<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Persistent Bi-directional Communication Channels</title>
	<atom:link href="http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Sun, 23 Nov 2008 13:05:19 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: AttackAPI 0.8 is OUT &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/#comment-123990</link>
		<dc:creator>AttackAPI 0.8 is OUT &#124; GNUCITIZEN</dc:creator>
		<pubDate>Fri, 10 Oct 2008 08:19:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels#comment-123990</guid>
		<description>[...] is currently available. That is important because the Web is very distributed and agile network and controlling dozens of infected clients is a mission on its [...]</description>
		<content:encoded><![CDATA[<p>[...] is currently available. That is important because the Web is very distributed and agile network and controlling dozens of infected clients is a mission on its [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mobile Zombies, XSSWW, hack the planet? &#171; RETURN $ecure;</title>
		<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/#comment-70964</link>
		<dc:creator>Mobile Zombies, XSSWW, hack the planet? &#171; RETURN $ecure;</dc:creator>
		<pubDate>Thu, 15 Nov 2007 03:00:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels#comment-70964</guid>
		<description>[...] using bi-directional persistent communication channels to control browsers isn&#8217;t anything new,Â  nor is theÂ  concept of a Cross Site Scripting [...]</description>
		<content:encoded><![CDATA[<p>[...] using bi-directional persistent communication channels to control browsers isn&#8217;t anything new,Â  nor is theÂ  concept of a Cross Site Scripting [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; Carnaval</title>
		<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/#comment-2436</link>
		<dc:creator>GNUCITIZEN &#187; Carnaval</dc:creator>
		<pubDate>Tue, 16 Jan 2007 12:56:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels#comment-2436</guid>
		<description>[...] The project was announced on August 24th, 2006 in a post called &#8220;Introducing Carnaval&#8221;. The concept behind Carnaval&#8217;s channel interface is covered in the &#8220;Persistent Bi-directional Communication Channels&#8221; article in October 2nd, 2006. [...]</description>
		<content:encoded><![CDATA[<p>[...] The project was announced on August 24th, 2006 in a post called &#8220;Introducing Carnaval&#8221;. The concept behind Carnaval&#8217;s channel interface is covered in the &#8220;Persistent Bi-directional Communication Channels&#8221; article in October 2nd, 2006. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: indubitably&#8230; &#187; Backframe JavaScript Attack Console</title>
		<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/#comment-1219</link>
		<dc:creator>indubitably&#8230; &#187; Backframe JavaScript Attack Console</dc:creator>
		<pubDate>Wed, 13 Dec 2006 18:09:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels#comment-1219</guid>
		<description>[...] Right now it is quite stable and it should work well with attack channels similar to the one described here: http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels [...]</description>
		<content:encoded><![CDATA[<p>[...] Right now it is quite stable and it should work well with attack channels similar to the one described here: <a href="http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels" rel="nofollow">http://www.gnucitizen.org/blog.....n-channels</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Backframe (Formerly Backweb) JavaScript Attack Console &#187;</title>
		<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/#comment-1197</link>
		<dc:creator>Backframe (Formerly Backweb) JavaScript Attack Console &#187;</dc:creator>
		<pubDate>Wed, 13 Dec 2006 02:49:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels#comment-1197</guid>
		<description>[...] Persistent Bi-directional Communication Channels [...]</description>
		<content:encoded><![CDATA[<p>[...] Persistent Bi-directional Communication Channels [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; Sploiter Splog</title>
		<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/#comment-696</link>
		<dc:creator>GNUCITIZEN &#187; Sploiter Splog</dc:creator>
		<pubDate>Sat, 18 Nov 2006 07:04:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels#comment-696</guid>
		<description>[...] Using the techniques such as persistent channels, backdoors in QuickTime, backdoors in Flash, backdoors in PDF, backdoors in RealMedia and backdoors in RSS feeds in conjunction with splogs one can achieve quite a lot. Sometimes I even scare myself when I start thinking more deeply about this problem. Moreover, I know that the process can be automated. Every flash file the sploger downloads can be altered; every sound, backdoored; every image, changed. It is not a war between the humans and the machines. It is a war between us and ourselves only. [...]</description>
		<content:encoded><![CDATA[<p>[...] Using the techniques such as persistent channels, backdoors in QuickTime, backdoors in Flash, backdoors in PDF, backdoors in RealMedia and backdoors in RSS feeds in conjunction with splogs one can achieve quite a lot. Sometimes I even scare myself when I start thinking more deeply about this problem. Moreover, I know that the process can be automated. Every flash file the sploger downloads can be altered; every sound, backdoored; every image, changed. It is not a war between the humans and the machines. It is a war between us and ourselves only. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; Backframe (0.1a)</title>
