<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Self-contained XSS Attacks</title>
	<atom:link href="http://www.gnucitizen.org/blog/self-contained-xss-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: A bag full of tricks &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-125026</link>
		<dc:creator>A bag full of tricks &#124; GNUCITIZEN</dc:creator>
		<pubDate>Fri, 02 Jan 2009 10:08:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-125026</guid>
		<description>[...] too long ago I presented a technique that can be used to compose self-contained html pages. Apart from the most obvious use [...]</description>
		<content:encoded><![CDATA[<p>[...] too long ago I presented a technique that can be used to compose self-contained html pages. Apart from the most obvious use [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-6746</link>
		<dc:creator>john</dc:creator>
		<pubDate>Tue, 13 Mar 2007 23:20:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-6746</guid>
		<description>nice</description>
		<content:encoded><![CDATA[<p>nice</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Life of an OWASP Chapter Leader &#187; Blog Archive &#187; JavaScript Badware</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-5115</link>
		<dc:creator>Life of an OWASP Chapter Leader &#187; Blog Archive &#187; JavaScript Badware</dc:creator>
		<pubDate>Thu, 22 Feb 2007 19:41:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-5115</guid>
		<description>[...] What worries me are the next stages. Recently XSS was the attack vector discovered in Google&#8217;s popular Desktop Search. One of the tools referenced in the research paper is the XSS proxy tool. This reminded me of the post by PDP on persistent XSS, stating &#8220;Persistent XSS is more dangerous since it allow attackers to control exploited clients for longer&#8221;. [...]</description>
		<content:encoded><![CDATA[<p>[...] What worries me are the next stages. Recently XSS was the attack vector discovered in Google&#8217;s popular Desktop Search. One of the tools referenced in the research paper is the XSS proxy tool. This reminded me of the post by PDP on persistent XSS, stating &#8220;Persistent XSS is more dangerous since it allow attackers to control exploited clients for longer&#8221;. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kishor</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-236</link>
		<dc:creator>Kishor</dc:creator>
		<pubDate>Wed, 11 Oct 2006 06:31:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-236</guid>
		<description>This is how Orkut thing could have happened http://wasjournal.blogspot.com/2006/10/my-interpretation-orkut-vector.html</description>
		<content:encoded><![CDATA[<p>This is how Orkut thing could have happened <a href="http://wasjournal.blogspot.com/2006/10/my-interpretation-orkut-vector.html" rel="nofollow">http://wasjournal.blogspot.com.....ector.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-218</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 09 Oct 2006 09:28:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-218</guid>
		<description>My original tests were a failure but now when you are saying that it is possible I must have a second look at this issue. Thanks, man.</description>
		<content:encoded><![CDATA[<p>My original tests were a failure but now when you are saying that it is possible I must have a second look at this issue. Thanks, man.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kishor</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-215</link>
		<dc:creator>Kishor</dc:creator>
		<pubDate>Mon, 09 Oct 2006 08:48:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-215</guid>
		<description>I&#039;m able to read cookies using this technique! Not directly but certainly possible. MustLive is right</description>
		<content:encoded><![CDATA[<p>I&#8217;m able to read cookies using this technique! Not directly but certainly possible. MustLive is right</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kishor</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-214</link>
		<dc:creator>Kishor</dc:creator>
		<pubDate>Mon, 09 Oct 2006 08:27:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-214</guid>
		<description>pdp,

Unfortunately I do not have the HTML stored, because they fixed it too quickly. Fortunately I had taken this snapshot. But I&#039;m sure many Indians have seen that flag that day. URL decoded version looks like this

&lt;pre&gt;&lt;code&gt;www.orkut.com/&quot;&gt;&lt;/a&gt;&lt;img src=&quot;http://www.bandeirasanimadas.com/Asia/India/3dflagsdotcom_india_2fawm.gif&quot;
onload=alert(1)&gt;&lt;a style=&quot;display:none&quot; href=&quot;&gt;/code rel=&quot;nofollow&quot;&lt;&lt;/pre&gt;&lt;/code&gt;</description>
		<content:encoded><![CDATA[<p>pdp,</p>
<p>Unfortunately I do not have the HTML stored, because they fixed it too quickly. Fortunately I had taken this snapshot. But I&#8217;m sure many Indians have seen that flag that day. URL decoded version looks like this</p>
<pre><code><a href="http://www.orkut.com/" rel="nofollow">http://www.orkut.com/</a>"&gt;&lt;/a&gt;&lt;img src="http://www.bandeirasanimadas.com/Asia/India/3dflagsdotcom_india_2fawm.gif"
onload=alert(1)&gt;&lt;a style="display:none" href="&gt;/code rel="nofollow"&lt;</code></pre>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-213</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 09 Oct 2006 02:16:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-213</guid>
		<description>Kishor, that is quite interesting but it will be even more if we can see some HTML. :)</description>
		<content:encoded><![CDATA[<p>Kishor, that is quite interesting but it will be even more if we can see some HTML. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kishor</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-207</link>
		<dc:creator>Kishor</dc:creator>
		<pubDate>Fri, 06 Oct 2006 18:01:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-207</guid>
		<description>Not sure under what topic should I put this.
http://wasjournal.blogspot.com/2006/10/orkut-xss-silently-fixed-www.html</description>
		<content:encoded><![CDATA[<p>Not sure under what topic should I put this.<br />
<a href="http://wasjournal.blogspot.com/2006/10/orkut-xss-silently-fixed-www.html" rel="nofollow">http://wasjournal.blogspot.com.....d-www.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MustLive</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-169</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Fri, 29 Sep 2006 15:01:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-169</guid>
		<description>pdp and RSnake. Why do you think, that cookies theft don&#039;t work with this attack vector. As I tested the alert(document.cookie) script is working fine and you may see cookie (and so you may steal it).

