<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Exploit-Me Firefox XSS and SQL scanning addon</title>
	<atom:link href="http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Tue, 24 Nov 2009 00:09:23 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: dan sinclair</title>
		<link>http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/comment-page-1/#comment-36976</link>
		<dc:creator>dan sinclair</dc:creator>
		<pubDate>Mon, 16 Jun 2008 16:49:12 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/#comment-36976</guid>
		<description>@sb: All of the tools are open sourced so if you&#039;re concerned with malicious activity you&#039;re free to audit the tools as you want. We&#039;ve been careful to remove anything that might be thought to track people. That&#039;s why we don&#039;t have any of the XSS attacks that reference external .js files included by default.&lt;br&gt;&lt;br&gt;@hali: Out of curiosity, where did you download the .xpi file from? Are you trying to say that running the xpi added a file to your desktop or it somehow downloaded a secondary file?&lt;br&gt;&lt;br&gt;The Exploit-Me files are .xpi files. They aren&#039;t exe&#039;s. They only run within Firefox.</description>
		<content:encoded><![CDATA[<p>@sb: All of the tools are open sourced so if you&#8217;re concerned with malicious activity you&#8217;re free to audit the tools as you want. We&#8217;ve been careful to remove anything that might be thought to track people. That&#8217;s why we don&#8217;t have any of the XSS attacks that reference external .js files included by default.</p>
<p>@hali: Out of curiosity, where did you download the .xpi file from? Are you trying to say that running the xpi added a file to your desktop or it somehow downloaded a secondary file?</p>
<p>The Exploit-Me files are .xpi files. They aren&#8217;t exe&#8217;s. They only run within Firefox.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hali</title>
		<link>http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/comment-page-1/#comment-36975</link>
		<dc:creator>Hali</dc:creator>
		<pubDate>Sun, 15 Jun 2008 01:59:43 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/#comment-36975</guid>
		<description>Beware, when I clicked the link to download this firefox plug-in, it dumped a file called &quot;xm86zte5.exe&quot; on my desktop.  I purged the file immediately.  Not sure what it does but that was unexpected behaviour.  This may be a malicious site.</description>
		<content:encoded><![CDATA[<p>Beware, when I clicked the link to download this firefox plug-in, it dumped a file called &#8220;xm86zte5.exe&#8221; on my desktop.  I purged the file immediately.  Not sure what it does but that was unexpected behaviour.  This may be a malicious site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Berube</title>
		<link>http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/comment-page-1/#comment-36974</link>
		<dc:creator>John Berube</dc:creator>
		<pubDate>Sat, 14 Jun 2008 17:09:30 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/#comment-36974</guid>
		<description>@SB: Well you can download the source</description>
		<content:encoded><![CDATA[<p>@SB: Well you can download the source</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick Fury</title>
		<link>http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/comment-page-1/#comment-36973</link>
		<dc:creator>Nick Fury</dc:creator>
		<pubDate>Sat, 14 Jun 2008 15:45:11 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/#comment-36973</guid>
		<description>I saw Dan present this at CarolinaCOn this past year along with a friend of his named Sahba (I hope I spelled that right).  It was a really interesting concept and led to some great questions from the audience.</description>
		<content:encoded><![CDATA[<p>I saw Dan present this at CarolinaCOn this past year along with a friend of his named Sahba (I hope I spelled that right).  It was a really interesting concept and led to some great questions from the audience.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ~SB</title>
		<link>http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/comment-page-1/#comment-36972</link>
		<dc:creator>~SB</dc:creator>
		<pubDate>Sat, 14 Jun 2008 13:54:48 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/#comment-36972</guid>
		<description>are these safe,&lt;br&gt;i mean no malicious activity in the background...</description>
		<content:encoded><![CDATA[<p>are these safe,<br />i mean no malicious activity in the background&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
