 2008 was already a very nice event, and I was looking forward to the announced talks for the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on CeBIT 2009 video by Jens</title>
		<link>http://blogs.23.nu/RedTeam/2009/03/cebit-2009-video/comment-page-1/#comment-233</link>
		<dc:creator>Jens</dc:creator>
		<pubDate>Mon, 23 Mar 2009 16:54:03 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=462#comment-233</guid>
		<description>Notice: The talk ends at 23:42 ;-)</description>
		<content:encoded><![CDATA[<p>Notice: The talk ends at 23:42 ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on CeBIT 2009 by RedTeam &#187; Blog Archive &#187; CeBIT 2009 video</title>
		<link>http://blogs.23.nu/RedTeam/2009/02/cebit-2009/comment-page-1/#comment-230</link>
		<dc:creator>RedTeam &#187; Blog Archive &#187; CeBIT 2009 video</dc:creator>
		<pubDate>Mon, 23 Mar 2009 08:28:06 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=383#comment-230</guid>
		<description>[...] mentioned here, the Linux Magazine streamed our talk at the CeBIT 2009 Open Source Forum. The video is now [...]</description>
		<content:encoded><![CDATA[<p>[...] mentioned here, the Linux Magazine streamed our talk at the CeBIT 2009 Open Source Forum. The video is now [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 16th DFN Workshop by RedTeam &#187; Blog Archive &#187; 16th DFN-CERT wrapup</title>
		<link>http://blogs.23.nu/RedTeam/2009/03/16th-dfn-workshop/comment-page-1/#comment-220</link>
		<dc:creator>RedTeam &#187; Blog Archive &#187; 16th DFN-CERT wrapup</dc:creator>
		<pubDate>Thu, 19 Mar 2009 15:36:36 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=430#comment-220</guid>
		<description>[...] RedTeam Seeing your network from the attacker&#8217;s perspective      &#171; 16th DFN Workshop [...]</description>
		<content:encoded><![CDATA[<p>[...] RedTeam Seeing your network from the attacker&#8217;s perspective      &laquo; 16th DFN Workshop [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on four in a row by RedTeam &#187; Blog Archive &#187; 16th DFN Workshop</title>
		<link>http://blogs.23.nu/RedTeam/2008/09/antville-19018/comment-page-1/#comment-201</link>
		<dc:creator>RedTeam &#187; Blog Archive &#187; 16th DFN Workshop</dc:creator>
		<pubDate>Thu, 12 Mar 2009 11:09:44 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/RedTeam/2008/09/antville-19018/#comment-201</guid>
		<description>[...] the enterprise and you - or - Who&#8217;s the JBoss now&#8221; which was already a success at the hack.lu 2008 last [...]</description>
		<content:encoded><![CDATA[<p>[...] the enterprise and you &#8211; or &#8211; Who&#8217;s the JBoss now&#8221; which was already a success at the hack.lu 2008 last [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Frontal21 by RedTeam &#187; Blog Archive &#187; Never trust your Printer</title>
		<link>http://blogs.23.nu/RedTeam/2008/06/antville-18238/comment-page-1/#comment-195</link>
		<dc:creator>RedTeam &#187; Blog Archive &#187; Never trust your Printer</dc:creator>
		<pubDate>Mon, 09 Mar 2009 14:14:16 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/RedTeam/2008/06/antville-18238/#comment-195</guid>
		<description>[...] reminded me why we always tell our clients to treat their printers like servers, security-wise. Additionally, never trust a machine with a LIBDecisionImpl.cxx. Who knows if [...]</description>
		<content:encoded><![CDATA[<p>[...] reminded me why we always tell our clients to treat their printers like servers, security-wise. Additionally, never trust a machine with a LIBDecisionImpl.cxx. Who knows if [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Flash and Parameter Passing by Cross Site Scripting &#187; Blog Archive &#187; Flash and Parameter Passing</title>
		<link>http://blogs.23.nu/RedTeam/2009/02/flash-and-parameter-passing/comment-page-1/#comment-147</link>
		<dc:creator>Cross Site Scripting &#187; Blog Archive &#187; Flash and Parameter Passing</dc:creator>
		<pubDate>Wed, 04 Feb 2009 18:59:57 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=354#comment-147</guid>
		<description>[...] This means Cross Site Scripting in your Flash movie: http://www.example.com/myapp.swf ?username=patrick &amp;userdata=javascript:alert(&#8217;RedTeam&#8217;). By loading external data without verifying it first, you make yourself (or more precisely, &#8230;Read More [...]</description>
		<content:encoded><![CDATA[<p>[...] This means Cross Site Scripting in your Flash movie: <a href="http://www.example.com/myapp.swf" rel="nofollow">http://www.example.com/myapp.swf</a> ?username=patrick &amp;userdata=javascript:alert(&#8217;RedTeam&#8217;). By loading external data without verifying it first, you make yourself (or more precisely, &#8230;Read More [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Flash and Parameter Passing by Pages tagged "javascript"</title>
		<link>http://blogs.23.nu/RedTeam/2009/02/flash-and-parameter-passing/comment-page-1/#comment-144</link>
		<dc:creator>Pages tagged "javascript"</dc:creator>
		<pubDate>Mon, 02 Feb 2009 18:35:46 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/RedTeam/?p=354#comment-144</guid>
		<description>[...] bookmarks tagged javascript Flash and Parameter Passing&#160;saved by 3 others  &#160;&#160;&#160;&#160;ifon1stdate bookmarked on 02/02/09 &#124; [...]</description>
		<content:encoded><![CDATA[<p>[...] bookmarks tagged javascript Flash and Parameter Passing&nbsp;saved by 3 others  &nbsp;&nbsp;&nbsp;&nbsp;ifon1stdate bookmarked on 02/02/09 | [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
