<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hacking-Gurus &#187; Web Applications</title>
	<atom:link href="http://www.hacking-gurus.net/tag/web-applications/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hacking-gurus.net</link>
	<description>Security Blog</description>
	<lastBuildDate>Sun, 22 Aug 2010 18:31:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Sahi V3</title>
		<link>http://www.hacking-gurus.net/2010/08/12/sahi-v3/</link>
		<comments>http://www.hacking-gurus.net/2010/08/12/sahi-v3/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 17:24:53 +0000</pubDate>
		<dc:creator>r00t</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Automation Tool]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[Proxy]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Texts]]></category>
		<category><![CDATA[Web Applications]]></category>
		<category><![CDATA[Web Pages]]></category>

		<guid isPermaLink="false">http://www.hacking-gurus.net/?p=201</guid>
		<description><![CDATA[
		
		
		
		Sahi V3: &#8220;Sahi is an automation tool to test web applications. Sahi injects javascript into web pages using a proxy and the javascript helps automate web applications.

(Via Hackers Center &#8211; Security Tools and Texts.)
]]></description>
			<content:encoded><![CDATA[<div style="float: right; width: 42px; padding-right: 10px; margin: 0 0 0 10px;">
		<script type="text/javascript">
		<!--
		digg_url = "http://www.hacking-gurus.net/2010/08/12/sahi-v3/";
		digg_bgcolor = "#FFFFFF";
		digg_skin = "";
		digg_window = "new";
		digg_title = "Sahi+V3";
		digg_media = "news";
		digg_topic = "";
		digg_bodytext = "Sahi V3: &#8220;Sahi is an automation tool to test web applications. Sahi injects javascript into web pages using a proxy and the javascript helps automate web applications.(Via Hackers Center &#8211; Security Tools and Texts.)";
		//-->
		</script>
		<script src="http://digg.com/tools/diggthis.js" type="text/javascript"></script></div><p><a href="http://feedproxy.google.com/~r/hackerscenter/HSCArchive/~3/3tJonkf9Gto/index.php">Sahi V3</a>: &#8220;<strong>Sahi</strong> is an automation tool to test web applications. Sahi injects javascript into web pages using a proxy and the javascript helps automate web applications.</p>
<p><span id="more-201"></span></p>
<p>(Via <a href="http://www.hackerscenter.com">Hackers Center &#8211; Security Tools and Texts</a>.)</p>
<img src="http://www.hacking-gurus.net/wp-content/plugins/pixelstats/trackingpixel.php?post_id=201&ts=1284071222" style="display:none;" alt="pixelstats trackingpixel"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacking-gurus.net/2010/08/12/sahi-v3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Top 10 Web Application security vulnerabilities</title>
		<link>http://www.hacking-gurus.net/2009/09/30/the-top-10-web-application-security-vulnerabilities/</link>
		<comments>http://www.hacking-gurus.net/2009/09/30/the-top-10-web-application-security-vulnerabilities/#comments</comments>
		<pubDate>Wed, 30 Sep 2009 05:24:02 +0000</pubDate>
		<dc:creator>r00t</dc:creator>
				<category><![CDATA[Server Security]]></category>
		<category><![CDATA[Tutorialz]]></category>
		<category><![CDATA[Website Security]]></category>
		<category><![CDATA[Common Security]]></category>
		<category><![CDATA[Critical Web]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Example Web]]></category>
		<category><![CDATA[Html Page]]></category>
		<category><![CDATA[Input Data]]></category>
		<category><![CDATA[Open Web]]></category>
		<category><![CDATA[Owasp]]></category>
		<category><![CDATA[Proper Html]]></category>
		<category><![CDATA[Query Parameters]]></category>
		<category><![CDATA[Security Problems]]></category>
		<category><![CDATA[Security Project]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Swingset]]></category>
		<category><![CDATA[Top Ten Security]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[Web Applications]]></category>
		<category><![CDATA[Webgoat]]></category>
		<category><![CDATA[Writeln]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hacking-gurus.net/?p=164</guid>
		<description><![CDATA[
		
		
		
