<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Soroush Dalili - Computer Security Is My Interest!</title>
	<atom:link href="http://soroush.secproject.com/blog/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://soroush.secproject.com/blog</link>
	<description>Soroush Dalili&#039;s blog - بلاگ سروش دلیلی</description>
	<lastBuildDate>Thu, 05 Jan 2012 08:06:32 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Drag and Drop XSS in Firefox by HTML5 (Cross Domain in frames) by Soroush Dalili</title>
		<link>http://soroush.secproject.com/blog/2011/12/drag-and-drop-xss-in-firefox-by-html5-cross-domain-in-frames/comment-page-1/#comment-5708</link>
		<dc:creator>Soroush Dalili</dc:creator>
		<pubDate>Thu, 05 Jan 2012 08:06:32 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=446#comment-5708</guid>
		<description>Thanks for the link. It seems very interesting and I am wondering why I&#039;ve missed this one. By the way, instead of finding a vulnerable add-on, if you can force the user to install a malicious one, you can run any code in the first place as you know.</description>
		<content:encoded><![CDATA[<p>Thanks for the link. It seems very interesting and I am wondering why I&#8217;ve missed this one. By the way, instead of finding a vulnerable add-on, if you can force the user to install a malicious one, you can run any code in the first place as you know.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Drag and Drop XSS in Firefox by HTML5 (Cross Domain in frames) by Human Organs</title>
		<link>http://soroush.secproject.com/blog/2011/12/drag-and-drop-xss-in-firefox-by-html5-cross-domain-in-frames/comment-page-1/#comment-5679</link>
		<dc:creator>Human Organs</dc:creator>
		<pubDate>Tue, 03 Jan 2012 00:46:56 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=446#comment-5679</guid>
		<description>This is great one exploit, never seen b4 this Drag and Drop XSS . Good job realy!</description>
		<content:encoded><![CDATA[<p>This is great one exploit, never seen b4 this Drag and Drop XSS . Good job realy!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Drag and Drop XSS in Firefox by HTML5 (Cross Domain in frames) by Roberto Suggi Liverani</title>
		<link>http://soroush.secproject.com/blog/2011/12/drag-and-drop-xss-in-firefox-by-html5-cross-domain-in-frames/comment-page-1/#comment-5673</link>
		<dc:creator>Roberto Suggi Liverani</dc:creator>
		<pubDate>Mon, 02 Jan 2012 11:33:12 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=446#comment-5673</guid>
		<description>Hi there,

Nice article - just an observation on your last paragraph.

Since you mention drag and drop in the chrome:// security zone as a further attack vector, I guess this white paper might be of interest for you: &quot;Cross Context Scripting with Firefox&quot;: http://bit.ly/sFrf0X - I covered such attack in section 2.1, assuming the scenario of a vulnerable Firefox addon which allows drag and drop action from an untrusted web page :-)

Good work.</description>
		<content:encoded><![CDATA[<p>Hi there,</p>
<p>Nice article &#8211; just an observation on your last paragraph.</p>
<p>Since you mention drag and drop in the chrome:// security zone as a further attack vector, I guess this white paper might be of interest for you: &#8220;Cross Context Scripting with Firefox&#8221;: <a href="http://bit.ly/sFrf0X" rel="nofollow">http://bit.ly/sFrf0X</a> &#8211; I covered such attack in section 2.1, assuming the scenario of a vulnerable Firefox addon which allows drag and drop action from an untrusted web page :-)</p>
<p>Good work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Drag and Drop XSS in Firefox by HTML5 (Cross Domain in frames) by jafar</title>
		<link>http://soroush.secproject.com/blog/2011/12/drag-and-drop-xss-in-firefox-by-html5-cross-domain-in-frames/comment-page-1/#comment-5663</link>
		<dc:creator>jafar</dc:creator>
		<pubDate>Sat, 31 Dec 2011 16:31:39 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=446#comment-5663</guid>
		<description>I tried your PoC , it works ok  but as you said the main challenging issue about exploiting this XSS is to deceive the users to drag it.

