<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Next Super Worm</title>
	<atom:link href="http://www.gnucitizen.org/blog/the-next-super-worm/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/the-next-super-worm/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Thu, 11 Mar 2010 22:49:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: netfish</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-123751</link>
		<dc:creator>netfish</dc:creator>
		<pubDate>Wed, 17 Sep 2008 18:46:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-123751</guid>
		<description>It is ridiculous how so many web developers and admins ignore to say on the top of their game by simply doing their homework, for example: checking sites such as XSSed.com, and even zone-H for mentions of their domains. 

I have several unfixed XSSes on my page which I have repeatedly warned the owners of the domains about, but they either leave the holes open or plainly, I assume, do not know how to patch vulnerabilities. 

Phishing attacks remain the most dangerous, in my opinion, due to the possible payloads.</description>
		<content:encoded><![CDATA[<p>It is ridiculous how so many web developers and admins ignore to say on the top of their game by simply doing their homework, for example: checking sites such as XSSed.com, and even zone-H for mentions of their domains. </p>
<p>I have several unfixed XSSes on my page which I have repeatedly warned the owners of the domains about, but they either leave the holes open or plainly, I assume, do not know how to patch vulnerabilities. </p>
<p>Phishing attacks remain the most dangerous, in my opinion, due to the possible payloads.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Uber0n</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-118519</link>
		<dc:creator>Uber0n</dc:creator>
		<pubDate>Wed, 09 Apr 2008 13:52:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-118519</guid>
		<description>I just wanted to add a few words here, since I often submit sites to XSSed.com

I report all XSS vulnerabilities I find to XSSed, and I contact the owners of the sites when I have the time and believe that they will care. For example when I find a XSS in Google I know that they will thank me for my help and patch it as soon as possible, but on smaller sites like personal home pages webmasters seldom even respond to my emails.

I think of this as a &#039;white-hat sport&#039;, if you can call it that. I can help people to increase their online security, but I also get points on XSSed proving that I do so. It may sound childish to collect points, but it sure works to keep me motivated ;)

Currently I have the highest amount of fixed XSS vulnerabilities of all XSSed submitters, and I&#039;ll try to keep it that way as long as the site stays online.

// Uber0n</description>
		<content:encoded><![CDATA[<p>I just wanted to add a few words here, since I often submit sites to XSSed.com</p>
<p>I report all XSS vulnerabilities I find to XSSed, and I contact the owners of the sites when I have the time and believe that they will care. For example when I find a XSS in Google I know that they will thank me for my help and patch it as soon as possible, but on smaller sites like personal home pages webmasters seldom even respond to my emails.</p>
<p>I think of this as a &#8216;white-hat sport&#8217;, if you can call it that. I can help people to increase their online security, but I also get points on XSSed proving that I do so. It may sound childish to collect points, but it sure works to keep me motivated ;)</p>
<p>Currently I have the highest amount of fixed XSS vulnerabilities of all XSSed submitters, and I&#8217;ll try to keep it that way as long as the site stays online.</p>
<p>// Uber0n</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dimitris Pagkalos</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-35418</link>
		<dc:creator>Dimitris Pagkalos</dc:creator>
		<pubDate>Sat, 14 Jul 2007 00:09:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-35418</guid>
		<description>And always bear in mind that the harsh judgments/criticisms you make about others, and the way you express them, are about the same things you resist recognizing in yourself. Millions of ppl agree! You can say the same thing for me, but that would just show immaturity since you know who started it all off. Only thing you will succeed is showing once more that you don&#039;t read carefully - thus not understanding well.

D</description>
		<content:encoded><![CDATA[<p>And always bear in mind that the harsh judgments/criticisms you make about others, and the way you express them, are about the same things you resist recognizing in yourself. Millions of ppl agree! You can say the same thing for me, but that would just show immaturity since you know who started it all off. Only thing you will succeed is showing once more that you don&#8217;t read carefully &#8211; thus not understanding well.</p>
<p>D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dim</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-35230</link>
		<dc:creator>Dim</dc:creator>
		<pubDate>Thu, 12 Jul 2007 05:46:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-35230</guid>
		<description>oh dear,

Guess what Renko Karman... I am now going to give a very very big answer! You stimulated my ego you see - YOUR perception of my ego since you know me from yesterday! :P Ego for you means smilies and long replies(excuses as you called mine). You have a very wrong way of perceivings things in general. You have a very wrong way of approaching people too with your poor &quot;lil&quot; criticism, and of communicating with people. If you want please tell me the truth, are you self-taught in IRONIC criticism with no positive context?

