<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title> RT @kellan: We're cranking up the security options on @Etsy, two-factor auth, SSL everywhere, and viewable login history http://tco/t5 </title><description>2012-10-10 01:19:24 - theharmonyguy :  RT @kellan: We're cranking up the security options on @Etsy, two-factor auth, SSL everywhere, and viewable login history http://tco/t5 </description><link>http://www.secuobs.com/twitter/news/349399.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/349399.shtml</guid></item>
<item><title> OK, I'm down to 26 tabs in my main Chrome window That's out of 7 open windows This is actually huge progress for me #modernstickynotes</title><description>Secuobs.com : 2012-10-09 04:45:02 - theharmonyguy -  OK, I'm down to 26 tabs in my main Chrome window That's out of 7 open windows This is actually huge progress for me #modernstickynotes</description><link>http://www.secuobs.com/twitter/news/349183.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/349183.shtml</guid></item>
<item><title> RT @ErrataRob: SHA1/SHA2/SHA512 are all based on MD4 Kᴇᴄᴄᴀᴋ is not, so any attack on SHA2 is unlikely to work on SHA3 Having both is good</title><description>Secuobs.com : 2012-10-03 09:04:11 -  theharmonyguy -  RT @ErrataRob: SHA1/SHA2/SHA512 are all based on MD4 Kᴇᴄᴄᴀᴋ is not, so any attack on SHA2 is unlikely to work on SHA3 Having both is good</description><link>http://www.secuobs.com/twitter/news/347817.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/347817.shtml</guid></item>
<item><title> @insertScript If a filter blacklists javascript:, data: URIs, perhaps blob: could still work</title><description>Secuobs.com : 2012-10-01 23:42:28 -  theharmonyguy -  @insertScript If a filter blacklists javascript:, data: URIs, perhaps blob: could still work</description><link>http://www.secuobs.com/twitter/news/347417.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/347417.shtml</guid></item>
<item><title> RT @superevr: RT @hasegawayosuke: Bypass IE's XSS Filter by @kinugawamasato  http://tco/r3vrusnd   nice</title><description>Secuobs.com : 2012-09-28 23:55:31 - theharmonyguy -  RT @superevr: RT @hasegawayosuke: Bypass IE's XSS Filter by @kinugawamasato  http://tco/r3vrusnd   nice</description><link>http://www.secuobs.com/twitter/news/346870.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/346870.shtml</guid></item>
<item><title> RT @scarybeasts: @0x6D6172696F @jeremiahg Ok, $1k of mine too : For max lulz / impact, challenge is: demo Chrome pwn that is _introed_  </title><description>Secuobs.com : 2012-09-20 20:14:26 - theharmonyguy -  RT @scarybeasts: @0x6D6172696F @jeremiahg Ok, $1k of mine too : For max lulz / impact, challenge is: demo Chrome pwn that is _introed_  </description><link>http://www.secuobs.com/twitter/news/345525.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/345525.shtml</guid></item>
<item><title> RT @RSnake: Finally got around to donating the XSS cheat sheet to @OWASP http://tco/EI1zI9AK Now everyone can edit/modify at will</title><description>Secuobs.com : 2012-09-18 22:24:39 - theharmonyguy -  RT @RSnake: Finally got around to donating the XSS cheat sheet to @OWASP http://tco/EI1zI9AK Now everyone can edit/modify at will</description><link>http://www.secuobs.com/twitter/news/344923.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/344923.shtml</guid></item>
<item><title> @aloria When someone asks me if they should uninstall Java: http://tco/PDOP5p6j #infosecreactions</title><description>Secuobs.com : 2012-09-10 11:32:39 - theharmonyguy -  @aloria When someone asks me if they should uninstall Java: http://tco/PDOP5p6j #infosecreactions</description><link>http://www.secuobs.com/twitter/news/342523.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/342523.shtml</guid></item>
<item><title> @aloria How I picture Shmoocon's server when registration starts: http://tco/z9BUfd1n #infosecreactions</title><description>Secuobs.com : 2012-09-10 11:32:39 - theharmonyguy -  @aloria How I picture Shmoocon's server when registration starts: http://tco/z9BUfd1n #infosecreactions</description><link>http://www.secuobs.com/twitter/news/342522.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/342522.shtml</guid></item>
<item><title> @theKos Shmoocon's February 15-17</title><description>Secuobs.com : 2012-09-09 11:51:40 - theharmonyguy -  @theKos Shmoocon's February 15-17</description><link>http://www.secuobs.com/twitter/news/342408.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/342408.shtml</guid></item>
<item><title> @jeremiahg @csoghoian For the record, he's also the Apache Software Foundation's director and an Apache HTTP Server co-founder…</title><description>Secuobs.com : 2012-09-08 18:08:48 - theharmonyguy -  @jeremiahg @csoghoian For the record, he's also the Apache Software Foundation's director and an Apache HTTP Server co-founder…</description><link>http://www.secuobs.com/twitter/news/342297.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/342297.shtml</guid></item>
<item><title> All of this suggests that the actual story of razors-and-blades is more complicated  more interesting PDF http://tco/MeDy9rqe via @jen_h</title><description>Secuobs.com : 2012-09-07 21:22:52 - theharmonyguy -  All of this suggests that the actual story of razors-and-blades is more complicated  more interesting PDF http://tco/MeDy9rqe via @jen_h</description><link>http://www.secuobs.com/twitter/news/342057.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/342057.shtml</guid></item>
<item><title> RT @DennisF: New Attack Uses SSL/TLS Information Leak to Hijack HTTPS Sessions Research from @julianor  http://tco/TvxhztyR</title><description>Secuobs.com : 2012-09-06 21:52:16 - theharmonyguy -  RT @DennisF: New Attack Uses SSL/TLS Information Leak to Hijack HTTPS Sessions Research from @julianor  http://tco/TvxhztyR</description><link>http://www.secuobs.com/twitter/news/341593.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/341593.shtml</guid></item>
<item><title> Just caught up on Amazon's announcements from today; pretty impressive But they'd better be working on at least an Apple TV competitor too</title><description>Secuobs.com : 2012-09-06 21:52:16 - theharmonyguy -  Just caught up on Amazon's announcements from today; pretty impressive But they'd better be working on at least an Apple TV competitor too</description><link>http://www.secuobs.com/twitter/news/341592.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/341592.shtml</guid></item>
<item><title> Apple and Amazon are both offering competing ecosystems Right now, Apple's integrates in more places due to Apple TV, iPhone, etc</title><description>Secuobs.com : 2012-09-06 21:52:16 - theharmonyguy -  Apple and Amazon are both offering competing ecosystems Right now, Apple's integrates in more places due to Apple TV, iPhone, etc</description><link>http://www.secuobs.com/twitter/news/341591.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/341591.shtml</guid></item>
<item><title> @randomdross Time to start watching for Natural keyboards during 0-day demos ;</title><description>Secuobs.com : 2012-08-20 12:36:50 - theharmonyguy -  @randomdross Time to start watching for Natural keyboards during 0-day demos ;</description><link>http://www.secuobs.com/twitter/news/340491.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/340491.shtml</guid></item>
<item><title> @random_walker I loved how it started with 0-day in your brain, then you read they had 10-40 pourcents chance of success Still, interesting work</title><description>Secuobs.com : 2012-08-20 12:36:50 -  theharmonyguy -  @random_walker I loved how it started with 0-day in your brain, then you read they had 10-40 pourcents chance of success Still, interesting work</description><link>http://www.secuobs.com/twitter/news/340490.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/340490.shtml</guid></item>
<item><title> If you come across any Facebook phishing sites, you can now report them via phish at http://tco/iUOxw9Lb: https://tco/jh1pko8F</title><description>Secuobs.com : 2012-08-10 12:11:29 - theharmonyguy -  If you come across any Facebook phishing sites, you can now report them via phish at http://tco/iUOxw9Lb: https://tco/jh1pko8F</description><link>http://www.secuobs.com/twitter/news/339411.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/339411.shtml</guid></item>
<item><title> RT @justinschuh: After two and a half years of work, we finally have Flash in the full Chrome sandbox on all versions of Windows: http:/ </title><description>Secuobs.com : 2012-08-09 11:28:33 - theharmonyguy -  RT @justinschuh: After two and a half years of work, we finally have Flash in the full Chrome sandbox on all versions of Windows: http:/ </description><link>http://www.secuobs.com/twitter/news/339183.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/339183.shtml</guid></item>
<item><title> @angelofsecurity If you scroll down to April 2011 here, you'll find slides to an XSS presentation I once did: https://tco/7EDnlPWm</title><description>Secuobs.com : 2012-08-08 11:09:11 - theharmonyguy -  @angelofsecurity If you scroll down to April 2011 here, you'll find slides to an XSS presentation I once did: https://tco/7EDnlPWm</description><link>http://www.secuobs.com/twitter/news/338972.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/338972.shtml</guid></item>
<item><title> @securityninja @jeremiahg But wasn't clear why it came up now And I said we'd talk about white-hat listing after I got back from Defcon</title><description>Secuobs.com : 2012-07-31 06:05:57 - theharmonyguy -  @securityninja @jeremiahg But wasn't clear why it came up now And I said we'd talk about white-hat listing after I got back from Defcon</description><link>http://www.secuobs.com/twitter/news/337084.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/337084.shtml</guid></item>
<item><title> Yay, I'm actually #1 in a @garethheyes XSS challenge http://tco/HYs1ynsC But probably won't last Going to try and get some sleep now :</title><description>Secuobs.com : 2012-07-27 03:04:44 - theharmonyguy -  Yay, I'm actually #1 in a @garethheyes XSS challenge http://tco/HYs1ynsC But probably won't last Going to try and get some sleep now :</description><link>http://www.secuobs.com/twitter/news/336221.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/336221.shtml</guid></item>
<item><title> RT @garethheyes: Did a write up on the #xss #challenge2 http://tco/nCpf5IN1 xss multi context injection contest well done @insertScript</title><description>Secuobs.com : 2012-07-27 03:04:44 - theharmonyguy -  RT @garethheyes: Did a write up on the #xss #challenge2 http://tco/nCpf5IN1 xss multi context injection contest well done @insertScript</description><link>http://www.secuobs.com/twitter/news/336220.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/336220.shtml</guid></item>
<item><title> Landed in Vegas Defcon, here I come</title><description>Secuobs.com : 2012-07-27 03:04:44 - theharmonyguy -  Landed in Vegas Defcon, here I come</description><link>http://www.secuobs.com/twitter/news/336219.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/336219.shtml</guid></item>
<item><title> RT @ashk4n: You don't always need a face to identify someone in a photo/video: FBI To Add Tattoos To Biometric ID Capabilities http://t </title><description>Secuobs.com : 2012-07-21 11:57:47 - theharmonyguy -  RT @ashk4n: You don't always need a face to identify someone in a photo/video: FBI To Add Tattoos To Biometric ID Capabilities http://t </description><link>http://www.secuobs.com/twitter/news/335210.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/335210.shtml</guid></item>