Good job</description>
		<content:encoded><![CDATA[<p>I tried your PoC , it works ok  but as you said the main challenging issue about exploiting this XSS is to deceive the users to drag it.</p>
<p>Good job</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Drag and Drop XSS in Firefox by HTML5 (Cross Domain in frames) by Soroush Dalili</title>
		<link>http://soroush.secproject.com/blog/2011/12/drag-and-drop-xss-in-firefox-by-html5-cross-domain-in-frames/comment-page-1/#comment-5662</link>
		<dc:creator>Soroush Dalili</dc:creator>
		<pubDate>Sat, 31 Dec 2011 15:56:47 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=446#comment-5662</guid>
		<description>Yes, in fact the risk was not high and that&#039;s why it has been published.</description>
		<content:encoded><![CDATA[<p>Yes, in fact the risk was not high and that&#8217;s why it has been published.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Drag and Drop XSS in Firefox by HTML5 (Cross Domain in frames) by AbiusX</title>
		<link>http://soroush.secproject.com/blog/2011/12/drag-and-drop-xss-in-firefox-by-html5-cross-domain-in-frames/comment-page-1/#comment-5661</link>
		<dc:creator>AbiusX</dc:creator>
		<pubDate>Sat, 31 Dec 2011 11:06:09 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=446#comment-5661</guid>
		<description>Good one, 
Although the impact is high, there are very few scenarios susceptible to the attack.</description>
		<content:encoded><![CDATA[<p>Good one,<br />
Although the impact is high, there are very few scenarios susceptible to the attack.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook Redirect Link &#8211; New Bypass Method – “:/” after the domain name by Soroush Dalili</title>
		<link>http://soroush.secproject.com/blog/2010/12/facebook-redirect-link-new-bypass-method-%e2%80%93-%e2%80%9c%e2%80%9d-after-the-domain-name/comment-page-1/#comment-5657</link>
		<dc:creator>Soroush Dalili</dc:creator>
		<pubDate>Sat, 31 Dec 2011 02:52:06 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=409#comment-5657</guid>
		<description>This issue had been solved on Facebook as far as I know.</description>
		<content:encoded><![CDATA[<p>This issue had been solved on Facebook as far as I know.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook Redirect Link &#8211; New Bypass Method – “:/” after the domain name by เย็ด</title>
		<link>http://soroush.secproject.com/blog/2010/12/facebook-redirect-link-new-bypass-method-%e2%80%93-%e2%80%9c%e2%80%9d-after-the-domain-name/comment-page-1/#comment-5282</link>
		<dc:creator>เย็ด</dc:creator>
		<pubDate>Tue, 04 Oct 2011 09:42:50 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=409#comment-5282</guid>
		<description>This issue had been reported to Facebook at least twice more than 1 month ago without having any response.</description>
		<content:encoded><![CDATA[<p>This issue had been reported to Facebook at least twice more than 1 month ago without having any response.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook Redirect Link &#8211; New Bypass Method – “:/” after the domain name by Aaron</title>
		<link>http://soroush.secproject.com/blog/2010/12/facebook-redirect-link-new-bypass-method-%e2%80%93-%e2%80%9c%e2%80%9d-after-the-domain-name/comment-page-1/#comment-5175</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Tue, 05 Jul 2011 05:02:03 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=409#comment-5175</guid>
		<description>Hi,

