<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress Cross Domain Redirect</title>
	<atom:link href="http://blogsecurity.net/news/news-110707-2/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/news/news-110707-2</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Abel Cheung</title>
		<link>http://blogsecurity.net/news/news-110707-2/comment-page-1#comment-287</link>
		<dc:creator>Abel Cheung</dc:creator>
		<pubDate>Wed, 18 Jul 2007 18:00:10 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=41#comment-287</guid>
		<description>Sadly fixing this kind of hole would also likely hinder other legitimate use. For example, &lt;a href=&quot;http://openid.net/&quot; rel=&quot;nofollow&quot;&gt;OpenID&lt;/a&gt; project depends largely on cross-domain redirection.</description>
		<content:encoded><![CDATA[<p>Sadly fixing this kind of hole would also likely hinder other legitimate use. For example, <a href="http://openid.net/" rel="nofollow">OpenID</a> project depends largely on cross-domain redirection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Кросс-доменная уязвимость в WordPress &#187; Russian Hosting Blog или хостинг по-русски</title>
		<link>http://blogsecurity.net/news/news-110707-2/comment-page-1#comment-285</link>
		<dc:creator>Кросс-доменная уязвимость в WordPress &#187; Russian Hosting Blog или хостинг по-русски</dc:creator>
		<pubDate>Fri, 13 Jul 2007 12:32:28 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=41#comment-285</guid>
		<description>[...] Оригинал (на англ.) Если Вам понравилась эта статья, подпишитесь на мой RSS-фид [...]</description>
		<content:encoded><![CDATA[<p>[...] Оригинал (на англ.) Если Вам понравилась эта статья, подпишитесь на мой RSS-фид [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://blogsecurity.net/news/news-110707-2/comment-page-1#comment-289</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Thu, 12 Jul 2007 13:30:16 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=41#comment-289</guid>
		<description>Thanks Dave!

Another example would be to redirect the victim to a website that exploits the latest vulnerabilities on IE/FF in order to install malware.

I personally think that cross-domain redirects can be very handy for attackers, especially when the domain that has the redirect feature belongs to a trusted brand name.</description>
		<content:encoded><![CDATA[<p>Thanks Dave!</p>
<p>Another example would be to redirect the victim to a website that exploits the latest vulnerabilities on IE/FF in order to install malware.</p>
<p>I personally think that cross-domain redirects can be very handy for attackers, especially when the domain that has the redirect feature belongs to a trusted brand name.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Del.icio.us bookmarks: Juli 11th &#124; Bloganbieter.de Blog</title>
		<link>http://blogsecurity.net/news/news-110707-2/comment-page-1#comment-288</link>
		<dc:creator>Del.icio.us bookmarks: Juli 11th &#124; Bloganbieter.de Blog</dc:creator>
		<pubDate>Thu, 12 Jul 2007 12:38:58 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=41#comment-288</guid>
		<description>[...] BlogSecurity » WordPress Cross Domain Redirect - [...]</description>
		<content:encoded><![CDATA[<p>[...] BlogSecurity » WordPress Cross Domain Redirect &#8211; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://blogsecurity.net/news/news-110707-2/comment-page-1#comment-286</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Thu, 12 Jul 2007 09:40:15 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=41#comment-286</guid>
		<description>Adrian, I think this is a nice proof of concept advisory for most redirect vulnerabilities, nicely done.</description>
		<content:encoded><![CDATA[<p>Adrian, I think this is a nice proof of concept advisory for most redirect vulnerabilities, nicely done.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