<item><title> YES RT @verge: Apple adds 20th Century Fox movies to iTunes in the Cloud, all major studios now on board http://tco/KiiP8Ld2</title><description>Secuobs.com : 2012-07-21 11:57:47 - theharmonyguy -  YES RT @verge: Apple adds 20th Century Fox movies to iTunes in the Cloud, all major studios now on board http://tco/KiiP8Ld2</description><link>http://www.secuobs.com/twitter/news/335209.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/335209.shtml</guid></item>
<item><title> @scalzi There's a Call Me Maybe spoof in there somewhere…</title><description>Secuobs.com : 2012-07-21 11:57:47 - theharmonyguy -  @scalzi There's a Call Me Maybe spoof in there somewhere…</description><link>http://www.secuobs.com/twitter/news/335208.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/335208.shtml</guid></item>
<item><title> RT @krvw: First draft of my OWASP Cheat Sheet for iOS App Developers is available at https://tco/PuzyJIOA Enjoy</title><description>Secuobs.com : 2012-07-19 06:02:51 - theharmonyguy -  RT @krvw: First draft of my OWASP Cheat Sheet for iOS App Developers is available at https://tco/PuzyJIOA Enjoy</description><link>http://www.secuobs.com/twitter/news/334523.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/334523.shtml</guid></item>
<item><title> RT @flyosity: Apple backtracks on EPEAT standards, Bob Mansfield pens an apology and explanation http://tco/kb3IEist</title><description>Secuobs.com : 2012-07-16 04:21:40 - theharmonyguy -  RT @flyosity: Apple backtracks on EPEAT standards, Bob Mansfield pens an apology and explanation http://tco/kb3IEist</description><link>http://www.secuobs.com/twitter/news/333428.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/333428.shtml</guid></item>
<item><title> RT @dakami: “@starien: @mikko q: How is JavaScript different from Java a: …how is hamster different from ham”  A hamster can run</title><description>Secuobs.com : 2012-07-13 18:51:37 - theharmonyguy -  RT @dakami: “@starien: @mikko q: How is JavaScript different from Java a: …how is hamster different from ham”  A hamster can run</description><link>http://www.secuobs.com/twitter/news/333082.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/333082.shtml</guid></item>
<item><title> btw, don't think I'd mentioned this yet: I'll be at Defcon this year</title><description>Secuobs.com : 2012-07-07 17:41:40 - theharmonyguy -  btw, don't think I'd mentioned this yet: I'll be at Defcon this year</description><link>http://www.secuobs.com/twitter/news/332309.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/332309.shtml</guid></item>
<item><title> RT @matt_presson: RT @LightOS @_websec: We are proud to present The SQL Injection KB http://tco/02JOhIKH by @LightOS #SQLi #Cheatsheet  </title><description>Secuobs.com : 2012-07-07 17:41:40 - theharmonyguy -  RT @matt_presson: RT @LightOS @_websec: We are proud to present The SQL Injection KB http://tco/02JOhIKH by @LightOS #SQLi #Cheatsheet  </description><link>http://www.secuobs.com/twitter/news/332308.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/332308.shtml</guid></item>
<item><title> RT @garethheyes: RT @0x6D6172696F: A new DOM protection lib in the vein of XSSMe  and XSSMe² has gone prototype-level today Working in  </title><description>Secuobs.com : 2012-07-07 17:41:40 - theharmonyguy -  RT @garethheyes: RT @0x6D6172696F: A new DOM protection lib in the vein of XSSMe  and XSSMe² has gone prototype-level today Working in  </description><link>http://www.secuobs.com/twitter/news/332307.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/332307.shtml</guid></item>
<item><title> @malliegator Given how people use the term social engineering, that may not be the best description to use for that article… :</title><description>Secuobs.com : 2012-07-07 17:41:40 - theharmonyguy -  @malliegator Given how people use the term social engineering, that may not be the best description to use for that article… :</description><link>http://www.secuobs.com/twitter/news/332306.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/332306.shtml</guid></item>
<item><title> @random_walker Per-track/album download - iTunes Stores, AmazonMP3, Bandcamp, etc</title><description>Secuobs.com : 2012-06-30 02:31:34 - theharmonyguy -  @random_walker Per-track/album download - iTunes Stores, AmazonMP3, Bandcamp, etc</description><link>http://www.secuobs.com/twitter/news/331116.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/331116.shtml</guid></item>
<item><title> RT @johnwilander: XSS advisory from 2000: Malicious HTML Tags Embedded in Client Web Requests Systems affected: Web browsers  se </title><description>Secuobs.com : 2012-06-25 07:43:16 - theharmonyguy -  RT @johnwilander: XSS advisory from 2000: Malicious HTML Tags Embedded in Client Web Requests Systems affected: Web browsers  se </description><link>http://www.secuobs.com/twitter/news/330021.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/330021.shtml</guid></item>
<item><title> Really interesting tricks here: Bypassing ASLR and DEP on Adobe Reader X http://tco/mRfffhuA</title><description>Secuobs.com : 2012-06-25 07:43:16 - theharmonyguy -  Really interesting tricks here: Bypassing ASLR and DEP on Adobe Reader X http://tco/mRfffhuA</description><link>http://www.secuobs.com/twitter/news/330020.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/330020.shtml</guid></item>
<item><title> So @0x6D6172696F has another XSS challenge up And it's driving me crazy http://tco/u7IKq61I #tryingtoavoidid</title><description>Secuobs.com : 2012-06-25 07:43:16 - theharmonyguy -  So @0x6D6172696F has another XSS challenge up And it's driving me crazy http://tco/u7IKq61I #tryingtoavoidid</description><link>http://www.secuobs.com/twitter/news/330019.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/330019.shtml</guid></item>
<item><title> RT @jeremiahg: DOM XSS found on Etsy Between the time the researchers finds it  has a chance to disclose, it gets fixed http://t </title><description>Secuobs.com : 2012-06-22 08:05:23 - theharmonyguy -  RT @jeremiahg: DOM XSS found on Etsy Between the time the researchers finds it  has a chance to disclose, it gets fixed http://t </description><link>http://www.secuobs.com/twitter/news/329257.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/329257.shtml</guid></item>
<item><title> RT @securityninja: RT @CNNMoneyTech: Not a hack or DDoS attack @twittercomms: Today's outage is due to a cascaded bug in one of our infr </title><description>Secuobs.com : 2012-06-22 08:05:23 - theharmonyguy -  RT @securityninja: RT @CNNMoneyTech: Not a hack or DDoS attack @twittercomms: Today's outage is due to a cascaded bug in one of our infr </description><link>http://www.secuobs.com/twitter/news/329256.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/329256.shtml</guid></item>
<item><title> RT @ericlaw: How'd IE10's JavaScript engine get so much faster Lots of work http://tco/OQtCNWev</title><description>Secuobs.com : 2012-06-15 07:34:33 - theharmonyguy -  RT @ericlaw: How'd IE10's JavaScript engine get so much faster Lots of work http://tco/OQtCNWev</description><link>http://www.secuobs.com/twitter/news/327614.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/327614.shtml</guid></item>
<item><title> @scarybeasts Can I just note to someone on Chrome team that I find shifting Recently Closed to put Web Store in the corner annoying :</title><description>Secuobs.com : 2012-06-12 13:03:04 - theharmonyguy -  @scarybeasts Can I just note to someone on Chrome team that I find shifting Recently Closed to put Web Store in the corner annoying :</description><link>http://www.secuobs.com/twitter/news/326885.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/326885.shtml</guid></item>
<item><title> RT @trailofbits: We have published our initial analysis of Flame's MD5 collision capabilities http://tco/rsvSp6ud</title><description>Secuobs.com : 2012-06-12 13:03:04 - theharmonyguy -  RT @trailofbits: We have published our initial analysis of Flame's MD5 collision capabilities http://tco/rsvSp6ud</description><link>http://www.secuobs.com/twitter/news/326884.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/326884.shtml</guid></item>
<item><title> RT @totally_unknown: 3x XSS in Google Gmail are fixed and here's the summary http://tco/LOLrUV11</title><description>Secuobs.com : 2012-06-12 13:03:04 - theharmonyguy -  RT @totally_unknown: 3x XSS in Google Gmail are fixed and here's the summary http://tco/LOLrUV11</description><link>http://www.secuobs.com/twitter/news/326883.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/326883.shtml</guid></item>
<item><title> Wait, the top story on Techmeme is that MD5 is no longer considered safe</title><description>Secuobs.com : 2012-06-09 01:42:11 - theharmonyguy -  Wait, the top story on Techmeme is that MD5 is no longer considered safe</description><link>http://www.secuobs.com/twitter/news/326214.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/326214.shtml</guid></item>
<item><title> RT @cjoh: Want to play a fun prank on the Internet Release a billion line file w/random md5 hashes Claim it's facebook passwords Wr </title><description>Secuobs.com : 2012-06-09 01:42:11 - theharmonyguy -  RT @cjoh: Want to play a fun prank on the Internet Release a billion line file w/random md5 hashes Claim it's facebook passwords Wr </description><link>http://www.secuobs.com/twitter/news/326213.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/326213.shtml</guid></item>
<item><title> RT @arbornetworks: Facebook now notifying DNSChanger victims via their pages Hooray   https://tco/FuegJ0jj</title><description>Secuobs.com : 2012-06-06 06:46:39 - theharmonyguy -  RT @arbornetworks: Facebook now notifying DNSChanger victims via their pages Hooray   https://tco/FuegJ0jj</description><link>http://www.secuobs.com/twitter/news/325529.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/325529.shtml</guid></item>
<item><title> If you're interested in stopping XSS, you should read this RT @garethheyes Finally a comprehensive write up on #JSLR http://tco/whRRIzrJ</title><description>Secuobs.com : 2012-06-06 06:46:39 - theharmonyguy -  If you're interested in stopping XSS, you should read this RT @garethheyes Finally a comprehensive write up on #JSLR http://tco/whRRIzrJ</description><link>http://www.secuobs.com/twitter/news/325528.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/325528.shtml</guid></item>
<item><title> RT @jeremiahg: CloudFlare hacked, they share details http://tco/AQPlB0Ji -- UGNazi disagree w/ scale of scope of their analysis http:// </title><description>Secuobs.com : 2012-06-04 03:37:04 - theharmonyguy -  RT @jeremiahg: CloudFlare hacked, they share details http://tco/AQPlB0Ji -- UGNazi disagree w/ scale of scope of their analysis http:// </description><link>http://www.secuobs.com/twitter/news/325254.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/325254.shtml</guid></item>
<item><title> RT @cschweitz: This is AWESOME: Engineering Students Design Non-Stick Ketchup Bottle http://tco/kew3FHFf Could save $15M in wasted </title><description>Secuobs.com : 2012-06-04 03:37:04 -  theharmonyguy -  RT @cschweitz: This is AWESOME: Engineering Students Design Non-Stick Ketchup Bottle http://tco/kew3FHFf Could save $15M in wasted </description><link>http://www.secuobs.com/twitter/news/325253.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/325253.shtml</guid></item>