As an egoist, I honestly believe that I owe you a better explanation... I did not defend against any accussation. I did not come here to defend the pride of XSSed or any pride. Based on pdp&#039;s scenario, me and Kevin came here to discuss with him and the readers possible ways to prevent it from occuring now and in the future (with more sites indexed in our db). We came also to consider opinions for improving our service. [read old news on our site]
All the discussions were polite, visitors of this blog post exchanged information (opinions and ideas), until you visited here and started throwing your cosmetic adjectives to me: &quot;and to me, your excuse certainly sounds cheap, so maybe you really are?&quot; etc [refer]

We took the initiative to create something for the webappsec community and with the scope of increasing security on the web. This service is up since February 2007. There is currently one &quot;flaw&quot; in its design. What is currently missing is a sophisticated early warning mailing list subscription feature. This feature is currenty being developed. Alternatively there are other methods of notifying webmasters for their XSS vulnerable sites: e-mail, our SEOed mirrors (check with &quot;yoursite.com xss&quot;). 

They care about their webappsec? XSS is webappvuln? XSSed deals with XSS? Surely they&#039;ll find us and manually monitor us for their websites. Until the early warning feature is completely coded, we are not going to publish major mirrors without making sure that submitters contacted them. Otherwise we contact them.

Obviously you have misunderstood my comments as excuses from your very first post and did not do your homework. It was this misunderstanding that made you think you are smart enough to sum up my &quot;statement&quot; in one sentence: “you are not obligated to warn anyone.” I never said anything like that my friend Renko Karman. Can you please clarify where your summing up is based? Show me your understanding for once!

You may have a different point of view about something, but you must know that a point of view is always based on your awareness of all or some aspects of that something. In case you did not get it, your point of view was based on incomplete knowledge. Incomplete knowledge usually comes from wrong understanding. Wrong understanding comes because you are dumb - generally speaking, no offense Renko!. 

As for the things you never said, it was my mistake to believe that you are quite good at receiving jokes and irony - judging of course from all your offensive type of comments. Treat for treat!

I hope that you understand better now... Cos an answer that long ain&#039;t bullshittin! Aiight? :P &lt;-- ego smiley,feeling of defeat. :P

PS1: I wanted to know your name because I like to know with whom I am discussing with... ;) You see... I am part of the &quot;Security Paranoia, keeping us clothed and fed since init().&quot; generation.

PS2: Anything that you might find offensive in this post, I would ask you please to cross it out of your mind. Thanks.

