<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Android executes everything you type</title>
	<atom:link href="http://hackaday.com/2008/11/09/android-executes-everything-you-type/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com/2008/11/09/android-executes-everything-you-type/</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Wed, 25 Nov 2009 17:45:18 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: cde</title>
		<link>http://hackaday.com/2008/11/09/android-executes-everything-you-type/comment-page-1/#comment-50233</link>
		<dc:creator>cde</dc:creator>
		<pubDate>Mon, 10 Nov 2008 20:38:46 +0000</pubDate>
		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=5660#comment-50233</guid>
		<description>@mrlipring
Credit where credit is due -_-

http://xkcd.com/327/</description>
		<content:encoded><![CDATA[<p>@mrlipring<br />
Credit where credit is due -_-</p>
<p><a href="http://xkcd.com/327/" rel="nofollow">http://xkcd.com/327/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mrlipring</title>
		<link>http://hackaday.com/2008/11/09/android-executes-everything-you-type/comment-page-1/#comment-50231</link>
		<dc:creator>mrlipring</dc:creator>
		<pubDate>Mon, 10 Nov 2008 19:54:11 +0000</pubDate>
		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=5660#comment-50231</guid>
		<description>Reminds me of this:

School: Did you really name your son Robert&#039;); Drop Table Students;--?
Mom: Oh. Yes. Little Bobby Tables we call him
School: Well, we&#039;ve lost this year&#039;s student records. I hope you&#039;re happy.
Mom: and I hope you&#039;ve learned to sanitize your database inputs.</description>
		<content:encoded><![CDATA[<p>Reminds me of this:</p>
<p>School: Did you really name your son Robert&#8217;); Drop Table Students;&#8211;?<br />
Mom: Oh. Yes. Little Bobby Tables we call him<br />
School: Well, we&#8217;ve lost this year&#8217;s student records. I hope you&#8217;re happy.<br />
Mom: and I hope you&#8217;ve learned to sanitize your database inputs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PocketBrain</title>
		<link>http://hackaday.com/2008/11/09/android-executes-everything-you-type/comment-page-1/#comment-50183</link>
		<dc:creator>PocketBrain</dc:creator>
		<pubDate>Mon, 10 Nov 2008 15:12:51 +0000</pubDate>
		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=5660#comment-50183</guid>
		<description>Reminds me of a friend from college who had to use a pseudonym to shop at Service Merchandise (they had a terminal entry supply system that shoppers could use).  His last name was &quot;Cancel&quot;.  Seriously. His orders would get canceled (no surprise) when submitted.</description>
		<content:encoded><![CDATA[<p>Reminds me of a friend from college who had to use a pseudonym to shop at Service Merchandise (they had a terminal entry supply system that shoppers could use).  His last name was &#8220;Cancel&#8221;.  Seriously. His orders would get canceled (no surprise) when submitted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anne H</title>
		<link>http://hackaday.com/2008/11/09/android-executes-everything-you-type/comment-page-1/#comment-50099</link>
		<dc:creator>Anne H</dc:creator>
		<pubDate>Mon, 10 Nov 2008 03:20:07 +0000</pubDate>
		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=5660#comment-50099</guid>
		<description>This reminds me of an early issue with Dow Jones News Retrieval Quotes during the dial-up dials. I don&#039;t recall which company had the ticker symbol &quot;DISC&quot; back then, but if you had it in your portfolio and requeted the quote, their service hung up. It was understood as DISConnect.</description>
		<content:encoded><![CDATA[<p>This reminds me of an early issue with Dow Jones News Retrieval Quotes during the dial-up dials. I don&#8217;t recall which company had the ticker symbol &#8220;DISC&#8221; back then, but if you had it in your portfolio and requeted the quote, their service hung up. It was understood as DISConnect.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jaduncan</title>
		<link>http://hackaday.com/2008/11/09/android-executes-everything-you-type/comment-page-1/#comment-50070</link>
		<dc:creator>jaduncan</dc:creator>
		<pubDate>Sun, 09 Nov 2008 23:04:16 +0000</pubDate>
		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=5660#comment-50070</guid>