<item><title> RT @kkotowicz: Gratz to Dr Mario Heiderich @0x6D6172696F Towards Elimination of XSS Attacksw/ a Trusted  Capability Ctrl-edDOM </title><description>Secuobs.com : 2012-06-01 05:36:20 - theharmonyguy -  RT @kkotowicz: Gratz to Dr Mario Heiderich @0x6D6172696F Towards Elimination of XSS Attacksw/ a Trusted  Capability Ctrl-edDOM </description><link>http://www.secuobs.com/twitter/news/324727.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/324727.shtml</guid></item>
<item><title> RT @dinodaizovi: Apple has released their whitepaper on iOS security for businesses and enterprises: http://tco/JedvdiQt</title><description>Secuobs.com : 2012-06-01 05:36:20 - theharmonyguy -  RT @dinodaizovi: Apple has released their whitepaper on iOS security for businesses and enterprises: http://tco/JedvdiQt</description><link>http://www.secuobs.com/twitter/news/324726.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/324726.shtml</guid></item>
<item><title> RT @securityninja: RT @curphey: SQL Injection Vulnerability in Ruby on Rails CVE-2012-2661 http://tco/2On4E6nk  boom</title><description>Secuobs.com : 2012-06-01 05:36:20 -  theharmonyguy -  RT @securityninja: RT @curphey: SQL Injection Vulnerability in Ruby on Rails CVE-2012-2661 http://tco/2On4E6nk  boom</description><link>http://www.secuobs.com/twitter/news/324725.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/324725.shtml</guid></item>
<item><title> Finally saw The Avengers Nerd check: Anyone else notice a Sun Oracle logo  think Surely Java's reactor clause bars dark energy tests :</title><description>Secuobs.com : 2012-05-30 07:51:43 - theharmonyguy -  Finally saw The Avengers Nerd check: Anyone else notice a Sun Oracle logo  think Surely Java's reactor clause bars dark energy tests :</description><link>http://www.secuobs.com/twitter/news/324234.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/324234.shtml</guid></item>
<item><title> RT @blowdart: If you can write #metro apps in html5 and javascript and now there's clippy for #jquery  METRO APPS WITH CLIPPY http: </title><description>Secuobs.com : 2012-05-30 07:51:43 - theharmonyguy -  RT @blowdart: If you can write #metro apps in html5 and javascript and now there's clippy for #jquery  METRO APPS WITH CLIPPY http: </description><link>http://www.secuobs.com/twitter/news/324233.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/324233.shtml</guid></item>
<item><title> New fingerprinting technique: render WebGL + fonts with HTML5 canvas, then check output pixels PDF: http://tco/6zb7iYxU</title><description>Secuobs.com : 2012-05-30 07:51:43 - theharmonyguy -  New fingerprinting technique: render WebGL + fonts with HTML5 canvas, then check output pixels PDF: http://tco/6zb7iYxU</description><link>http://www.secuobs.com/twitter/news/324232.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/324232.shtml</guid></item>
<item><title> OK I'm worried now : RT @kkotowicz cool new ideas popping up after meeting @theKos Chrome users, take care in the future :</title><description>Secuobs.com : 2012-05-21 17:11:33 - theharmonyguy -  OK I'm worried now : RT @kkotowicz cool new ideas popping up after meeting @theKos Chrome users, take care in the future :</description><link>http://www.secuobs.com/twitter/news/322002.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/322002.shtml</guid></item>
<item><title> @vogon Perhaps - I'm using Chrome with a Flash-blocking extension; sidebar wouldn't load until I turned it off or added an exception</title><description>Secuobs.com : 2012-05-17 05:19:44 - theharmonyguy -  @vogon Perhaps - I'm using Chrome with a Flash-blocking extension; sidebar wouldn't load until I turned it off or added an exception</description><link>http://www.secuobs.com/twitter/news/321120.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/321120.shtml</guid></item>
<item><title> RT @aplusbi: I'm refractoring my cloud-based heroku django social media geo-located app to HTML9 http://tco/fw0n7ict</title><description>Secuobs.com : 2012-05-10 07:41:05 - theharmonyguy -  RT @aplusbi: I'm refractoring my cloud-based heroku django social media geo-located app to HTML9 http://tco/fw0n7ict</description><link>http://www.secuobs.com/twitter/news/319353.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/319353.shtml</guid></item>
<item><title> @micahcrenwelge You'll want to disable Java and any other unnecessary plug-ins, then keep all other plug-ins and software up-to-date</title><description>Secuobs.com : 2012-05-02 09:04:04 - theharmonyguy -  @micahcrenwelge You'll want to disable Java and any other unnecessary plug-ins, then keep all other plug-ins and software up-to-date</description><link>http://www.secuobs.com/twitter/news/317253.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/317253.shtml</guid></item>
<item><title> RT @flyosity: Random colors generated by measuring the real-time quantum fluctuations of a vacuum in a lab in Australia http://tco/Qjc </title><description>Secuobs.com : 2012-04-20 05:56:43 - theharmonyguy -  RT @flyosity: Random colors generated by measuring the real-time quantum fluctuations of a vacuum in a lab in Australia http://tco/Qjc </description><link>http://www.secuobs.com/twitter/news/314054.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/314054.shtml</guid></item>
<item><title> RT @superevr: Exploiting XSS in Ajax Web Applications https://tco/V8K9maJT</title><description>Secuobs.com : 2012-04-13 04:53:45 -  theharmonyguy -  RT @superevr: Exploiting XSS in Ajax Web Applications https://tco/V8K9maJT</description><link>http://www.secuobs.com/twitter/news/312073.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/312073.shtml</guid></item>
<item><title> Cleaning old files; found a Dec 2010 txt with what looked like XSS vectors for popular site and they still work Guess I need to report</title><description>Secuobs.com : 2012-04-11 06:18:10 -  theharmonyguy -  Cleaning old files; found a Dec 2010 txt with what looked like XSS vectors for popular site and they still work Guess I need to report</description><link>http://www.secuobs.com/twitter/news/311237.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/311237.shtml</guid></item>
<item><title> A positive take on selling zero-day exploits eg VUPEN: https://tco/oORDj2Qt via @shawnmoyer</title><description>Secuobs.com : 2012-04-07 00:15:03 - theharmonyguy -  A positive take on selling zero-day exploits eg VUPEN: https://tco/oORDj2Qt via @shawnmoyer</description><link>http://www.secuobs.com/twitter/news/310132.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/310132.shtml</guid></item>
<item><title> In case you missed it Facebook runs on a single 15GB executable updated via BitTorrent  other engineering tales: http://tco/IfTRVF4k</title><description>Secuobs.com : 2012-04-07 00:15:03 - theharmonyguy -  In case you missed it Facebook runs on a single 15GB executable updated via BitTorrent  other engineering tales: http://tco/IfTRVF4k</description><link>http://www.secuobs.com/twitter/news/310131.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/310131.shtml</guid></item>
<item><title> RT @ashk4n: requisite spoof version of Google Glass project: ADmented reality http://tco/RTthWZHX via @joebeone #there_i_fixed_it</title><description>Secuobs.com : 2012-04-06 13:20:29 - theharmonyguy -  RT @ashk4n: requisite spoof version of Google Glass project: ADmented reality http://tco/RTthWZHX via @joebeone #there_i_fixed_it</description><link>http://www.secuobs.com/twitter/news/309939.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/309939.shtml</guid></item>
<item><title> RT @shanselman: HTTPS  SSL doesn't mean trust this It means this is private You may be having a private conversation with Satan</title><description>Secuobs.com : 2012-04-05 15:58:59 - theharmonyguy -  RT @shanselman: HTTPS  SSL doesn't mean trust this It means this is private You may be having a private conversation with Satan</description><link>http://www.secuobs.com/twitter/news/309648.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/309648.shtml</guid></item>
<item><title> RT @kkotowicz: Chrome addons hacking: Bye Bye AdBlock filters http://tco/sG3ZNTyV</title><description>Secuobs.com : 2012-03-28 11:52:05 - theharmonyguy -  RT @kkotowicz: Chrome addons hacking: Bye Bye AdBlock filters http://tco/sG3ZNTyV</description><link>http://www.secuobs.com/twitter/news/307281.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/307281.shtml</guid></item>
<item><title> So reportedly PayPal had XSS in their search box: http://tco/CUHopqMl via @securityshell</title><description>Secuobs.com : 2012-03-22 20:09:17 -  theharmonyguy -  So reportedly PayPal had XSS in their search box: http://tco/CUHopqMl via @securityshell</description><link>http://www.secuobs.com/twitter/news/305775.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/305775.shtml</guid></item>
<item><title> Pinterest search of best buy gift cards seems to confirm RT @jeremiahg Reports of an XSS attack targeting Pinterest http://tco/yItqOGiZ</title><description>Secuobs.com : 2012-03-20 02:07:38 - theharmonyguy -  Pinterest search of best buy gift cards seems to confirm RT @jeremiahg Reports of an XSS attack targeting Pinterest http://tco/yItqOGiZ</description><link>http://www.secuobs.com/twitter/news/304894.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/304894.shtml</guid></item>
<item><title> Pinterest appears to have already deleted the pin with XSS payload and the user account that posted it Attack could have done much more</title><description>Secuobs.com : 2012-03-20 02:07:38 - theharmonyguy -  Pinterest appears to have already deleted the pin with XSS payload and the user account that posted it Attack could have done much more</description><link>http://www.secuobs.com/twitter/news/304893.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/304893.shtml</guid></item>
<item><title> @biosshadow @jeremiahg If the post were still accessible, the payload actually removes links for reporting or removing</title><description>Secuobs.com : 2012-03-20 02:07:38 - theharmonyguy -  @biosshadow @jeremiahg If the post were still accessible, the payload actually removes links for reporting or removing</description><link>http://www.secuobs.com/twitter/news/304892.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/304892.shtml</guid></item>
<item><title> @garethheyes So you're saying an injected payload could potentially control the location object and use that to persist</title><description>Secuobs.com : 2012-03-16 11:58:14 - theharmonyguy -  @garethheyes So you're saying an injected payload could potentially control the location object and use that to persist</description><link>http://www.secuobs.com/twitter/news/303990.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/303990.shtml</guid></item>
<item><title> RT @p01: JS1K Speech Synthesis - http://tco/c9Jg8FpA - Speaks as you type and whole sentences in 1K of JavaScript #spoiler #formant #sy </title><description>Secuobs.com : 2012-03-15 19:41:31 -  theharmonyguy -  RT @p01: JS1K Speech Synthesis - http://tco/c9Jg8FpA - Speaks as you type and whole sentences in 1K of JavaScript #spoiler #formant #sy </description><link>http://www.secuobs.com/twitter/news/303834.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/303834.shtml</guid></item>