My Best Regards and Wishes for your digital life,

D</description>
		<content:encoded><![CDATA[<p>oh dear,</p>
<p>Guess what Renko Karman&#8230; I am now going to give a very very big answer! You stimulated my ego you see &#8211; YOUR perception of my ego since you know me from yesterday! :P Ego for you means smilies and long replies(excuses as you called mine). You have a very wrong way of perceivings things in general. You have a very wrong way of approaching people too with your poor &#8220;lil&#8221; criticism, and of communicating with people. If you want please tell me the truth, are you self-taught in IRONIC criticism with no positive context?</p>
<p>As an egoist, I honestly believe that I owe you a better explanation&#8230; I did not defend against any accussation. I did not come here to defend the pride of XSSed or any pride. Based on pdp&#8217;s scenario, me and Kevin came here to discuss with him and the readers possible ways to prevent it from occuring now and in the future (with more sites indexed in our db). We came also to consider opinions for improving our service. [read old news on our site]<br />
All the discussions were polite, visitors of this blog post exchanged information (opinions and ideas), until you visited here and started throwing your cosmetic adjectives to me: &#8220;and to me, your excuse certainly sounds cheap, so maybe you really are?&#8221; etc [refer]</p>
<p>We took the initiative to create something for the webappsec community and with the scope of increasing security on the web. This service is up since February 2007. There is currently one &#8220;flaw&#8221; in its design. What is currently missing is a sophisticated early warning mailing list subscription feature. This feature is currenty being developed. Alternatively there are other methods of notifying webmasters for their XSS vulnerable sites: e-mail, our SEOed mirrors (check with &#8220;yoursite.com xss&#8221;). </p>
<p>They care about their webappsec? XSS is webappvuln? XSSed deals with XSS? Surely they&#8217;ll find us and manually monitor us for their websites. Until the early warning feature is completely coded, we are not going to publish major mirrors without making sure that submitters contacted them. Otherwise we contact them.</p>
<p>Obviously you have misunderstood my comments as excuses from your very first post and did not do your homework. It was this misunderstanding that made you think you are smart enough to sum up my &#8220;statement&#8221; in one sentence: “you are not obligated to warn anyone.” I never said anything like that my friend Renko Karman. Can you please clarify where your summing up is based? Show me your understanding for once!</p>
<p>You may have a different point of view about something, but you must know that a point of view is always based on your awareness of all or some aspects of that something. In case you did not get it, your point of view was based on incomplete knowledge. Incomplete knowledge usually comes from wrong understanding. Wrong understanding comes because you are dumb &#8211; generally speaking, no offense Renko!. </p>
<p>As for the things you never said, it was my mistake to believe that you are quite good at receiving jokes and irony &#8211; judging of course from all your offensive type of comments. Treat for treat!</p>
<p>I hope that you understand better now&#8230; Cos an answer that long ain&#8217;t bullshittin! Aiight? :P <&#8211; ego smiley,feeling of defeat. :P</p>
<p>PS1: I wanted to know your name because I like to know with whom I am discussing with&#8230; ;) You see&#8230; I am part of the &#8220;Security Paranoia, keeping us clothed and fed since init().&#8221; generation.</p>
<p>PS2: Anything that you might find offensive in this post, I would ask you please to cross it out of your mind. Thanks.</p>
<p>My Best Regards and Wishes for your digital life,</p>
<p>D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacking Like in The Movies - The Web2.0 Style &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-34921</link>
		<dc:creator>Hacking Like in The Movies - The Web2.0 Style &#124; GNUCITIZEN</dc:creator>
		<pubDate>Tue, 10 Jul 2007 14:37:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-34921</guid>
		<description>[...] to create a Pipe&#8217;s and Google&#8217;s like killer mashup development environment. As I mentioned on several occasions, mashup technology will change the Web and the Internet landscape for good or [...]</description>
		<content:encoded><![CDATA[<p>[...] to create a Pipe&#8217;s and Google&#8217;s like killer mashup development environment. As I mentioned on several occasions, mashup technology will change the Web and the Internet landscape for good or [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Renko</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-34894</link>
		<dc:creator>Renko</dc:creator>
		<pubDate>Tue, 10 Jul 2007 11:53:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-34894</guid>
		<description>Dimitris Pagkalos:

Your ego is way to big to be supported by your weak words. anyway...

first of all, my mom and dad called me renko, thats why my friends call me that too now... i dunno what you are getting at with the &quot;use your real name&quot;. i guess you needed some stick to beat me with or something and the name was the best you could find? anyway lets say my name is renko karman (happy now?). hope you see how silly your accusation is about me being afraid to use it in full. you want my email addy too? it&#039;s rkarman@hotmail.com .... (yes of course it&#039;s a spam addy silly... and i didn&#039;t use my real addy since i am AFRAID ... of spam ...)

second, i never said you phisically hurt animals or humans. i did say you hurt people, by helping kiddies and criminals to steal &quot;personal&quot; info and corrupt computer systems.

then let me also sum up your point of view: &quot;you are not obligated to warn anyone.&quot; it&#039;s your whole statement summed up in 1 sentence and guess what... your statement is also lacking politeness, informative content and good points... bravo!!!

