<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Computer Security Is My Interest!</title>
	<atom:link href="http://soroush.secproject.com/blog/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://soroush.secproject.com/blog</link>
	<description>Soroush Dalili's Weblog</description>
	<lastBuildDate>Sun, 03 Jan 2010 16:37:53 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Microsoft IIS Semi-Colon Vulnerability by Soroush Dalili</title>
		<link>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/comment-page-1/#comment-4043</link>
		<dc:creator>Soroush Dalili</dc:creator>
		<pubDate>Sun, 03 Jan 2010 16:37:53 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=185#comment-4043</guid>
		<description>Please read: http://soroush.secproject.com/blog/2010/01/microsoft-contradiction/</description>
		<content:encoded><![CDATA[<p>Please read: <a href="http://soroush.secproject.com/blog/2010/01/microsoft-contradiction/" rel="nofollow">http://soroush.secproject.com/blog/2010/01/microsoft-contradiction/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Microsoft IIS Semi-Colon Vulnerability by Soroush Dalili</title>
		<link>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/comment-page-1/#comment-4042</link>
		<dc:creator>Soroush Dalili</dc:creator>
		<pubDate>Sun, 03 Jan 2010 15:49:16 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=185#comment-4042</guid>
		<description>Dear Hamid,
Thanks for your comment. Please contact me via my ymsgri ID (irsdl). I do not want to discuss it here more than this (because of some personal reasons).</description>
		<content:encoded><![CDATA[<p>Dear Hamid,<br />
Thanks for your comment. Please contact me via my ymsgri ID (irsdl). I do not want to discuss it here more than this (because of some personal reasons).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Microsoft IIS Semi-Colon Vulnerability by Ottmar Freudenberger</title>
		<link>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/comment-page-1/#comment-4037</link>
		<dc:creator>Ottmar Freudenberger</dc:creator>
		<pubDate>Wed, 30 Dec 2009 06:56:41 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=185#comment-4037</guid>
		<description>Well, you&#039;ve noticed MS final(?) statement on the issue already, did you?
&lt;a href=&quot;http://blogs.technet.com/msrc/archive/2009/12/29/results-of-investigation-into-holiday-iis-claim.aspx&quot; rel=&quot;nofollow&quot;&gt;MSRC Blog entry&lt;/a&gt;:
&lt;cite&gt;We&#039;ve completed our investigation into the claims that came up over the holiday of a possible vulnerability in IIS and found that there is no vulnerability in IIS.[...]
for the scenario to work, the IIS server must already be configured to allow both “write” and “execute” privileges on the same directory. This is not the default configuration for IIS and is contrary to all of our published best practices. Quite simply, an IIS server configured in this manner is inherently vulnerable to attack&lt;/cite&gt;
And &lt;a href=&quot;http://blogs.iis.net/nazim/archive/2009/12/29/public-disclosure-of-iis-security-issue-with-semi-colons-in-url.aspx&quot; rel=&quot;nofollow&quot;&gt;IIS Blog entry&lt;/a&gt;:
&lt;cite&gt;The issue in question affects only IIS 6 (Windows Server 2003) and arises when you send a URL with a semi-colon in it. IIS 6 uses the path before the semi-colon to determine the script handler for it.[...]
In summary, there is a functionality issue here, but there is no security issue unless you already had a poorly configured server to begin with.&lt;/cite&gt;</description>
		<content:encoded><![CDATA[<p>Well, you&#8217;ve noticed MS final(?) statement on the issue already, did you?<br />
<a href="http://blogs.technet.com/msrc/archive/2009/12/29/results-of-investigation-into-holiday-iis-claim.aspx" rel="nofollow">MSRC Blog entry</a>:<br />
<cite>We&#8217;ve completed our investigation into the claims that came up over the holiday of a possible vulnerability in IIS and found that there is no vulnerability in IIS.[...]<br />
for the scenario to work, the IIS server must already be configured to allow both “write” and “execute” privileges on the same directory. This is not the default configuration for IIS and is contrary to all of our published best practices. Quite simply, an IIS server configured in this manner is inherently vulnerable to attack</cite><br />
And <a href="http://blogs.iis.net/nazim/archive/2009/12/29/public-disclosure-of-iis-security-issue-with-semi-colons-in-url.aspx" rel="nofollow">IIS Blog entry</a>:<br />
<cite>The issue in question affects only IIS 6 (Windows Server 2003) and arises when you send a URL with a semi-colon in it. IIS 6 uses the path before the semi-colon to determine the script handler for it.[...]<br />
In summary, there is a functionality issue here, but there is no security issue unless you already had a poorly configured server to begin with.</cite></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Microsoft IIS Semi-Colon Vulnerability by Hamid.k</title>
		<link>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/comment-page-1/#comment-4032</link>
		<dc:creator>Hamid.k</dc:creator>
		<pubDate>Mon, 28 Dec 2009 08:33:43 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=185#comment-4032</guid>
		<description>Hi Soroush.
Nice finding! I&#039;ve checked out your advisory and also comments you&#039;ve wrote following it but there are still some shady points remaining unclear to me.
The nature of the vulnerability itself is clear and obvious, but.:
It`s main dependency is lack of MIME/type validation of affected (wep)application. While it`s spreading the wrong way by many people that simply bypassing the file extension will do the job, the case in real-world is that many web-applications out there also validate the content too (by either checking size,header,etc...) .
The other point as PhilG mentioned is that, having script execution access is the second dependency, on vulnerable target which is _usually_ considered when deploying application.

