<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Friendly AJAX XSS Worm for WordPress</title>
	<atom:link href="http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: .mario</title>
		<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/comment-page-1/#comment-38512</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Thu, 02 Aug 2007 14:33:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress#comment-38512</guid>
		<description>Yep - just caught that too via my feeds - so maybe now you know what I mean with no review no usage.</description>
		<content:encoded><![CDATA[<p>Yep &#8211; just caught that too via my feeds &#8211; so maybe now you know what I mean with no review no usage.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net Â» Patching WordPress, WormLess</title>
		<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/comment-page-1/#comment-38497</link>
		<dc:creator>hackademix.net Â» Patching WordPress, WormLess</dc:creator>
		<pubDate>Thu, 02 Aug 2007 11:53:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress#comment-38497</guid>
		<description>[...] the other hand, I fully subscribe to .mario&#8217;s concerns &#8212; w/o code review no usage &#8212; and looks like Symantec agrees about this beastie being [...]</description>
		<content:encoded><![CDATA[<p>[...] the other hand, I fully subscribe to .mario&#8217;s concerns &#8212; w/o code review no usage &#8212; and looks like Symantec agrees about this beastie being [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zqyves</title>
		<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/comment-page-1/#comment-38475</link>
		<dc:creator>zqyves</dc:creator>
		<pubDate>Thu, 02 Aug 2007 09:23:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress#comment-38475</guid>
		<description>hello all,

have a look at that:

http://www.symantec.com/enterprise/security_response/weblog/2007/08/wordpress_xss_exploit_solves_p.html

there is actually a problem in the code of the XSS worm resulting in the &quot;+&quot; not encoded and interpreted as &quot; &quot; (space) by the browser.</description>
		<content:encoded><![CDATA[<p>hello all,</p>
<p>have a look at that:</p>
<p><a href="http://www.symantec.com/enterprise/security_response/weblog/2007/08/wordpress_xss_exploit_solves_p.html" rel="nofollow">http://www.symantec.com/enterp.....ves_p.html</a></p>
<p>there is actually a problem in the code of the XSS worm resulting in the &#8220;+&#8221; not encoded and interpreted as &#8221; &#8221; (space) by the browser.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mybeNi websecurity</title>
		<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/comment-page-1/#comment-38336</link>
		<dc:creator>mybeNi websecurity</dc:creator>
		<pubDate>Wed, 01 Aug 2007 20:28:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress#comment-38336</guid>
		<description>Hell, it is javascript, you&#039;ll find the scrip tags on your own</description>
		<content:encoded><![CDATA[<p>Hell, it is javascript, you&#8217;ll find the scrip tags on your own</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/comment-page-1/#comment-38293</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Wed, 01 Aug 2007 14:48:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress#comment-38293</guid>
		<description>Thanks for the explanation but as I already said - w/o code review no usage - don&#039;t get me wrong please. 

And at the moment I have no time to set up a testblog etc.

What&#039;s the problem with publishing the sources? You&#039;d like to wait until the vulns are fixed?</description>
		<content:encoded><![CDATA[<p>Thanks for the explanation but as I already said &#8211; w/o code review no usage &#8211; don&#8217;t get me wrong please. </p>
<p>And at the moment I have no time to set up a testblog etc.</p>
<p>What&#8217;s the problem with publishing the sources? You&#8217;d like to wait until the vulns are fixed?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mybeNi websecurity</title>
		<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/comment-page-1/#comment-38256</link>
		<dc:creator>mybeNi websecurity</dc:creator>
		<pubDate>Wed, 01 Aug 2007 10:26:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress#comment-38256</guid>
		<description>mario:
If you refer from your admin panel to my page, it pops up and asks you if you&#039;d like to fix these vulns, then it goes to your admin panel back again, carrying its XSS payload and creating a Small setup, which tells the Admin where to add which parts of code to his Wordpress files in order to Fix the Vulnerabilities.
At the end, the Admin is prompet wheter he&#039;d like to continue the worm by pasting a small &quot;Referal-Checking&quot; php line to his sidebar (manually by copy&amp;paste) or if he&#039;d like to add a blogroll link to my blog (of course automatically) ;)

--cheers beni</description>
		<content:encoded><![CDATA[<p>mario:<br />
If you refer from your admin panel to my page, it pops up and asks you if you&#8217;d like to fix these vulns, then it goes to your admin panel back again, carrying its XSS payload and creating a Small setup, which tells the Admin where to add which parts of code to his WordPress files in order to Fix the Vulnerabilities.<br />
At the end, the Admin is prompet wheter he&#8217;d like to continue the worm by pasting a small &#8220;Referal-Checking&#8221; php line to his sidebar (manually by copy&amp;paste) or if he&#8217;d like to add a blogroll link to my blog (of course automatically) ;)</p>
<p>&#8211;cheers beni</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/comment-page-1/#comment-38240</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 01 Aug 2007 08:38:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress#comment-38240</guid>
		<description>good stuff byNi... let&#039;s see how long it will take wordpress to release a new version.</description>
		<content:encoded><![CDATA[<p>good stuff byNi&#8230; let&#8217;s see how long it will take wordpress to release a new version.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mybeNi websecurity</title>
		<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/comment-page-1/#comment-38235</link>
		<dc:creator>mybeNi websecurity</dc:creator>
		<pubDate>Wed, 01 Aug 2007 07:59:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress#comment-38235</guid>
		<description>yes, right after I pressed the Post Button, I created some Tickets at the Wordpress Bugtracker (trac.wordpress.com). They already fixed some parts, hope the release won&#039;t take too long.</description>
		<content:encoded><![CDATA[<p>yes, right after I pressed the Post Button, I created some Tickets at the WordPress Bugtracker (trac.wordpress.com). They already fixed some parts, hope the release won&#8217;t take too long.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/comment-page-1/#comment-38229</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Wed, 01 Aug 2007 07:42:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress#comment-38229</guid>
		<description>Yep - very nice work indeed! But as pdp already said please release the sources. There&#039;s no way for me using this tool w/o knowing what it really does.</description>
		<content:encoded><![CDATA[<p>Yep &#8211; very nice work indeed! But as pdp already said please release the sources. There&#8217;s no way for me using this tool w/o knowing what it really does.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/comment-page-1/#comment-38140</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Tue, 31 Jul 2007 23:33:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress#comment-38140</guid>
		<description>pdp, heh, I have checked the mans work ... trying to rope him in for a chat :-)</description>
		<content:encoded><![CDATA[<p>pdp, heh, I have checked the mans work &#8230; trying to rope him in for a chat :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/comment-page-1/#comment-38130</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 31 Jul 2007 22:45:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress#comment-38130</guid>
		<description>heh :) this is less critical but still. interesting research btw. have you informed the wordpress guys?</description>
		<content:encoded><![CDATA[<p>heh :) this is less critical but still. interesting research btw. have you informed the wordpress guys?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mybeNi websecurity</title>
		<link>http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress/comment-page-1/#comment-38129</link>
		<dc:creator>mybeNi websecurity</dc:creator>
		<pubDate>Tue, 31 Jul 2007 22:37:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/friendly-ajax-xss-worm-for-wordpress#comment-38129</guid>
		<description>Hey pdp!

The worm asks for permission and every step must be authorized by the Administrator, it just guides him through the process of applying the workarounds for the security vulnerabilities onto his Wordpress code. ;)</description>
		<content:encoded><![CDATA[<p>Hey pdp!</p>
<p>The worm asks for permission and every step must be authorized by the Administrator, it just guides him through the process of applying the workarounds for the security vulnerabilities onto his WordPress code. ;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