anyway i see you are too happy being you and too dumb to look for something positive in a lil criticism. i guess you are going to give a big answer now, but it won&#039;t help anymore since in your first awnser you already choose what i am to you instead of trying to see how it was possible that i saw things different. but then again, there is also a need for narrow minded people in this world right?</description>
		<content:encoded><![CDATA[<p>Dimitris Pagkalos:</p>
<p>Your ego is way to big to be supported by your weak words. anyway&#8230;</p>
<p>first of all, my mom and dad called me renko, thats why my friends call me that too now&#8230; i dunno what you are getting at with the &#8220;use your real name&#8221;. i guess you needed some stick to beat me with or something and the name was the best you could find? anyway lets say my name is renko karman (happy now?). hope you see how silly your accusation is about me being afraid to use it in full. you want my email addy too? it&#8217;s <a href="mailto:rkarman@hotmail.com">rkarman@hotmail.com</a> &#8230;. (yes of course it&#8217;s a spam addy silly&#8230; and i didn&#8217;t use my real addy since i am AFRAID &#8230; of spam &#8230;)</p>
<p>second, i never said you phisically hurt animals or humans. i did say you hurt people, by helping kiddies and criminals to steal &#8220;personal&#8221; info and corrupt computer systems.</p>
<p>then let me also sum up your point of view: &#8220;you are not obligated to warn anyone.&#8221; it&#8217;s your whole statement summed up in 1 sentence and guess what&#8230; your statement is also lacking politeness, informative content and good points&#8230; bravo!!!</p>
<p>anyway i see you are too happy being you and too dumb to look for something positive in a lil criticism. i guess you are going to give a big answer now, but it won&#8217;t help anymore since in your first awnser you already choose what i am to you instead of trying to see how it was possible that i saw things different. but then again, there is also a need for narrow minded people in this world right?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dimitris Pagkalos</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-34104</link>
		<dc:creator>Dimitris Pagkalos</dc:creator>
		<pubDate>Fri, 06 Jul 2007 01:47:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-34104</guid>
		<description>Your real name is not Renko... Maybe your friends call you Renko, and I have nothing to hide Renko. What you believe about someone, keep it for yourself. Your weak assessment of my personality lacks of some serious evidence. Now you just really assumed, and nothing more. Certainly I&#039;ll have a good time being my real self comrade! :P

Anyway, if you have anything more specific to add (relating to this post by pdp and the comments), add it and don&#039;t waste my time with your history lessons. Otherwise don&#039;t just post because you want to have the final word.

D</description>
		<content:encoded><![CDATA[<p>Your real name is not Renko&#8230; Maybe your friends call you Renko, and I have nothing to hide Renko. What you believe about someone, keep it for yourself. Your weak assessment of my personality lacks of some serious evidence. Now you just really assumed, and nothing more. Certainly I&#8217;ll have a good time being my real self comrade! :P</p>
<p>Anyway, if you have anything more specific to add (relating to this post by pdp and the comments), add it and don&#8217;t waste my time with your history lessons. Otherwise don&#8217;t just post because you want to have the final word.</p>
<p>D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Renko</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-33906</link>
		<dc:creator>Renko</dc:creator>
		<pubDate>Wed, 04 Jul 2007 23:30:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-33906</guid>
		<description>My real name is Renko. i dunno why you act so upset calling me all the obvious crap.. you know comunism is used in some countries to justify government sponsored killing squads... now i believe you showed your real self. anyway, have a nice time being you :oP</description>
		<content:encoded><![CDATA[<p>My real name is Renko. i dunno why you act so upset calling me all the obvious crap.. you know comunism is used in some countries to justify government sponsored killing squads&#8230; now i believe you showed your real self. anyway, have a nice time being you :oP</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dimitris Pagkalos</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-33473</link>
		<dc:creator>Dimitris Pagkalos</dc:creator>
		<pubDate>Tue, 03 Jul 2007 02:52:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-33473</guid>
		<description>Dear Renko,

As you commented, I am not upholding that I seriously believe all of the XSS vulnerabilities were reported to &quot;the site owners&quot; by the people who report them to us. The individual who spotted and submitted to us the XSS flaw, has the ethical option to contact the webmasters in order to let them know about the issue, or even better help them to resolve it. We strongly support that option but cannot force it - just advise. The webmasters of the affected sites can now use the RSS feeds - xssed.com/rss - and the early warning mailing list subscription feature if they want to be instantly notified and thus mitigate possible associated risks in a short time span - of course how quickly they mitigate risks depends on their level of professionalism, customer service, lazyness and other important factors.

Mirroring significantly helps the webmasters and web communities to be notified faster.

We personally believe that your comment is mad. I am convinced that you did not carefully read all the above comments and just falsely filtered out what YOU considered to be the &quot;juice&quot; of this subject matter. Obviously there is a very high possibility that you either fall victim of XSS exploitation and you&#039;re indexed in XSSed, or you&#039;re just jealous that we are making &quot;bucks&quot;. If you are nothing of the above, then you are just a cyber commie... Highly possible as well, since you are now reading this on GNUcitizen.org - no offence pdp, you kewl. ;-)

Nevertheless thank you for giving me once more the opportunity to express my &quot;cheap excuses&quot; - :P - to people like you with an attitude of an accuser - chipmunk! 