		The Top 10 Web Application security vulnerabilities


This and the next series of blog entries will highlight the Top 10 most critical web application security vulnerabilities identified by the Open Web Application Security Project (OWASP).
You can use OWASP&#8217;s WebGoat to learn more about the OWASP Top Ten security vulnerabilties. WebGoat is an example web application, which has lessons showing [...]]]></description>
			<content:encoded><![CDATA[<div style="float: right; width: 42px; padding-right: 10px; margin: 0 0 0 10px;">
		<script type="text/javascript">
		<!--
		digg_url = "http://www.hacking-gurus.net/2009/09/30/the-top-10-web-application-security-vulnerabilities/";
		digg_bgcolor = "#FFFFFF";
		digg_skin = "";
		digg_window = "new";
		digg_title = "The+Top+10+Web+Application+security+vulnerabilities";
		digg_media = "news";
		digg_topic = "";
		digg_bodytext = "The Top 10 Web Application security vulnerabilitiesThis and the next series of blog entries will highlight the Top 10 most critical web application security vulnerabilities identified by the Open Web Application Security Project (OWASP).You can use OWASP&#8217;s WebGoat to learn more about the OWASP Top Ten security vulnerabilties. WebGoat is an...";
		//-->
		</script>
		<script src="http://digg.com/tools/diggthis.js" type="text/javascript"></script></div><p><span style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;">The Top 10 Web Application security vulnerabilities<br />
<span id="more-164"></span></p>
<h1></h1>
<p>This and the next series of blog entries will highlight the <a style="color: #2244bb;" href="http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project" target="_blank">Top 10 most critical web application security vulnerabilities</a> identified by the <a style="color: #2244bb;" href="http://www.owasp.org/index.php/Main_Page" target="_blank">Open Web Application Security Project (OWASP)</a>.</p>
<p>You can use OWASP&#8217;s <a style="color: #2244bb;" href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project" target="_blank">WebGoat</a> to learn more about the OWASP Top Ten security vulnerabilties. WebGoat is an example web application, which has lessons showing &#8220;what not to do code&#8221;, how to exploit the code, and corrected code for each vulnerability.</p>
<p><img style="width: 300px; height: 252px;" src="http://blogs.sun.com/carolmcdonald/resource/300px-WebGoat-Phishing-XSS-Lesson.JPG" alt="" /></p>
<p>You can use the <a style="color: #2244bb;" href="http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API" target="_blank">OWASP Enterprise Security API </a>Toolkit to protect against the OWASP Top Ten security vulnerabilties.</p>
<p><img style="width: 550px; height: 314px;" src="http://blogs.sun.com/carolmcdonald/resource/550px-Esapi-before-after.JPG" alt="" /></p>
<p><a style="color: #2244bb;" href="http://www.owasp.org/index.php/ESAPI_Swingset" target="_blank">The ESAPI Swingset </a>is a web application which demonstrates the many uses of the Enterprise Security API.</p>
<p><img style="width: 352px; height: 325px;" src="http://blogs.sun.com/carolmcdonald/resource/swingset.jpg" alt="" /></p>
<h2>OWASP Top 10 number 1: XSS = Cross Site Scripting</h2>
<p>Cross Site Scripting (XSS) is one of the most common security problems in today&#8217;s web applications. According to the <a style="color: #2244bb;" href="http://www.sans.org/top-cyber-security-risks/" target="_blank">SANS Top Cyber Security Risks</a>, 60% of the total attack attempts observed on the Internet are against Web applications and SQL injection and Cross-Site Scripting account for more than 80% of the vulnerabilities being discovered. You are at risk of an XSS attack any time you put content that could contain scripts from someone un-trusted into your web pages.<br />
There are 3 types of cross site scripting:</p>
<ul>
<li><span style="font-weight: bold;">Reflected XSS: </span>is when an html page reflects user input data, e.g. from HTTP query parameters or a HTML form, back to the browser, without properly sanitizing the response. Below is an example of this in a servlet:</li>
</ul>
<p></span></p>
<table border="0" cellspacing="0" cellpadding="10" width="100%">
