<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Paralliverse</title>
	<atom:link href="http://log0.wordpress.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://log0.wordpress.com</link>
	<description></description>
	<lastBuildDate>Tue, 01 Sep 2009 10:15:25 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on URL Bruteforce Discovery by log0</title>
		<link>http://log0.wordpress.com/2008/09/02/url-bruteforce-discovery/#comment-274</link>
		<dc:creator>log0</dc:creator>
		<pubDate>Tue, 01 Sep 2009 10:15:25 +0000</pubDate>
		<guid isPermaLink="false">http://log0.wordpress.com/?p=28#comment-274</guid>
		<description>Hi Bd boy,

Thanks for reading. This blog is past and I now write at http://onhacks.org , webappsec is kind of a little drifted interest.

Answering your question, yes there were, in fact you get a lot of results by automating. You can find this implemented in tools like W3AF. =)</description>
		<content:encoded><![CDATA[<p>Hi Bd boy,</p>
<p>Thanks for reading. This blog is past and I now write at <a href="http://onhacks.org" rel="nofollow">http://onhacks.org</a> , webappsec is kind of a little drifted interest.</p>
<p>Answering your question, yes there were, in fact you get a lot of results by automating. You can find this implemented in tools like W3AF. =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on URL Bruteforce Discovery by Bd boy</title>
		<link>http://log0.wordpress.com/2008/09/02/url-bruteforce-discovery/#comment-273</link>
		<dc:creator>Bd boy</dc:creator>
		<pubDate>Tue, 01 Sep 2009 06:58:43 +0000</pubDate>
		<guid isPermaLink="false">http://log0.wordpress.com/?p=28#comment-273</guid>
		<description>Hey , nice post . I didnt thought off that way ... But i would like to ask you that did u had any success till now in brute forcing secret files ?...</description>
		<content:encoded><![CDATA[<p>Hey , nice post . I didnt thought off that way &#8230; But i would like to ask you that did u had any success till now in brute forcing secret files ?&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on URL Redirection Attack With Examples by Josh</title>
		<link>http://log0.wordpress.com/2008/06/23/url-redirection-attack-with-examples/#comment-268</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Sun, 11 Jan 2009 15:06:27 +0000</pubDate>
		<guid isPermaLink="false">http://log0.wordpress.com/?p=19#comment-268</guid>
		<description>First of all congratulation for such a great site. I learned a lot reading here today. I will make sure i visit this site more often so I can learn more.

&lt;a href=&quot;http://yiyd.com&quot; rel=&quot;nofollow&quot;&gt;Make your long Urls shorter - Free Url redirection - Hide your affilate URLS&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>First of all congratulation for such a great site. I learned a lot reading here today. I will make sure i visit this site more often so I can learn more.</p>
<p><a href="http://yiyd.com" rel="nofollow">Make your long Urls shorter &#8211; Free Url redirection &#8211; Hide your affilate URLS</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on First look on Cookies by log0</title>
		<link>http://log0.wordpress.com/2008/12/08/first-look-on-cookies/#comment-266</link>
		<dc:creator>log0</dc:creator>
		<pubDate>Tue, 09 Dec 2008 08:01:26 +0000</pubDate>
		<guid isPermaLink="false">http://log0.wordpress.com/?p=160#comment-266</guid>
		<description>&gt;&gt;Kuza55

Thanks for the articles, really great stuffs. I will come and hook you guys up sometime. =)

I&#039;m looking forward to the posts, you can write really well, and I guess I have to digest a lot of articles again. hah.</description>
		<content:encoded><![CDATA[<p>&gt;&gt;Kuza55</p>
<p>Thanks for the articles, really great stuffs. I will come and hook you guys up sometime. =)</p>
<p>I&#8217;m looking forward to the posts, you can write really well, and I guess I have to digest a lot of articles again. hah.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on China is a Good Place to Pen Test by log0</title>
		<link>http://log0.wordpress.com/2008/09/29/pen-test-china/#comment-265</link>
		<dc:creator>log0</dc:creator>
		<pubDate>Tue, 09 Dec 2008 07:43:27 +0000</pubDate>
		<guid isPermaLink="false">http://log0.wordpress.com/?p=61#comment-265</guid>
		<description>&gt;&gt;Chris

A simple research turns out some sites :

http://www.nohack.cn/bugs/
http://www.sitedir.com.cn/index.htm ( This one is really like milworm )
http://www.xfocus.net/vuls/ ( This is very well known, Kuza55 went to gave a presentation there this year in Beijing, just the 22nd Nov last month .)</description>
		<content:encoded><![CDATA[<p>&gt;&gt;Chris</p>
<p>A simple research turns out some sites :</p>
<p><a href="http://www.nohack.cn/bugs/" rel="nofollow">http://www.nohack.cn/bugs/</a><br />
<a href="http://www.sitedir.com.cn/index.htm" rel="nofollow">http://www.sitedir.com.cn/index.htm</a> ( This one is really like milworm )<br />
<a href="http://www.xfocus.net/vuls/" rel="nofollow">http://www.xfocus.net/vuls/</a> ( This is very well known, Kuza55 went to gave a presentation there this year in Beijing, just the 22nd Nov last month .)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on China is a Good Place to Pen Test by log0</title>
		<link>http://log0.wordpress.com/2008/09/29/pen-test-china/#comment-264</link>
		<dc:creator>log0</dc:creator>
		<pubDate>Tue, 09 Dec 2008 07:38:59 +0000</pubDate>
		<guid isPermaLink="false">http://log0.wordpress.com/?p=61#comment-264</guid>
		<description>&gt;&gt;Chris