PS1: I am cheap and we are &quot;unwittingly&quot; hurting people and making the world a worse place - this is almost your whole comment summed up in one line. Now how cheap is this... Lacks of politeness, informative content and good points which influence irony-free web security related discussions - the type of discussions you are not used to.

PS2: We did not hurt any people or animals.

PS3: I hope you received the answer you deserve.

PS4: Next time put your real name... Nothing to be afraid of...

PS5: January of 2015 :)

Best Regards</description>
		<content:encoded><![CDATA[<p>Dear Renko,</p>
<p>As you commented, I am not upholding that I seriously believe all of the XSS vulnerabilities were reported to &#8220;the site owners&#8221; by the people who report them to us. The individual who spotted and submitted to us the XSS flaw, has the ethical option to contact the webmasters in order to let them know about the issue, or even better help them to resolve it. We strongly support that option but cannot force it &#8211; just advise. The webmasters of the affected sites can now use the RSS feeds &#8211; xssed.com/rss &#8211; and the early warning mailing list subscription feature if they want to be instantly notified and thus mitigate possible associated risks in a short time span &#8211; of course how quickly they mitigate risks depends on their level of professionalism, customer service, lazyness and other important factors.</p>
<p>Mirroring significantly helps the webmasters and web communities to be notified faster.</p>
<p>We personally believe that your comment is mad. I am convinced that you did not carefully read all the above comments and just falsely filtered out what YOU considered to be the &#8220;juice&#8221; of this subject matter. Obviously there is a very high possibility that you either fall victim of XSS exploitation and you&#8217;re indexed in XSSed, or you&#8217;re just jealous that we are making &#8220;bucks&#8221;. If you are nothing of the above, then you are just a cyber commie&#8230; Highly possible as well, since you are now reading this on GNUcitizen.org &#8211; no offence pdp, you kewl. ;-)</p>
<p>Nevertheless thank you for giving me once more the opportunity to express my &#8220;cheap excuses&#8221; &#8211; :P &#8211; to people like you with an attitude of an accuser &#8211; chipmunk! </p>
<p>PS1: I am cheap and we are &#8220;unwittingly&#8221; hurting people and making the world a worse place &#8211; this is almost your whole comment summed up in one line. Now how cheap is this&#8230; Lacks of politeness, informative content and good points which influence irony-free web security related discussions &#8211; the type of discussions you are not used to.</p>
<p>PS2: We did not hurt any people or animals.</p>
<p>PS3: I hope you received the answer you deserve.</p>
<p>PS4: Next time put your real name&#8230; Nothing to be afraid of&#8230;</p>
<p>PS5: January of 2015 :)</p>
<p>Best Regards</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Renko</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-32694</link>
		<dc:creator>Renko</dc:creator>
		<pubDate>Fri, 29 Jun 2007 01:51:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-32694</guid>
		<description>To Dimitris Pagkalos:

I think you are very lenient on yourself... just claiming the easy way out that you are not responsible for warning the affected site. You are also not responsible of providing a place where kiddies can show of their skill in finding XSS vulnerabilities, right? Yet you are all too happy to provide that service. so as that service significantly increases the risk of people being hurt (even though that was never your intention and it might not go away when you stop your service) you should feel responsible for everything you CAN (not must) do... You can help the world to be a better place, just like you unwittingly help make the world a worse place. It certainly is your responsibility to uphold your intentions of helping. Do as much good as possible, help limiting as much bad that result from it...

