<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Exploiting IE8 UTF-7 XSS Vulnerability using Local Redirection</title>
	<atom:link href="http://securethoughts.com/2009/05/exploiting-ie8-utf-7-xss-vulnerability-using-local-redirection/feed/" rel="self" type="application/rss+xml" />
	<link>http://securethoughts.com/2009/05/exploiting-ie8-utf-7-xss-vulnerability-using-local-redirection/</link>
	<description>Inferno&#039;s Blog on Application Security</description>
	<lastBuildDate>Thu, 17 Dec 2009 00:27:19 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: hacky</title>
		<link>http://securethoughts.com/2009/05/exploiting-ie8-utf-7-xss-vulnerability-using-local-redirection/comment-page-1/#comment-303</link>
		<dc:creator>hacky</dc:creator>
		<pubDate>Sat, 28 Nov 2009 16:33:08 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=223#comment-303</guid>
		<description>To make things worse MS put the same IE code on windows 7 too... latest IE still vulnerable...</description>
		<content:encoded><![CDATA[<p>To make things worse MS put the same IE code on windows 7 too&#8230; latest IE still vulnerable&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/05/exploiting-ie8-utf-7-xss-vulnerability-using-local-redirection/comment-page-1/#comment-276</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Mon, 16 Nov 2009 21:59:04 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=223#comment-276</guid>
		<description>@Dave, if you are seeing XSS, then script is executing, which means that your IE is vulnerable. If you want to see the cookie as well, you need to signup for a 50webs.com account, signin and then go to the exploit page.</description>
		<content:encoded><![CDATA[<p>@Dave, if you are seeing XSS, then script is executing, which means that your IE is vulnerable. If you want to see the cookie as well, you need to signup for a 50webs.com account, signin and then go to the exploit page.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Dows</title>
		<link>http://securethoughts.com/2009/05/exploiting-ie8-utf-7-xss-vulnerability-using-local-redirection/comment-page-1/#comment-275</link>
		<dc:creator>Dave Dows</dc:creator>
		<pubDate>Mon, 16 Nov 2009 17:53:00 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=223#comment-275</guid>
		<description>If I understand your test correctly, then my IE8 is not vulnerable or one of my security products is blocking this. The popup contains only the text &quot;XSS&quot; without your 50webs.com member cookie. 

IE8 Version	8.0.6001.18702
Windows XP Build 2600.xpsp.080320-1628 (Service Pack 3) fully patched
AVG LinkScanner® version: 8.5.362  
SnoopFree Privacy Shield 1.0.7
NIS 2010, MBAM, SAS</description>
		<content:encoded><![CDATA[<p>If I understand your test correctly, then my IE8 is not vulnerable or one of my security products is blocking this. The popup contains only the text &#8220;XSS&#8221; without your 50webs.com member cookie. </p>
<p>IE8 Version	8.0.6001.18702<br />
Windows XP Build 2600.xpsp.080320-1628 (Service Pack 3) fully patched<br />
AVG LinkScanner® version: 8.5.362<br />
SnoopFree Privacy Shield 1.0.7<br />
NIS 2010, MBAM, SAS</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LayZee</title>
		<link>http://securethoughts.com/2009/05/exploiting-ie8-utf-7-xss-vulnerability-using-local-redirection/comment-page-1/#comment-248</link>
		<dc:creator>LayZee</dc:creator>
		<pubDate>Mon, 21 Sep 2009 23:12:10 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=223#comment-248</guid>
		<description>Been around since IE6 and still not patched in IE8?! Shame on you, M$!!

Tested and found vulnerable on IE 8.0.7600.16385 @ Windows 7 Pro x64.</description>
		<content:encoded><![CDATA[<p>Been around since IE6 and still not patched in IE8?! Shame on you, M$!!</p>
<p>Tested and found vulnerable on IE 8.0.7600.16385 @ Windows 7 Pro x64.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/05/exploiting-ie8-utf-7-xss-vulnerability-using-local-redirection/comment-page-1/#comment-219</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Mon, 24 Aug 2009 03:47:17 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=223#comment-219</guid>
		<description>hi breezy, IE does not encode the URL, = and &amp; are allowable in URL. Vulnerability exists in GET and other scenarios as well such as POST, persistent XSS, etc.</description>
		<content:encoded><![CDATA[<p>hi breezy, IE does not encode the URL, = and &amp; are allowable in URL. Vulnerability exists in GET and other scenarios as well such as POST, persistent XSS, etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Breezy</title>
		<link>http://securethoughts.com/2009/05/exploiting-ie8-utf-7-xss-vulnerability-using-local-redirection/comment-page-1/#comment-218</link>
		<dc:creator>Breezy</dc:creator>
		<pubDate>Mon, 24 Aug 2009 02:22:11 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=223#comment-218</guid>
		<description>Nice find.  Would it be correct to assume that if a page&#039;s URL must contain the characters = or &amp;, then the page is not vulnerable in this context?  IE seems to be encoding the URL in the GET request as such:

http://example.com/test.php?thing1=1&amp;thing2=2
becomes
http://example.com/test.php?thing1+AD0-1+ACY-thing2+AD0-2