<tbody>
<tr>
<td>
<pre style="font-size: 11px;"> out.writeln(“You searched for: “+request.getParameter(“query”);</pre>
</td>
</tr>
</tbody>
</table>
<p><span style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"></p>
<ul>
<li></li>
<li><span style="font-weight: bold;">Stored XSS:</span> is when an Attacker’s input script is stored on the server (eg a database) and later displayed in the web server html pages, without proper HTML filtering. Examples of this are in blogs, or forums where users can input data that will be displayed to others. Below is an example of this in a servlet data is retrieved from the database and returned in the HTML page without any validation:</li>
</ul>
<p></span></p>
<table border="0" cellspacing="0" cellpadding="10" width="100%">
<tbody>
<tr>
<td>
<pre style="font-size: 11px;">out.writeln("&lt;tr&gt;&lt;td&gt;" + guest.name + "&lt;td&gt;" + guest.comment);</pre>
</td>
</tr>
</tbody>
</table>
<p><span style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"></p>
<ul>
<li></li>
<li><span style="font-weight: bold;">DOM XSS</span>: is when JavaScript uses input data or data from the server to write dynamic HTML (DOM) elements, again without HTML sanitizing/escaping/filtering.</li>
</ul>
<p>XSS can be used to:</p>
<ul>
<li>deface web pages</li>
<li>hijack user sessions</li>
<li>conduct phishing attacks</li>
<li>execute malicious code in the context of the user&#8217;s session</li>
<li>spread malware</li>
</ul>
<h3>Protecting against XSS</h3>
<p>To protect against XSS all the parameters in the application should be validated and/or encoded before being output in HTML pages.</p>
<ul>
<li>Always validate on the server side for data integrity and security:
<ul>
<li>Validate all input data to the application:</li>
<li>Validate for type, format, length, range, and context before storing or displaying</li>
<li>Use white-listing (what is allowed), reject if invalid, instead of filtering out black-list (what is not allowed)</li>
</ul>
</li>
<li>Output encoding:
<ul>
<li>Explicitly set character encoding for all web pages (ISO-8859-1 or UTF 8):<br />
<span style="font-family: monospace;">&lt;%@ page contentType=&#8221;text/html;charset=ISO-8859-1&#8243; language=&#8221;java&#8221; %&gt;</span></li>
<li>all user supplied data should be HTML or XML entity encoded before rendering</li>
</ul>
</li>
</ul>
<h3>Java specific Protecting against XSS</h3>
<h4>Validating Input with Java</h4>
<ul>
<li>You can use Java regular expressions to validate input, this example from WebGoat allows whitespace, a-zA-Z_0-9, and the characters &#8211; and ,</li>
</ul>
<p></span></p>
<table border="0" cellspacing="0" cellpadding="10" width="100%">
<tbody>
<tr>
<td>
<pre style="font-size: 11px;">
String regex = "[\s\w-,]*";
Pattern pattern = Pattern.compile(regex);
validate(stringToValidate, pattern);</pre>
</td>
</tr>
</tbody>
</table>
<p><span style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"></p>
<ul>
<li></li>
<li>Use Framework (Struts, JSF, Spring&#8230;) validators. With Java EE 6 you can use the Bean Validation Framework to centrally define validation constraints on model objects and with JSF 2.0 to extend model validation to the UI. For example here is a JSF 2.0 input field:</li>
</ul>
<p></span></p>
<table border="0" cellspacing="0" cellpadding="10" width="100%">
<tbody>
<tr>
<td>
<pre style="font-size: 11px;">&lt;h:inputText id="creditCard" value="#{booking.creditCardNumber}"/&gt;</pre>
</td>
</tr>
</tbody>
</table>
<p><span style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"></p>
<ul>
<li><span style="font-weight: bold;"> </span>Here is the JSF 2.0 booking Managed Bean using the Bean Validation Framework :</li>
</ul>
<p></span></p>
<table border="0" cellspacing="0" cellpadding="10" width="100%">
<tbody>
<tr>
<td>
<pre style="font-size: 11px;">@ManagedBean
public class Booking {
 ...
 @NotNull(message = "Credit card number is required")
 @Size(min = 16, max = 16,
 message = "Credit card number must 16 digits long")
 @Pattern(regexp = "^\d*$",
 message = "Credit card number must be numeric")
 public String getCreditCardNumber() {
 return creditCardNumber;
 }
}</pre>
</td>
</tr>
</tbody>
</table>