Or are you seriously going to uphold that you seriously believe all of the XSS vulnerabilities were reported to &quot;the site owners&quot; by the people who report them to you? They help you make a buck on the vulnerabilities, not warning makes you susceptible to conflict of interest.... and to me, your excuse certainly sounds cheap, so maybe you really are? ...</description>
		<content:encoded><![CDATA[<p>To Dimitris Pagkalos:</p>
<p>I think you are very lenient on yourself&#8230; just claiming the easy way out that you are not responsible for warning the affected site. You are also not responsible of providing a place where kiddies can show of their skill in finding XSS vulnerabilities, right? Yet you are all too happy to provide that service. so as that service significantly increases the risk of people being hurt (even though that was never your intention and it might not go away when you stop your service) you should feel responsible for everything you CAN (not must) do&#8230; You can help the world to be a better place, just like you unwittingly help make the world a worse place. It certainly is your responsibility to uphold your intentions of helping. Do as much good as possible, help limiting as much bad that result from it&#8230;</p>
<p>Or are you seriously going to uphold that you seriously believe all of the XSS vulnerabilities were reported to &#8220;the site owners&#8221; by the people who report them to you? They help you make a buck on the vulnerabilities, not warning makes you susceptible to conflict of interest&#8230;. and to me, your excuse certainly sounds cheap, so maybe you really are? &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Generic XSS Worm &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-30384</link>
		<dc:creator>The Generic XSS Worm &#124; GNUCITIZEN</dc:creator>
		<pubDate>Wed, 20 Jun 2007 22:52:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-30384</guid>
		<description>[...] resources to identify targets (i.e. Google, xssed.com) - pdp recently released an article titled, The Next Super Worm which basically uses xssed.com to identify vulnerable targets. Note that this example [...]</description>
		<content:encoded><![CDATA[<p>[...] resources to identify targets (i.e. Google, xssed.com) &#8211; pdp recently released an article titled, The Next Super Worm which basically uses xssed.com to identify vulnerable targets. Note that this example [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; Client-side Security</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-28358</link>
		<dc:creator>GNUCITIZEN &#187; Client-side Security</dc:creator>
		<pubDate>Mon, 11 Jun 2007 17:11:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-28358</guid>
		<description>[...] the server are in very delicate situation. Here is a quote from a previous GNUCITIZEN article about the Next Super Worm. clients and servers are in symbiosis. The security of the server depends on the security of the [...]</description>
		<content:encoded><![CDATA[<p>[...] the server are in very delicate situation. Here is a quote from a previous GNUCITIZEN article about the Next Super Worm. clients and servers are in symbiosis. The security of the server depends on the security of the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dimitris Pagkalos</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-26825</link>
		<dc:creator>Dimitris Pagkalos</dc:creator>
		<pubDate>Tue, 05 Jun 2007 20:45:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-26825</guid>
		<description>We believe that it is significantly helping! It is important to mention that people who are responsible for the websites in that list, are thanking us via e-mails for bringing the issues to their attention. The users of the listed websites can see who cares the most about their security. Anyway, these are the websites with the most users on the web. Thus, we expose the vulnerability details in order to be quickly fixed.

Already most of the *.yahoo.com XSS vulnerabilities are fixed. Of course we are willing to assist the webmasters with fixing the vulnerabilities - for free. :-) This is what the XSS submitters should do!

I agree that we &quot;show off&quot; our skills in indexing and listing affected websites with the most traffic on the web. However, this is not the only thing we &quot;show off&quot;, but also the skills of the XSS discoverers/submitters. Maybe some of them feel uber proud knowing their nick is listed in that list. Good for them. =)

Google&#039;s mission is to organise the very large amount of information available on the web.
We actively take part in that mission by organising information relating to XSS vulnerabilities for the major search engines.

What if someone uses the publicized XSS vulnerability information for malicious purposes?
Well, since the XSS vulnerability details are public, there is little or no excuse for not being able to fix them in a timely manner. Conscious and concerned web companies, their webmasters and web security people, must be looking on the web every minute or second for public security vulnerabilities affecting them.

It is up to the discoverer&#039;s ethical attitudes whether or not to contact the webmasters for flaws. 

As I am typing, Kevin is adding a feature to check which websites in the list have fixed the XSS vuln affecting them.

Can you please clarify what most real security websites do? I think they publish vulnerabilities which are either patched or unpatched... Same kind of thing pretty much, no?


