<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: CSRF with MS Word</title>
	<atom:link href="http://michaeldaw.org/md-hacks/csrf-with-msword/feed" rel="self" type="application/rss+xml" />
	<link>http://michaeldaw.org/md-hacks/csrf-with-msword</link>
	<description>Weekly humour</description>
	<lastBuildDate>Thu, 07 May 2009 20:09:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: lain</title>
		<link>http://michaeldaw.org/md-hacks/csrf-with-msword/comment-page-1#comment-48194</link>
		<dc:creator>lain</dc:creator>
		<pubDate>Sun, 23 Sep 2007 08:28:43 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/csrf-with-msword/#comment-48194</guid>
		<description>kewl stuff , wanna try it s00n :D :D :D</description>
		<content:encoded><![CDATA[<p>kewl stuff , wanna try it s00n :D :D :D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Top Web Hacks of 2006 &#187; Hack Report</title>
		<link>http://michaeldaw.org/md-hacks/csrf-with-msword/comment-page-1#comment-2934</link>
		<dc:creator>Top Web Hacks of 2006 &#187; Hack Report</dc:creator>
		<pubDate>Tue, 02 Jan 2007 04:07:16 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/csrf-with-msword/#comment-2934</guid>
		<description>[...] 1. Web Browser Intranet Hacking / Port Scanning - (with JavaScript and with HTML-only and the improved model) 2. Internet Explorer 7 &#8220;mhtml:&#8221; Redirection Information Disclosure 3. Anti-DNS Pinning and Circumventing Anti-Anti DNS pinning 4. Web Browser History Stealing - (with CSS, evil marketing, JS login-detection, and authenticated images) 5. Backdooring Media Files (QuickTime, Flash, PDF, Images, Word [2], and MP3&#8217;s) 6. Forging HTTP request headers with Flash 7. Exponential XSS 8. Encoding Filter Bypass (UTF-7, Variable Width, US-ASCII) 9. Web Worms - (AdultSpace, MySpace, Xanga) 10. Hacking RSS Feeds [...]</description>
		<content:encoded><![CDATA[<p>[...] 1. Web Browser Intranet Hacking / Port Scanning &#8211; (with JavaScript and with HTML-only and the improved model) 2. Internet Explorer 7 &#8220;mhtml:&#8221; Redirection Information Disclosure 3. Anti-DNS Pinning and Circumventing Anti-Anti DNS pinning 4. Web Browser History Stealing &#8211; (with CSS, evil marketing, JS login-detection, and authenticated images) 5. Backdooring Media Files (QuickTime, Flash, PDF, Images, Word [2], and MP3&#8217;s) 6. Forging HTTP request headers with Flash 7. Exponential XSS 8. Encoding Filter Bypass (UTF-7, Variable Width, US-ASCII) 9. Web Worms &#8211; (AdultSpace, MySpace, Xanga) 10. Hacking RSS Feeds [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ha.ckers.org web application security lab - Archive &#187; CSRF with Word Part II</title>
		<link>http://michaeldaw.org/md-hacks/csrf-with-msword/comment-page-1#comment-1894</link>
		<dc:creator>ha.ckers.org web application security lab - Archive &#187; CSRF with Word Part II</dc:creator>
		<pubDate>Fri, 15 Dec 2006 19:40:49 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/csrf-with-msword/#comment-1894</guid>
		<description>[...] Okay, I didn&#8217;t write part I, and really didn&#8217;t even know about it until today. Although I invented something like it months and months ago. But the first person to talk about CSRF within Word was Michael Daw. Very interesting concept. In the context that I was using a similar technique I was using it primarily as a web-bug. Michael Daw&#8217;s technique is good, but I like mine better, because it&#8217;s probably as noisy, however, it leaves no visible queues to the victim. [...]</description>
		<content:encoded><![CDATA[<p>[...] Okay, I didn&#8217;t write part I, and really didn&#8217;t even know about it until today. Although I invented something like it months and months ago. But the first person to talk about CSRF within Word was Michael Daw. Very interesting concept. In the context that I was using a similar technique I was using it primarily as a web-bug. Michael Daw&#8217;s technique is good, but I like mine better, because it&#8217;s probably as noisy, however, it leaves no visible queues to the victim. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david.kierznowski</title>
		<link>http://michaeldaw.org/md-hacks/csrf-with-msword/comment-page-1#comment-1470</link>
		<dc:creator>david.kierznowski</dc:creator>
		<pubDate>Sat, 25 Nov 2006 20:19:20 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/csrf-with-msword/#comment-1470</guid>
		<description>Guys at SANS made some interesting comments regarding the article:
http://isc.sans.org/diary.php?storyid=1886</description>
		<content:encoded><![CDATA[<p>Guys at SANS made some interesting comments regarding the article:<br />
<a href="http://isc.sans.org/diary.php?storyid=1886" rel="nofollow">http://isc.sans.org/diary.php?storyid=1886</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
