<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Two SiteMinder Flaws and Painful Disclosure</title>
	<atom:link href="http://i8jesus.com/?feed=rss2&#038;p=55" rel="self" type="application/rss+xml" />
	<link>http://i8jesus.com/?p=55</link>
	<description>because arshan's too cheap to license OneNote</description>
	<lastBuildDate>Wed, 01 Sep 2010 06:10:02 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Amruta</title>
		<link>http://i8jesus.com/?p=55&#038;cpage=1#comment-35104</link>
		<dc:creator>Amruta</dc:creator>
		<pubDate>Wed, 01 Sep 2010 06:10:02 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=55#comment-35104</guid>
		<description>Hey Arshan,

First, the way you have explained is fantastic! Second and may be I am too late, but I was browsing for XSS vulnerabilities in Siteminder to snap back some foolish souls who say &quot;We have Siteminder and hence no XSS&quot;, when I came across your blog. Further search also shows that both NIST and NVD is making a note of your blog for these vulnerabilities: http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=35 and http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-2704. 
But ya, CA Sucks Big Time!</description>
		<content:encoded><![CDATA[<p>Hey Arshan,</p>
<p>First, the way you have explained is fantastic! Second and may be I am too late, but I was browsing for XSS vulnerabilities in Siteminder to snap back some foolish souls who say &#8220;We have Siteminder and hence no XSS&#8221;, when I came across your blog. Further search also shows that both NIST and NVD is making a note of your blog for these vulnerabilities: <a href="http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=35" rel="nofollow">http://www.sans.org/newsletters/risk/display.php?v=8&amp;i=35</a> and <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-2704" rel="nofollow">http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-2704</a>.<br />
But ya, CA Sucks Big Time!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Fedon</title>
		<link>http://i8jesus.com/?p=55&#038;cpage=1#comment-33061</link>
		<dc:creator>Giorgio Fedon</dc:creator>
		<pubDate>Tue, 29 Jun 2010 07:59:10 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=55#comment-33061</guid>
		<description>Hi Arshan,

we also discovered the following issue on Siteminder policy editor. As you can see CA does not plan to fix it...

http://blog.mindedsecurity.com/2010/06/ca-siteminder-oneview-monitor-remote.html</description>
		<content:encoded><![CDATA[<p>Hi Arshan,</p>
<p>we also discovered the following issue on Siteminder policy editor. As you can see CA does not plan to fix it&#8230;</p>
<p><a href="http://blog.mindedsecurity.com/2010/06/ca-siteminder-oneview-monitor-remote.html" rel="nofollow">http://blog.mindedsecurity.com/2010/06/ca-siteminder-oneview-monitor-remote.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Juan Carlos Calderon</title>
		<link>http://i8jesus.com/?p=55&#038;cpage=1#comment-21854</link>
		<dc:creator>Juan Carlos Calderon</dc:creator>
		<pubDate>Wed, 16 Sep 2009 18:10:10 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=55#comment-21854</guid>
		<description>I guess next time you could try CERT to handle the all hassle for you.</description>
		<content:encoded><![CDATA[<p>I guess next time you could try CERT to handle the all hassle for you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anton Chuvakin</title>
		<link>http://i8jesus.com/?p=55&#038;cpage=1#comment-16056</link>
		<dc:creator>Anton Chuvakin</dc:creator>
		<pubDate>Fri, 10 Jul 2009 19:03:24 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=55#comment-16056</guid>
		<description>It was in Info Security Magazine a few years ago; don&#039;t remember the year.</description>
		<content:encoded><![CDATA[<p>It was in Info Security Magazine a few years ago; don&#8217;t remember the year.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan dabirsiaghi</title>
		<link>http://i8jesus.com/?p=55&#038;cpage=1#comment-15914</link>
		<dc:creator>arshan dabirsiaghi</dc:creator>
		<pubDate>Thu, 09 Jul 2009 17:29:53 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=55#comment-15914</guid>
		<description>haha - who called them that? url plz!</description>
		<content:encoded><![CDATA[<p>haha &#8211; who called them that? url plz!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anton Chuvakin</title>
		<link>http://i8jesus.com/?p=55&#038;cpage=1#comment-15833</link>
		<dc:creator>Anton Chuvakin</dc:creator>
		<pubDate>Wed, 08 Jul 2009 16:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=55#comment-15833</guid>
		<description>Hmm.. how come you expected ANYTHING different? This is CA, the company that invented &quot;worst of breed&quot; in security.</description>
		<content:encoded><![CDATA[<p>Hmm.. how come you expected ANYTHING different? This is CA, the company that invented &#8220;worst of breed&#8221; in security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan dabirsiaghi</title>
		<link>http://i8jesus.com/?p=55&#038;cpage=1#comment-15236</link>
		<dc:creator>arshan dabirsiaghi</dc:creator>
		<pubDate>Sat, 04 Jul 2009 04:07:33 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=55#comment-15236</guid>
		<description>any collection of bytes will pass as long as they don&#039;t overlap with the bad characters in ascii values 0-128</description>
		<content:encoded><![CDATA[<p>any collection of bytes will pass as long as they don&#8217;t overlap with the bad characters in ascii values 0-128</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bbq ribs dud</title>
		<link>http://i8jesus.com/?p=55&#038;cpage=1#comment-14863</link>
		<dc:creator>bbq ribs dud</dc:creator>
		<pubDate>Tue, 30 Jun 2009 22:19:50 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=55#comment-14863</guid>
		<description>does your assertion include Hangul Syllables?</description>
		<content:encoded><![CDATA[<p>does your assertion include Hangul Syllables?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan dabirsiaghi</title>
		<link>http://i8jesus.com/?p=55&#038;cpage=1#comment-13618</link>
		<dc:creator>arshan dabirsiaghi</dc:creator>
		<pubDate>Sun, 14 Jun 2009 19:41:48 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=55#comment-13618</guid>
		<description>i have to say your comment was perfection</description>
		<content:encoded><![CDATA[<p>i have to say your comment was perfection</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Manico</title>
		<link>http://i8jesus.com/?p=55&#038;cpage=1#comment-13137</link>
		<dc:creator>Jim Manico</dc:creator>
		<pubDate>Tue, 09 Jun 2009 22:20:52 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=55#comment-13137</guid>
		<description>This is a brilliant piece of work and pursuit of the truth. I have no technical comment because the message above already achieved perfection.</description>
		<content:encoded><![CDATA[<p>This is a brilliant piece of work and pursuit of the truth. I have no technical comment because the message above already achieved perfection.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
