<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Computer Security Is My Interest! &#187; XSS Vulnerability</title>
	<atom:link href="http://soroush.secproject.com/blog/tag/xss-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://soroush.secproject.com/blog</link>
	<description>Soroush Dalili's Weblog</description>
	<lastBuildDate>Thu, 01 Jul 2010 19:05:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>My belief: 70% of websites are vulnerable</title>
		<link>http://soroush.secproject.com/blog/2009/11/my-belief-70-of-websites-are-vulnerable/</link>
		<comments>http://soroush.secproject.com/blog/2009/11/my-belief-70-of-websites-are-vulnerable/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 15:57:31 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Articles]]></category>
		<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[Critical vulnerabilities]]></category>
		<category><![CDATA[CSRF Attacks]]></category>
		<category><![CDATA[OWASP top 10]]></category>
		<category><![CDATA[SQL Injection Vulnerability]]></category>
		<category><![CDATA[website vulnerability]]></category>
		<category><![CDATA[XSS Vulnerability]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=180</guid>
		<description><![CDATA[When I was searching for a ticket in nationalrail.co.uk website, I suddenly found an XSS and also a SQL Injection vulnerabilities in it. I reported these two vulns. to its website just for having more security. And, I think these two vulnerabilities are fixed now. However, I believe that still 70% of webistes are vulnerable [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">When I was searching for a ticket in nationalrail.co.uk website, I suddenly found an XSS and also a SQL Injection vulnerabilities in it.</p>
<p style="text-align: justify;">I reported these two vulns. to its website just for having more security. And, I think these two vulnerabilities are fixed now.</p>
<p style="text-align: justify;">However, <strong>I believe that still 70% of webistes are vulnerable against the <a href="http://owasp.org/">OWASP</a> TOP 10! </strong></p>
<p style="text-align: justify;">Also, I think you should read &#8220;<a href="http://www.securityfocus.com/brief/1036"><span>Survey: Majority of Web sites vulnerable</span></a>&#8221; as well.</p>
<p style="text-align: justify;">Cheers,</p>
<p style="text-align: justify;">Soroush</p>
<p style="text-align: justify;">
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/11/my-belief-70-of-websites-are-vulnerable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Travian Game Vulnerabilities in progress&#8230;</title>
		<link>http://soroush.secproject.com/blog/2009/11/travian-game-vulnerabilities-in-progress/</link>
		<comments>http://soroush.secproject.com/blog/2009/11/travian-game-vulnerabilities-in-progress/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 14:54:08 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Normal Posts]]></category>
		<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[logical flaw]]></category>
		<category><![CDATA[travian game]]></category>
		<category><![CDATA[travian hack]]></category>
		<category><![CDATA[travian online game]]></category>
		<category><![CDATA[website vulnerability]]></category>
		<category><![CDATA[XSS Vulnerability]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=176</guid>
		<description><![CDATA[3 weeks ago, I sent an email about some small but effective vulnerabilities in Travian online game to its providers. By using these vulnerabilities a player can make several accounts by the same email address (because of a logical flaw), and also, he/she can login to other players&#8217; accounts (by using an XSS vulnerability which [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">3 weeks ago, I sent an email about some small but effective vulnerabilities in Travian online game to its providers. By using these vulnerabilities a player can make several accounts by the same email address (because of a logical flaw), and also, he/she can login to other players&#8217; accounts (by using an XSS vulnerability which is completely proved).</p>
<p>Now, I&#8217;m still waiting for their final response as I don&#8217;t want to be harmful for them!</p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/11/travian-game-vulnerabilities-in-progress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to prevent phishing attacks? ‐ In 3 Pages ‐</title>
		<link>http://soroush.secproject.com/blog/2009/11/how-to-prevent-phishing-attacks-%e2%80%90-in-3-pages-%e2%80%90/</link>
		<comments>http://soroush.secproject.com/blog/2009/11/how-to-prevent-phishing-attacks-%e2%80%90-in-3-pages-%e2%80%90/#comments</comments>
		<pubDate>Sat, 21 Nov 2009 18:06:46 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Articles]]></category>
		<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[Phishing attacks]]></category>
		<category><![CDATA[Phishing methods]]></category>
		<category><![CDATA[Phishing prevention]]></category>
		<category><![CDATA[XSS in phishing attacks]]></category>
		<category><![CDATA[XSS Vulnerability]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=166</guid>
		<description><![CDATA[In only 3 pages, I tried to explain Phishing attacks and prevention methods. Although there are some books about this topic, I tried to do my best in 3 pages only! :D I hope you enjoy :) Click here to download this mini-article! Cheers, Soroush]]></description>
			<content:encoded><![CDATA[<p>In only 3 pages, I tried to explain Phishing attacks and prevention methods. Although there are some books about this topic, I tried to do my best in 3 pages only! :D</p>
<p>I hope you enjoy :)</p>
<p><a title="phishing_in_3_pages_march_2009.pdf" href="http://soroush.secproject.com/downloadable/phishing_in_3_pages_march_2009.pdf" target="_blank">Click here to download this mini-article!</a></p>
<p>Cheers,</p>
<p>Soroush</p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/11/how-to-prevent-phishing-attacks-%e2%80%90-in-3-pages-%e2%80%90/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Blog Template Was Updated</title>
		<link>http://soroush.secproject.com/blog/2009/01/blog-template-was-updated/</link>
		<comments>http://soroush.secproject.com/blog/2009/01/blog-template-was-updated/#comments</comments>
		<pubDate>Sat, 31 Jan 2009 22:20:30 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Normal Posts]]></category>
		<category><![CDATA[Blog Template]]></category>
		<category><![CDATA[XSS Vulnerability]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=130</guid>
		<description><![CDATA[I found some XSS vulnerabilities in my blog&#8217;s template, so I reported them to its creator (Inanis). Thanks from Inanis because of fast fix and also for this beautiful template. You can see these in this link: http://www.inanis.net/blog/index.php/downloads/inanis-glass-wordpress-theme/inanis-glass-readme/]]></description>
			<content:encoded><![CDATA[<p>I found some XSS vulnerabilities in my blog&#8217;s template, so I reported them to its creator (Inanis).</p>
<p>Thanks from Inanis because of fast fix and also for this beautiful template.</p>
<p>You can see these in this link:</p>
<p><a href="http://www.inanis.net/blog/index.php/downloads/inanis-glass-wordpress-theme/inanis-glass-readme/" target="_blank">http://www.inanis.net/blog/index.php/downloads/inanis-glass-wordpress-theme/inanis-glass-readme/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/01/blog-template-was-updated/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 0.565 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2010-07-17 07:41:08 -->