Regards</description>
		<content:encoded><![CDATA[<p>We believe that it is significantly helping! It is important to mention that people who are responsible for the websites in that list, are thanking us via e-mails for bringing the issues to their attention. The users of the listed websites can see who cares the most about their security. Anyway, these are the websites with the most users on the web. Thus, we expose the vulnerability details in order to be quickly fixed.</p>
<p>Already most of the *.yahoo.com XSS vulnerabilities are fixed. Of course we are willing to assist the webmasters with fixing the vulnerabilities &#8211; for free. :-) This is what the XSS submitters should do!</p>
<p>I agree that we &#8220;show off&#8221; our skills in indexing and listing affected websites with the most traffic on the web. However, this is not the only thing we &#8220;show off&#8221;, but also the skills of the XSS discoverers/submitters. Maybe some of them feel uber proud knowing their nick is listed in that list. Good for them. =)</p>
<p>Google&#8217;s mission is to organise the very large amount of information available on the web.<br />
We actively take part in that mission by organising information relating to XSS vulnerabilities for the major search engines.</p>
<p>What if someone uses the publicized XSS vulnerability information for malicious purposes?<br />
Well, since the XSS vulnerability details are public, there is little or no excuse for not being able to fix them in a timely manner. Conscious and concerned web companies, their webmasters and web security people, must be looking on the web every minute or second for public security vulnerabilities affecting them.</p>
<p>It is up to the discoverer&#8217;s ethical attitudes whether or not to contact the webmasters for flaws. </p>
<p>As I am typing, Kevin is adding a feature to check which websites in the list have fixed the XSS vuln affecting them.</p>
<p>Can you please clarify what most real security websites do? I think they publish vulnerabilities which are either patched or unpatched&#8230; Same kind of thing pretty much, no?</p>
<p>Regards</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-26784</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 05 Jun 2007 18:15:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-26784</guid>
		<description>agree!</description>
		<content:encoded><![CDATA[<p>agree!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carl Federer</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-26388</link>
		<dc:creator>Carl Federer</dc:creator>
		<pubDate>Mon, 04 Jun 2007 19:18:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-26388</guid>
		<description>I&#039;m sorry guys, but I do not agree that public disclosure of such details will help at all. In fact, creating a &quot;Top PageRank List&quot;... where does that help? At least, order the XSS list by date and that&#039;s it.

But what you are doing there is exposing other vulnerabilities, something that gentleman don&#039;t do. If you want to do it, at least don&#039;t expose them by &quot;popularity&quot;. That clearly shows that your intentions are not only &quot;to help&quot; but maybe to show off...

Why exposing the &quot;good guys&quot; with such detail? You can simply do as most real security webSites do. Why do you think they behave that way?

Carl.</description>
		<content:encoded><![CDATA[<p>I&#8217;m sorry guys, but I do not agree that public disclosure of such details will help at all. In fact, creating a &#8220;Top PageRank List&#8221;&#8230; where does that help? At least, order the XSS list by date and that&#8217;s it.</p>
<p>But what you are doing there is exposing other vulnerabilities, something that gentleman don&#8217;t do. If you want to do it, at least don&#8217;t expose them by &#8220;popularity&#8221;. That clearly shows that your intentions are not only &#8220;to help&#8221; but maybe to show off&#8230;</p>
<p>Why exposing the &#8220;good guys&#8221; with such detail? You can simply do as most real security webSites do. Why do you think they behave that way?</p>
<p>Carl.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-25368</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 01 Jun 2007 21:32:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-25368</guid>
		<description>Kevin,

Believe me, I see where you are going and I know and understand your point of view. However, legally speaking, it is an offence. Consult with a lawyer and you will see. I am sure that no action will be taken against XSSED.com right now though, but as I said things will get a lot worse in the future. Keep that in mind.

One last thing; XSS vulnerabilities are just like SQL Injection vulnerabilities and they should be treated with the same respect. Just because XSS affects the client, it doesn&#039;t mean that they are less dangerous. As I mentioned before:

&lt;div class=&quot;message&quot;&gt;clients and servers are in symbiosis. The security of the server depends on the security of the client and vice versa&lt;/div&gt;</description>
		<content:encoded><![CDATA[<p>Kevin,</p>
<p>Believe me, I see where you are going and I know and understand your point of view. However, legally speaking, it is an offence. Consult with a lawyer and you will see. I am sure that no action will be taken against XSSED.com right now though, but as I said things will get a lot worse in the future. Keep that in mind.</p>
<p>One last thing; XSS vulnerabilities are just like SQL Injection vulnerabilities and they should be treated with the same respect. Just because XSS affects the client, it doesn&#8217;t mean that they are less dangerous. As I mentioned before:</p>
<div class="message">clients and servers are in symbiosis. The security of the server depends on the security of the client and vice versa</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin Fernandez</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-25308</link>
		<dc:creator>Kevin Fernandez</dc:creator>
		<pubDate>Fri, 01 Jun 2007 16:44:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-25308</guid>
		<description>pdp,