And the question: You&#039;ve mentioned in advisory that you&#039;ve tested some applications and 70% of them (uploaders?) seems to be vulnerable to this specific type of attack (mix of IIS bug+flawed extension checking by web-app+flawed  type validation) when hosted by IIS. 

If possible, I`d like to hear more accurate test results from you about your tests on the case:
1-Was it just testing uploaders, or entire web-applications being tested, which represented that result?
2-Is your estimation an educated guess based on  OWASP yearly reports or it has been a personal test?
3-If it was a personal research, it would be great to know about number of tested cases.

These would help me have more clear idea about true impact of this case in real-world , not just relaying on blind estimations or hypes.</description>
		<content:encoded><![CDATA[<p>Hi Soroush.<br />
Nice finding! I&#8217;ve checked out your advisory and also comments you&#8217;ve wrote following it but there are still some shady points remaining unclear to me.<br />
The nature of the vulnerability itself is clear and obvious, but.:<br />
It`s main dependency is lack of MIME/type validation of affected (wep)application. While it`s spreading the wrong way by many people that simply bypassing the file extension will do the job, the case in real-world is that many web-applications out there also validate the content too (by either checking size,header,etc&#8230;) .<br />
The other point as PhilG mentioned is that, having script execution access is the second dependency, on vulnerable target which is _usually_ considered when deploying application.</p>
<p>And the question: You&#8217;ve mentioned in advisory that you&#8217;ve tested some applications and 70% of them (uploaders?) seems to be vulnerable to this specific type of attack (mix of IIS bug+flawed extension checking by web-app+flawed  type validation) when hosted by IIS. </p>
<p>If possible, I`d like to hear more accurate test results from you about your tests on the case:<br />
1-Was it just testing uploaders, or entire web-applications being tested, which represented that result?<br />
2-Is your estimation an educated guess based on  OWASP yearly reports or it has been a personal test?<br />
3-If it was a personal research, it would be great to know about number of tested cases.</p>
<p>These would help me have more clear idea about true impact of this case in real-world , not just relaying on blind estimations or hypes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Microsoft IIS Semi-Colon Vulnerability by Soroush Dalili</title>
		<link>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/comment-page-1/#comment-4031</link>
		<dc:creator>Soroush Dalili</dc:creator>
		<pubDate>Mon, 28 Dec 2009 01:40:47 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=185#comment-4031</guid>
		<description>Hello, Thanks for your comment. I think you did not understand the purpose of this vulnerability. Although this vulnerability is because of IIS, its effect is on the web applications. As I had written in the PDF file: &quot;Many file uploaders protect the system by checking only the last section of the filename as its extension. And by using this vulnerability, an attacker can bypass this protection and upload a dangerous executable file on the server.&quot;. It is obvious that there are many files which should be accessible by using the web URL directly, such as the images, flash files, java applets, and so on. The cost of putting these files out of the web folder directory and using a script to download them indirectly is not reasonable in most cases (Except for non-free materials).
If you do a real penetration testing against some websites, you will realize the value of this vulnerability. You can find many of these web applications which are exploitable by using this vulnerability. For example, I want to refer to the DNN (Dot Net Nuke) application vulnerability in which an attacker could upload an image, a flash, or a document file on the system; and, by mixing with this vulnerability, an attacker could get a web-shell from the system. As another example, in some cases although you can gain access to the admin panel of the website, you can only upload some images. Now, perhaps you can bypass it and upload a web-shell to read all the source codes, download some important data, and so on.
