<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Google AJAX Feed API Dangers</title>
	<atom:link href="http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Tue, 06 Jan 2009 05:51:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Kishor</title>
		<link>http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers/comment-page-1/#comment-16702</link>
		<dc:creator>Kishor</dc:creator>
		<pubDate>Wed, 25 Apr 2007 12:56:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers#comment-16702</guid>
		<description>I can't wait any longer to see what you present at OWASP con. 

But I live faaar away from Italy, and therefore a video would help!

Otherwise I'm sure you'll share it in some other form anyway.</description>
		<content:encoded><![CDATA[<p>I can&#8217;t wait any longer to see what you present at OWASP con. </p>
<p>But I live faaar away from Italy, and therefore a video would help!</p>
<p>Otherwise I&#8217;m sure you&#8217;ll share it in some other form anyway.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers/comment-page-1/#comment-16645</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 25 Apr 2007 10:22:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers#comment-16645</guid>
		<description>you are telling me that... :) wait for the OWASP con. I have some really good stuff for it.</description>
		<content:encoded><![CDATA[<p>you are telling me that&#8230; :) wait for the OWASP con. I have some really good stuff for it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kishor</title>
		<link>http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers/comment-page-1/#comment-16615</link>
		<dc:creator>Kishor</dc:creator>
		<pubDate>Wed, 25 Apr 2007 09:02:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers#comment-16615</guid>
		<description>One thing is for sure. Now we can have thousands of web pages subscribing to
http://sla.ckers.org/forum/rss.php
http://www.securityfocus.com/rss/vulnerabilities.xml
etc.

And along with google search API, they can exploit sites as soon as the advisories are released.</description>
		<content:encoded><![CDATA[<p>One thing is for sure. Now we can have thousands of web pages subscribing to<br />
<a href="http://sla.ckers.org/forum/rss.php" rel="nofollow">http://sla.ckers.org/forum/rss.php</a><br />
<a href="http://www.securityfocus.com/rss/vulnerabilities.xml" rel="nofollow">http://www.securityfocus.com/r.....lities.xml</a><br />
etc.</p>
<p>And along with google search API, they can exploit sites as soon as the advisories are released.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers/comment-page-1/#comment-15657</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 23 Apr 2007 08:40:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers#comment-15657</guid>
		<description>MustLive, actually I am actively taking part in the "Public site vulnerability research" panel so I will try present my point of view.

I think that OWASP does a good job at exposing what has been discussed on their conferences. However, If the miss something I most definitely put it on GNUCITIZEN.</description>
		<content:encoded><![CDATA[<p>MustLive, actually I am actively taking part in the &#8220;Public site vulnerability research&#8221; panel so I will try present my point of view.</p>
<p>I think that OWASP does a good job at exposing what has been discussed on their conferences. However, If the miss something I most definitely put it on GNUCITIZEN.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MustLive</title>
		<link>http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers/comment-page-1/#comment-15337</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Sun, 22 Apr 2007 01:35:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers#comment-15337</guid>
		<description>Google AJAX Feed API is nice. And yes, it has dangers :-). The security aspects of this are obvious.

And you remember about it for web community once more (it is necessary to remember periodically about danger of some things to people). Circumventing of SOP especially. In some case SOP need to be circumvented (for hackers).

P.S.

You can talk about the legal side of disclosing bugs at conference, if you are going to. But you need to incline that it is legal and good ;-). Disclosure policy need to be considered, but in any case it is for good purposes.</description>
		<content:encoded><![CDATA[<p>Google AJAX Feed API is nice. And yes, it has dangers :-). The security aspects of this are obvious.</p>
<p>And you remember about it for web community once more (it is necessary to remember periodically about danger of some things to people). Circumventing of SOP especially. In some case SOP need to be circumvented (for hackers).</p>
<p>P.S.</p>
<p>You can talk about the legal side of disclosing bugs at conference, if you are going to. But you need to incline that it is legal and good ;-). Disclosure policy need to be considered, but in any case it is for good purposes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MustLive</title>
		<link>http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers/comment-page-1/#comment-15334</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Sun, 22 Apr 2007 01:24:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers#comment-15334</guid>
		<description>The 6th OWASP Conference will be nice event and it is good that you will be there and take part in conference.

Pdp, please, think about writing summary about OWASP Conference. You may write brief info about whole conference (what was the most interesting and what do you liked more) and write detailed info about your speech (Advance Web Hacking Revealed) and your last projects.

Also there are some other nice topics:
* Panel: "Public site vulnerability research - good or evil?â€ (for good ;-) )
* Protecting Web Applications from Universal PDF XSS: A discussion of how weird the web application security world has become (UXSS is a hot topic)
* Testing Flash Applications: A new attack vector for XSS and XSFlashing (it will be simultaneously with your speech)

About these topics you may write additional posts (with more details than just in brief post). I think there will be a lot of interesting information on conference.</description>
		<content:encoded><![CDATA[<p>The 6th OWASP Conference will be nice event and it is good that you will be there and take part in conference.</p>
<p>Pdp, please, think about writing summary about OWASP Conference. You may write brief info about whole conference (what was the most interesting and what do you liked more) and write detailed info about your speech (Advance Web Hacking Revealed) and your last projects.</p>
<p>Also there are some other nice topics:<br />
* Panel: &#8220;Public site vulnerability research - good or evil?â€ (for good ;-) )<br />
* Protecting Web Applications from Universal PDF XSS: A discussion of how weird the web application security world has become (UXSS is a hot topic)<br />
* Testing Flash Applications: A new attack vector for XSS and XSFlashing (it will be simultaneously with your speech)</p>
<p>About these topics you may write additional posts (with more details than just in brief post). I think there will be a lot of interesting information on conference.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; TinyURL FS among Other Things</title>
		<link>http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers/comment-page-1/#comment-15047</link>
		<dc:creator>GNUCITIZEN &#187; TinyURL FS among Other Things</dc:creator>
		<pubDate>Fri, 20 Apr 2007 11:36:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-ajax-feed-api-dangers#comment-15047</guid>
		<description>[...] I guess I repeat myself but I wanted to inform you one more time about the current state of my public research. As I mentioned in my previous post, I am doing a talk on 6th OWASP conference about too many interesting things. I am not planning to talk on BlackHast or Defcon because I will be extremely busy at the time when they take place, so I will try to get out as mush information in a form of podcasts, screencasts and blog posts after OWASP. [...]</description>
		<content:encoded><![CDATA[<p>[...] I guess I repeat myself but I wanted to inform you one more time about the current state of my public research. As I mentioned in my previous post, I am doing a talk on 6th OWASP conference about too many interesting things. I am not planning to talk on BlackHast or Defcon because I will be extremely busy at the time when they take place, so I will try to get out as mush information in a form of podcasts, screencasts and blog posts after OWASP. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
