<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: “Cross” just like in XSS</title>
	<atom:link href="http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40/feed" rel="self" type="application/rss+xml" />
	<link>http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40</link>
	<description>Blog of Sven Vetsch / Disenchant</description>
	<lastBuildDate>Tue, 02 Mar 2010 12:16:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: nEUrOO</title>
		<link>http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40/comment-page-1#comment-2577</link>
		<dc:creator>nEUrOO</dc:creator>
		<pubDate>Mon, 12 Feb 2007 15:32:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40#comment-2577</guid>
		<description>You&#039;re absolutely right for the permanent xss, i didn&#039;t even think about it :X</description>
		<content:encoded><![CDATA[<p>You&#8217;re absolutely right for the permanent xss, i didn&#8217;t even think about it :X</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Disenchant</title>
		<link>http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40/comment-page-1#comment-2575</link>
		<dc:creator>Disenchant</dc:creator>
		<pubDate>Mon, 12 Feb 2007 14:54:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40#comment-2575</guid>
		<description>I don&#039;t agree with &quot;you cannot totally deface a website with XSS&quot; because with Javascript, we can access the DOM tree and so we can modify all the elements on a website or to make it extremely simple, we can just use innerHTML for rewriting the whole site content and of course you can also do permanent XSSing and at least then really nasty things can going on, for example if you modify the text of a political site during general elections or stuff like this ;)
But of course I fully agree with you that most of the time as I already wrote in my last comment, you&#039;ll need a second site for doing serious attacks but from my point of view it&#039;s nonsense if we call one attack different every time after the way it&#039;s exploited.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t agree with &#8220;you cannot totally deface a website with XSS&#8221; because with Javascript, we can access the DOM tree and so we can modify all the elements on a website or to make it extremely simple, we can just use innerHTML for rewriting the whole site content and of course you can also do permanent XSSing and at least then really nasty things can going on, for example if you modify the text of a political site during general elections or stuff like this <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
But of course I fully agree with you that most of the time as I already wrote in my last comment, you&#8217;ll need a second site for doing serious attacks but from my point of view it&#8217;s nonsense if we call one attack different every time after the way it&#8217;s exploited.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nEUrOO</title>
		<link>http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40/comment-page-1#comment-2574</link>
		<dc:creator>nEUrOO</dc:creator>
		<pubDate>Mon, 12 Feb 2007 14:39:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40#comment-2574</guid>
		<description>Hum, you&#039;re right for the defacement with XSS, but I really used not to consider this as a &quot;real-important-whatever&quot; attack; I mean... Well, at least as far as I know, you cannot totally deface a website with XSS (i mean only XSS, not db storage etc. beside) but only modifying your local view of the page which may be able to see with a link (phishing).
That&#039;s why I consider that the important attacks at least need an other site to store scripts (worm), to send data (stealing information) etc.

Maybe I missed something for the defacement thus I am waiting for your answer ;)</description>
		<content:encoded><![CDATA[<p>Hum, you&#8217;re right for the defacement with XSS, but I really used not to consider this as a &#8220;real-important-whatever&#8221; attack; I mean&#8230; Well, at least as far as I know, you cannot totally deface a website with XSS (i mean only XSS, not db storage etc. beside) but only modifying your local view of the page which may be able to see with a link (phishing).<br />
That&#8217;s why I consider that the important attacks at least need an other site to store scripts (worm), to send data (stealing information) etc.</p>
<p>Maybe I missed something for the defacement thus I am waiting for your answer <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Disenchant</title>
		<link>http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40/comment-page-1#comment-2571</link>
		<dc:creator>Disenchant</dc:creator>
		<pubDate>Mon, 12 Feb 2007 14:17:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40#comment-2571</guid>
		<description>Hi nEUrOO,
why do you think that? For example a temporary XSS which you can exploit over a normal URL GET request, doesn&#039;t need another site for example to get cookies or something else. I think your point is, that after an attack like this you have to send the victim to another site or at least some of his data to have a complete attack and here you&#039;re right but then we still have attack scenarios like site defacements through XSS and here you don&#039;t have any other site which is involved. So I think normally an attacker will need at least one other site for doing a real attack most of the time but still &quot;cross site scripting&quot; is from my point of view not the term which matches exactly to what a XSS attack does but I&#039;m interested in your point of view :)</description>
		<content:encoded><![CDATA[<p>Hi nEUrOO,<br />
why do you think that? For example a temporary XSS which you can exploit over a normal URL GET request, doesn&#8217;t need another site for example to get cookies or something else. I think your point is, that after an attack like this you have to send the victim to another site or at least some of his data to have a complete attack and here you&#8217;re right but then we still have attack scenarios like site defacements through XSS and here you don&#8217;t have any other site which is involved. So I think normally an attacker will need at least one other site for doing a real attack most of the time but still &#8220;cross site scripting&#8221; is from my point of view not the term which matches exactly to what a XSS attack does but I&#8217;m interested in your point of view <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nEUrOO</title>
		<link>http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40/comment-page-1#comment-2569</link>
		<dc:creator>nEUrOO</dc:creator>
		<pubDate>Mon, 12 Feb 2007 13:18:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40#comment-2569</guid>
		<description>Btw, I think that if you think about the attack and not the vulnerabilities, you have to have the &quot;cross site&quot; :)</description>
		<content:encoded><![CDATA[<p>Btw, I think that if you think about the attack and not the vulnerabilities, you have to have the &#8220;cross site&#8221; <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Disenchant</title>
		<link>http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40/comment-page-1#comment-2528</link>
		<dc:creator>Disenchant</dc:creator>
		<pubDate>Sun, 11 Feb 2007 15:19:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40#comment-2528</guid>
		<description>I didn&#039;t see that before but it&#039;s funny that other people asked the question about the name too, thanks for it :)

PS: And of course Marc Slemko is right when he says &quot;Believe me, we have had more important things to do than think of a better name.&quot;</description>
		<content:encoded><![CDATA[<p>I didn&#8217;t see that before but it&#8217;s funny that other people asked the question about the name too, thanks for it <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>PS: And of course Marc Slemko is right when he says &#8220;Believe me, we have had more important things to do than think of a better name.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ory</title>
		<link>http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40/comment-page-1#comment-2527</link>
		<dc:creator>Ory</dc:creator>
		<pubDate>Sun, 11 Feb 2007 15:10:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/%e2%80%9ccross%e2%80%9d-just-like-in-xss/40#comment-2527</guid>
		<description>Hey,

The XSS naming issue was raised several times before :-) Take a look at the Wikipedia XSS page:
http://en.wikipedia.org/wiki/Cross_site_scripting

&quot;This issue isn&#039;t just about scripting, and there isn&#039;t necessarily anything cross-site about it. So why the name? It was coined earlier on when the problem was less understood, and it stuck. Believe me, we have had more important things to do than think of a better name.&quot; (XSS pioneer Marc Slemko)</description>
		<content:encoded><![CDATA[<p>Hey,</p>
<p>The XSS naming issue was raised several times before <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  Take a look at the Wikipedia XSS page:<br />
<a href="http://en.wikipedia.org/wiki/Cross_site_scripting" rel="nofollow">http://en.wikipedia.org/wiki/Cross_site_scripting</a></p>
<p>&#8220;This issue isn&#8217;t just about scripting, and there isn&#8217;t necessarily anything cross-site about it. So why the name? It was coined earlier on when the problem was less understood, and it stuck. Believe me, we have had more important things to do than think of a better name.&#8221; (XSS pioneer Marc Slemko)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
