<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Forget sidejacking, clickjacking, and carjacking: enter &#8220;Formjacking&#8221;</title>
	<atom:link href="http://i8jesus.com/?feed=rss2&#038;p=48" rel="self" type="application/rss+xml" />
	<link>http://i8jesus.com/?p=48</link>
	<description>because arshan's too cheap to license OneNote</description>
	<lastBuildDate>Wed, 01 Sep 2010 06:10:02 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Some dude</title>
		<link>http://i8jesus.com/?p=48&#038;cpage=1#comment-32934</link>
		<dc:creator>Some dude</dc:creator>
		<pubDate>Fri, 25 Jun 2010 14:48:38 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=48#comment-32934</guid>
		<description>Bear in mind that HTML is not XML (unless of course it is XHTML). So expecting HTML to behave like XML will lead you astray. Your test pages are HTML.

In HTML there is no such thing as a self closing tag so it is behaving exactly as you would expect it to.

If you altered your test pages to be XHTML (appropriate doctype etc.) then they *might* behave differently.</description>
		<content:encoded><![CDATA[<p>Bear in mind that HTML is not XML (unless of course it is XHTML). So expecting HTML to behave like XML will lead you astray. Your test pages are HTML.</p>
<p>In HTML there is no such thing as a self closing tag so it is behaving exactly as you would expect it to.</p>
<p>If you altered your test pages to be XHTML (appropriate doctype etc.) then they *might* behave differently.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Serge Droganov</title>
		<link>http://i8jesus.com/?p=48&#038;cpage=1#comment-22387</link>
		<dc:creator>Serge Droganov</dc:creator>
		<pubDate>Fri, 25 Sep 2009 22:53:51 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=48#comment-22387</guid>
		<description>Hi.
Interesting fact...
This has nothing in common with script tag, it&#039;s insane to allow it with the policy.

And what about the forms this could be fixed with a policy file as well. AntiSamy could accept only local or global locations for example. And not both together.

And of course this is not a good idea to have so permissive policy with the public website. &#039;Only formatting tags policy&#039; is OK in most of the cases.

All controls should be defined as custom tags like in google blogs template editor: [show:loginform/] — self-contained and no attributes.</description>
		<content:encoded><![CDATA[<p>Hi.<br />
Interesting fact&#8230;<br />
This has nothing in common with script tag, it&#8217;s insane to allow it with the policy.</p>
<p>And what about the forms this could be fixed with a policy file as well. AntiSamy could accept only local or global locations for example. And not both together.</p>
<p>And of course this is not a good idea to have so permissive policy with the public website. &#8216;Only formatting tags policy&#8217; is OK in most of the cases.</p>
<p>All controls should be defined as custom tags like in google blogs template editor: [show:loginform/] — self-contained and no attributes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jerry</title>
		<link>http://i8jesus.com/?p=48&#038;cpage=1#comment-11715</link>
		<dc:creator>Jerry</dc:creator>
		<pubDate>Sun, 24 May 2009 20:21:33 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=48#comment-11715</guid>
		<description>Formjacking is just a joke name - the real name is unclosed-tag-jacking, which I think we can all agree is a great name.</description>
		<content:encoded><![CDATA[<p>Formjacking is just a joke name &#8211; the real name is unclosed-tag-jacking, which I think we can all agree is a great name.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric</title>
		<link>http://i8jesus.com/?p=48&#038;cpage=1#comment-11145</link>
		<dc:creator>Eric</dc:creator>
		<pubDate>Wed, 13 May 2009 21:35:49 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=48#comment-11145</guid>
		<description>That&#039;s pretty sweet. Works in Chrome as well, so the other WebKit browsers should do the same thing.</description>
		<content:encoded><![CDATA[<p>That&#8217;s pretty sweet. Works in Chrome as well, so the other WebKit browsers should do the same thing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Friese &#187; Formjacking</title>
		<link>http://i8jesus.com/?p=48&#038;cpage=1#comment-11144</link>
		<dc:creator>Eric Friese &#187; Formjacking</dc:creator>
		<pubDate>Wed, 13 May 2009 21:32:38 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=48#comment-11144</guid>
		<description>[...] read a cool post over at omg.wtf.bbq about a new attack called “formjacking”. Not sure about the attack name, but this is pretty [...]</description>
		<content:encoded><![CDATA[<p>[...] read a cool post over at omg.wtf.bbq about a new attack called “formjacking”. Not sure about the attack name, but this is pretty [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan dabirsiaghi</title>
		<link>http://i8jesus.com/?p=48&#038;cpage=1#comment-11079</link>
		<dc:creator>arshan dabirsiaghi</dc:creator>
		<pubDate>Tue, 12 May 2009 12:31:16 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=48#comment-11079</guid>
		<description>well we do need names for things, but yes the name was a joke. =)</description>
		<content:encoded><![CDATA[<p>well we do need names for things, but yes the name was a joke. =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Troll</title>
		<link>http://i8jesus.com/?p=48&#038;cpage=1#comment-10931</link>
		<dc:creator>Troll</dc:creator>
		<pubDate>Sat, 09 May 2009 09:41:06 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=48#comment-10931</guid>
		<description>Formjacking? Another term for a very silly attack!? Names for vulns suck!! we should all use &quot;xss&quot; for everything, from csrf to rfi!!!</description>
		<content:encoded><![CDATA[<p>Formjacking? Another term for a very silly attack!? Names for vulns suck!! we should all use &#8220;xss&#8221; for everything, from csrf to rfi!!!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
