<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Every Link You Click is Dangerous</title>
	<atom:link href="http://www.gnucitizen.org/blog/every-link-you-click-is-dangerous/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/every-link-you-click-is-dangerous/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Thu, 11 Mar 2010 22:49:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Aodhhan</title>
		<link>http://www.gnucitizen.org/blog/every-link-you-click-is-dangerous/comment-page-1/#comment-127413</link>
		<dc:creator>Aodhhan</dc:creator>
		<pubDate>Wed, 03 Jun 2009 16:47:37 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2743#comment-127413</guid>
		<description>Perhaps not tap into a PC, the unfortunate truth is how people use the same username and password for many different places where they must authenticate. A little bit of social engineering, or pulling their browser list can go a long way.</description>
		<content:encoded><![CDATA[<p>Perhaps not tap into a PC, the unfortunate truth is how people use the same username and password for many different places where they must authenticate. A little bit of social engineering, or pulling their browser list can go a long way.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/every-link-you-click-is-dangerous/comment-page-1/#comment-126430</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 01 Apr 2009 23:49:41 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2743#comment-126430</guid>
		<description>it is hard to say :)</description>
		<content:encoded><![CDATA[<p>it is hard to say :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mellow</title>
		<link>http://www.gnucitizen.org/blog/every-link-you-click-is-dangerous/comment-page-1/#comment-126424</link>
		<dc:creator>mellow</dc:creator>
		<pubDate>Mon, 30 Mar 2009 13:18:52 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2743#comment-126424</guid>
		<description>Sometimes I notice this behavior when logging in at my hotmail account. I&#039;m quite sure I typed my password like it should but it says wrong password. When I type it in again, I&#039;m in. Could it be possible that their login page mail.live.com is compromised?</description>
		<content:encoded><![CDATA[<p>Sometimes I notice this behavior when logging in at my hotmail account. I&#8217;m quite sure I typed my password like it should but it says wrong password. When I type it in again, I&#8217;m in. Could it be possible that their login page mail.live.com is compromised?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: shuli Totoy</title>
		<link>http://www.gnucitizen.org/blog/every-link-you-click-is-dangerous/comment-page-1/#comment-126201</link>
		<dc:creator>shuli Totoy</dc:creator>
		<pubDate>Sun, 01 Mar 2009 06:38:11 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2743#comment-126201</guid>
		<description>Asprox is also a silent website defacement. These worms utilize innocent web surfers&#039; PC&#039;s to Google after vulnerable web sites. Once a list of suspects has been compiled, automatic signature-evasive Blind Sql Injection attacks are blindly shot at every GET / POST parameter within the web application.</description>
		<content:encoded><![CDATA[<p>Asprox is also a silent website defacement. These worms utilize innocent web surfers&#8217; PC&#8217;s to Google after vulnerable web sites. Once a list of suspects has been compiled, automatic signature-evasive Blind Sql Injection attacks are blindly shot at every GET / POST parameter within the web application.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/every-link-you-click-is-dangerous/comment-page-1/#comment-126177</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 27 Feb 2009 08:11:24 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2743#comment-126177</guid>
		<description>don&#039;t know! I haven&#039;t been following Mozie&#039;s research. but if this is the case than his stuff are based on an old technique previously discussed on this blog and mozilla&#039;s bugzilla.</description>
		<content:encoded><![CDATA[<p>don&#8217;t know! I haven&#8217;t been following Mozie&#8217;s research. but if this is the case than his stuff are based on an old technique previously discussed on this blog and mozilla&#8217;s bugzilla.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Oper8or</title>
		<link>http://www.gnucitizen.org/blog/every-link-you-click-is-dangerous/comment-page-1/#comment-126173</link>
		<dc:creator>Oper8or</dc:creator>
		<pubDate>Fri, 27 Feb 2009 05:04:26 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2743#comment-126173</guid>
		<description>What you speak is complete truth. What makes it evne more dangerous is that the GP pays no attention to the surrounding inputs the shell itself gives. It answers questions for you and shows you if something has changed. In most cases a simple glance at the browser directory, or even the source, will reveal what has happened. Some times I feel overly cautious. Then upon reading this I realize I&#039;m not.</description>
		<content:encoded><![CDATA[<p>What you speak is complete truth. What makes it evne more dangerous is that the GP pays no attention to the surrounding inputs the shell itself gives. It answers questions for you and shows you if something has changed. In most cases a simple glance at the browser directory, or even the source, will reveal what has happened. Some times I feel overly cautious. Then upon reading this I realize I&#8217;m not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: marc</title>
		<link>http://www.gnucitizen.org/blog/every-link-you-click-is-dangerous/comment-page-1/#comment-126162</link>
		<dc:creator>marc</dc:creator>
		<pubDate>Thu, 26 Feb 2009 11:10:27 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2743#comment-126162</guid>
		<description>What is the difference with this weakness and attack and the one described by Moxie Marlinspike during the last BH Washington ? Effects and step by step operations seems to be very close between those to hacks
Tnks</description>
		<content:encoded><![CDATA[<p>What is the difference with this weakness and attack and the one described by Moxie Marlinspike during the last BH Washington ? Effects and step by step operations seems to be very close between those to hacks<br />
Tnks</p>
]]></content:encoded>
	</item>
</channel>
</rss>
