<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Ghost Busters</title>
	<atom:link href="http://www.gnucitizen.org/blog/ghost-busters/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/ghost-busters/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Fri, 21 Nov 2008 21:24:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: w2Networks &#187; Internet Explorer no restringe el acceso a marcos</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-123088</link>
		<dc:creator>w2Networks &#187; Internet Explorer no restringe el acceso a marcos</dc:creator>
		<pubDate>Fri, 25 Jul 2008 13:51:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-123088</guid>
		<description>[...] Ghost Busters http://www.gnucitizen.org/blog/ghost-busters/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Ghost Busters <a href="http://www.gnucitizen.org/blog/ghost-busters/" rel="nofollow">http://www.gnucitizen.org/blog/ghost-busters/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ghost Busters: Zero-day flaw haunts Internet Explorer &#124; Andrea Lazzari's blog</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-123086</link>
		<dc:creator>Ghost Busters: Zero-day flaw haunts Internet Explorer &#124; Andrea Lazzari's blog</dc:creator>
		<pubDate>Fri, 25 Jul 2008 10:40:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-123086</guid>
		<description>[...] Ghost Busters &#124; GNUCITIZEN  [...]</description>
		<content:encoded><![CDATA[<p>[...] Ghost Busters | GNUCITIZEN  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alok</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-122805</link>
		<dc:creator>Alok</dc:creator>
		<pubDate>Thu, 03 Jul 2008 10:24:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-122805</guid>
		<description>Nice wrk .. key loggers working with simple html pages.</description>
		<content:encoded><![CDATA[<p>Nice wrk .. key loggers working with simple html pages.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-122722</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Sun, 29 Jun 2008 08:42:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-122722</guid>
		<description>@Foobar:
&#62; Caballeroâ€™s work is much greater than this. He can insert cross domain javascript etcâ€¦

I dont think so.. but an interesting discovery, revealed that this one can also make stuff cross-domain ;)

http://www.ph4nt0m.org-a.googlepages.com/PSTZine_0x02_0x04.txt

So well.. yeah..</description>
		<content:encoded><![CDATA[<p>@Foobar:<br />
&gt; Caballeroâ€™s work is much greater than this. He can insert cross domain javascript etcâ€¦</p>
<p>I dont think so.. but an interesting discovery, revealed that this one can also make stuff cross-domain ;)</p>
<p><a href="http://www.ph4nt0m.org-a.googlepages.com/PSTZine_0x02_0x04.txt" rel="nofollow">http://www.ph4nt0m.org-a.googl.....215;04.txt</a></p>
<p>So well.. yeah..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Internet Explorer no restringe el acceso a marcos - Foro de Informatica para tod@s! -Necesitamos expertos en Photoshop ¿Te unes?</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-122712</link>
		<dc:creator>Internet Explorer no restringe el acceso a marcos - Foro de Informatica para tod@s! -Necesitamos expertos en Photoshop ¿Te unes?</dc:creator>
		<pubDate>Sat, 28 Jun 2008 07:38:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-122712</guid>
		<description>[...] Explorer fails to properly restrict access to frames US-CERT Vulnerability Notes  Ghost Busters Ghost Busters &#124; GNUCITIZEN  Ghosts for IE8 and IE7.5730 sirdarckcat: Ghosts for IE8 and IE7.5730  Browser's Ghost Busters [...]</description>
		<content:encoded><![CDATA[<p>[...] Explorer fails to properly restrict access to frames US-CERT Vulnerability Notes  Ghost Busters Ghost Busters | GNUCITIZEN  Ghosts for IE8 and IE7.5730 sirdarckcat: Ghosts for IE8 and IE7.5730  Browser&#8217;s Ghost Busters [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Internet Explorer no restringe el acceso a marcos &#171; SeMaToVe</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-122710</link>
		<dc:creator>Internet Explorer no restringe el acceso a marcos &#171; SeMaToVe</dc:creator>
		<pubDate>Sat, 28 Jun 2008 07:13:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-122710</guid>
		<description>[...] Ghost Busters http://www.gnucitizen.org/blog/ghost-busters/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Ghost Busters <a href="http://www.gnucitizen.org/blog/ghost-busters/" rel="nofollow">http://www.gnucitizen.org/blog/ghost-busters/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Venom23</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-122709</link>
		<dc:creator>Venom23</dc:creator>
		<pubDate>Sat, 28 Jun 2008 06:55:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-122709</guid>
		<description>I found a PoC link. Perhaps some reader is interested. 