Those uploaders which checked the file’s header and source code of the file are already bypassed. And, by using this vulnerability, those checked the files’ extensions are also bypassed.
You can read the “Fast Solution/Recommendation” section in the PDF file as the possible solutions for this vulnerability. Those who performed these solutions are secured not only against this weakness, but also against the entire file uploading vulnerabilities.</description>
		<content:encoded><![CDATA[<p>Hello, Thanks for your comment. I think you did not understand the purpose of this vulnerability. Although this vulnerability is because of IIS, its effect is on the web applications. As I had written in the PDF file: &#8220;Many file uploaders protect the system by checking only the last section of the filename as its extension. And by using this vulnerability, an attacker can bypass this protection and upload a dangerous executable file on the server.&#8221;. It is obvious that there are many files which should be accessible by using the web URL directly, such as the images, flash files, java applets, and so on. The cost of putting these files out of the web folder directory and using a script to download them indirectly is not reasonable in most cases (Except for non-free materials).<br />
If you do a real penetration testing against some websites, you will realize the value of this vulnerability. You can find many of these web applications which are exploitable by using this vulnerability. For example, I want to refer to the DNN (Dot Net Nuke) application vulnerability in which an attacker could upload an image, a flash, or a document file on the system; and, by mixing with this vulnerability, an attacker could get a web-shell from the system. As another example, in some cases although you can gain access to the admin panel of the website, you can only upload some images. Now, perhaps you can bypass it and upload a web-shell to read all the source codes, download some important data, and so on.<br />
Those uploaders which checked the file’s header and source code of the file are already bypassed. And, by using this vulnerability, those checked the files’ extensions are also bypassed.<br />
You can read the “Fast Solution/Recommendation” section in the PDF file as the possible solutions for this vulnerability. Those who performed these solutions are secured not only against this weakness, but also against the entire file uploading vulnerabilities.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Microsoft IIS Semi-Colon Vulnerability by PhilG</title>
		<link>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/comment-page-1/#comment-4029</link>
		<dc:creator>PhilG</dc:creator>
		<pubDate>Sun, 27 Dec 2009 22:07:23 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=185#comment-4029</guid>
		<description>Hi Soroush,
This error you reported on is a non-issue. Even with the basic default configuration in place, this does not produce an executable attack. It would require a very specific set of configuration errors (where most of the defaults were changed) to create an executable attack such as, 
  Enabling execute on the upload folder,
  Putting the uploaded files in the web tree itself,
  The web application not performing any file type validation,
  Disabling built in input validation,
  The application not performing any input validation itself. 

While it is possible to create a scenario that would be exploitable, it would take a conscious effort to do so.  Admittedly, if this was a web site running on IIS 5, built in the late 1990&#039;s you would be likely to find just such conditions, but any modern web site would be unlikely to be vulnerable to this unless the creator of the site did some very bad things intentionally. (albeit unknowingly)

If you tried this on one of your sites and it worked, you might want to re-visit basic security practices and fix up your code. 

