<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: The state of JavaScript Hacking</title>
	<atom:link href="http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Sun, 23 Nov 2008 17:18:17 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-23044</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 21 May 2007 20:46:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-23044</guid>
		<description>why not... JavaScript is fully functional language and can do everything other languages can do. what's the problem?</description>
		<content:encoded><![CDATA[<p>why not&#8230; JavaScript is fully functional language and can do everything other languages can do. what&#8217;s the problem?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marc</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-23028</link>
		<dc:creator>Marc</dc:creator>
		<pubDate>Mon, 21 May 2007 18:39:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-23028</guid>
		<description>JavaScript hacking yea right ...
JavaScript would be able to do some confusing things to a client but not hacking</description>
		<content:encoded><![CDATA[<p>JavaScript hacking yea right &#8230;<br />
JavaScript would be able to do some confusing things to a client but not hacking</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-1259</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sun, 17 Dec 2006 08:08:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-1259</guid>
		<description>f0rg3, glad to hear that</description>
		<content:encoded><![CDATA[<p>f0rg3, glad to hear that</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: f0rg3</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-1244</link>
		<dc:creator>f0rg3</dc:creator>
		<pubDate>Fri, 15 Dec 2006 13:58:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-1244</guid>
		<description>Thanks for the read. I enjoyed it immensely..i am in your wake...a reader from Africa who's very much into Javascript hacking :)</description>
		<content:encoded><![CDATA[<p>Thanks for the read. I enjoyed it immensely..i am in your wake&#8230;a reader from Africa who&#8217;s very much into Javascript hacking :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-982</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 06 Dec 2006 02:02:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-982</guid>
		<description>True, although, from my quick observation, OpenLaszlo is based purely on Flash. Flash in a way is limited. Apollo provides a lot more features that I am not sure how OpenLaszlo's developers will achieve unless they extend the Flash player in someway or integrate somehow with Apollo.</description>
		<content:encoded><![CDATA[<p>True, although, from my quick observation, OpenLaszlo is based purely on Flash. Flash in a way is limited. Apollo provides a lot more features that I am not sure how OpenLaszlo&#8217;s developers will achieve unless they extend the Flash player in someway or integrate somehow with Apollo.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-954</link>
		<dc:creator>Bob</dc:creator>
		<pubDate>Tue, 05 Dec 2006 09:41:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-954</guid>
		<description>No mention of OpenLaszlo, which Flex and Apollo try to copy?</description>
		<content:encoded><![CDATA[<p>No mention of OpenLaszlo, which Flex and Apollo try to copy?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 5V3N.5P4C3 &#187; The internet will become more evil!</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-797</link>
		<dc:creator>5V3N.5P4C3 &#187; The internet will become more evil!</dc:creator>
		<pubDate>Tue, 28 Nov 2006 09:58:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-797</guid>
		<description>[...] Aber deis sei nur eine kleine satirische Einleitung zu einem eher trockenen und technischen Them: The state of JavaScript hacking geschrieben von pdp(architect) auf GNUcitizen. [...]</description>
		<content:encoded><![CDATA[<p>[...] Aber deis sei nur eine kleine satirische Einleitung zu einem eher trockenen und technischen Them: The state of JavaScript hacking geschrieben von pdp(architect) auf GNUcitizen. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-791</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 28 Nov 2006 03:21:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-791</guid>
		<description>.mario, I am glad to hear that. Backframe will remain that simple in the future. However, I am planning some changes that will make it even better. I expect to release the new version around Christmas. BTW, this thing with the JS-code on paper transfer sheet is rather cool. I remember thinking about doing SQL Injection over a &lt;a href="http://www.vocera.com/" rel="nofollow"&gt;Vocera badge&lt;/a&gt; with voice.