Maybe you can help me. I&#039;ve directed / forwarded my url / domain to my facebook page. But before the redirect to the page, a prompt appears where you have to click &quot;Go To Facebook&quot; before you can access / land on the Facebook page. Is there a way to solve this? Thanks!</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Maybe you can help me. I&#8217;ve directed / forwarded my url / domain to my facebook page. But before the redirect to the page, a prompt appears where you have to click &#8220;Go To Facebook&#8221; before you can access / land on the Facebook page. Is there a way to solve this? Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Excel Advanced Search Add-In Application by &#8220;Advisories&#8221; has been updated &#171; Soroush Dalili&#039;s Mirror Blog &#8211; بلاگ آینه ای سروش دلیلی</title>
		<link>http://soroush.secproject.com/blog/projects/exceladvancedsearchapplication/comment-page-1/#comment-5151</link>
		<dc:creator>&#8220;Advisories&#8221; has been updated &#171; Soroush Dalili&#039;s Mirror Blog &#8211; بلاگ آینه ای سروش دلیلی</dc:creator>
		<pubDate>Tue, 17 May 2011 20:42:47 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/#comment-5151</guid>
		<description>[...] my articles or even write about the vulnerabilities in details. Moreover, I need to update my “Excel Advanced Search” Add-In to be compatible with Office 2010, and also I need to put my “Secure Text Steganography [...]</description>
		<content:encoded><![CDATA[<p>[...] my articles or even write about the vulnerabilities in details. Moreover, I need to update my “Excel Advanced Search” Add-In to be compatible with Office 2010, and also I need to put my “Secure Text Steganography [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SQL Injection Tutorial Video by Hamid Ajandies</title>
		<link>http://soroush.secproject.com/blog/2009/01/sql-injection-tutorial-video/comment-page-1/#comment-5071</link>
		<dc:creator>Hamid Ajandies</dc:creator>
		<pubDate>Sat, 05 Mar 2011 18:54:38 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=143#comment-5071</guid>
		<description>please make a video tutorial on how to use cpanel bruter i have a script Aria cPanel cracker version is it going to be uploaded to a website in what format? i have been seening it on my website meaning hackers getting access to my root folder but i don&#039;t know how it work. thanks</description>
		<content:encoded><![CDATA[<p>please make a video tutorial on how to use cpanel bruter i have a script Aria cPanel cracker version is it going to be uploaded to a website in what format? i have been seening it on my website meaning hackers getting access to my root folder but i don&#8217;t know how it work. thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Travian Game Vulnerabilities in progress&#8230; by Travian Game Patch – Finally! &#171; Soroush Dalili&#039;s Mirror Blog &#8211; بلاگ آینه ای سروش دلیلی</title>
		<link>http://soroush.secproject.com/blog/2009/11/travian-game-vulnerabilities-in-progress/comment-page-1/#comment-5020</link>
		<dc:creator>Travian Game Patch – Finally! &#171; Soroush Dalili&#039;s Mirror Blog &#8211; بلاگ آینه ای سروش دلیلی</dc:creator>
		<pubDate>Mon, 31 Jan 2011 19:47:11 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=176#comment-5020</guid>
		<description>[...] These issues go back to June 2009. Related Link: http://soroush.secproject.com/blog/2009/11/travian-game-vulnerabilities-in-progress/ [...]</description>
		<content:encoded><![CDATA[<p>[...] These issues go back to June 2009. Related Link: <a href="http://soroush.secproject.com/blog/2009/11/travian-game-vulnerabilities-in-progress/" rel="nofollow">http://soroush.secproject.com/blog/2009/11/travian-game-vulnerabilities-in-progress/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Unrestricted File Download V1.0 – Windows Server by holiman</title>
		<link>http://soroush.secproject.com/blog/2011/01/unrestricted_file_download_v1_0/comment-page-1/#comment-5019</link>
		<dc:creator>holiman</dc:creator>
		<pubDate>Sun, 30 Jan 2011 00:10:21 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=421#comment-5019</guid>
		<description>A third solution to the whole problem of sanitizing filenames is, simply, don&#039;t. The problem with black/whistlisting characters is that it is difficult to do it right, and even if you do, it is not portable between languages and operating systems. E.g. perhaps it is allowed for a file to have all kinds of crazy characters on the OS that is used. 

So, the third solution is to open the file via the framework used. *After* the file is opened, query the file-object for information about path, name and suffix. At that point, it is time for applying whitelists to see that these values are all ok. 

(Obviously, don&#039;t do this on frameworks which allow command execution in the same API calls as file opening - but this method should work for all moden high-level frameworks which have dedicated file APIs.)