Thanks for sharing your findings.</description>
		<content:encoded><![CDATA[<p>Hi Soroush,<br />
This error you reported on is a non-issue. Even with the basic default configuration in place, this does not produce an executable attack. It would require a very specific set of configuration errors (where most of the defaults were changed) to create an executable attack such as,<br />
  Enabling execute on the upload folder,<br />
  Putting the uploaded files in the web tree itself,<br />
  The web application not performing any file type validation,<br />
  Disabling built in input validation,<br />
  The application not performing any input validation itself. </p>
<p>While it is possible to create a scenario that would be exploitable, it would take a conscious effort to do so.  Admittedly, if this was a web site running on IIS 5, built in the late 1990&#8217;s you would be likely to find just such conditions, but any modern web site would be unlikely to be vulnerable to this unless the creator of the site did some very bad things intentionally. (albeit unknowingly)</p>
<p>If you tried this on one of your sites and it worked, you might want to re-visit basic security practices and fix up your code. </p>
<p>Thanks for sharing your findings.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Microsoft IIS Semi-Colon Vulnerability by Denis</title>
		<link>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/comment-page-1/#comment-4028</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sun, 27 Dec 2009 20:42:04 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=185#comment-4028</guid>
		<description>Thank you for the answer and good work !</description>
		<content:encoded><![CDATA[<p>Thank you for the answer and good work !</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Microsoft IIS Semi-Colon Vulnerability by Soroush Dalili</title>
		<link>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/comment-page-1/#comment-4027</link>
		<dc:creator>Soroush Dalili</dc:creator>
		<pubDate>Sun, 27 Dec 2009 20:02:07 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=185#comment-4027</guid>
		<description>Thanks for the question.
Unfortunately, I was too busy at that time. And, I wanted to publish it after getting my MSc. degree ;)</description>
		<content:encoded><![CDATA[<p>Thanks for the question.<br />
Unfortunately, I was too busy at that time. And, I wanted to publish it after getting my MSc. degree ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Google captured my privacy! by Soroush Dalili</title>
		<link>http://soroush.secproject.com/blog/2009/12/google-captured-my-privacy/comment-page-1/#comment-4026</link>
		<dc:creator>Soroush Dalili</dc:creator>
		<pubDate>Sun, 27 Dec 2009 19:46:35 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=183#comment-4026</guid>
		<description>You are right. But, according to &quot;http://www.mozilla.com/en-US/firefox/phishing-protection/&quot;:
&quot;Before blocking the site, Firefox will request a double-check to ensure that the reported site has not been removed from the list since your last update. In both cases, existing cookies you have from google.com, our list provider, may also be sent.&quot;
Google has this chance to write down the name of the website which has been blocked such as &quot;milw0rm.com&quot; and we want to visit it. And, perhaps an especial website can be inserted in this list intently, and then it can be discarded during the second check. So, no one can realize it...</description>
		<content:encoded><![CDATA[<p>You are right. But, according to &#8220;http://www.mozilla.com/en-US/firefox/phishing-protection/&#8221;:<br />
&#8220;Before blocking the site, Firefox will request a double-check to ensure that the reported site has not been removed from the list since your last update. In both cases, existing cookies you have from google.com, our list provider, may also be sent.&#8221;<br />
Google has this chance to write down the name of the website which has been blocked such as &#8220;milw0rm.com&#8221; and we want to visit it. And, perhaps an especial website can be inserted in this list intently, and then it can be discarded during the second check. So, no one can realize it&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Microsoft IIS Semi-Colon Vulnerability by Denis</title>
		<link>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/comment-page-1/#comment-4025</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sun, 27 Dec 2009 15:46:01 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=185#comment-4025</guid>
		<description>Hello,

I read in your document :
&quot;Finding Date: April 2008
Report Date: Dec. 2009&quot;

