<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Stealing More Files with Safari</title>
	<atom:link href="http://xs-sniper.com/blog/2009/02/13/stealing-more-files-with-safari/feed/" rel="self" type="application/rss+xml" />
	<link>http://xs-sniper.com/blog/2009/02/13/stealing-more-files-with-safari/</link>
	<description>Thoughts on Security in an Uncivilized World…</description>
	<lastBuildDate>Wed, 08 Sep 2010 02:39:08 -0700</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: mike face</title>
		<link>http://xs-sniper.com/blog/2009/02/13/stealing-more-files-with-safari/comment-page-1/#comment-749</link>
		<dc:creator>mike face</dc:creator>
		<pubDate>Tue, 24 Mar 2009 21:43:46 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=219#comment-749</guid>
		<description>i like to share all your p@rn thru this exploit.</description>
		<content:encoded><![CDATA[<p>i like to share all your p@rn thru this exploit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xssniper</title>
		<link>http://xs-sniper.com/blog/2009/02/13/stealing-more-files-with-safari/comment-page-1/#comment-735</link>
		<dc:creator>xssniper</dc:creator>
		<pubDate>Tue, 17 Feb 2009 06:29:34 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=219#comment-735</guid>
		<description>@John - From a pure security engineering standpoint, giving the feed:// protocol access to the local file system is a bad idea.  I&#039;m not sure why the design is as it is, but I&#039;m guessing that it is a side effect of loading the feed HTML templates from the local file system</description>
		<content:encoded><![CDATA[<p>@John &#8211; From a pure security engineering standpoint, giving the feed:// protocol access to the local file system is a bad idea.  I&#8217;m not sure why the design is as it is, but I&#8217;m guessing that it is a side effect of loading the feed HTML templates from the local file system</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Grab bag: Simplify Media and the stimulus package (Jarrett House North)</title>
		<link>http://xs-sniper.com/blog/2009/02/13/stealing-more-files-with-safari/comment-page-1/#comment-734</link>
		<dc:creator>Grab bag: Simplify Media and the stimulus package (Jarrett House North)</dc:creator>
		<pubDate>Tue, 17 Feb 2009 01:08:15 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=219#comment-734</guid>
		<description>[...] Stealing More Files with Safari (Billy (BK) Rios) Explaining the XSS vulnerability in Safari&#8217;s RSS feed reader. Seems to have been a specific problem for the filtering strategy that Apple used to filter feed content. (tags: security xss safari) [...]</description>
		<content:encoded><![CDATA[<p>[...] Stealing More Files with Safari (Billy (BK) Rios) Explaining the XSS vulnerability in Safari&#8217;s RSS feed reader. Seems to have been a specific problem for the filtering strategy that Apple used to filter feed content. (tags: security xss safari) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john fsck</title>
		<link>http://xs-sniper.com/blog/2009/02/13/stealing-more-files-with-safari/comment-page-1/#comment-731</link>
		<dc:creator>john fsck</dc:creator>
		<pubDate>Sat, 14 Feb 2009 09:36:13 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=219#comment-731</guid>
		<description>Hey, just curious, any legitimate reason why feed:// would need access to the local filesystem? I thought it would behave similar to other cross domain situations.</description>
		<content:encoded><![CDATA[<p>Hey, just curious, any legitimate reason why feed:// would need access to the local filesystem? I thought it would behave similar to other cross domain situations.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.322 seconds -->