<item><title> RT @securityshell: Sergey Glazunov  -Full Chrome Pwn win $60,000 https://tco/ezt0SIi8</title><description>Secuobs.com : 2012-03-08 03:47:03 - theharmonyguy -  RT @securityshell: Sergey Glazunov  -Full Chrome Pwn win $60,000 https://tco/ezt0SIi8</description><link>http://www.secuobs.com/twitter/news/301085.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/301085.shtml</guid></item>
<item><title> RT @theKos: This is a great SQL Injection resource http://tco/Qn9pOSvC</title><description>Secuobs.com : 2012-03-01 00:25:53 - theharmonyguy -  RT @theKos: This is a great SQL Injection resource http://tco/Qn9pOSvC</description><link>http://www.secuobs.com/twitter/news/298896.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/298896.shtml</guid></item>
<item><title> @securityshell lol, haven't been checking for XSS, just using it for searches</title><description>Secuobs.com : 2012-02-28 22:13:14 -  theharmonyguy -  @securityshell lol, haven't been checking for XSS, just using it for searches</description><link>http://www.secuobs.com/twitter/news/298392.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/298392.shtml</guid></item>
<item><title> RT @PascalVanHecke: http://tco/g98KYwLm encrypts yr files BEFORE you trust them to a cloud service Dropbox/SkyDrive/BoxDotNet/GoogleDr </title><description>Secuobs.com : 2012-02-24 05:57:47 - theharmonyguy -  RT @PascalVanHecke: http://tco/g98KYwLm encrypts yr files BEFORE you trust them to a cloud service Dropbox/SkyDrive/BoxDotNet/GoogleDr </description><link>http://www.secuobs.com/twitter/news/297077.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/297077.shtml</guid></item>
<item><title> Plug-in security more than just Flash/Java: RT @kkotowicz Chrome addons hacking: want XSS on http://tco/wmp3ZiRp http://tco/mqjb0nMh</title><description>Secuobs.com : 2012-02-22 06:12:37 - theharmonyguy -  Plug-in security more than just Flash/Java: RT @kkotowicz Chrome addons hacking: want XSS on http://tco/wmp3ZiRp http://tco/mqjb0nMh</description><link>http://www.secuobs.com/twitter/news/296209.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/296209.shtml</guid></item>
<item><title> @dakami XSS in the City, with sequel XSS in the City: alert2 #nerdflix</title><description>Secuobs.com : 2012-02-19 20:48:38 - theharmonyguy -  @dakami XSS in the City, with sequel XSS in the City: alert2 #nerdflix</description><link>http://www.secuobs.com/twitter/news/295697.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/295697.shtml</guid></item>
<item><title> RT @jeremiahg: If you're into Advanced Oracle SQL Injection, this post is required reading: http://tco/vVHi8PFf @WhiteHatSec TRC  </title><description>Secuobs.com : 2012-02-18 10:26:01 - theharmonyguy -  RT @jeremiahg: If you're into Advanced Oracle SQL Injection, this post is required reading: http://tco/vVHi8PFf @WhiteHatSec TRC  </description><link>http://www.secuobs.com/twitter/news/295465.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/295465.shtml</guid></item>
<item><title> @jeremiahg Nice I could have used that on an app last year : Reminds me of another fun blind SQLi where I got pw hashes 1 char at a time</title><description>Secuobs.com : 2012-02-18 10:26:01 - theharmonyguy -  @jeremiahg Nice I could have used that on an app last year : Reminds me of another fun blind SQLi where I got pw hashes 1 char at a time</description><link>http://www.secuobs.com/twitter/news/295464.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/295464.shtml</guid></item>
<item><title> RT @kkotowicz: Intro to Chrome addons hacking: fingerprinting I know what addons you use http://tco/lO0Wj4JP</title><description>Secuobs.com : 2012-02-17 20:50:31 - theharmonyguy -  RT @kkotowicz: Intro to Chrome addons hacking: fingerprinting I know what addons you use http://tco/lO0Wj4JP</description><link>http://www.secuobs.com/twitter/news/295233.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/295233.shtml</guid></item>
<item><title> RT @joedevon: WOW That OWASP cheatsheet list I just RT'ed is the motherlode They even have a REST security cheatsheet BOOKMARKED http </title><description>Secuobs.com : 2012-02-16 21:27:38 - theharmonyguy -  RT @joedevon: WOW That OWASP cheatsheet list I just RT'ed is the motherlode They even have a REST security cheatsheet BOOKMARKED http </description><link>http://www.secuobs.com/twitter/news/294802.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/294802.shtml</guid></item>
<item><title> RT @jeremiahg:  Adobe patches Flash amidst report of a universal xss “is being exploited in the wild in active targeted attacks” http </title><description>Secuobs.com : 2012-02-16 06:36:01 - theharmonyguy -  RT @jeremiahg:  Adobe patches Flash amidst report of a universal xss “is being exploited in the wild in active targeted attacks” http </description><link>http://www.secuobs.com/twitter/news/294582.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/294582.shtml</guid></item>
<item><title> RT @sdw: I was convinced  product shots were 3D, but apparently some are photos with insane focus stacking: http://tco/QhEgjzU1 /via @ </title><description>Secuobs.com : 2012-02-16 01:05:01 - theharmonyguy -  RT @sdw: I was convinced  product shots were 3D, but apparently some are photos with insane focus stacking: http://tco/QhEgjzU1 /via @ </description><link>http://www.secuobs.com/twitter/news/294451.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/294451.shtml</guid></item>
<item><title> @vogon Chrome It's by GeoIP, I assume - it's not using the geolocation feature with the UI prompt Just auto-filling Washington DC</title><description>Secuobs.com : 2012-02-15 19:20:11 -  theharmonyguy -  @vogon Chrome It's by GeoIP, I assume - it's not using the geolocation feature with the UI prompt Just auto-filling Washington DC</description><link>http://www.secuobs.com/twitter/news/294256.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/294256.shtml</guid></item>
<item><title> RT @kkotowicz: “@0x6D6172696F: Not too well-known yet not so uncommon XSS technique where HTML entities won't protect you http://tco/t7 </title><description>Secuobs.com : 2012-02-12 01:40:21 -  theharmonyguy -  RT @kkotowicz: “@0x6D6172696F: Not too well-known yet not so uncommon XSS technique where HTML entities won't protect you http://tco/t7 </description><link>http://www.secuobs.com/twitter/news/293221.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/293221.shtml</guid></item>
<item><title> @manicode Yeah, if I remember right, it grew out of this XSS challenge: http://tco/ff7R0C1j Theory was if XSS could be solved in the DOM</title><description>Secuobs.com : 2012-02-09 19:10:01 - theharmonyguy -  @manicode Yeah, if I remember right, it grew out of this XSS challenge: http://tco/ff7R0C1j Theory was if XSS could be solved in the DOM</description><link>http://www.secuobs.com/twitter/news/292471.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/292471.shtml</guid></item>
<item><title> RT @WisecWisec: I can still see your actions on Google Maps over SSL http://tco/V5KEoyLL via @cesarcer //LOLTerrific</title><description>Secuobs.com : 2012-02-09 19:10:01 - theharmonyguy -  RT @WisecWisec: I can still see your actions on Google Maps over SSL http://tco/V5KEoyLL via @cesarcer //LOLTerrific</description><link>http://www.secuobs.com/twitter/news/292470.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/292470.shtml</guid></item>
<item><title> RT @securityshell: Creating Backdoors Using SQL Injection http://tco/ClHjiQO0</title><description>Secuobs.com : 2012-02-09 02:05:22 - theharmonyguy -  RT @securityshell: Creating Backdoors Using SQL Injection http://tco/ClHjiQO0</description><link>http://www.secuobs.com/twitter/news/292255.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/292255.shtml</guid></item>
<item><title> So, who's going to be first to setup a proxy and start checking a bunch of popular iOS apps for address book uploads</title><description>Secuobs.com : 2012-02-09 02:05:22 - theharmonyguy -  So, who's going to be first to setup a proxy and start checking a bunch of popular iOS apps for address book uploads</description><link>http://www.secuobs.com/twitter/news/292254.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/292254.shtml</guid></item>
<item><title> RT @jeremiahg: New Blog Post: A Single-Site Browser’s impact on XSS, CSRF, and Clickjacking http://tco/5kzFnIxb Cc: @ma1 @theharmonyguy</title><description>Secuobs.com : 2012-02-08 22:14:00 -  theharmonyguy -  RT @jeremiahg: New Blog Post: A Single-Site Browser’s impact on XSS, CSRF, and Clickjacking http://tco/5kzFnIxb Cc: @ma1 @theharmonyguy</description><link>http://www.secuobs.com/twitter/news/292144.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/292144.shtml</guid></item>
<item><title> @randomdross @jeremiahg @secureideas The Skype for iOS XSS also demonstrates another avenue for XSS in single-site/mobile apps</title><description>Secuobs.com : 2012-02-08 03:00:06 - theharmonyguy -  @randomdross @jeremiahg @secureideas The Skype for iOS XSS also demonstrates another avenue for XSS in single-site/mobile apps</description><link>http://www.secuobs.com/twitter/news/291799.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/291799.shtml</guid></item>
<item><title> @secureideas @jeremiahg How would they limit exfiltration If XSS can load in a DOM it can talk to external resources, right</title><description>Secuobs.com : 2012-02-08 03:00:06 - theharmonyguy -  @secureideas @jeremiahg How would they limit exfiltration If XSS can load in a DOM it can talk to external resources, right</description><link>http://www.secuobs.com/twitter/news/291798.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/291798.shtml</guid></item>
<item><title> RT @randomdross: RT @mathias: The Eval that Men Do — a large-scale study of the use of `eval` in JavaScript apps: http://tco/MwWAXlWJ  </title><description>Secuobs.com : 2012-02-07 00:46:53 - theharmonyguy -  RT @randomdross: RT @mathias: The Eval that Men Do — a large-scale study of the use of `eval` in JavaScript apps: http://tco/MwWAXlWJ  </description><link>http://www.secuobs.com/twitter/news/291354.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/291354.shtml</guid></item>
<item><title> As Open Graph apps grow and given Facebook's anti-clickjacking code, I wonder if scammers/attackers will shift more to CSRF/CJ against apps</title><description>Secuobs.com : 2012-02-07 00:46:53 - theharmonyguy -  As Open Graph apps grow and given Facebook's anti-clickjacking code, I wonder if scammers/attackers will shift more to CSRF/CJ against apps</description><link>http://www.secuobs.com/twitter/news/291353.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/291353.shtml</guid></item>
<item><title> RT @mubix: {blog} A @textfiles approach at gathering the world's DNS - Slides http://tco/96EiAScu</title><description>Secuobs.com : 2012-02-04 03:14:36 - theharmonyguy -  RT @mubix: {blog} A @textfiles approach at gathering the world's DNS - Slides http://tco/96EiAScu</description><link>http://www.secuobs.com/twitter/news/290670.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/290670.shtml</guid></item>
<item><title> In case you missed it yesterday What you should know before caching JavaScript in HTML5 localStorage: http://tco/4vcvUvXs #XSS</title><description>Secuobs.com : 2012-02-03 02:04:01 - theharmonyguy -  In case you missed it yesterday What you should know before caching JavaScript in HTML5 localStorage: http://tco/4vcvUvXs #XSS</description><link>http://www.secuobs.com/twitter/news/290297.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/290297.shtml</guid></item>
