<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: RSS Injection in Sage part 2</title>
	<atom:link href="http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/feed" rel="self" type="application/rss+xml" />
	<link>http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2</link>
	<description>Weekly humour</description>
	<lastBuildDate>Thu, 07 May 2009 20:09:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Operation n &#187; Malware Security Testing</title>
		<link>http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/comment-page-1#comment-52388</link>
		<dc:creator>Operation n &#187; Malware Security Testing</dc:creator>
		<pubDate>Thu, 08 Jan 2009 23:01:45 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/#comment-52388</guid>
		<description>[...] have recently found or reported serious malware potential in Quicktime, MP3, PDF, Flash and RSS to name a [...]</description>
		<content:encoded><![CDATA[<p>[...] have recently found or reported serious malware potential in Quicktime, MP3, PDF, Flash and RSS to name a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: naisioxerloro</title>
		<link>http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/comment-page-1#comment-49414</link>
		<dc:creator>naisioxerloro</dc:creator>
		<pubDate>Thu, 29 Nov 2007 00:13:40 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/#comment-49414</guid>
		<description>Hi. 
Good design, who make it?</description>
		<content:encoded><![CDATA[<p>Hi.<br />
Good design, who make it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Operation n &#187; Firebug XSS Mayhem</title>
		<link>http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/comment-page-1#comment-18724</link>
		<dc:creator>Operation n &#187; Firebug XSS Mayhem</dc:creator>
		<pubDate>Thu, 05 Apr 2007 09:03:18 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/#comment-18724</guid>
		<description>[...] vulnerability in Firebug - we have seen previous vulnerabilities in Firefox plugins including the Sage RSS reader exploits myself and pdp exploited in the past. The awesome concept here was using Mozilla code to load executables files. [...]</description>
		<content:encoded><![CDATA[<p>[...] vulnerability in Firebug &#8211; we have seen previous vulnerabilities in Firefox plugins including the Sage RSS reader exploits myself and pdp exploited in the past. The awesome concept here was using Mozilla code to load executables files. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter Andrews</title>
		<link>http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/comment-page-1#comment-1291</link>
		<dc:creator>Peter Andrews</dc:creator>
		<pubDate>Sat, 18 Nov 2006 04:53:57 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/#comment-1291</guid>
		<description>Sage 1.3.9 has been released to address this and other issues:

http://sage.mozdev.org/blog/archives/2006/11/sage_1_3_9_released.html</description>
		<content:encoded><![CDATA[<p>Sage 1.3.9 has been released to address this and other issues:</p>
<p><a href="http://sage.mozdev.org/blog/archives/2006/11/sage_1_3_9_released.html" rel="nofollow">http://sage.mozdev.org/blog/archives/2006/11/sage_1_3_9_released.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter Andrews</title>
		<link>http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/comment-page-1#comment-1261</link>
		<dc:creator>Peter Andrews</dc:creator>
		<pubDate>Fri, 17 Nov 2006 03:06:34 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/#comment-1261</guid>
		<description>Thanks for bringing this to light David.  Bug filed:

http://mozdev.org/bugs/show_bug.cgi?id=15767

A maintenance release will follow shortly.</description>
		<content:encoded><![CDATA[<p>Thanks for bringing this to light David.  Bug filed:</p>
<p><a href="http://mozdev.org/bugs/show_bug.cgi?id=15767" rel="nofollow">http://mozdev.org/bugs/show_bug.cgi?id=15767</a></p>
<p>A maintenance release will follow shortly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; Web Pages from Hell 2</title>
		<link>http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/comment-page-1#comment-1184</link>
		<dc:creator>GNUCITIZEN &#187; Web Pages from Hell 2</dc:creator>
		<pubDate>Wed, 15 Nov 2006 02:43:28 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/#comment-1184</guid>
		<description>[...] Update: dwk found another RSS XSS vuln on the latest version of Sage (1.3.8 at time of writing). Additionally, Rick also found another RSS XSS vuln on the latest version. [...]</description>
		<content:encoded><![CDATA[<p>[...] Update: dwk found another RSS XSS vuln on the latest version of Sage (1.3.8 at time of writing). Additionally, Rick also found another RSS XSS vuln on the latest version. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david.kierznowski</title>
		<link>http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/comment-page-1#comment-1129</link>
		<dc:creator>david.kierznowski</dc:creator>
		<pubDate>Sat, 11 Nov 2006 18:24:59 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/#comment-1129</guid>
		<description>Mike, an email was sent to Peter Andrews - Project Lead, Developer.</description>
		<content:encoded><![CDATA[<p>Mike, an email was sent to Peter Andrews &#8211; Project Lead, Developer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Shaver</title>
		<link>http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/comment-page-1#comment-1128</link>
		<dc:creator>Mike Shaver</dc:creator>
		<pubDate>Sat, 11 Nov 2006 18:14:41 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/#comment-1128</guid>
		<description>Was this vulnerability reported to the Sage authors?</description>
		<content:encoded><![CDATA[<p>Was this vulnerability reported to the Sage authors?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david.kierznowski</title>
		<link>http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/comment-page-1#comment-1084</link>
		<dc:creator>david.kierznowski</dc:creator>
		<pubDate>Thu, 09 Nov 2006 21:50:28 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/#comment-1084</guid>
		<description>Rick, thanks for checking that. I have corrected the missing ). I have also included an alert(&#039;blah&#039;) into the Windows exploit.</description>
		<content:encoded><![CDATA[<p>Rick, thanks for checking that. I have corrected the missing ). I have also included an alert(&#8217;blah&#8217;) into the Windows exploit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kd</title>
		<link>http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/comment-page-1#comment-1081</link>
		<dc:creator>kd</dc:creator>
		<pubDate>Thu, 09 Nov 2006 19:32:41 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/md-hacks/rss-injection-in-sage-part-2/#comment-1081</guid>
		<description>I too cannot get the alert(&#039;blah&#039;) to work. Any ideas?</description>
		<content:encoded><![CDATA[<p>I too cannot get the alert(&#8217;blah&#8217;) to work. Any ideas?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
