<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>avoiding script injection and other lessons</title><link>http://blogs.msdn.com/jeffdav/archive/2004/02/06/68908.aspx</link><description>MSDN has had an article entitled Security Considerations: Dynamic HTML for a while. It is a good article, but it simply says what not to do. Everytime I run across it I promise myself I am going to write something more useful someday, something that says</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: avoiding script injection and other lessons</title><link>http://blogs.msdn.com/jeffdav/archive/2004/02/06/68908.aspx#69225</link><pubDate>Sat, 07 Feb 2004 12:31:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:69225</guid><dc:creator>José Jeria</dc:creator><description>How about updating (easily done) the code so it also works in Mozilla and other browsers with great DOM support?</description></item><item><title>re: avoiding script injection and other lessons</title><link>http://blogs.msdn.com/jeffdav/archive/2004/02/06/68908.aspx#69533</link><pubDate>Sun, 08 Feb 2004 07:13:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:69533</guid><dc:creator>Raymond Chen</dc:creator><description>Example of social engineering attack: The &amp;quot;Do you want to make 'XYZ' your new home page?&amp;quot; prompt used to allow you to embed newlines into 'XYZ', thereby enabling such misleading dialogs as&lt;br&gt;&lt;br&gt;Do you want to make 'http://&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;CLICK&lt;br&gt;YES&lt;br&gt;TO&lt;br&gt;CONTINUE&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;@hackersite.com' your new home page?&lt;br&gt;&lt;br&gt;[Yes] [No]</description></item><item><title>Take Outs: The Digital Doggy Bag of Blog Bits for 9 February 2004 </title><link>http://blogs.msdn.com/jeffdav/archive/2004/02/06/68908.aspx#70364</link><pubDate>Tue, 10 Feb 2004 06:49:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:70364</guid><dc:creator>Enjoy Every Sandwich</dc:creator><description>The daily list of stuff I found interesting while blogreading.</description></item><item><title>re: avoiding script injection and other lessons</title><link>http://blogs.msdn.com/jeffdav/archive/2004/02/06/68908.aspx#70583</link><pubDate>Tue, 10 Feb 2004 12:35:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:70583</guid><dc:creator>Stefan Demetz</dc:creator><description>&lt;a target="_new" href="http://dotnetjunkies.com/WebLog/stefandemetz/archive/2004/02/06/6748.aspx"&gt;http://dotnetjunkies.com/WebLog/stefandemetz/archive/2004/02/06/6748.aspx&lt;/a&gt;</description></item><item><title>re: avoiding script injection and other lessons</title><link>http://blogs.msdn.com/jeffdav/archive/2004/02/06/68908.aspx#179398</link><pubDate>Sat, 10 Jul 2004 14:10:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:179398</guid><dc:creator>stefan demetz</dc:creator><description>Lobby MS to eliminate SQL injection&lt;br&gt;&lt;a target="_new" href="http://dotnetjunkies.com/WebLog/stefandemetz/archive/2004/07/10/18763.aspx"&gt;http://dotnetjunkies.com/WebLog/stefandemetz/archive/2004/07/10/18763.aspx&lt;/a&gt;</description></item><item><title> jeff s WebLog avoiding script injection and other lessons | low cost car insurance</title><link>http://blogs.msdn.com/jeffdav/archive/2004/02/06/68908.aspx#9765653</link><pubDate>Wed, 17 Jun 2009 07:19:22 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9765653</guid><dc:creator> jeff s WebLog avoiding script injection and other lessons | low cost car insurance</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://lowcostcarinsurances.info/story.php?id=3457"&gt;http://lowcostcarinsurances.info/story.php?id=3457&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>