		<description>The SUID problem on telnet is then presumably not a SUID problem. User account types it, telnetd fails to create the port. However, the background root service starts it. For further fun of this type, merely enter &quot;rm -rf /&quot; as the user and wait for the phone to turn off by itself!</description>
		<content:encoded><![CDATA[<p>The SUID problem on telnet is then presumably not a SUID problem. User account types it, telnetd fails to create the port. However, the background root service starts it. For further fun of this type, merely enter &#8220;rm -rf /&#8221; as the user and wait for the phone to turn off by itself!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: macegr</title>
		<link>http://hackaday.com/2008/11/09/android-executes-everything-you-type/comment-page-1/#comment-50067</link>
		<dc:creator>macegr</dc:creator>
		<pubDate>Sun, 09 Nov 2008 22:32:45 +0000</pubDate>
		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=5660#comment-50067</guid>
		<description>I&#039;m having difficulty figuring out how this could have been set up accidentally. It must have been used to run some commands in the early tests before the user interface was completely finished.</description>
		<content:encoded><![CDATA[<p>I&#8217;m having difficulty figuring out how this could have been set up accidentally. It must have been used to run some commands in the early tests before the user interface was completely finished.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: herbicide</title>
		<link>http://hackaday.com/2008/11/09/android-executes-everything-you-type/comment-page-1/#comment-50066</link>
		<dc:creator>herbicide</dc:creator>
		<pubDate>Sun, 09 Nov 2008 22:29:34 +0000</pubDate>
		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=5660#comment-50066</guid>
		<description>That&#039;s a definite oops.</description>
		<content:encoded><![CDATA[<p>That&#8217;s a definite oops.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sean</title>
		<link>http://hackaday.com/2008/11/09/android-executes-everything-you-type/comment-page-1/#comment-50064</link>
		<dc:creator>Sean</dc:creator>
		<pubDate>Sun, 09 Nov 2008 21:52:51 +0000</pubDate>
		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=5660#comment-50064</guid>
		<description>wow... how could that be missed? that is certainly one enormous design flaw.</description>
		<content:encoded><![CDATA[<p>wow&#8230; how could that be missed? that is certainly one enormous design flaw.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PocketBrain</title>
		<link>http://hackaday.com/2008/11/09/android-executes-everything-you-type/comment-page-1/#comment-50060</link>
		<dc:creator>PocketBrain</dc:creator>
		<pubDate>Sun, 09 Nov 2008 21:20:20 +0000</pubDate>
		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=5660#comment-50060</guid>
		<description>How did _that_ one get by the dev team?  Just think of the power you have... to accidentally screw things up.  Maybe it was a debug feature that was supposed to be closed up and wasn&#039;t.</description>
		<content:encoded><![CDATA[<p>How did _that_ one get by the dev team?  Just think of the power you have&#8230; to accidentally screw things up.  Maybe it was a debug feature that was supposed to be closed up and wasn&#8217;t.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TheBlunderbuss</title>
		<link>http://hackaday.com/2008/11/09/android-executes-everything-you-type/comment-page-1/#comment-50057</link>
		<dc:creator>TheBlunderbuss</dc:creator>
		<pubDate>Sun, 09 Nov 2008 21:01:49 +0000</pubDate>
		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=5660#comment-50057</guid>
		<description>It&#039;s not a bug either!</description>
		<content:encoded><![CDATA[<p>It&#8217;s not a bug either!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: therian</title>
		<link>http://hackaday.com/2008/11/09/android-executes-everything-you-type/comment-page-1/#comment-50052</link>
		<dc:creator>therian</dc:creator>
		<pubDate>Sun, 09 Nov 2008 20:50:23 +0000</pubDate>
		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=5660#comment-50052</guid>
		<description>this is not a but, it is a feature :)</description>
		<content:encoded><![CDATA[<p>this is not a but, it is a feature :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