Why wait so long before reporting ?</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>I read in your document :<br />
&#8220;Finding Date: April 2008<br />
Report Date: Dec. 2009&#8243;</p>
<p>Why wait so long before reporting ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Google captured my privacy! by xanda</title>
		<link>http://soroush.secproject.com/blog/2009/12/google-captured-my-privacy/comment-page-1/#comment-4024</link>
		<dc:creator>xanda</dc:creator>
		<pubDate>Sun, 27 Dec 2009 11:16:19 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=183#comment-4024</guid>
		<description>“Browsers use Google to detect web forgery -&gt; So, a browser send a request to Google before openning a website for you! …  &lt;= Hi, from my understanding, firefox will download the hash from Google Safe Browsing API and stored locally, URL will be compared locally instead of send the request to Google ;)

more info: http://code.google.com/apis/safebrowsing/developers_guide.html</description>
		<content:encoded><![CDATA[<p>“Browsers use Google to detect web forgery -&gt; So, a browser send a request to Google before openning a website for you! …  &lt;= Hi, from my understanding, firefox will download the hash from Google Safe Browsing API and stored locally, URL will be compared locally instead of send the request to Google ;)</p>
<p>more info: <a href="http://code.google.com/apis/safebrowsing/developers_guide.html" rel="nofollow">http://code.google.com/apis/safebrowsing/developers_guide.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to prevent phishing attacks? ‐ In 3 Pages ‐ by Soroush Dalili</title>
		<link>http://soroush.secproject.com/blog/2009/11/how-to-prevent-phishing-attacks-%e2%80%90-in-3-pages-%e2%80%90/comment-page-1/#comment-3969</link>
		<dc:creator>Soroush Dalili</dc:creator>
		<pubDate>Sun, 29 Nov 2009 22:11:43 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=166#comment-3969</guid>
		<description>The body I mean buddy ;)</description>
		<content:encoded><![CDATA[<p>The body I mean buddy ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to stop hardware key-loggers by Shaghayegh</title>
		<link>http://soroush.secproject.com/blog/2009/11/how-to-stop-hardware-key-loggers/comment-page-1/#comment-3968</link>
		<dc:creator>Shaghayegh</dc:creator>
		<pubDate>Sun, 29 Nov 2009 20:59:39 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=171#comment-3968</guid>
		<description>Wow!</description>
		<content:encoded><![CDATA[<p>Wow!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to prevent phishing attacks? ‐ In 3 Pages ‐ by Shaghayegh</title>
		<link>http://soroush.secproject.com/blog/2009/11/how-to-prevent-phishing-attacks-%e2%80%90-in-3-pages-%e2%80%90/comment-page-1/#comment-3967</link>
		<dc:creator>Shaghayegh</dc:creator>
		<pubDate>Sun, 29 Nov 2009 20:52:57 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=166#comment-3967</guid>
		<description>It&#039;s 7 pages! :D :P</description>
		<content:encoded><![CDATA[<p>It&#8217;s 7 pages! :D :P</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SQL Injection Tutorial Video by irsdl</title>
		<link>http://soroush.secproject.com/blog/2009/01/sql-injection-tutorial-video/comment-page-1/#comment-3962</link>
		<dc:creator>irsdl</dc:creator>
		<pubDate>Mon, 09 Nov 2009 22:50:59 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=143#comment-3962</guid>
		<description>I&#039;m sorry for long delay. You should open it with a browser and click on the download link.</description>
		<content:encoded><![CDATA[<p>I&#8217;m sorry for long delay. You should open it with a browser and click on the download link.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SQL Injection Tutorial Video by Fred</title>
		<link>http://soroush.secproject.com/blog/2009/01/sql-injection-tutorial-video/comment-page-1/#comment-3954</link>
		<dc:creator>Fred</dc:creator>
		<pubDate>Tue, 20 Oct 2009 02:40:58 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=143#comment-3954</guid>
		<description>upon extracting Part2.2, I get the error message &quot;Data error ... File is broken&quot;.</description>
		<content:encoded><![CDATA[<p>upon extracting Part2.2, I get the error message &#8220;Data error &#8230; File is broken&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Vote in Toluna.com with a Script Automatically! by Ysinotelodigo</title>
		<link>http://soroush.secproject.com/blog/2009/01/vote-in-tolunacom-with-a-script-automatically/comment-page-1/#comment-3931</link>
		<dc:creator>Ysinotelodigo</dc:creator>
		<pubDate>Sat, 22 Aug 2009 23:21:40 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=112#comment-3931</guid>
		<description>Hey!