= and &amp; seem to be an impossibility for the target URL</description>
		<content:encoded><![CDATA[<p>Nice find.  Would it be correct to assume that if a page&#8217;s URL must contain the characters = or &amp;, then the page is not vulnerable in this context?  IE seems to be encoding the URL in the GET request as such:</p>
<p><a href="http://example.com/test.php?thing1=1&amp;thing2=2" rel="nofollow">http://example.com/test.php?thing1=1&amp;thing2=2</a><br />
becomes<br />
<a href="http://example.com/test.php?thing1+AD0-1+ACY-thing2+AD0-2" rel="nofollow">http://example.com/test.php?thing1+AD0-1+ACY-thing2+AD0-2</a></p>
<p>= and &amp; seem to be an impossibility for the target URL</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/05/exploiting-ie8-utf-7-xss-vulnerability-using-local-redirection/comment-page-1/#comment-154</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Thu, 02 Jul 2009 03:38:50 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=223#comment-154</guid>
		<description>Hi Joe, As far as I know, Microsoft hasn&#039;t patched this yet. So, it should work fine on your machine. Try two things - (1) try loading http://webappsec.50webs.com/utf-71.html directly to see if you can access the child page [you should see utf-7 string and no DNS error] (2) then try disabling blink antimalware and seeing what results you get when accessing http://www.securethoughts.com/security/ie8utf7/ie8utf-7.html</description>
		<content:encoded><![CDATA[<p>Hi Joe, As far as I know, Microsoft hasn&#8217;t patched this yet. So, it should work fine on your machine. Try two things &#8211; (1) try loading <a href="http://webappsec.50webs.com/utf-71.html" rel="nofollow">http://webappsec.50webs.com/utf-71.html</a> directly to see if you can access the child page [you should see utf-7 string and no DNS error] (2) then try disabling blink antimalware and seeing what results you get when accessing <a href="http://www.securethoughts.com/security/ie8utf7/ie8utf-7.html" rel="nofollow">http://www.securethoughts.com/security/ie8utf7/ie8utf-7.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe</title>
		<link>http://securethoughts.com/2009/05/exploiting-ie8-utf-7-xss-vulnerability-using-local-redirection/comment-page-1/#comment-153</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Thu, 02 Jul 2009 02:45:30 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=223#comment-153</guid>
		<description>My one data point:

I tried the link http://www.securethoughts.com/security/ie8utf7/ie8utf-7.html using IE 8.0 .6001.18783 on Vista Home Premium. I did not see the popup. I got a DNS error in the iframe.

I am running Blink antimalware to help protect against this kind of rogue behavior, but there was nothing in the event logs.</description>
		<content:encoded><![CDATA[<p>My one data point:</p>
<p>I tried the link <a href="http://www.securethoughts.com/security/ie8utf7/ie8utf-7.html" rel="nofollow">http://www.securethoughts.com/security/ie8utf7/ie8utf-7.html</a> using IE 8.0 .6001.18783 on Vista Home Premium. I did not see the popup. I got a DNS error in the iframe.</p>
<p>I am running Blink antimalware to help protect against this kind of rogue behavior, but there was nothing in the event logs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/05/exploiting-ie8-utf-7-xss-vulnerability-using-local-redirection/comment-page-1/#comment-133</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Sat, 27 Jun 2009 00:24:07 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=223#comment-133</guid>
		<description>Hi Nik,

Thanks for bringing this up. I forgot to mention Google Chrome in the post. Google Chrome is not vulnerable to this exploit. The version I tested was 2.0.172.33.</description>
		<content:encoded><![CDATA[<p>Hi Nik,</p>
<p>Thanks for bringing this up. I forgot to mention Google Chrome in the post. Google Chrome is not vulnerable to this exploit. The version I tested was 2.0.172.33.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: N Blackwell</title>
		<link>http://securethoughts.com/2009/05/exploiting-ie8-utf-7-xss-vulnerability-using-local-redirection/comment-page-1/#comment-131</link>
		<dc:creator>N Blackwell</dc:creator>
		<pubDate>Fri, 26 Jun 2009 20:49:12 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=223#comment-131</guid>
		<description>Is Google Chrome affected by this?</description>
		<content:encoded><![CDATA[<p>Is Google Chrome affected by this?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
