<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Merry XssMas</title>
	<link>http://hackademix.net/2007/12/25/merry-xssmas/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Tue, 07 Feb 2012 09:14:56 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: yawnmoth</title>
		<link>http://hackademix.net/2007/12/25/merry-xssmas/#comment-9146</link>
		<dc:creator>yawnmoth</dc:creator>
		<pubDate>Sun, 24 Aug 2008 20:54:38 +0000</pubDate>
		<guid>http://hackademix.net/2007/12/25/merry-xssmas/#comment-9146</guid>
		<description>Oh.  Well...  I guess that explains it, then, heh.  Honestly, I've not, yet, seen a legit use of -moz-binding, be it cross-site or otherwise.</description>
		<content:encoded><![CDATA[<p>Oh.  Well&#8230;  I guess that explains it, then, heh.  Honestly, I&#8217;ve not, yet, seen a legit use of -moz-binding, be it cross-site or otherwise.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2007/12/25/merry-xssmas/#comment-9144</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sun, 24 Aug 2008 17:32:39 +0000</pubDate>
		<guid>http://hackademix.net/2007/12/25/merry-xssmas/#comment-9144</guid>
		<description>@&lt;b&gt;yawnmoth&lt;/b&gt;:
Yes, cross-site -moz-binding support (including &lt;em&gt;data:&lt;/em&gt; URLs from non &lt;em&gt;chrome:&lt;/em&gt; origins) has been removed from final Firefox 3.0 release.</description>
		<content:encoded><![CDATA[<p>@<b>yawnmoth</b>:<br />
Yes, cross-site -moz-binding support (including <em>data:</em> URLs from non <em>chrome:</em> origins) has been removed from final Firefox 3.0 release.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yawnmoth</title>
		<link>http://hackademix.net/2007/12/25/merry-xssmas/#comment-9143</link>
		<dc:creator>yawnmoth</dc:creator>
		<pubDate>Sun, 24 Aug 2008 17:21:54 +0000</pubDate>
		<guid>http://hackademix.net/2007/12/25/merry-xssmas/#comment-9143</guid>
		<description>I'm trying to get this particular vector working and am having some difficulty.

http://www.frostjedi.com/terra/scripts/demo/moz-binding.php

Any ideas as to why that's not working?</description>
		<content:encoded><![CDATA[<p>I&#8217;m trying to get this particular vector working and am having some difficulty.</p>
<p><a href="http://www.frostjedi.com/terra/scripts/demo/moz-binding.php" rel="nofollow">http://www.frostjedi.com/terra/scripts/demo/moz-binding.php</a></p>
<p>Any ideas as to why that&#8217;s not working?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2007/12/25/merry-xssmas/#comment-3604</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Thu, 27 Dec 2007 17:17:20 +0000</pubDate>
		<guid>http://hackademix.net/2007/12/25/merry-xssmas/#comment-3604</guid>
		<description>@&lt;b&gt;Mads Dam&lt;/b&gt;:
no problem with the logo.
Cheers :)</description>
		<content:encoded><![CDATA[<p>@<b>Mads Dam</b>:<br />
no problem with the logo.<br />
Cheers :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mads Dam</title>
		<link>http://hackademix.net/2007/12/25/merry-xssmas/#comment-3561</link>
		<dc:creator>Mads Dam</dc:creator>
		<pubDate>Thu, 27 Dec 2007 01:29:50 +0000</pubDate>
		<guid>http://hackademix.net/2007/12/25/merry-xssmas/#comment-3561</guid>
		<description>Thanks for the geolocation-answer; now I'm less puzzled.