I agree that indexing SQL injections would be illegal, it would be completly stupid. But indexing XSS is another thing, they do not &quot;attack&quot; the server, but the end users for most of the time. I also don&#039;t think that they can sue us, because there are good ways to defend: for example, the fact that it is legitimate to warn everybody when a danger is &quot;know&quot;. To say the truth, i got this idea to create xssed when one of the zone-h members got his mailbox hacked because of a stupid XSS hole in a Microsoft web site (this was in december 2006), if that hole became public, Microsoft would have fixed it faster, or that user would have behaved more carefully. I believe this was more the fault of Microsoft than his fault, and i believe archiving and publishing is the only way to fight against XSS, i am sure that it will greatly improve our security.</description>
		<content:encoded><![CDATA[<p>pdp,</p>
<p>I agree that indexing SQL injections would be illegal, it would be completly stupid. But indexing XSS is another thing, they do not &#8220;attack&#8221; the server, but the end users for most of the time. I also don&#8217;t think that they can sue us, because there are good ways to defend: for example, the fact that it is legitimate to warn everybody when a danger is &#8220;know&#8221;. To say the truth, i got this idea to create xssed when one of the zone-h members got his mailbox hacked because of a stupid XSS hole in a Microsoft web site (this was in december 2006), if that hole became public, Microsoft would have fixed it faster, or that user would have behaved more carefully. I believe this was more the fault of Microsoft than his fault, and i believe archiving and publishing is the only way to fight against XSS, i am sure that it will greatly improve our security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-25263</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 01 Jun 2007 13:15:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-25263</guid>
		<description>heh :)</description>
		<content:encoded><![CDATA[<p>heh :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jon</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-25241</link>
		<dc:creator>jon</dc:creator>
		<pubDate>Fri, 01 Jun 2007 11:57:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-25241</guid>
		<description>Good article but lol @ the use of the word &quot;vector&quot;</description>
		<content:encoded><![CDATA[<p>Good article but lol @ the use of the word &#8220;vector&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/the-next-super-worm/comment-page-1/#comment-25207</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 01 Jun 2007 09:29:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-next-super-worm#comment-25207</guid>
		<description>Dimitris,

thanks for the complete response

&lt;blockquote&gt;What is your point of view about full public disclosure of XSS vulnerabilities? What do think about my point of view?&lt;/blockquote&gt;

Personally, I don&#039;t think that it is correct to disclose vulnerabilities in public websites. The right think to do when you find a XSS or SQL Injection flaw on a public website is to contact the webmaster and in general the people who are responsible for the site maintenance. The situation is a bit different when it comes to software and in general applications, which can be installed on your computer and tested in designed for that purpose testing environments. Again, you should contact the vendor when you discover a vulnerability. In number of cases, depending totally on the situation, you may go and release the issue right away. I&#039;ve done that in the past on a number of cases. However, I have also disclosed vulnerabilities in a responsible way as well.

In respect to XSSED.com, I do not think that you guys are disclosing any vulnerabilities but simple listing, indexing and organizing whatever is already public. According to the British Computer Misuse Act you are breaking the law, though. That of course does not apply to you, however, the point is that you have to be careful with these things because the legal system will get tougher in the future when it comes to IT crimes.</description>
		<content:encoded><![CDATA[<p>Dimitris,</p>
<p>thanks for the complete response</p>
<blockquote><p>What is your point of view about full public disclosure of XSS vulnerabilities? What do think about my point of view?</p></blockquote>
<p>Personally, I don&#8217;t think that it is correct to disclose vulnerabilities in public websites. The right think to do when you find a XSS or SQL Injection flaw on a public website is to contact the webmaster and in general the people who are responsible for the site maintenance. The situation is a bit different when it comes to software and in general applications, which can be installed on your computer and tested in designed for that purpose testing environments. Again, you should contact the vendor when you discover a vulnerability. In number of cases, depending totally on the situation, you may go and release the issue right away. I&#8217;ve done that in the past on a number of cases. However, I have also disclosed vulnerabilities in a responsible way as well.</p>
<p>In respect to XSSED.com, I do not think that you guys are disclosing any vulnerabilities but simple listing, indexing and organizing whatever is already public. According to the British Computer Misuse Act you are breaking the law, though. That of course does not apply to you, however, the point is that you have to be careful with these things because the legal system will get tougher in the future when it comes to IT crimes.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