http://raffon.net/research/ms/ie/crossdomain/string.html#</description>
		<content:encoded><![CDATA[<p>I found a PoC link. Perhaps some reader is interested. </p>
<p><a href="http://raffon.net/research/ms/ie/crossdomain/string.html#" rel="nofollow">http://raffon.net/research/ms/.....ring.html#</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero Day mobile edition</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-122676</link>
		<dc:creator>Zero Day mobile edition</dc:creator>
		<pubDate>Thu, 26 Jun 2008 10:58:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-122676</guid>
		<description>[...] zero-day flaw, which has been reported to Microsoft, is a variation of Eduardo Vela&#8217;s IE Ghost Busters talk: Do you believe in ghosts? Imagine an invisible script that silently follows you while you [...]</description>
		<content:encoded><![CDATA[<p>[...] zero-day flaw, which has been reported to Microsoft, is a variation of Eduardo Vela&#8217;s IE Ghost Busters talk: Do you believe in ghosts? Imagine an invisible script that silently follows you while you [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ForumKral.Org &#187; Blog Archive &#187; G&#252;nl&#252;k Maceralar</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-122304</link>
		<dc:creator>ForumKral.Org &#187; Blog Archive &#187; G&#252;nl&#252;k Maceralar</dc:creator>
		<pubDate>Tue, 27 May 2008 20:46:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-122304</guid>
		<description>[...] - Manual   Debian OpenSSL Predictable PRNG Toys   Giving SQL Injection the Respect it Deserves   Ghost Busters   String Format - Made Simple   OphCrack 3.0 in the wild   The Ethics of Vulnerability Research   [...]</description>
		<content:encoded><![CDATA[<p>[...] - Manual   Debian OpenSSL Predictable PRNG Toys   Giving SQL Injection the Respect it Deserves   Ghost Busters   String Format - Made Simple   OphCrack 3.0 in the wild   The Ethics of Vulnerability Research   [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ð’Ñ‹ Ð²ÐµÑ€Ð¸Ñ‚Ðµ Ð² Ð¿Ñ€Ð¸Ð·Ñ€Ð°ÐºÐ¾Ð²? &#124; Raz0r.name - Ð±Ð»Ð¾Ð³ Ð¾ web-Ð±ÐµÐ·Ð¾Ð¿Ð°ÑÐ½Ð¾ÑÑ‚Ð¸</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-122206</link>
		<dc:creator>Ð’Ñ‹ Ð²ÐµÑ€Ð¸Ñ‚Ðµ Ð² Ð¿Ñ€Ð¸Ð·Ñ€Ð°ÐºÐ¾Ð²? &#124; Raz0r.name - Ð±Ð»Ð¾Ð³ Ð¾ web-Ð±ÐµÐ·Ð¾Ð¿Ð°ÑÐ½Ð¾ÑÑ‚Ð¸</dc:creator>
		<pubDate>Thu, 22 May 2008 18:28:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-122206</guid>
		<description>[...] Ð»ÑŽÐ±Ð¾Ð¿Ñ‹Ñ‚Ð½Ñ‹Ð¹ Ð¿Ð¾ÑÑ‚ Ð½ÐµÐ´Ð°Ð²Ð½Ð¾ Ð¿Ð¾ÑÐ²Ð¸Ð»ÑÑ Ð½Ð° GNUCITIZEN. Ð’ Ð½ÐµÐ¼ Ñ€Ð°ÑÑÐºÐ°Ð·Ñ‹Ð²Ð°ÐµÑ‚ÑÑ Ð¾ [...]</description>
		<content:encoded><![CDATA[<p>[...] Ð»ÑŽÐ±Ð¾Ð¿Ñ‹Ñ‚Ð½Ñ‹Ð¹ Ð¿Ð¾ÑÑ‚ Ð½ÐµÐ´Ð°Ð²Ð½Ð¾ Ð¿Ð¾ÑÐ²Ð¸Ð»ÑÑ Ð½Ð° GNUCITIZEN. Ð’ Ð½ÐµÐ¼ Ñ€Ð°ÑÑÐºÐ°Ð·Ñ‹Ð²Ð°ÐµÑ‚ÑÑ Ð¾ [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Interesting Information Security Bits for May 16th, 2008 &#171; Infosec Ramblings</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-122027</link>
		<dc:creator>Interesting Information Security Bits for May 16th, 2008 &#171; Infosec Ramblings</dc:creator>
		<pubDate>Fri, 16 May 2008 18:04:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-122027</guid>
		<description>[...] has another good post up that takes a look at resident scripts and cross-domain issues using [...]</description>
		<content:encoded><![CDATA[<p>[...] has another good post up that takes a look at resident scripts and cross-domain issues using [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Foobar</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-122025</link>
		<dc:creator>Foobar</dc:creator>
		<pubDate>Fri, 16 May 2008 17:41:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-122025</guid>
		<description>Yah,