<item><title> RT @manicode: I have a @whitehatsec webinar on Feb 8th regarding new research on XSS defense https://tco/wKPcLVqj</title><description>Secuobs.com : 2012-02-01 03:27:04 - theharmonyguy -  RT @manicode: I have a @whitehatsec webinar on Feb 8th regarding new research on XSS defense https://tco/wKPcLVqj</description><link>http://www.secuobs.com/twitter/news/289721.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/289721.shtml</guid></item>
<item><title> RT @jeremiahg: Apache httpOnly Cookie Disclosure http://tco/EaJoK1Ca clever</title><description>Secuobs.com : 2012-01-31 21:24:09 - theharmonyguy -  RT @jeremiahg: Apache httpOnly Cookie Disclosure http://tco/EaJoK1Ca clever</description><link>http://www.secuobs.com/twitter/news/289547.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/289547.shtml</guid></item>
<item><title> RT @theKos: I have one shmoocon ticket available, first person to tell me they want it gets buys it Also, will trade for 0day</title><description>Secuobs.com : 2012-01-26 19:36:40 -  theharmonyguy -  RT @theKos: I have one shmoocon ticket available, first person to tell me they want it gets buys it Also, will trade for 0day</description><link>http://www.secuobs.com/twitter/news/287959.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/287959.shtml</guid></item>
<item><title> RT @securityshell: SQL Backdoors howto with Wordpress  PHPBB3 Examples: http://tco/SyfOkhko @BlackhatStaff </title><description>Secuobs.com : 2012-01-26 00:00:10 - theharmonyguy -  RT @securityshell: SQL Backdoors howto with Wordpress  PHPBB3 Examples: http://tco/SyfOkhko @BlackhatStaff </description><link>http://www.secuobs.com/twitter/news/287624.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/287624.shtml</guid></item>
<item><title> I want to start a really slow ad network on http://tco/XbMeTpz8 so when sites load in Chrome I'll see Waiting for http://tco/XbMeTpz8</title><description>Secuobs.com : 2012-01-25 00:29:53 - theharmonyguy -  I want to start a really slow ad network on http://tco/XbMeTpz8 so when sites load in Chrome I'll see Waiting for http://tco/XbMeTpz8</description><link>http://www.secuobs.com/twitter/news/287230.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/287230.shtml</guid></item>
<item><title> Or if it makes sense to you : RT @yoz If you find yourself laughing harder at the Javascript output YOU ARE A NERD https://tco/e7k6D7FW</title><description>Secuobs.com : 2012-01-21 00:44:26 - theharmonyguy -  Or if it makes sense to you : RT @yoz If you find yourself laughing harder at the Javascript output YOU ARE A NERD https://tco/e7k6D7FW</description><link>http://www.secuobs.com/twitter/news/286020.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/286020.shtml</guid></item>
<item><title> RT @WeldPond: What Happens To Your Files When a Cloud Service Shuts Down XDA-Developers has 200K links to #megaupload http://tco/JGssJlUt</title><description>Secuobs.com : 2012-01-21 00:44:26 - theharmonyguy -  RT @WeldPond: What Happens To Your Files When a Cloud Service Shuts Down XDA-Developers has 200K links to #megaupload http://tco/JGssJlUt</description><link>http://www.secuobs.com/twitter/news/286019.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/286019.shtml</guid></item>
<item><title> RT @pedramamini: littleblackbox, a database of private SSL/SSH keys for embedded devices: https://tco/ulFwiTcE</title><description>Secuobs.com : 2012-01-17 23:09:15 - theharmonyguy -  RT @pedramamini: littleblackbox, a database of private SSL/SSH keys for embedded devices: https://tco/ulFwiTcE</description><link>http://www.secuobs.com/twitter/news/284795.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/284795.shtml</guid></item>
<item><title> That site in my last RT also has an excellent, thorough article on the logic behind XSS and it's from 2008: http://tco/ZDqSHdzk</title><description>Secuobs.com : 2012-01-17 01:25:58 - theharmonyguy -  That site in my last RT also has an excellent, thorough article on the logic behind XSS and it's from 2008: http://tco/ZDqSHdzk</description><link>http://www.secuobs.com/twitter/news/284442.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/284442.shtml</guid></item>
<item><title> RT @skeptic_fx: Adobe Flash Webcam clickjacking - The security fix that wasn't and the hole that was  http://tco/foRTQVia</title><description>Secuobs.com : 2012-01-13 01:02:53 - theharmonyguy -  RT @skeptic_fx: Adobe Flash Webcam clickjacking - The security fix that wasn't and the hole that was  http://tco/foRTQVia</description><link>http://www.secuobs.com/twitter/news/283243.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/283243.shtml</guid></item>
<item><title> RT @securityninja: RT @packetwerks: This is how you know to use another register PCI wut http://tco/wzVuPXkJ</title><description>Secuobs.com : 2012-01-13 01:02:53 - theharmonyguy -  RT @securityninja: RT @packetwerks: This is how you know to use another register PCI wut http://tco/wzVuPXkJ</description><link>http://www.secuobs.com/twitter/news/283242.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/283242.shtml</guid></item>
<item><title> RT @johnwilander: JSZip - Create zip files with JavaScript Why Good for file uploads http://tco/igkGB5lF via @jerome_etienne @mrdoob </title><description>Secuobs.com : 2012-01-13 01:02:53 - theharmonyguy -  RT @johnwilander: JSZip - Create zip files with JavaScript Why Good for file uploads http://tco/igkGB5lF via @jerome_etienne @mrdoob </description><link>http://www.secuobs.com/twitter/news/283241.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/283241.shtml</guid></item>
<item><title> @jeremiahg @manicode With so many other issues, has CSRF really been needed much in actual attacks</title><description>Secuobs.com : 2012-01-11 05:24:27 - theharmonyguy -  @jeremiahg @manicode With so many other issues, has CSRF really been needed much in actual attacks</description><link>http://www.secuobs.com/twitter/news/282561.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/282561.shtml</guid></item>
<item><title> How have I not seen this before Lenovo USB hard drive with built-in AES256 and keypad for 8- to 16-character password: http://tco/abvN67sJ</title><description>Secuobs.com : 2012-01-11 05:24:27 - theharmonyguy -  How have I not seen this before Lenovo USB hard drive with built-in AES256 and keypad for 8- to 16-character password: http://tco/abvN67sJ</description><link>http://www.secuobs.com/twitter/news/282560.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/282560.shtml</guid></item>
<item><title> @mattjay @jeremiahg @manicode I suppose that gets back to definitions - if you're using XSS to launch, is it really a CSRF attack</title><description>Secuobs.com : 2012-01-11 05:24:27 - theharmonyguy -  @mattjay @jeremiahg @manicode I suppose that gets back to definitions - if you're using XSS to launch, is it really a CSRF attack</description><link>http://www.secuobs.com/twitter/news/282559.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/282559.shtml</guid></item>
<item><title> @jeremiahg @skeptic_fx My concern would be more XSS on site with permissions UI implementation seems to avoid clickjacking</title><description>Secuobs.com : 2012-01-10 18:54:23 -  theharmonyguy -  @jeremiahg @skeptic_fx My concern would be more XSS on site with permissions UI implementation seems to avoid clickjacking</description><link>http://www.secuobs.com/twitter/news/282397.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/282397.shtml</guid></item>
<item><title> RT @digdns: DNS-blocking explained in a simple picture http://tco/PT7E6o4R</title><description>Secuobs.com : 2012-01-10 01:45:47 - theharmonyguy -  RT @digdns: DNS-blocking explained in a simple picture http://tco/PT7E6o4R</description><link>http://www.secuobs.com/twitter/news/282225.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/282225.shtml</guid></item>
<item><title> @mckt_ @matthewhughes To the cloud</title><description>Secuobs.com : 2012-01-10 01:45:47 - theharmonyguy -  @mckt_ @matthewhughes To the cloud</description><link>http://www.secuobs.com/twitter/news/282224.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/282224.shtml</guid></item>
<item><title> ATT mHealth Alpha - consumers can have single cloud aggregate health data from doctor offices insurance companies Wait, what</title><description>Secuobs.com : 2012-01-09 22:03:02 - theharmonyguy -  ATT mHealth Alpha - consumers can have single cloud aggregate health data from doctor offices insurance companies Wait, what</description><link>http://www.secuobs.com/twitter/news/282110.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/282110.shtml</guid></item>
<item><title> Antichrist, meet SQL injection Actual quote from a conversation involving eschatology</title><description>Secuobs.com : 2012-01-09 22:03:02 -  theharmonyguy -  Antichrist, meet SQL injection Actual quote from a conversation involving eschatology</description><link>http://www.secuobs.com/twitter/news/282109.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/282109.shtml</guid></item>
<item><title> @kkotowicz @0x6D6172696F @theKos @mattjay So remember that HTML5-related XSS I mentioned It's gotten worse Mind if I email y'all about it</title><description>Secuobs.com : 2012-01-07 03:45:53 - theharmonyguy -  @kkotowicz @0x6D6172696F @theKos @mattjay So remember that HTML5-related XSS I mentioned It's gotten worse Mind if I email y'all about it</description><link>http://www.secuobs.com/twitter/news/281391.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/281391.shtml</guid></item>
<item><title> Remember, XSS is not just about scripting By @0x6D6172696F: RT @jeremiahg browser keystroke logger w/o javascript: http://tco/JTzFSYrn</title><description>Secuobs.com : 2012-01-05 22:50:03 - theharmonyguy -  Remember, XSS is not just about scripting By @0x6D6172696F: RT @jeremiahg browser keystroke logger w/o javascript: http://tco/JTzFSYrn</description><link>http://www.secuobs.com/twitter/news/281024.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/281024.shtml</guid></item>
<item><title> Also, on Facebook as a proxy - would you really want to use a proxy that requires you to be logged in with Facebook credentials</title><description>Secuobs.com : 2011-12-23 20:36:05 - theharmonyguy -  Also, on Facebook as a proxy - would you really want to use a proxy that requires you to be logged in with Facebook credentials</description><link>http://www.secuobs.com/twitter/news/277921.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/277921.shtml</guid></item>
<item><title> @IHTeam But why use it for SQLi or crawling if Facebook can track all of your requests and tie them to your account</title><description>Secuobs.com : 2011-12-23 20:36:05 - theharmonyguy -  @IHTeam But why use it for SQLi or crawling if Facebook can track all of your requests and tie them to your account</description><link>http://www.secuobs.com/twitter/news/277920.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/277920.shtml</guid></item>
<item><title> @0x6D6172696F Hang on, you can regexp a URL and apply CSS rules based on that More potential for scriptless XSS there</title><description>Secuobs.com : 2011-12-23 20:36:05 - theharmonyguy -  @0x6D6172696F Hang on, you can regexp a URL and apply CSS rules based on that More potential for scriptless XSS there</description><link>http://www.secuobs.com/twitter/news/277919.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/277919.shtml</guid></item>