You just need to put a link with appropriate (encrypted) data in href attribute on site. And than cookies tricks will be possible in current domain.</description>
		<content:encoded><![CDATA[<p>pdp and RSnake. Why do you think, that cookies theft don&#8217;t work with this attack vector. As I tested the alert(document.cookie) script is working fine and you may see cookie (and so you may steal it).</p>
<p>You just need to put a link with appropriate (encrypted) data in href attribute on site. And than cookies tricks will be possible in current domain.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: matthewtheexploit</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-153</link>
		<dc:creator>matthewtheexploit</dc:creator>
		<pubDate>Tue, 26 Sep 2006 01:29:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-153</guid>
		<description>heh nice guys, i&#039;ve known about this for a while, didnt think it would work for other applications, nice jobb i love your guy&#039;s work at this site :)</description>
		<content:encoded><![CDATA[<p>heh nice guys, i&#8217;ve known about this for a while, didnt think it would work for other applications, nice jobb i love your guy&#8217;s work at this site :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-136</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sat, 23 Sep 2006 12:35:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-136</guid>
		<description>Hi superlone,

As far as I know IE6 and IE7 does not support data URLs. However, I believe that this is quite useful feature that could benefit many AJAX applications. I won&#039;t be surprised if Microsoft implements data URLs or similar mechanism some day.

Again, although it is quite useful, keep in mind that this can be used in very bad ways.</description>
		<content:encoded><![CDATA[<p>Hi superlone,</p>
<p>As far as I know IE6 and IE7 does not support data URLs. However, I believe that this is quite useful feature that could benefit many AJAX applications. I won&#8217;t be surprised if Microsoft implements data URLs or similar mechanism some day.</p>
<p>Again, although it is quite useful, keep in mind that this can be used in very bad ways.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: superlone</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-134</link>
		<dc:creator>superlone</dc:creator>
		<pubDate>Sat, 23 Sep 2006 11:24:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-134</guid>
		<description>this is very useful and helpful article.But i have one question,the uri like this:

&lt;pre&gt;&lt;code&gt;data:text/html;base64,PHNjcmlwdD4NCmFsZXJ0KCJTZWxmLWNvbnRhaW5lZCBYU1MiKTsNCjwvc2NyaXB0Pg==&lt;/code&gt;&lt;/pre&gt;

can it work on IE?i really want to know,thanks!</description>
		<content:encoded><![CDATA[<p>this is very useful and helpful article.But i have one question,the uri like this:</p>
<pre><code>data:text/html;base64,PHNjcmlwdD4NCmFsZXJ0KCJTZWxmLWNvbnRhaW5lZCBYU1MiKTsNCjwvc2NyaXB0Pg==</code></pre>
<p>can it work on IE?i really want to know,thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: manus</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-129</link>
		<dc:creator>manus</dc:creator>
		<pubDate>Sat, 23 Sep 2006 02:14:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-129</guid>
		<description>This reminds me of the old functionality (now disabled) in Netscape&#039;s about: &quot;protocol&quot;.  Circa &#039;98 I used to set the start pages on my high school&#039;s machines to &quot;about:Hi [the admin&#039;s name]!&quot; or something stupid like that.

Also see http://www.guninski.com/netscape.html</description>
		<content:encoded><![CDATA[<p>This reminds me of the old functionality (now disabled) in Netscape&#8217;s about: &#8220;protocol&#8221;.  Circa &#8217;98 I used to set the start pages on my high school&#8217;s machines to &#8220;about:Hi [the admin's name]!&#8221; or something stupid like that.</p>
<p>Also see <a href="http://www.guninski.com/netscape.html" rel="nofollow">http://www.guninski.com/netscape.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-126</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Fri, 22 Sep 2006 22:36:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-126</guid>
		<description>Nice work pdp! Another reminder that we shouldn&#039;t trust anything when we go online.

