<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Universal XSS Vulnerability in all Google Services can compromise your personal information</title>
	<atom:link href="http://securethoughts.com/2009/05/universal-xss-vulnerability-in-all-google-services-can-compromise-your-personal-information/feed/" rel="self" type="application/rss+xml" />
	<link>http://securethoughts.com/2009/05/universal-xss-vulnerability-in-all-google-services-can-compromise-your-personal-information/</link>
	<description>Inferno&#039;s Blog on Application Security</description>
	<lastBuildDate>Fri, 02 Apr 2010 17:28:55 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Goolag Scanner &#124; PenTestIT</title>
		<link>http://securethoughts.com/2009/05/universal-xss-vulnerability-in-all-google-services-can-compromise-your-personal-information/comment-page-1/#comment-75</link>
		<dc:creator>Goolag Scanner &#124; PenTestIT</dc:creator>
		<pubDate>Fri, 12 Jun 2009 16:44:21 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=252#comment-75</guid>
		<description>[...] Universal XSS Vulnerability in all Google Services can compromise &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] Universal XSS Vulnerability in all Google Services can compromise &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ocean</title>
		<link>http://securethoughts.com/2009/05/universal-xss-vulnerability-in-all-google-services-can-compromise-your-personal-information/comment-page-1/#comment-49</link>
		<dc:creator>ocean</dc:creator>
		<pubDate>Wed, 20 May 2009 10:02:12 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=252#comment-49</guid>
		<description>Great work inferno</description>
		<content:encoded><![CDATA[<p>Great work inferno</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Google Quietly Patches Huge Vulnerability - News: Everything-e</title>
		<link>http://securethoughts.com/2009/05/universal-xss-vulnerability-in-all-google-services-can-compromise-your-personal-information/comment-page-1/#comment-40</link>
		<dc:creator>Google Quietly Patches Huge Vulnerability - News: Everything-e</dc:creator>
		<pubDate>Tue, 12 May 2009 21:19:36 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=252#comment-40</guid>
		<description>[...] handle of &#8220;Inferno&#8221; discovered a cross-site scripting ( XSS) vulnerability in mid-April affecting a range of Google services like Gmail, Google Documents, iGoogle, and [...]</description>
		<content:encoded><![CDATA[<p>[...] handle of &ldquo;Inferno&rdquo; discovered a cross-site scripting ( XSS) vulnerability in mid-April affecting a range of Google services like Gmail, Google Documents, iGoogle, and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dobberpop</title>
		<link>http://securethoughts.com/2009/05/universal-xss-vulnerability-in-all-google-services-can-compromise-your-personal-information/comment-page-1/#comment-39</link>
		<dc:creator>dobberpop</dc:creator>
		<pubDate>Mon, 11 May 2009 22:18:54 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=252#comment-39</guid>
		<description>Grateful, compliments (amazing. To find Google did not itself found the gap)</description>
		<content:encoded><![CDATA[<p>Grateful, compliments (amazing. To find Google did not itself found the gap)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/05/universal-xss-vulnerability-in-all-google-services-can-compromise-your-personal-information/comment-page-1/#comment-38</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Mon, 11 May 2009 15:30:15 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=252#comment-38</guid>
		<description>@Gabriel, @vinod - thanks for your comments and appreciation....</description>
		<content:encoded><![CDATA[<p>@Gabriel, @vinod &#8211; thanks for your comments and appreciation&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lost in the Noise &#187; Blog Archive &#187; Ernstig lek in Google.com gedicht</title>
		<link>http://securethoughts.com/2009/05/universal-xss-vulnerability-in-all-google-services-can-compromise-your-personal-information/comment-page-1/#comment-37</link>
		<dc:creator>Lost in the Noise &#187; Blog Archive &#187; Ernstig lek in Google.com gedicht</dc:creator>
		<pubDate>Mon, 11 May 2009 13:21:06 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=252#comment-37</guid>
		<description>[...] werd de update uitgerold. Een proof-of-concept van het inmiddels niet meer werkende lek is op het blog van de onderzoeker te vinden. Google mag blij zijn dat Inferno het lek bij hen meldde, volgens [...]</description>
		<content:encoded><![CDATA[<p>[...] werd de update uitgerold. Een proof-of-concept van het inmiddels niet meer werkende lek is op het blog van de onderzoeker te vinden. Google mag blij zijn dat Inferno het lek bij hen meldde, volgens [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vinod</title>
		<link>http://securethoughts.com/2009/05/universal-xss-vulnerability-in-all-google-services-can-compromise-your-personal-information/comment-page-1/#comment-36</link>
		<dc:creator>vinod</dc:creator>
		<pubDate>Mon, 11 May 2009 10:57:49 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=252#comment-36</guid>
		<description>Hi Bro,

Good stuff.

keep posting.</description>
		<content:encoded><![CDATA[<p>Hi Bro,</p>
<p>Good stuff.</p>
<p>keep posting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gabriel Lima</title>
		<link>http://securethoughts.com/2009/05/universal-xss-vulnerability-in-all-google-services-can-compromise-your-personal-information/comment-page-1/#comment-35</link>
		<dc:creator>Gabriel Lima</dc:creator>
		<pubDate>Mon, 11 May 2009 03:45:58 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=252#comment-35</guid>
		<description>Hi,
Congratulations for your analysis and thanks for this great post!

Regards,
Gabriel Lima.</description>
		<content:encoded><![CDATA[<p>Hi,<br />
Congratulations for your analysis and thanks for this great post!</p>
<p>Regards,<br />
Gabriel Lima.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/05/universal-xss-vulnerability-in-all-google-services-can-compromise-your-personal-information/comment-page-1/#comment-34</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Sun, 10 May 2009 21:55:15 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=252#comment-34</guid>
		<description>Hi Maximiliano,

Thanks for your comments. I believe in responsible disclosure, so i waited for this vulnerability to get fixed completely. Now it is published in places such as bugtraq - http://www.securityfocus.com/archive/1/503389 and caught some press here - http://securityandthe.net/2009/05/09/xss-against-google-services-scary-but-fixed-fast/.

Thanks and Regards,
Inferno</description>
		<content:encoded><![CDATA[<p>Hi Maximiliano,</p>
<p>Thanks for your comments. I believe in responsible disclosure, so i waited for this vulnerability to get fixed completely. Now it is published in places such as bugtraq &#8211; <a href="http://www.securityfocus.com/archive/1/503389" rel="nofollow">http://www.securityfocus.com/archive/1/503389</a> and caught some press here &#8211; <a href="http://securityandthe.net/2009/05/09/xss-against-google-services-scary-but-fixed-fast/" rel="nofollow">http://securityandthe.net/2009/05/09/xss-against-google-services-scary-but-fixed-fast/</a>.</p>
<p>Thanks and Regards,<br />
Inferno</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maximiliano Soler</title>
		<link>http://securethoughts.com/2009/05/universal-xss-vulnerability-in-all-google-services-can-compromise-your-personal-information/comment-page-1/#comment-33</link>
		<dc:creator>Maximiliano Soler</dc:creator>
		<pubDate>Sun, 10 May 2009 21:03:11 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=252#comment-33</guid>
		<description>Hi Inferno;
Good job, excellent.

Very professional you, not publishing the vulnerability.

You know as Google includes everything with a account. ;)

Regards;
Maximiliano.</description>
		<content:encoded><![CDATA[<p>Hi Inferno;<br />
Good job, excellent.</p>
<p>Very professional you, not publishing the vulnerability.</p>
<p>You know as Google includes everything with a account. <img src='http://securethoughts.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Regards;<br />
Maximiliano.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