<item><title> @shreeraj Hey, on CORjacking - isn't XSS still required to pull this off I'm not really seeing what's new here</title><description>Secuobs.com : 2011-12-23 20:36:05 - theharmonyguy -  @shreeraj Hey, on CORjacking - isn't XSS still required to pull this off I'm not really seeing what's new here</description><link>http://www.secuobs.com/twitter/news/277918.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/277918.shtml</guid></item>
<item><title> RT @osxreverser: Microsoft that indicates that the company is adding JavaScript and HTML5 support to Office MORE HOLES  o/  </title><description>Secuobs.com : 2011-12-22 20:58:40 - theharmonyguy -  RT @osxreverser: Microsoft that indicates that the company is adding JavaScript and HTML5 support to Office MORE HOLES  o/  </description><link>http://www.secuobs.com/twitter/news/277596.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/277596.shtml</guid></item>
<item><title> RT @jeresig: New Blog Post: JavaScript as a First Language: http://tco/kjyucBkN</title><description>Secuobs.com : 2011-12-21 23:48:23 - theharmonyguy -  RT @jeresig: New Blog Post: JavaScript as a First Language: http://tco/kjyucBkN</description><link>http://www.secuobs.com/twitter/news/277353.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/277353.shtml</guid></item>
<item><title> RT @neiltyson: The best engineering flow chart ever: http://tco/Rs7GNh4U</title><description>Secuobs.com : 2011-12-21 23:48:23 - theharmonyguy -  RT @neiltyson: The best engineering flow chart ever: http://tco/Rs7GNh4U</description><link>http://www.secuobs.com/twitter/news/277352.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/277352.shtml</guid></item>
<item><title> btw, haven't forgotten about the HTML5-related XSS I mentioned last week - much to write and it's a live vuln so waiting on disclosure</title><description>Secuobs.com : 2011-12-21 23:48:23 -  theharmonyguy -  btw, haven't forgotten about the HTML5-related XSS I mentioned last week - much to write and it's a live vuln so waiting on disclosure</description><link>http://www.secuobs.com/twitter/news/277351.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/277351.shtml</guid></item>
<item><title> RT @nathansmith: The Rise and Rise of JavaScript by @tastapod — http://tco/01LX7Qe0 /via @mundizzle</title><description>Secuobs.com : 2011-12-21 01:17:36 -  theharmonyguy -  RT @nathansmith: The Rise and Rise of JavaScript by @tastapod — http://tco/01LX7Qe0 /via @mundizzle</description><link>http://www.secuobs.com/twitter/news/277088.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/277088.shtml</guid></item>
<item><title> RT @randomdross: XSS Filter Tech: Later is Better  http://tco/Wb0NPkZf</title><description>Secuobs.com : 2011-12-20 21:22:52 - theharmonyguy -  RT @randomdross: XSS Filter Tech: Later is Better  http://tco/Wb0NPkZf</description><link>http://www.secuobs.com/twitter/news/276988.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/276988.shtml</guid></item>
<item><title> RT @elie: Attacking NoSQL and Nodejs: Server-Side JavaScript Injection  - http://tco/c4aHZHlO  pretty cool #security #infosec #dev </title><description>Secuobs.com : 2011-12-20 08:03:42 - theharmonyguy -  RT @elie: Attacking NoSQL and Nodejs: Server-Side JavaScript Injection  - http://tco/c4aHZHlO  pretty cool #security #infosec #dev </description><link>http://www.secuobs.com/twitter/news/276772.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/276772.shtml</guid></item>
<item><title> RT @runasand: Dear Santa, all I want for Christmas is a Burp Pro license, a Raspberry Pi, Little Printer, and two tickets to ShmooCon</title><description>Secuobs.com : 2011-12-20 00:49:51 - theharmonyguy -  RT @runasand: Dear Santa, all I want for Christmas is a Burp Pro license, a Raspberry Pi, Little Printer, and two tickets to ShmooCon</description><link>http://www.secuobs.com/twitter/news/276664.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/276664.shtml</guid></item>
<item><title> RT @gattaca: “@ZDNet: Yahoo Mail introduces two factor authentication http://tco/vJR9o8uM”  but still no default SSL</title><description>Secuobs.com : 2011-12-20 00:49:51 -  theharmonyguy -  RT @gattaca: “@ZDNet: Yahoo Mail introduces two factor authentication http://tco/vJR9o8uM”  but still no default SSL</description><link>http://www.secuobs.com/twitter/news/276663.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/276663.shtml</guid></item>
<item><title> I'm one XSS hole away from a pretty disconcerting PoC I'm sure someone's done similar research before, but I don't think I've seen it</title><description>Secuobs.com : 2011-12-17 02:53:28 - theharmonyguy -  I'm one XSS hole away from a pretty disconcerting PoC I'm sure someone's done similar research before, but I don't think I've seen it</description><link>http://www.secuobs.com/twitter/news/276030.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/276030.shtml</guid></item>
<item><title> And score Hopefully next week: Blog post on how HTML5 can turn reflective XSS into persistent, cross-domain XSS #notkidding</title><description>Secuobs.com : 2011-12-17 02:53:28 - theharmonyguy -  And score Hopefully next week: Blog post on how HTML5 can turn reflective XSS into persistent, cross-domain XSS #notkidding</description><link>http://www.secuobs.com/twitter/news/276029.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/276029.shtml</guid></item>
<item><title> PDF: RT @superevr Great write up on HTML5 Security: http://tco/u0DN6mHT</title><description>Secuobs.com : 2011-12-16 21:28:32 - theharmonyguy -  PDF: RT @superevr Great write up on HTML5 Security: http://tco/u0DN6mHT</description><link>http://www.secuobs.com/twitter/news/275940.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/275940.shtml</guid></item>
<item><title> RT @nathansmith: Google Chrome passes IE8, becomes most popular browser worldwide: http://tco/ug5EiDrj /via @dotcomlarry</title><description>Secuobs.com : 2011-12-16 01:22:49 - theharmonyguy -  RT @nathansmith: Google Chrome passes IE8, becomes most popular browser worldwide: http://tco/ug5EiDrj /via @dotcomlarry</description><link>http://www.secuobs.com/twitter/news/275630.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/275630.shtml</guid></item>
<item><title> @benadida Nice Chrome is my default, but I'll have to check this out</title><description>Secuobs.com : 2011-12-16 01:22:49 -  theharmonyguy -  @benadida Nice Chrome is my default, but I'll have to check this out</description><link>http://www.secuobs.com/twitter/news/275629.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/275629.shtml</guid></item>
<item><title> Links on upcoming HTML webcam access: http://tco/NdcfKwI6 http://tco/yeYSt8VB http://tco/3O5y7Xrz cc @jeremiahg @jloidl</title><description>Secuobs.com : 2011-12-14 07:50:11 - theharmonyguy -  Links on upcoming HTML webcam access: http://tco/NdcfKwI6 http://tco/yeYSt8VB http://tco/3O5y7Xrz cc @jeremiahg @jloidl</description><link>http://www.secuobs.com/twitter/news/274965.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/274965.shtml</guid></item>
<item><title> @dakami @jeremiahg Devil's Advocate: Fewer computers had webcams and good connections in 2004 But yeah, we'll see</title><description>Secuobs.com : 2011-12-14 07:50:11 - theharmonyguy -  @dakami @jeremiahg Devil's Advocate: Fewer computers had webcams and good connections in 2004 But yeah, we'll see</description><link>http://www.secuobs.com/twitter/news/274964.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/274964.shtml</guid></item>
<item><title> Today I learned that an upcoming HTML feature is native browser access to a user's webcam Should make for some interesting XSS attacks</title><description>Secuobs.com : 2011-12-14 00:53:56 - theharmonyguy -  Today I learned that an upcoming HTML feature is native browser access to a user's webcam Should make for some interesting XSS attacks</description><link>http://www.secuobs.com/twitter/news/274845.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/274845.shtml</guid></item>
<item><title> @vogon XSS continues to fascinate me - in a sense, you could call it my favorite vuln :</title><description>Secuobs.com : 2011-12-14 00:53:56 - theharmonyguy -  @vogon XSS continues to fascinate me - in a sense, you could call it my favorite vuln :</description><link>http://www.secuobs.com/twitter/news/274844.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/274844.shtml</guid></item>
<item><title> I should note that I'm sure HTML webcam access will require authorization, as geolocation does today I just wonder about implementation</title><description>Secuobs.com : 2011-12-14 00:53:56 - theharmonyguy -  I should note that I'm sure HTML webcam access will require authorization, as geolocation does today I just wonder about implementation</description><link>http://www.secuobs.com/twitter/news/274843.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/274843.shtml</guid></item>
<item><title> RT @digininja: RT @beefproject: RT @antisnatchor: @mtrojnar - Root via XSS oh yes, on the new amazon Kindle http://tco/a4PT8xyA</title><description>Secuobs.com : 2011-12-14 00:53:56 - theharmonyguy -  RT @digininja: RT @beefproject: RT @antisnatchor: @mtrojnar - Root via XSS oh yes, on the new amazon Kindle http://tco/a4PT8xyA</description><link>http://www.secuobs.com/twitter/news/274842.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/274842.shtml</guid></item>
<item><title> Wait, Chrome doesn't already have fully sandboxed Flash Guess I hadn't been keeping track but I thought that had already been released</title><description>Secuobs.com : 2011-12-10 07:16:49 - theharmonyguy -  Wait, Chrome doesn't already have fully sandboxed Flash Guess I hadn't been keeping track but I thought that had already been released</description><link>http://www.secuobs.com/twitter/news/273832.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/273832.shtml</guid></item>
<item><title> RT @justinschuh: Chrome Canary and Dev have an optional alpha of the upcoming fully sandboxed Flash on Windows: http://tco/rsd4hulX</title><description>Secuobs.com : 2011-12-10 07:16:49 - theharmonyguy -  RT @justinschuh: Chrome Canary and Dev have an optional alpha of the upcoming fully sandboxed Flash on Windows: http://tco/rsd4hulX</description><link>http://www.secuobs.com/twitter/news/273831.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/273831.shtml</guid></item>
<item><title> @internot_ @kkotowicz @0x6d6172696f Apparently it works in Java 7 but not Java 6</title><description>Secuobs.com : 2011-12-10 07:16:49 - theharmonyguy -  @internot_ @kkotowicz @0x6d6172696f Apparently it works in Java 7 but not Java 6</description><link>http://www.secuobs.com/twitter/news/273830.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/273830.shtml</guid></item>
<item><title> RT @kkotowicz: http://tco/GTsY228I Do you think you can dance XSS contest by @0x6D6172696F and @kkotowicz results Gratz for all winners</title><description>Secuobs.com : 2011-12-09 17:44:25 - theharmonyguy -  RT @kkotowicz: http://tco/GTsY228I Do you think you can dance XSS contest by @0x6D6172696F and @kkotowicz results Gratz for all winners</description><link>http://www.secuobs.com/twitter/news/273607.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/273607.shtml</guid></item>
<item><title> @0x6D6172696F No, I'm on Java 6 - is that the issue</title><description>Secuobs.com : 2011-12-09 17:44:25 - theharmonyguy -  @0x6D6172696F No, I'm on Java 6 - is that the issue</description><link>http://www.secuobs.com/twitter/news/273606.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/273606.shtml</guid></item>
