<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Web Pages from Hell 2</title>
	<atom:link href="http://www.gnucitizen.org/blog/web-pages-from-hell-2/feed/" rel="self" type="application/rss+xml" />
	<link>/blog/web-pages-from-hell-2/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Thu, 21 Aug 2008 19:54:37 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Content-Disposition Hacking &#124; GNUCITIZEN</title>
		<link>/blog/web-pages-from-hell-2/#comment-65350</link>
		<dc:creator>Content-Disposition Hacking &#124; GNUCITIZEN</dc:creator>
		<pubDate>Mon, 05 Nov 2007 12:44:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-pages-from-hell-2#comment-65350</guid>
		<description>[...] insert all the JavaScript in the HTML body directly. I prepared a PoC which is based on a payload I wrote a year ago. The idea is that if the user is tricked to visit the attack URL, and then clicks on [...]</description>
		<content:encoded><![CDATA[<p>[...] insert all the JavaScript in the HTML body directly. I prepared a PoC which is based on a payload I wrote a year ago. The idea is that if the user is tricked to visit the attack URL, and then clicks on [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