<p><span style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"></p>
<ul>
<li>In addition there are new JSF 2.0 Validators:
<ul>
<li><a style="color: #2244bb;" href="https://javaserverfaces.dev.java.net/nonav/docs/2.0/pdldocs/facelets/f/validateBean.html" target="_blank">&lt;f:validateBean&gt;</a> is a validator that delegates the validation of the local value to the Bean Validation API.</li>
<li>&lt;f:validateRequired&gt; provides required field validation.</li>
<li><a style="color: #2244bb;" href="https://javaserverfaces.dev.java.net/nonav/docs/2.0/pdldocs/facelets/f/validateRegex.html" target="_blank">&lt;f:validateRegexp&gt;</a> provides regular expression-based validation</li>
</ul>
</li>
<li>Use the <a style="color: #2244bb;" href="http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API" target="_blank">OWASP Enterprise Security API</a> Java Toolkit&#8217;s Validator interface:</li>
</ul>
<p></span></p>
<table border="0" cellspacing="0" cellpadding="10" width="100%">
<tbody>
<tr>
<td>
<pre style="font-size: 11px;">ESAPI.validator().getValidInput(String context,String input,String type,int maxLength,
   boolean allowNull,ValidationErrorList errorList)</pre>
</td>
</tr>
</tbody>
</table>
<p><span style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"></p>
<ul>
<li><span style="font-family: monospace;">ESAPI.validator().getValidInput() </span>returns canonicalized and validated input as a String. Invalid input will generate a descriptive ValidationErrorList, and input that is clearly an attack will generate a descriptive IntrusionException.</li>
</ul>
<h4>Output Encoding with Java</h4>
<ul>
<li>You can use Struts output mechanisms such as <span style="font-family: monospace;">&lt;bean:write… &gt;, </span>or use the default JSTL<span style="font-family: monospace;">escapeXML=&#8221;true&#8221;</span> attribute in <span style="font-family: monospace;">&lt;c:out … &gt; </span></li>
<li>You can use the <a style="color: #2244bb;" href="http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API" target="_blank">OWASP Enterprise Security API</a> Java Toolkit&#8217;s <span style="font-family: monospace;">ESAPI Encoder.encodeForHTML()</span>method to encode data for use in HTML content. The encodeForHTML() method uses a &#8220;whitelist&#8221; HTML entity encoding algorithm to ensure that encoded data can not be interpreted as script. This call should be used to wrap any user input being rendered in HTML element content. For example:</li>
</ul>
<p></span></p>
<table border="0" cellspacing="0" cellpadding="10" width="100%">
<tbody>
<tr>
<td><span style="font-family: monospace;">&lt;p&gt;Hello, &lt;%=ESAPI.encoder().encodeForHTML(name)%&gt;&lt;/p&gt;</span></td>
</tr>
</tbody>
</table>
<img src="http://www.hacking-gurus.net/wp-content/plugins/pixelstats/trackingpixel.php?post_id=164&ts=1284071222" style="display:none;" alt="pixelstats trackingpixel"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacking-gurus.net/2009/09/30/the-top-10-web-application-security-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Cross Site Scripting (XSS) Explained!</title>
		<link>http://www.hacking-gurus.net/2009/09/21/cross-site-scripting-xss-explained/</link>
		<comments>http://www.hacking-gurus.net/2009/09/21/cross-site-scripting-xss-explained/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 03:44:56 +0000</pubDate>
		<dc:creator>r00t</dc:creator>
				<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Network Tools]]></category>
		<category><![CDATA[Tutorialz]]></category>
		<category><![CDATA[Arne]]></category>
		<category><![CDATA[Input Output]]></category>
		<category><![CDATA[Latest Software]]></category>
		<category><![CDATA[Legitimate User]]></category>
		<category><![CDATA[Malicious Hackers]]></category>
		<category><![CDATA[Output Tags]]></category>
		<category><![CDATA[Pointer]]></category>
		<category><![CDATA[Scripts]]></category>
		<category><![CDATA[Software Websites]]></category>
		<category><![CDATA[Validation]]></category>
		<category><![CDATA[Video Series]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Web Applications]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hacking-gurus.net/?p=148</guid>
		<description><![CDATA[
		
