<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: All Your Google Docs are Belong To US&#8230;</title>
	<atom:link href="http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/feed/" rel="self" type="application/rss+xml" />
	<link>http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/</link>
	<description>Thoughts on Security in an Uncivilized World…</description>
	<lastBuildDate>Fri, 13 Nov 2009 09:32:59 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Tim Acheson</title>
		<link>http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/comment-page-1/#comment-817</link>
		<dc:creator>Tim Acheson</dc:creator>
		<pubDate>Thu, 16 Jul 2009 14:35:50 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/#comment-817</guid>
		<description>Twitter&#039;s internal systems have just been hacked into, along with the accounts of Twitter users (including celebrities):

http://www.timacheson.com/Blog/2009/jul/twitter_hacked_via_google_apps

The initial point of entry wasn&#039;t a gap in Twitter&#039;s security. The hacker(s) gained access through a Google Apps account. The worry with a Google account is, it&#039;s web-based and therefore only as secure as the rest of the Internet. If yuor Google account is compromised and you use Google Docs in a serious commercial setting, your Twitter account will be the least of your worries.</description>
		<content:encoded><![CDATA[<p>Twitter&#8217;s internal systems have just been hacked into, along with the accounts of Twitter users (including celebrities):</p>
<p><a href="http://www.timacheson.com/Blog/2009/jul/twitter_hacked_via_google_apps" rel="nofollow">http://www.timacheson.com/Blog/2009/jul/twitter_hacked_via_google_apps</a></p>
<p>The initial point of entry wasn&#8217;t a gap in Twitter&#8217;s security. The hacker(s) gained access through a Google Apps account. The worry with a Google account is, it&#8217;s web-based and therefore only as secure as the rest of the Internet. If yuor Google account is compromised and you use Google Docs in a serious commercial setting, your Twitter account will be the least of your worries.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yahoo on vanindita domain name &#187; &#187; Google Mashups Vulnerability</title>
		<link>http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/comment-page-1/#comment-743</link>
		<dc:creator>yahoo on vanindita domain name &#187; &#187; Google Mashups Vulnerability</dc:creator>
		<pubDate>Fri, 27 Feb 2009 18:37:00 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/#comment-743</guid>
		<description>[...] I wanted to be part of this hell of a week (Google&#8217;s Dark [...]</description>
		<content:encoded><![CDATA[<p>[...] I wanted to be part of this hell of a week (Google&#8217;s Dark [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Google Health &#171; NonaTheNinja</title>
		<link>http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/comment-page-1/#comment-488</link>
		<dc:creator>Google Health &#171; NonaTheNinja</dc:creator>
		<pubDate>Fri, 23 May 2008 14:05:34 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/#comment-488</guid>
		<description>[...] on the article, mentioning several past vulnerabilities: ownership of content issues, Google Docs theft, a cross-domain hole, Google XSS, and a Google Picasa protocol handler issue leading to the theft [...]</description>
		<content:encoded><![CDATA[<p>[...] on the article, mentioning several past vulnerabilities: ownership of content issues, Google Docs theft, a cross-domain hole, Google XSS, and a Google Picasa protocol handler issue leading to the theft [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero Day mobile edition</title>
		<link>http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/comment-page-1/#comment-482</link>
		<dc:creator>Zero Day mobile edition</dc:creator>
		<pubDate>Thu, 22 May 2008 15:03:37 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/#comment-482</guid>
		<description>[...] This means that some of the more interesting attacks pulled off on Google applications, see Billy Rios and my previous work on Google Docs, get&#8217;s only as much coverage as the security researcher [...]</description>
		<content:encoded><![CDATA[<p>[...] This means that some of the more interesting attacks pulled off on Google applications, see Billy Rios and my previous work on Google Docs, get&#8217;s only as much coverage as the security researcher [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero Day mobile edition</title>
		<link>http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/comment-page-1/#comment-298</link>
		<dc:creator>Zero Day mobile edition</dc:creator>
		<pubDate>Wed, 19 Mar 2008 05:06:26 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/#comment-298</guid>
		<description>[...] This reminds me a lot of the work that Billy Rios has helped Google out with, as referenced here, here, and here. In these examples arbitrary user&#8217;s documents could be stolen from the Google Docs [...]</description>
		<content:encoded><![CDATA[<p>[...] This reminds me a lot of the work that Billy Rios has helped Google out with, as referenced here, here, and here. In these examples arbitrary user&#8217;s documents could be stolen from the Google Docs [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ibz</title>
		<link>http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/comment-page-1/#comment-187</link>
		<dc:creator>ibz</dc:creator>
		<pubDate>Sat, 29 Sep 2007 19:27:50 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/#comment-187</guid>
		<description>kudos to the Gst team..at least theyre fast at patching vulnerabilities...unlike  microcrap</description>
		<content:encoded><![CDATA[<p>kudos to the Gst team..at least theyre fast at patching vulnerabilities&#8230;unlike  microcrap</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/comment-page-1/#comment-185</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Fri, 28 Sep 2007 16:48:59 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/#comment-185</guid>
		<description>muahaha, now I&#039;m part of the Google&#039;s Dark Week

http://sirdarckcat.blogspot.com/2007/09/google-mashups-vulnerability.html

This is a historic event hehe

Greetz!!</description>
		<content:encoded><![CDATA[<p>muahaha, now I&#8217;m part of the Google&#8217;s Dark Week</p>
<p><a href="http://sirdarckcat.blogspot.com/2007/09/google-mashups-vulnerability.html" rel="nofollow">http://sirdarckcat.blogspot.com/2007/09/google-mashups-vulnerability.html</a></p>
<p>This is a historic event hehe</p>
<p>Greetz!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan McFeters</title>
		<link>http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/comment-page-1/#comment-184</link>
		<dc:creator>Nathan McFeters</dc:creator>
		<pubDate>Fri, 28 Sep 2007 15:02:29 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/#comment-184</guid>
		<description>Whoa whoa whoa, WE use AppScan, we don&#039;t need consultants!  Hahaha.  Nothing against WebInspect, AppScan, Fortify, any of them.  They are great tools, but they are simply that tools.  A machine will never be able to replace the thinking, feeling human mind when it comes to this kind of testing.  An application can&#039;t purchase a TV for -$1,000.00 and know that if it get&#039;s credited back to their credit card it&#039;s a bad thing.

I&#039;ve worked with Billy a lot over the last two years, this is just another of the many examples we&#039;ve provided during that time that show you cannot replace the value of a good app security tester.</description>
		<content:encoded><![CDATA[<p>Whoa whoa whoa, WE use AppScan, we don&#8217;t need consultants!  Hahaha.  Nothing against WebInspect, AppScan, Fortify, any of them.  They are great tools, but they are simply that tools.  A machine will never be able to replace the thinking, feeling human mind when it comes to this kind of testing.  An application can&#8217;t purchase a TV for -$1,000.00 and know that if it get&#8217;s credited back to their credit card it&#8217;s a bad thing.</p>
<p>I&#8217;ve worked with Billy a lot over the last two years, this is just another of the many examples we&#8217;ve provided during that time that show you cannot replace the value of a good app security tester.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kishor</title>
		<link>http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/comment-page-1/#comment-183</link>
		<dc:creator>Kishor</dc:creator>
		<pubDate>Fri, 28 Sep 2007 13:59:45 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/28/all-your-google-docs-are-belong-to-us/#comment-183</guid>
		<description>Good stuff!</description>
		<content:encoded><![CDATA[<p>Good stuff!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.661 seconds -->