I have blog-like section on my site, and I have just recommended NoScript.
Is it ok to include the NoScript logo (http://noscript.net/noscript/logo.png)

The blog I'm referring to is here: http://blog.madsdam.net

Merry NewYear!</description>
		<content:encoded><![CDATA[<p>Thanks for the geolocation-answer; now I&#8217;m less puzzled.</p>
<p>I have blog-like section on my site, and I have just recommended NoScript.<br />
Is it ok to include the NoScript logo (http://noscript.net/noscript/logo.png)</p>
<p>The blog I&#8217;m referring to is here: <a href="http://blog.madsdam.net" rel="nofollow">http://blog.madsdam.net</a></p>
<p>Merry NewYear!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2007/12/25/merry-xssmas/#comment-3511</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Wed, 26 Dec 2007 07:56:34 +0000</pubDate>
		<guid>http://hackademix.net/2007/12/25/merry-xssmas/#comment-3511</guid>
		<description>@&lt;b&gt;sirdarkcat&lt;/b&gt;:
Nice, it's a bit I'm entertaining the idea of replacing ReCaptcha (the IFRAME-based fallback is a bit cumbersome, but I've got no time at all :(

@&lt;b&gt;Mads Dam&lt;/b&gt;:
Geolocation is telling the truth. 
It's a small world, and it's good placing servers here and here, when you can: you never know, calamities, wars... happy 2008!</description>
		<content:encoded><![CDATA[<p>@<b>sirdarkcat</b>:<br />
Nice, it&#8217;s a bit I&#8217;m entertaining the idea of replacing ReCaptcha (the IFRAME-based fallback is a bit cumbersome, but I&#8217;ve got no time at all :(</p>
<p>@<b>Mads Dam</b>:<br />
Geolocation is telling the truth.<br />
It&#8217;s a small world, and it&#8217;s good placing servers here and here, when you can: you never know, calamities, wars&#8230; happy 2008!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mads Dam</title>
		<link>http://hackademix.net/2007/12/25/merry-xssmas/#comment-3508</link>
		<dc:creator>Mads Dam</dc:creator>
		<pubDate>Wed, 26 Dec 2007 06:51:44 +0000</pubDate>
		<guid>http://hackademix.net/2007/12/25/merry-xssmas/#comment-3508</guid>
		<description>Hi, I just noticed hackademix.net after the latest update of NoScript.

I've barely begun reading it, so I have no comments yet, only a single question:

You're italian, but your IP location seem to be danish..?

(My own IP-location is also Denmark, but then again, I live there.)

How can geolocation be that MUCH off, I'm puzzled. Could you enlighten me..?

Regards Mads Dam</description>
		<content:encoded><![CDATA[<p>Hi, I just noticed hackademix.net after the latest update of NoScript.</p>
<p>I&#8217;ve barely begun reading it, so I have no comments yet, only a single question:</p>
<p>You&#8217;re italian, but your IP location seem to be danish..?</p>
<p>(My own IP-location is also Denmark, but then again, I live there.)</p>
<p>How can geolocation be that MUCH off, I&#8217;m puzzled. Could you enlighten me..?</p>
<p>Regards Mads Dam</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://hackademix.net/2007/12/25/merry-xssmas/#comment-3489</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Wed, 26 Dec 2007 05:21:28 +0000</pubDate>
		<guid>http://hackademix.net/2007/12/25/merry-xssmas/#comment-3489</guid>
		<description>Happy 2008!!

Santa has 110 friends!! and they are all infected, it's going pretty slow.. 

and yeah :P Santa is not as hot as sammy, but this worm whishes you merry christmas every 3 seconds, that's cool isn't it?

btw I think I found a way of bypassing reCaptcha... awezome..</description>
		<content:encoded><![CDATA[<p>Happy 2008!!</p>
<p>Santa has 110 friends!! and they are all infected, it&#8217;s going pretty slow.. </p>
<p>and yeah :P Santa is not as hot as sammy, but this worm whishes you merry christmas every 3 seconds, that&#8217;s cool isn&#8217;t it?</p>
<p>btw I think I found a way of bypassing reCaptcha&#8230; awezome..</p>
]]></content:encoded>
	</item>
</channel>
</rss>