Caballero's work is much greater than this. He can insert cross domain javascript etc...</description>
		<content:encoded><![CDATA[<p>Yah,</p>
<p>Caballero&#8217;s work is much greater than this. He can insert cross domain javascript etc&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-122022</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 16 May 2008 17:13:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-122022</guid>
		<description>yes, excellent research and very interesting indeed. Will mention it tmrw at CONFidence.</description>
		<content:encoded><![CDATA[<p>yes, excellent research and very interesting indeed. Will mention it tmrw at CONFidence.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Awesome AnDrEw</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-122010</link>
		<dc:creator>Awesome AnDrEw</dc:creator>
		<pubDate>Fri, 16 May 2008 14:02:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-122010</guid>
		<description>Although I did not use the open method I did come up with something quite similar months ago for an example, which was able to capture the keystrokes placed within an IFRAME element in order to then transmit them back through images in order to provide a basic web key-logger. I do believe I read about this presentation on some other website, but no proof of concept was attached at the time. Nice work.</description>
		<content:encoded><![CDATA[<p>Although I did not use the open method I did come up with something quite similar months ago for an example, which was able to capture the keystrokes placed within an IFRAME element in order to then transmit them back through images in order to provide a basic web key-logger. I do believe I read about this presentation on some other website, but no proof of concept was attached at the time. Nice work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tilki</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-121989</link>
		<dc:creator>tilki</dc:creator>
		<pubDate>Fri, 16 May 2008 10:14:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-121989</guid>
		<description>hi.. good ... :)the turkhackteam...!!! tirtil...</description>
		<content:encoded><![CDATA[<p>hi.. good &#8230; :)the turkhackteam&#8230;!!! tirtil&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-121974</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Fri, 16 May 2008 07:39:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-121974</guid>
		<description>Awesome research and very good writeup, SDC. I wouldn't have expected anything but quality from you anyway ;) 

Greetings, .mario</description>
		<content:encoded><![CDATA[<p>Awesome research and very good writeup, SDC. I wouldn&#8217;t have expected anything but quality from you anyway ;) </p>
<p>Greetings, .mario</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fragge</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-121961</link>
		<dc:creator>fragge</dc:creator>
		<pubDate>Fri, 16 May 2008 04:48:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-121961</guid>
		<description>Excellent post Eduardo ;) keylogging script from a hyperlink! wow.</description>
		<content:encoded><![CDATA[<p>Excellent post Eduardo ;) keylogging script from a hyperlink! wow.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: echoHI</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-121957</link>
		<dc:creator>echoHI</dc:creator>
		<pubDate>Fri, 16 May 2008 04:11:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-121957</guid>
		<description>cool:) I will try to do the further work.</description>
		<content:encoded><![CDATA[<p>cool:) I will try to do the further work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fazed</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-121932</link>
		<dc:creator>fazed</dc:creator>
		<pubDate>Thu, 15 May 2008 23:45:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-121932</guid>
		<description>nice work :)</description>
		<content:encoded><![CDATA[<p>nice work :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rewind</title>
		<link>http://www.gnucitizen.org/blog/ghost-busters/#comment-121901</link>
		<dc:creator>Rewind</dc:creator>
		<pubDate>Thu, 15 May 2008 20:04:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/ghost-busters/#comment-121901</guid>
		<description>I have thought about something of the kind (using onkeydown). My idea was to create a page which set web browser fullscreen, for hiding the real address bar, and remake it with an input balise. After that, you can control what you want, can't you ?</description>
		<content:encoded><![CDATA[<p>I have thought about something of the kind (using onkeydown). My idea was to create a page which set web browser fullscreen, for hiding the real address bar, and remake it with an input balise. After that, you can control what you want, can&#8217;t you ?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