Yea. What are some precautions do you think we should take to disclose responsibly our findings?</description>
		<content:encoded><![CDATA[<p>&gt;&gt;Chris</p>
<p>Yea. What are some precautions do you think we should take to disclose responsibly our findings?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on China is a Good Place to Pen Test by log0</title>
		<link>http://log0.wordpress.com/2008/09/29/pen-test-china/#comment-263</link>
		<dc:creator>log0</dc:creator>
		<pubDate>Tue, 09 Dec 2008 07:38:21 +0000</pubDate>
		<guid isPermaLink="false">http://log0.wordpress.com/?p=61#comment-263</guid>
		<description>&gt;&gt;Chris

You brought up a good point. I should find the local ones. However I just discovered one sooooooooooooooooooooooooooooooooo alike of milworm, you know... *sigh* it just hurts to see so many duplicates ( triplicates! in fact ) around.</description>
		<content:encoded><![CDATA[<p>&gt;&gt;Chris</p>
<p>You brought up a good point. I should find the local ones. However I just discovered one sooooooooooooooooooooooooooooooooo alike of milworm, you know&#8230; *sigh* it just hurts to see so many duplicates ( triplicates! in fact ) around.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on First look on Cookies by kuza55</title>
		<link>http://log0.wordpress.com/2008/12/08/first-look-on-cookies/#comment-262</link>
		<dc:creator>kuza55</dc:creator>
		<pubDate>Tue, 09 Dec 2008 02:43:31 +0000</pubDate>
		<guid isPermaLink="false">http://log0.wordpress.com/?p=160#comment-262</guid>
		<description>It could be because I was setting cookies with javaScript, rather than Set-Cookie headers.

I just ran a test using some dodgy javascript:
javascript:for (i=0;i&lt;100;i++) {document.cookie = i+&quot;=123&quot;;} alert(document.cookie);
And it still seems to be 50 (cookies 50-99 remain)

Sure, hit me up some time, me and some other smart people are usually on irc.irchighway.net #slackers, or just email me or whatever :) I&#039;ll post my slides from xcon soon as well...</description>
		<content:encoded><![CDATA[<p>It could be because I was setting cookies with javaScript, rather than Set-Cookie headers.</p>
<p>I just ran a test using some dodgy javascript:<br />
javascript:for (i=0;i&lt;100;i++) {document.cookie = i+&#8221;=123&#8243;;} alert(document.cookie);<br />
And it still seems to be 50 (cookies 50-99 remain)</p>
<p>Sure, hit me up some time, me and some other smart people are usually on irc.irchighway.net #slackers, or just email me or whatever <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I&#8217;ll post my slides from xcon soon as well&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to debug a Stack Overflow for beginners? by log0</title>
		<link>http://log0.wordpress.com/2008/12/05/how-to-debug-a-stack-overflow-for-beginners/#comment-261</link>
		<dc:creator>log0</dc:creator>
		<pubDate>Tue, 09 Dec 2008 01:58:39 +0000</pubDate>
		<guid isPermaLink="false">http://log0.wordpress.com/?p=96#comment-261</guid>
		<description>&gt;&gt;Chris

Yep. I know of the gflags. That was something I didn&#039;t use though, but I&#039;ll be testing another. Those are good things along with a lot of tools Microsoft develoeped.

That is a DoS, by flooding the program with arbitrary client requests. Unfortunately, I haven&#039;t locate any user-input buffers ( well, I have the source code =) )</description>
		<content:encoded><![CDATA[<p>&gt;&gt;Chris</p>
<p>Yep. I know of the gflags. That was something I didn&#8217;t use though, but I&#8217;ll be testing another. Those are good things along with a lot of tools Microsoft develoeped.</p>
<p>That is a DoS, by flooding the program with arbitrary client requests. Unfortunately, I haven&#8217;t locate any user-input buffers ( well, I have the source code =) )</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to debug a Stack Overflow for beginners? by Chris Weber</title>
		<link>http://log0.wordpress.com/2008/12/05/how-to-debug-a-stack-overflow-for-beginners/#comment-260</link>
		<dc:creator>Chris Weber</dc:creator>
		<pubDate>Tue, 09 Dec 2008 00:17:30 +0000</pubDate>
		<guid isPermaLink="false">http://log0.wordpress.com/?p=96#comment-260</guid>
		<description>It&#039;s important to enable full pageheap checking with gflags too, so you can catch heap corruption issues.  If you found a buffer overrun here, Windbg would have reported STATUS_STACK_BUFFER_OVERRUN too, but with the STACK_OVERRUN it looks like you have a DoS instead - or did you find a better exploit?</description>
		<content:encoded><![CDATA[<p>It&#8217;s important to enable full pageheap checking with gflags too, so you can catch heap corruption issues.  If you found a buffer overrun here, Windbg would have reported STATUS_STACK_BUFFER_OVERRUN too, but with the STACK_OVERRUN it looks like you have a DoS instead &#8211; or did you find a better exploit?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