<item><title> @kkotowicz @antisnatchor This challenge has certainly not endeared me any more to Java :</title><description>Secuobs.com : 2011-12-09 17:44:25 -  theharmonyguy -  @kkotowicz @antisnatchor This challenge has certainly not endeared me any more to Java :</description><link>http://www.secuobs.com/twitter/news/273605.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/273605.shtml</guid></item>
<item><title> RT @JoshConstine: Facebook Confirms Corporate Reorganization, Focusing On Mobile, Ads, Product, Engineering, Profile http://tco/Aqmp1nt </title><description>Secuobs.com : 2011-12-09 02:59:49 - theharmonyguy -  RT @JoshConstine: Facebook Confirms Corporate Reorganization, Focusing On Mobile, Ads, Product, Engineering, Profile http://tco/Aqmp1nt </description><link>http://www.secuobs.com/twitter/news/273413.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/273413.shtml</guid></item>
<item><title> RT @briankrebs: CNET's Download dot com bundling adware, toolbars in vs to policy Pushing toolbars with Wireshark, Nmap, etc http:// </title><description>Secuobs.com : 2011-12-07 04:45:18 - theharmonyguy -  RT @briankrebs: CNET's Download dot com bundling adware, toolbars in vs to policy Pushing toolbars with Wireshark, Nmap, etc http:// </description><link>http://www.secuobs.com/twitter/news/272541.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/272541.shtml</guid></item>
<item><title> Sounds like the mad scientist @0x6D6172696F is now building a web-based password cracker using CSS and no JavaScript</title><description>Secuobs.com : 2011-12-06 19:25:55 - theharmonyguy -  Sounds like the mad scientist @0x6D6172696F is now building a web-based password cracker using CSS and no JavaScript</description><link>http://www.secuobs.com/twitter/news/272338.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/272338.shtml</guid></item>
<item><title> XSS is generally considered to be a browser attack, but #addingtomyfiles RT @mattjay Look how awesome @theKos is: http://tco/8lPZJBkz</title><description>Secuobs.com : 2011-12-06 19:25:55 - theharmonyguy -  XSS is generally considered to be a browser attack, but #addingtomyfiles RT @mattjay Look how awesome @theKos is: http://tco/8lPZJBkz</description><link>http://www.secuobs.com/twitter/news/272337.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/272337.shtml</guid></item>
<item><title> After my last tweet, I've realized that the list I keep of interesting XSS attacks simply must be called The XSS-Files</title><description>Secuobs.com : 2011-12-06 19:25:55 - theharmonyguy -  After my last tweet, I've realized that the list I keep of interesting XSS attacks simply must be called The XSS-Files</description><link>http://www.secuobs.com/twitter/news/272336.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/272336.shtml</guid></item>
<item><title> RT @BrianHonan: RT @ I've realized the list I keep of interesting XSS attacks simply must be called The XSS-Files  T </title><description>Secuobs.com : 2011-12-06 19:25:55 - theharmonyguy -  RT @BrianHonan: RT @ I've realized the list I keep of interesting XSS attacks simply must be called The XSS-Files  T </description><link>http://www.secuobs.com/twitter/news/272335.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/272335.shtml</guid></item>
<item><title> RT @paul_irish: http://tco/dIlIYYsc features a snappy search UI to all of MDN's javascript/css/html/dom documentation Very nice</title><description>Secuobs.com : 2011-12-06 19:25:55 - theharmonyguy -  RT @paul_irish: http://tco/dIlIYYsc features a snappy search UI to all of MDN's javascript/css/html/dom documentation Very nice</description><link>http://www.secuobs.com/twitter/news/272334.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/272334.shtml</guid></item>
<item><title> @jeremiahg @codepo8 Some interesting points, but still strikes me as an oversimplification Many of Google's Chrome-only apps are</title><description>Secuobs.com : 2011-12-06 02:10:04 - theharmonyguy -  @jeremiahg @codepo8 Some interesting points, but still strikes me as an oversimplification Many of Google's Chrome-only apps are</description><link>http://www.secuobs.com/twitter/news/272066.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/272066.shtml</guid></item>
<item><title> @jeremiahg @codepo8 limited by choice/distribution, not technology For instance, Chrome Angry Birds runs fine in Firefox</title><description>Secuobs.com : 2011-12-06 02:10:04 - theharmonyguy -  @jeremiahg @codepo8 limited by choice/distribution, not technology For instance, Chrome Angry Birds runs fine in Firefox</description><link>http://www.secuobs.com/twitter/news/272065.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/272065.shtml</guid></item>
<item><title> RT @paul_irish: When you're optimizing performance of your site/app, your priorities are 1 Network connections 2 DOM access 3 Javascr </title><description>Secuobs.com : 2011-12-04 00:01:31 -  theharmonyguy -  RT @paul_irish: When you're optimizing performance of your site/app, your priorities are 1 Network connections 2 DOM access 3 Javascr </description><link>http://www.secuobs.com/twitter/news/271565.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/271565.shtml</guid></item>
<item><title> Note the first one - eval also not good for performance reasons RT @johnwilander A guide to efficient JavaScript: http://tco/jyvJbcZg</title><description>Secuobs.com : 2011-12-02 23:45:40 - theharmonyguy -  Note the first one - eval also not good for performance reasons RT @johnwilander A guide to efficient JavaScript: http://tco/jyvJbcZg</description><link>http://www.secuobs.com/twitter/news/271311.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/271311.shtml</guid></item>
<item><title> RT @gattaca: “@CNETNews: How Carrier IQ was wrongly accused of keylogging  http://tco/H0EPJ0mV”  by some perhaps The potential fo </title><description>Secuobs.com : 2011-12-02 23:45:40 - theharmonyguy -  RT @gattaca: “@CNETNews: How Carrier IQ was wrongly accused of keylogging  http://tco/H0EPJ0mV”  by some perhaps The potential fo </description><link>http://www.secuobs.com/twitter/news/271310.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/271310.shtml</guid></item>
<item><title> RT @securityninja: Reverse Engineering Web Apps: Architectural Composition another great blog post from @kuzushi http://tco/KFRnoISP</title><description>Secuobs.com : 2011-12-02 01:36:34 - theharmonyguy -  RT @securityninja: Reverse Engineering Web Apps: Architectural Composition another great blog post from @kuzushi http://tco/KFRnoISP</description><link>http://www.secuobs.com/twitter/news/270885.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/270885.shtml</guid></item>
<item><title> This is madness This is JAVA</title><description>Secuobs.com : 2011-12-01 01:22:38 - theharmonyguy -  This is madness This is JAVA</description><link>http://www.secuobs.com/twitter/news/270559.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/270559.shtml</guid></item>
<item><title> Think I just earned a heart in the So you think you can dance XSS challenge : Learned a ton Try it yourself: http://tco/rh2hbCrI</title><description>Secuobs.com : 2011-12-01 01:22:38 - theharmonyguy -  Think I just earned a heart in the So you think you can dance XSS challenge : Learned a ton Try it yourself: http://tco/rh2hbCrI</description><link>http://www.secuobs.com/twitter/news/270558.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/270558.shtml</guid></item>
<item><title> Work on this Java-based XSS challenge is not increasing my love for Java</title><description>Secuobs.com : 2011-11-30 02:29:53 - theharmonyguy -  Work on this Java-based XSS challenge is not increasing my love for Java</description><link>http://www.secuobs.com/twitter/news/270185.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/270185.shtml</guid></item>
<item><title> Yikes, an XSS challenge that requires Java See if you can outsmart @0x6D6172696F and @kkotowicz: http://tco/8ZxLFt0O</title><description>Secuobs.com : 2011-11-29 01:20:29 - theharmonyguy -  Yikes, an XSS challenge that requires Java See if you can outsmart @0x6D6172696F and @kkotowicz: http://tco/8ZxLFt0O</description><link>http://www.secuobs.com/twitter/news/269797.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/269797.shtml</guid></item>
<item><title> @0x6D6172696F @thewildcat lol very nice - I'm still working on figuring out this Java interface</title><description>Secuobs.com : 2011-11-29 01:20:29 - theharmonyguy -  @0x6D6172696F @thewildcat lol very nice - I'm still working on figuring out this Java interface</description><link>http://www.secuobs.com/twitter/news/269796.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/269796.shtml</guid></item>
<item><title> FYI: New XSS challenge from @0x6D6172696F and @kkotowicz apparently arriving today at 3 pm Eastern</title><description>Secuobs.com : 2011-11-28 17:47:24 - theharmonyguy -  FYI: New XSS challenge from @0x6D6172696F and @kkotowicz apparently arriving today at 3 pm Eastern</description><link>http://www.secuobs.com/twitter/news/269659.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/269659.shtml</guid></item>
<item><title> Worked on my iPhone #jsrocks RT @dakami http://tco/UxrqHW0w Face Detection In JavaScript rly</title><description>Secuobs.com : 2011-11-24 02:31:55 - theharmonyguy -  Worked on my iPhone #jsrocks RT @dakami http://tco/UxrqHW0w Face Detection In JavaScript rly</description><link>http://www.secuobs.com/twitter/news/268611.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/268611.shtml</guid></item>
<item><title> Speculation that SSL certificates abused in the wild had their 512-bit RSA keys factored: http://tco/8tFPzTGK via @mikko</title><description>Secuobs.com : 2011-11-23 04:05:55 - theharmonyguy -  Speculation that SSL certificates abused in the wild had their 512-bit RSA keys factored: http://tco/8tFPzTGK via @mikko</description><link>http://www.secuobs.com/twitter/news/268295.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/268295.shtml</guid></item>
<item><title> From the Never Underestimate JavaScript Dept: RT @securityninja JavaScript JVM runs Java  wow http://tco/R80BuSwV</title><description>Secuobs.com : 2011-11-21 20:51:22 - theharmonyguy -  From the Never Underestimate JavaScript Dept: RT @securityninja JavaScript JVM runs Java  wow http://tco/R80BuSwV</description><link>http://www.secuobs.com/twitter/news/267910.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/267910.shtml</guid></item>
<item><title> RT @superevr: RT @garethheyes: JavaScript is the cause of and solution to the web's problems  That's deep</title><description>Secuobs.com : 2011-11-21 20:51:22 - theharmonyguy -  RT @superevr: RT @garethheyes: JavaScript is the cause of and solution to the web's problems  That's deep</description><link>http://www.secuobs.com/twitter/news/267909.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/267909.shtml</guid></item>
<item><title> @satnam Perhaps I think the main point is that while the effect is the same as XSS, the action/method is quite different</title><description>Secuobs.com : 2011-11-17 09:01:04 - theharmonyguy -  @satnam Perhaps I think the main point is that while the effect is the same as XSS, the action/method is quite different</description><link>http://www.secuobs.com/twitter/news/266619.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/266619.shtml</guid></item>