The link is breaked. Are you earn discount with this system?

Sorry to write bad. I&#039;m Spanish.
Good-Bye</description>
		<content:encoded><![CDATA[<p>Hey!</p>
<p>The link is breaked. Are you earn discount with this system?</p>
<p>Sorry to write bad. I&#8217;m Spanish.<br />
Good-Bye</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Critical vulnerabilities in the website of my department! &#8230; were solved! by Pouya</title>
		<link>http://soroush.secproject.com/blog/2009/02/critical-vulnerabilities-in-the-website-of-my-department-were-solved/comment-page-1/#comment-3930</link>
		<dc:creator>Pouya</dc:creator>
		<pubDate>Wed, 12 Aug 2009 02:56:33 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=155#comment-3930</guid>
		<description>! :D 
belakhare in az iran baz ! :D</description>
		<content:encoded><![CDATA[<p>! :D<br />
belakhare in az iran baz ! :D</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on March 2009 Updated: FaceBook Automatic Friends Adder from the Apllications&#8217; Walls by Meta</title>
		<link>http://soroush.secproject.com/blog/2009/01/facebook-automatic-friends-adder-from-the-apllications-walls/comment-page-1/#comment-3894</link>
		<dc:creator>Meta</dc:creator>
		<pubDate>Tue, 21 Apr 2009 08:08:28 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=134#comment-3894</guid>
		<description>Thanks for this nice script 
Could you make oen for adding friends of friends too or members of a grupe .
 woud be too great ;-)
One question woud be what are the FB limits of adding not too much Friends at one time .Get a abused account 
Thanks for sharing this</description>
		<content:encoded><![CDATA[<p>Thanks for this nice script<br />
Could you make oen for adding friends of friends too or members of a grupe .<br />
 woud be too great ;-)<br />
One question woud be what are the FB limits of adding not too much Friends at one time .Get a abused account<br />
Thanks for sharing this</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on March 2009 Updated: FaceBook Automatic Friends Adder from the Apllications&#8217; Walls by john</title>
		<link>http://soroush.secproject.com/blog/2009/01/facebook-automatic-friends-adder-from-the-apllications-walls/comment-page-1/#comment-3888</link>
		<dc:creator>john</dc:creator>
		<pubDate>Sat, 18 Apr 2009 14:34:47 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=134#comment-3888</guid>
		<description>nice code thanks.

i have a question, i&#039;m trying to say &quot;add me&quot; or something on the wall but imacros won&#039;t let me send the text.. here&#039;s what i record modified with a wildcard(*):

TAB T=1
URL GOTO=http://apps.facebook.com/guerra-de-pandillas/discussion.php
TAG POS=1 TYPE=TEXTAREA FORM=ACTION:http://www.facebook.com/wallpost.php ATTR=ID:wall_text_* CONTENT=ADDME

imacros fills the textarea but it won&#039;t press the send button.. what am i doing wrong?
thanks in advance</description>
		<content:encoded><![CDATA[<p>nice code thanks.</p>
<p>i have a question, i&#8217;m trying to say &#8220;add me&#8221; or something on the wall but imacros won&#8217;t let me send the text.. here&#8217;s what i record modified with a wildcard(*):</p>
<p>TAB T=1<br />
URL GOTO=http://apps.facebook.com/guerra-de-pandillas/discussion.php<br />
TAG POS=1 TYPE=TEXTAREA FORM=ACTION:http://www.facebook.com/wallpost.php ATTR=ID:wall_text_* CONTENT=ADDME</p>
<p>imacros fills the textarea but it won&#8217;t press the send button.. what am i doing wrong?<br />
thanks in advance</p>
]]></content:encoded>
	</item>
</channel>
</rss>