		<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/#comment-500</link>
		<dc:creator>GNUCITIZEN &#187; Backframe (0.1a)</dc:creator>
		<pubDate>Mon, 06 Nov 2006 03:22:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels#comment-500</guid>
		<description>[...] The application is in its 0.1a release currently. This means that a lot more work needs to be done. Right now it is quite stable and it should work well with attack channels similar to the one described here. Check the AttackAPI project for the attack channel complete source code. [...]</description>
		<content:encoded><![CDATA[<p>[...] The application is in its 0.1a release currently. This means that a lot more work needs to be done. Right now it is quite stable and it should work well with attack channels similar to the one described here. Check the AttackAPI project for the attack channel complete source code. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; Introducing Backweb</title>
		<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/#comment-389</link>
		<dc:creator>GNUCITIZEN &#187; Introducing Backweb</dc:creator>
		<pubDate>Mon, 30 Oct 2006 09:36:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels#comment-389</guid>
		<description>[...] The application is in its 0.1a release currently. This means that a lot more work needs to be done. Right now it is quite stable and it should work well with attack channels similar to the one described here. Check the AttackAPI project for the attack channel complete source code. [...]</description>
		<content:encoded><![CDATA[<p>[...] The application is in its 0.1a release currently. This means that a lot more work needs to be done. Right now it is quite stable and it should work well with attack channels similar to the one described here. Check the AttackAPI project for the attack channel complete source code. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/#comment-200</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 06 Oct 2006 01:32:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels#comment-200</guid>
		<description>Brad, very good point. I have a few more things to finish before going into this issue. I get the feeling that it is possible but than I again I've been wrong before, so you are right: the theory might not work in practice. Let's see.</description>
		<content:encoded><![CDATA[<p>Brad, very good point. I have a few more things to finish before going into this issue. I get the feeling that it is possible but than I again I&#8217;ve been wrong before, so you are right: the theory might not work in practice. Let&#8217;s see.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Neuberg</title>
		<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/#comment-194</link>
		<dc:creator>Brad Neuberg</dc:creator>
		<pubDate>Thu, 05 Oct 2006 12:58:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels#comment-194</guid>
		<description>The reason I say this is the devil is in the details when it comes to JavaScript Flash communication, so the theory might not work in practice (which Im hoping ;)</description>
		<content:encoded><![CDATA[<p>The reason I say this is the devil is in the details when it comes to JavaScript Flash communication, so the theory might not work in practice (which Im hoping ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/#comment-188</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 05 Oct 2006 01:34:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels#comment-188</guid>
		<description>Hi Brad,

I am planning to write hacked version of Flash Storage model soon. In this article I am presenting the technique and the theory behind it. Of course that is not sufficient.

Soon there will be an examples as well and I am planning to do this in the 0.9 release of AttackAPI. Thanks for the comment.</description>
		<content:encoded><![CDATA[<p>Hi Brad,</p>
<p>I am planning to write hacked version of Flash Storage model soon. In this article I am presenting the technique and the theory behind it. Of course that is not sufficient.</p>
<p>Soon there will be an examples as well and I am planning to do this in the 0.9 release of AttackAPI. Thanks for the comment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Neuberg</title>
		<link>http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels/#comment-186</link>
		<dc:creator>Brad Neuberg</dc:creator>
		<pubDate>Wed, 04 Oct 2006 19:36:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/persistent-bi-directional-communication-channels#comment-186</guid>
		<description>This is interesting but I'd like to see an actual working example. My Dojo Storage flash code, for example, must be invoked and loaded on page load since it depends on a document.write; I'm not sure if a dynamic SCRIPT tag could invoke it and set it up. If the original domain already has Dojo Storage or the given flash file then that is one thing, but what if it doesn't?</description>
		<content:encoded><![CDATA[<p>This is interesting but I&#8217;d like to see an actual working example. My Dojo Storage flash code, for example, must be invoked and loaded on page load since it depends on a document.write; I&#8217;m not sure if a dynamic SCRIPT tag could invoke it and set it up. If the original domain already has Dojo Storage or the given flash file then that is one thing, but what if it doesn&#8217;t?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
