<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: The Cross Site Scripting FAQ</title>
	<atom:link href="http://blog.sonufifu.com/seo/the-cross-site-scripting-faq/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sonufifu.com/seo/the-cross-site-scripting-faq/</link>
	<description>sonufifu</description>
	<pubDate>Wed, 10 Mar 2010 22:16:18 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Search Engine Optimization (SEO) Journal &#187; Blog Archive &#187; Proof of Concept</title>
		<link>http://blog.sonufifu.com/seo/the-cross-site-scripting-faq/comment-page-1/#comment-5</link>
		<dc:creator>Search Engine Optimization (SEO) Journal &#187; Blog Archive &#187; Proof of Concept</dc:creator>
		<pubDate>Fri, 07 Jul 2006 19:16:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sonufifu.com/?p=30#comment-5</guid>
		<description>[...] I&#8217;ve actually noticed the same thing myself. One of the hardest parts of XSS is locating what is and isn&#8217;t valid XSS. Some things can include HTML injection but there is no way to reasonably exploit the vulnerability. Does that make it less scary? Yes! The reason XSS is scary is because it can lead to information disclosure, but if there is no way to get another user to see the HTML you injected, then it&#8217;s not a real vulnerability. Sloppy coding? Yes. Vulnerability? No. [...]</description>
		<content:encoded><![CDATA[<p>[...] I&#8217;ve actually noticed the same thing myself. One of the hardest parts of XSS is locating what is and isn&#8217;t valid XSS. Some things can include HTML injection but there is no way to reasonably exploit the vulnerability. Does that make it less scary? Yes! The reason XSS is scary is because it can lead to information disclosure, but if there is no way to get another user to see the HTML you injected, then it&#8217;s not a real vulnerability. Sloppy coding? Yes. Vulnerability? No. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ha.ckers.org web application security lab - Archive &#187; Proof of Concept</title>
		<link>http://blog.sonufifu.com/seo/the-cross-site-scripting-faq/comment-page-1/#comment-4</link>
		<dc:creator>ha.ckers.org web application security lab - Archive &#187; Proof of Concept</dc:creator>
		<pubDate>Tue, 04 Jul 2006 18:17:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sonufifu.com/?p=30#comment-4</guid>
		<description>[...] I&#8217;ve actually noticed the same thing myself. One of the hardest parts of XSS is locating what is and isn&#8217;t valid XSS. Some things can include HTML injection but there is no way to reasonably exploit the vulnerability. Does that make it less scary? Yes! The reason XSS is scary is because it can lead to information disclosure, but if there is no way to get another user to see the HTML you injected, then it&#8217;s not a real vulnerability. Sloppy coding? Yes. Vulnerability? No. [...]</description>
		<content:encoded><![CDATA[<p>[...] I&#8217;ve actually noticed the same thing myself. One of the hardest parts of XSS is locating what is and isn&#8217;t valid XSS. Some things can include HTML injection but there is no way to reasonably exploit the vulnerability. Does that make it less scary? Yes! The reason XSS is scary is because it can lead to information disclosure, but if there is no way to get another user to see the HTML you injected, then it&#8217;s not a real vulnerability. Sloppy coding? Yes. Vulnerability? No. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