		
		
		Cross Site Scripting (XSS) is a code injection vulnerability found in web applications and is generally used by malicious hackers to hijack a legitimate user&#8217;s session with the website. XSS vulnerabilities are caused because of improper validation of user input by the Server and then sending this invalidated input back to the user in some [...]]]></description>
			<content:encoded><![CDATA[<div style="float: right; width: 42px; padding-right: 10px; margin: 0 0 0 10px;">
		<script type="text/javascript">
		<!--
		digg_url = "http://www.hacking-gurus.net/2009/09/21/cross-site-scripting-xss-explained/";
		digg_bgcolor = "#FFFFFF";
		digg_skin = "";
		digg_window = "new";
		digg_title = "Cross+Site+Scripting+%28XSS%29+Explained%21";
		digg_media = "news";
		digg_topic = "";
		digg_bodytext = "Cross Site Scripting (XSS) is a code injection vulnerability found in web applications and is generally used by malicious hackers to hijack a legitimate user&#8217;s session with the website. XSS vulnerabilities are caused because of improper validation of user input by the Server and then sending this invalidated input back to the user in some exploitable...";
		//-->
		</script>
		<script src="http://digg.com/tools/diggthis.js" type="text/javascript"></script></div><p><a href="http://en.wikipedia.org/wiki/Cross-site_scripting" target="_blank">Cross Site Scripting (XSS)</a> is a code injection vulnerability found in web applications and is generally used by malicious hackers to hijack a legitimate user&#8217;s session with the website. XSS vulnerabilities are caused because of improper validation of user input by the Server and then sending this invalidated input back to the user in some exploitable form. A great resource to track the latest XSS vulnerable software, websites and latest research is <a href="http://xssed.com/" target="_blank">XSSed.com</a></p>
<p><span id="more-148"></span></p>
<p>In this 4 part video series <a href="http://www.aachen-method.com/" target="_blank">Arne from Aachen Method</a> gives a detailed primer on XSS.</p>
<p>1. <span style="font-weight: bold;">Quick Overview</span>: This video explains the basics of XSS, kinds of XSS &#8211; Persistent, Non-Persistent and DOM based.</p>
<div><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="500" height="525" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/yzJG7GPuFyo&amp;hl=en&amp;fs=1&amp;color1=0x2b405b&amp;color2=0x6b8ab6&amp;border=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="500" height="525" src="http://www.youtube.com/v/yzJG7GPuFyo&amp;hl=en&amp;fs=1&amp;color1=0x2b405b&amp;color2=0x6b8ab6&amp;border=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></div>
<div>2. <span style="font-weight: bold;">Protecting your Website against XSS Attacks</span>: This video explains various techniques which can be used to mitigate XSS vulnerabilities on your website &#8211; input / output validation, modification of output tags etc.</div>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.youtube.com/v/bF8UpDbAuJk&amp;rel=0&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=en&amp;feature=player_embedded&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/bF8UpDbAuJk&amp;rel=0&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=en&amp;feature=player_embedded&amp;fs=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>3. <span style="font-weight: bold;">Finding XSS weaknesses in websites</span>: Pointer to Rsnake&#8217;s website <a href="http://ha.ckers.org/xss.html" target="_blank">http://ha.ckers.org/xss.html</a></p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.youtube.com/v/ETav2QMvmK4&amp;rel=0&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=en&amp;feature=player_embedded&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/ETav2QMvmK4&amp;rel=0&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=en&amp;feature=player_embedded&amp;fs=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>4. <span style="font-weight: bold;">Protecting yourself from XSS attacks as a user</span>: By turning off scripts, not clicking on untrusted links etc.</p>
<p><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/kkz-SNJCzqE&#038;rel=0&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;hl=en&#038;feature=player_embedded&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="allowScriptAccess" value="always"></param><embed src="http://www.youtube.com/v/kkz-SNJCzqE&#038;rel=0&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;hl=en&#038;feature=player_embedded&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="425" height="344"></embed></object></p>
<img src="http://www.hacking-gurus.net/wp-content/plugins/pixelstats/trackingpixel.php?post_id=148&ts=1284071222" style="display:none;" alt="pixelstats trackingpixel"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacking-gurus.net/2009/09/21/cross-site-scripting-xss-explained/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