<item><title> @satnam I'm just seeing people say browsers allow XSS to happen or that the attack is being caused by XSS vulnerabilities</title><description>Secuobs.com : 2011-11-17 09:01:04 - theharmonyguy -  @satnam I'm just seeing people say browsers allow XSS to happen or that the attack is being caused by XSS vulnerabilities</description><link>http://www.secuobs.com/twitter/news/266618.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/266618.shtml</guid></item>
<item><title> RT @garethheyes: Here are my non-alphanumeric JavaScript  PHP slides http://tco/0dbhNdS3 powerpoint http://tco/EtniM1Jf pdf</title><description>Secuobs.com : 2011-11-17 09:01:04 - theharmonyguy -  RT @garethheyes: Here are my non-alphanumeric JavaScript  PHP slides http://tco/0dbhNdS3 powerpoint http://tco/EtniM1Jf pdf</description><link>http://www.secuobs.com/twitter/news/266617.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/266617.shtml</guid></item>
<item><title> @jeremiahg @bsterne @satnam In my tests, type j first still fails in IE9 and of course Firefox but works in Chrome</title><description>Secuobs.com : 2011-11-17 09:01:04 - theharmonyguy -  @jeremiahg @bsterne @satnam In my tests, type j first still fails in IE9 and of course Firefox but works in Chrome</description><link>http://www.secuobs.com/twitter/news/266616.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/266616.shtml</guid></item>
<item><title> RT @CodeWisdom: Java is to JavaScript what Car is to Carpet - Chris Heilmann</title><description>Secuobs.com : 2011-11-16 22:50:13 - theharmonyguy -  RT @CodeWisdom: Java is to JavaScript what Car is to Carpet - Chris Heilmann</description><link>http://www.secuobs.com/twitter/news/266468.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/266468.shtml</guid></item>
<item><title> Seeing the term self-XSS create some confusion in the tech media about the differences between it and actual XSS</title><description>Secuobs.com : 2011-11-16 22:50:13 - theharmonyguy -  Seeing the term self-XSS create some confusion in the tech media about the differences between it and actual XSS</description><link>http://www.secuobs.com/twitter/news/266467.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/266467.shtml</guid></item>
<item><title> @Ansjh Getting a user to paste JavaScript into the address bar Same effect as XSS, but the user manually executes the script</title><description>Secuobs.com : 2011-11-16 22:50:13 - theharmonyguy -  @Ansjh Getting a user to paste JavaScript into the address bar Same effect as XSS, but the user manually executes the script</description><link>http://www.secuobs.com/twitter/news/266466.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/266466.shtml</guid></item>
<item><title> If XSS is someone poisoning your drink, self-XSS is you poisoning it yourself and browser patches for self-XSS are locks on your poison jar</title><description>Secuobs.com : 2011-11-16 22:50:13 -  theharmonyguy -  If XSS is someone poisoning your drink, self-XSS is you poisoning it yourself and browser patches for self-XSS are locks on your poison jar</description><link>http://www.secuobs.com/twitter/news/266465.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/266465.shtml</guid></item>
<item><title> @satnam @paperghost @Wh1t3Rabbit Maybe for quicker detection and limiting scope, but we are talking XSS here - only so much you can do</title><description>Secuobs.com : 2011-11-16 09:54:29 - theharmonyguy -  @satnam @paperghost @Wh1t3Rabbit Maybe for quicker detection and limiting scope, but we are talking XSS here - only so much you can do</description><link>http://www.secuobs.com/twitter/news/266294.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/266294.shtml</guid></item>
<item><title> RT @lcamtuf: The Tangled Web is out Instantly downloadable PDF with print copies Use code TANGLEDWEB to get 40 pourcents off: http://tco/ZpM </title><description>Secuobs.com : 2011-11-16 01:38:45 - theharmonyguy -  RT @lcamtuf: The Tangled Web is out Instantly downloadable PDF with print copies Use code TANGLEDWEB to get 40 pourcents off: http://tco/ZpM </description><link>http://www.secuobs.com/twitter/news/266134.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/266134.shtml</guid></item>
<item><title> @jjarmoc Copy/paste XSS scams have spread pretty well in the past I wonder what browsers the victims were using</title><description>Secuobs.com : 2011-11-16 01:38:45 - theharmonyguy -  @jjarmoc Copy/paste XSS scams have spread pretty well in the past I wonder what browsers the victims were using</description><link>http://www.secuobs.com/twitter/news/266133.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/266133.shtml</guid></item>
<item><title> @skeptic_fx Death The JavaScript frame buster is still there in addition to X-Frame-Options</title><description>Secuobs.com : 2011-11-12 02:39:39 - theharmonyguy -  @skeptic_fx Death The JavaScript frame buster is still there in addition to X-Frame-Options</description><link>http://www.secuobs.com/twitter/news/265301.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/265301.shtml</guid></item>
<item><title> RT @ErikArvidsson: Operator  and = overloading in JavaScript* http://tco/qB1hCisi* = Traceur Compiler</title><description>Secuobs.com : 2011-11-12 02:39:39 - theharmonyguy -  RT @ErikArvidsson: Operator  and = overloading in JavaScript* http://tco/qB1hCisi* = Traceur Compiler</description><link>http://www.secuobs.com/twitter/news/265300.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/265300.shtml</guid></item>
<item><title> RT @securityninja: RT @XSSniper: Try SQLi on this  http://tco/zjNBR5yC</title><description>Secuobs.com : 2011-11-11 01:01:48 - theharmonyguy -  RT @securityninja: RT @XSSniper: Try SQLi on this  http://tco/zjNBR5yC</description><link>http://www.secuobs.com/twitter/news/264959.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/264959.shtml</guid></item>
<item><title> @garethheyes So if xss= or iframe, style, etc, the 2nd lives But attribs stripped, scripts whitelisted</title><description>Secuobs.com : 2011-11-11 01:01:48 - theharmonyguy -  @garethheyes So if xss= or iframe, style, etc, the 2nd lives But attribs stripped, scripts whitelisted</description><link>http://www.secuobs.com/twitter/news/264958.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/264958.shtml</guid></item>
<item><title> @KimZetter Shouldn't it be DNS hijacking, not clickjacking Not trying to be too picky, but accepted definition of latter is different</title><description>Secuobs.com : 2011-11-10 00:26:37 - theharmonyguy -  @KimZetter Shouldn't it be DNS hijacking, not clickjacking Not trying to be too picky, but accepted definition of latter is different</description><link>http://www.secuobs.com/twitter/news/264384.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/264384.shtml</guid></item>
<item><title> @Joab_Jackson Shouldn't it be DNS hijacking, not clickjacking Not trying to be too picky, but latter's accepted definition is different</title><description>Secuobs.com : 2011-11-10 00:26:37 -  theharmonyguy -  @Joab_Jackson Shouldn't it be DNS hijacking, not clickjacking Not trying to be too picky, but latter's accepted definition is different</description><link>http://www.secuobs.com/twitter/news/264383.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/264383.shtml</guid></item>
<item><title> RT @jonoberheide: For everyone freaking out over UDP: it's a refcount so it'll probably take 2^32 packets to overflow the counter, and o </title><description>Secuobs.com : 2011-11-09 16:37:48 - theharmonyguy -  RT @jonoberheide: For everyone freaking out over UDP: it's a refcount so it'll probably take 2^32 packets to overflow the counter, and o </description><link>http://www.secuobs.com/twitter/news/264244.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/264244.shtml</guid></item>
<item><title> @skeptic_fx Ah, correct - I didn't realize Firefox had removed execution of javascript: URLs in the address bar with version 6</title><description>Secuobs.com : 2011-11-09 16:37:48 -  theharmonyguy -  @skeptic_fx Ah, correct - I didn't realize Firefox had removed execution of javascript: URLs in the address bar with version 6</description><link>http://www.secuobs.com/twitter/news/264243.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/264243.shtml</guid></item>
<item><title> @garethheyes Does that actually execute the script on one browser I tried it in Chrome, Firefox, and IE</title><description>Secuobs.com : 2011-11-08 23:01:21 - theharmonyguy -  @garethheyes Does that actually execute the script on one browser I tried it in Chrome, Firefox, and IE</description><link>http://www.secuobs.com/twitter/news/264050.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/264050.shtml</guid></item>
<item><title> @garethheyes Hmm, not working for me in FF7 and Chrome 17, though the output is different</title><description>Secuobs.com : 2011-11-08 23:01:21 - theharmonyguy -  @garethheyes Hmm, not working for me in FF7 and Chrome 17, though the output is different</description><link>http://www.secuobs.com/twitter/news/264049.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/264049.shtml</guid></item>
<item><title> @superevr @garethheyes I want to play with these vectors, but for me, the img stays in comments on Chrome/IE, attribs get stripped in FF</title><description>Secuobs.com : 2011-11-08 23:01:21 - theharmonyguy -  @superevr @garethheyes I want to play with these vectors, but for me, the img stays in comments on Chrome/IE, attribs get stripped in FF</description><link>http://www.secuobs.com/twitter/news/264048.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/264048.shtml</guid></item>
<item><title> @AndyPalmer Type +pepsi in Chrome's address bar</title><description>Secuobs.com : 2011-11-08 04:14:54 -  theharmonyguy -  @AndyPalmer Type +pepsi in Chrome's address bar</description><link>http://www.secuobs.com/twitter/news/263835.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/263835.shtml</guid></item>
<item><title> @garethheyes I was thinking maybe you could set a payload for windowonload that would execute after JSLR has run</title><description>Secuobs.com : 2011-11-07 23:22:38 - theharmonyguy -  @garethheyes I was thinking maybe you could set a payload for windowonload that would execute after JSLR has run</description><link>http://www.secuobs.com/twitter/news/263729.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/263729.shtml</guid></item>
<item><title> Interesting: Amazon noticed I'd been ignoring all their AmazonLocal emails, so they're automatically unsubscribing me</title><description>Secuobs.com : 2011-11-07 23:22:38 - theharmonyguy -  Interesting: Amazon noticed I'd been ignoring all their AmazonLocal emails, so they're automatically unsubscribing me</description><link>http://www.secuobs.com/twitter/news/263728.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/263728.shtml</guid></item>
<item><title> If you love XSS challenges and you aren't trying to tear apart JSLR, you're seriously missing out: http://tco/W9PmQuP6</title><description>Secuobs.com : 2011-11-07 23:22:38 - theharmonyguy -  If you love XSS challenges and you aren't trying to tear apart JSLR, you're seriously missing out: http://tco/W9PmQuP6</description><link>http://www.secuobs.com/twitter/news/263727.shtml</link><guid isPermaLink="false">http://www.secuobs.com/twitter/news/263727.shtml</guid></item>
</channel>
</rss>
 