Robert, surely I will get on #webappsec as soon as I have some free time. ;)

Vijay, it is like that with every technology. What we need to do is to raise the user awareness.</description>
		<content:encoded><![CDATA[<p>.mario, I am glad to hear that. Backframe will remain that simple in the future. However, I am planning some changes that will make it even better. I expect to release the new version around Christmas. BTW, this thing with the JS-code on paper transfer sheet is rather cool. I remember thinking about doing SQL Injection over a <a href="http://www.vocera.com/" rel="nofollow">Vocera badge</a> with voice.</p>
<p>Robert, surely I will get on #webappsec as soon as I have some free time. ;)</p>
<p>Vijay, it is like that with every technology. What we need to do is to raise the user awareness.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-789</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 28 Nov 2006 02:25:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-789</guid>
		<description>Here is an interesting question:

&lt;blockquote&gt;So what you are trying to say is that JavaScript is bad, because it nowadays runs on more than one platform?&lt;/blockquote&gt;

JavaScript is not bad. However, like any other technology JavaScript has quite a few security implications. What I am trying to say is that raising the awareness of the masses is important. People should consider JavaScript as a serious and very powerful language and they should not give their trust to obscure web pages and applications so lightly.</description>
		<content:encoded><![CDATA[<p>Here is an interesting question:</p>
<blockquote><p>So what you are trying to say is that JavaScript is bad, because it nowadays runs on more than one platform?</p></blockquote>
<p>JavaScript is not bad. However, like any other technology JavaScript has quite a few security implications. What I am trying to say is that raising the awareness of the masses is important. People should consider JavaScript as a serious and very powerful language and they should not give their trust to obscure web pages and applications so lightly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vijay</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-788</link>
		<dc:creator>Vijay</dc:creator>
		<pubDate>Tue, 28 Nov 2006 01:48:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-788</guid>
		<description>I realy appreciate your post, fourth generation languages are not safe.</description>
		<content:encoded><![CDATA[<p>I realy appreciate your post, fourth generation languages are not safe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-787</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Tue, 28 Nov 2006 01:36:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-787</guid>
		<description>Good to hear about XUL/WPF/XAML publically spoken about! I myself am doing some research into these technologies. Hop on irc.freenode.net #webappsec sometime to chat :)</description>
		<content:encoded><![CDATA[<p>Good to hear about XUL/WPF/XAML publically spoken about! I myself am doing some research into these technologies. Hop on irc.freenode.net #webappsec sometime to chat :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-786</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Mon, 27 Nov 2006 21:11:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-786</guid>
		<description>Very interesting post, I agree completely with what you're saying.

Apollo is definitely something to look forward to and I'm sure Adobe will want to distribute Apollo to as many computers out there as possible.</description>
		<content:encoded><![CDATA[<p>Very interesting post, I agree completely with what you&#8217;re saying.</p>
<p>Apollo is definitely something to look forward to and I&#8217;m sure Adobe will want to distribute Apollo to as many computers out there as possible.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.gnucitizen.org/blog/the-state-of-javascript-hacking/#comment-785</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Mon, 27 Nov 2006 20:14:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-state-of-javascript-hacking#comment-785</guid>
		<description>Unfortunately you are right. I don't know if you heard about the XSS-Hack via bank transfer. Some guys wrote JS-Code in the subject field on a (papermade) transfer sheet and brought it to the bank - some days later they got some client on their monitor who really executed the code. 

Even if this would be an urban legend it shows the capabilities of modern scripting languages and their dangers. With growing possibilites the number of security holes are rising exponentially too. As developer and 'underpaid-security-guy' i know what you are talking about.

Please keep up the good work and btw - i like Backframe. This piece of software is simple but evil. I will use for demonstration in a presentation in two days.

Greetings,
.mario</description>
		<content:encoded><![CDATA[<p>Unfortunately you are right. I don&#8217;t know if you heard about the XSS-Hack via bank transfer. Some guys wrote JS-Code in the subject field on a (papermade) transfer sheet and brought it to the bank - some days later they got some client on their monitor who really executed the code. </p>
<p>Even if this would be an urban legend it shows the capabilities of modern scripting languages and their dangers. With growing possibilites the number of security holes are rising exponentially too. As developer and &#8216;underpaid-security-guy&#8217; i know what you are talking about.</p>
<p>Please keep up the good work and btw - i like Backframe. This piece of software is simple but evil. I will use for demonstration in a presentation in two days.</p>
<p>Greetings,<br />
.mario</p>
]]></content:encoded>
	</item>
</channel>
</rss>