Regards!</description>
		<content:encoded><![CDATA[<p>A third solution to the whole problem of sanitizing filenames is, simply, don&#8217;t. The problem with black/whistlisting characters is that it is difficult to do it right, and even if you do, it is not portable between languages and operating systems. E.g. perhaps it is allowed for a file to have all kinds of crazy characters on the OS that is used. </p>
<p>So, the third solution is to open the file via the framework used. *After* the file is opened, query the file-object for information about path, name and suffix. At that point, it is time for applying whitelists to see that these values are all ok. </p>
<p>(Obviously, don&#8217;t do this on frameworks which allow command execution in the same API calls as file opening &#8211; but this method should work for all moden high-level frameworks which have dedicated file APIs.)</p>
<p>Regards!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on A Dotty Salty Directory: A Secret Place in NTFS for Secret Files! by jimmy</title>
		<link>http://soroush.secproject.com/blog/2010/12/a-dotty-salty-directory-a-secret-place-in-ntfs-for-secret-files/comment-page-1/#comment-5000</link>
		<dc:creator>jimmy</dc:creator>
		<pubDate>Mon, 24 Jan 2011 18:22:19 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=398#comment-5000</guid>
		<description>very interesting post  my friend, thanks and greetings:)</description>
		<content:encoded><![CDATA[<p>very interesting post  my friend, thanks and greetings:)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cross Site URL Hijacking by using Error Object in Mozilla Firefox by Happy Reading 15 Web Hacking Techniques &#8230; &#171; Jae Ho&#039;s Weblog</title>
		<link>http://soroush.secproject.com/blog/2010/05/cross-site-url-hijacking-by-using-error-object-in-mozilla-firefox/comment-page-1/#comment-4970</link>
		<dc:creator>Happy Reading 15 Web Hacking Techniques &#8230; &#171; Jae Ho&#039;s Weblog</dc:creator>
		<pubDate>Wed, 12 Jan 2011 05:56:55 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=245#comment-4970</guid>
		<description>[...] Cross Site URL Hijacking by using Error Object in Mozilla Firefox [...]</description>
		<content:encoded><![CDATA[<p>[...] Cross Site URL Hijacking by using Error Object in Mozilla Firefox [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on IE7-8 drive list enumeration! by chr1x</title>
		<link>http://soroush.secproject.com/blog/2010/03/ie7-8-drive-list-enumeration/comment-page-1/#comment-4946</link>
		<dc:creator>chr1x</dc:creator>
		<pubDate>Tue, 04 Jan 2011 17:58:13 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=230#comment-4946</guid>
		<description>Excellent work! keep rocking mate!

chr1x</description>
		<content:encoded><![CDATA[<p>Excellent work! keep rocking mate!</p>
<p>chr1x</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How Secunia PSI put the privacy in danger by Leo</title>
		<link>http://soroush.secproject.com/blog/2010/12/how-secunia-psi-put-the-privacy-in-danger/comment-page-1/#comment-4797</link>
		<dc:creator>Leo</dc:creator>
		<pubDate>Tue, 07 Dec 2010 19:33:12 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=378#comment-4797</guid>
		<description>It&#039;s a mesh on the internet, what about google etc???</description>
		<content:encoded><![CDATA[<p>It&#8217;s a mesh on the internet, what about google etc???</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How Secunia PSI put the privacy in danger by Retyt</title>
		<link>http://soroush.secproject.com/blog/2010/12/how-secunia-psi-put-the-privacy-in-danger/comment-page-1/#comment-4782</link>
		<dc:creator>Retyt</dc:creator>
		<pubDate>Sat, 04 Dec 2010 16:50:32 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=378#comment-4782</guid>
		<description>Great article, I really want a Secunia reply now!</description>
		<content:encoded><![CDATA[<p>Great article, I really want a Secunia reply now!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cross Site Request Forgery (CSRF) PoC Template (by Javascript) by Cross Site Request Forgery (CSRF) PoC Template</title>
		<link>http://soroush.secproject.com/blog/projects/csrf_poc_template/comment-page-1/#comment-4573</link>
		<dc:creator>Cross Site Request Forgery (CSRF) PoC Template</dc:creator>
		<pubDate>Tue, 09 Nov 2010 17:47:03 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/#comment-4573</guid>
		<description>[...] here to read more   Tagged with: CSRF&#160;     0 Comments   Leave A [...]</description>
		<content:encoded><![CDATA[<p>[...] here to read more   Tagged with: CSRF&nbsp;     0 Comments   Leave A [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Excel Advanced Search Add-In Application by npnbkck</title>
		<link>http://soroush.secproject.com/blog/2010/08/download-excel-advanced-search/comment-page-1/#comment-4504</link>
		<dc:creator>npnbkck</dc:creator>
		<pubDate>Thu, 23 Sep 2010 08:35:07 +0000</pubDate>
		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=348#comment-4504</guid>
		<description>I love your works very much!

Could you add the checklist box of all sheets per workbook that I can choose some of sheets to search in the next version?

Thank you!</description>
		<content:encoded><![CDATA[<p>I love your works very much!</p>
<p>Could you add the checklist box of all sheets per workbook that I can choose some of sheets to search in the next version?</p>
<p>Thank you!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic page generated in 0.638 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2012-01-22 22:32:20 -->
<!-- Compression = gzip -->