Here is my personal recipe for those users that are paranoid:

- go online using restricted-user privileges
- use a browser extension which allows you to whitelist which domains are allowed to run scripting (i.e.: Firefox&#039;s NoScript)
- use common sense!

Will keep checking your site regularly pdp!</description>
		<content:encoded><![CDATA[<p>Nice work pdp! Another reminder that we shouldn&#8217;t trust anything when we go online.</p>
<p>Here is my personal recipe for those users that are paranoid:</p>
<p>- go online using restricted-user privileges<br />
- use a browser extension which allows you to whitelist which domains are allowed to run scripting (i.e.: Firefox&#8217;s NoScript)<br />
- use common sense!</p>
<p>Will keep checking your site regularly pdp!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-125</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Fri, 22 Sep 2006 20:37:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-125</guid>
		<description>RSnake, I didn&#039;t even know this attack vector was in your cheat sheet and I have been through it loads of times - A table of contents might be cool.

pdp, cool paper.. I think this area needed additional light and explanation.

I would like to think that any half decent application filter should be able to decode base64 and check it for script tags, but heck, who am I kidding :)</description>
		<content:encoded><![CDATA[<p>RSnake, I didn&#8217;t even know this attack vector was in your cheat sheet and I have been through it loads of times &#8211; A table of contents might be cool.</p>
<p>pdp, cool paper.. I think this area needed additional light and explanation.</p>
<p>I would like to think that any half decent application filter should be able to decode base64 and check it for script tags, but heck, who am I kidding :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-124</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 22 Sep 2006 18:48:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-124</guid>
		<description>Hi Denver,

I stated that it doesn&#039;t work in IE6 and IE7. I don&#039;t quite agree that it is harmless for reasons I have already discussed in this post.</description>
		<content:encoded><![CDATA[<p>Hi Denver,</p>
<p>I stated that it doesn&#8217;t work in IE6 and IE7. I don&#8217;t quite agree that it is harmless for reasons I have already discussed in this post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blad3</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-123</link>
		<dc:creator>Blad3</dc:creator>
		<pubDate>Fri, 22 Sep 2006 17:36:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-123</guid>
		<description>RSnake, would you like to describe in more detaila what do you mean with &quot;building CSRF tools&quot;. CSRF - cross site request forgery - I suppose.

Thanks</description>
		<content:encoded><![CDATA[<p>RSnake, would you like to describe in more detaila what do you mean with &#8220;building CSRF tools&#8221;. CSRF &#8211; cross site request forgery &#8211; I suppose.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denver</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-122</link>
		<dc:creator>Denver</dc:creator>
		<pubDate>Fri, 22 Sep 2006 16:38:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-122</guid>
		<description>this is not work in IE.6.0

&lt;pre&gt;&lt;code&gt;data:text/html;base64,PHNjcmlwdD4NCmFsZXJ0KCJTZWxmLWNvbnRhaW5lZCBYU1MiKTsNCjwvc2NyaXB0Pg==&lt;/code&gt;&lt;/pre&gt;

The browser shows that &quot;the page can not be displayed&quot;. Even if it works, all this is harmless, just useless tricks.. I cannot get remote control, cannnot install files remotely, cannot change/delete html pages..</description>
		<content:encoded><![CDATA[<p>this is not work in IE.6.0</p>
<pre><code>data:text/html;base64,PHNjcmlwdD4NCmFsZXJ0KCJTZWxmLWNvbnRhaW5lZCBYU1MiKTsNCjwvc2NyaXB0Pg==</code></pre>
<p>The browser shows that &#8220;the page can not be displayed&#8221;. Even if it works, all this is harmless, just useless tricks.. I cannot get remote control, cannnot install files remotely, cannot change/delete html pages..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/self-contained-xss-attacks/comment-page-1/#comment-121</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 22 Sep 2006 16:07:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/self-contained-xss-attacks#comment-121</guid>
		<description>RSnake,

I am not claiming it is new. In fact I clearly stated in my post that some of you may already be familiar with it. Apparently you are.

To be honest with you, cookie theft is probably one of least things I am interested in. Data URLs are brilliant for enabling very powerful attacks. I am surprised that they have been covered so vaguely in past. There is so much potential in them.

I am quite concerned about JavaScript tools being able to assemble PDF and DOC documents on the fly. What about worms that carry their payloads in a single URL? IMHO this is a serious security issue.</description>
		<content:encoded><![CDATA[<p>RSnake,</p>
<p>I am not claiming it is new. In fact I clearly stated in my post that some of you may already be familiar with it. Apparently you are.</p>
<p>To be honest with you, cookie theft is probably one of least things I am interested in. Data URLs are brilliant for enabling very powerful attacks. I am surprised that they have been covered so vaguely in past. There is so much potential in them.</p>
<p>I am quite concerned about JavaScript tools being able to assemble PDF and DOC documents on the fly. What about worms that carry their payloads in a single URL? IMHO this is a serious security issue.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
