<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx</link><description>You might have read the c|net article " Blog feeds may carry security risk " which summarizes the presentation given by Robert Auger and Caleb Sima of SPI Dynamics. The presentation points to potential dangers of malicious script embedded in feeds. This</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#691352</link><pubDate>Mon, 07 Aug 2006 23:02:33 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:691352</guid><dc:creator>Federico</dc:creator><description>&amp;quot;Also, text fields, like the title element, are treated as text and not as HTML, so HTML tags are entity encoded.&amp;quot;&lt;br&gt;I guess this does not apply to Atom 1.0 when atom:title[type=&amp;quot;xhtml&amp;quot;] or atom:title[type=&amp;quot;html&amp;quot;]. :)</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#691586</link><pubDate>Tue, 08 Aug 2006 03:25:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:691586</guid><dc:creator>Sean Lyndersay [MSFT]</dc:creator><description>&amp;quot;I guess this does not apply to Atom 1.0 when atom:title[type=&amp;quot;xhtml&amp;quot;] or atom:title[type=&amp;quot;html&amp;quot;].&amp;quot;&lt;br&gt;&lt;br&gt;A good point that deserves some clarification: &lt;br&gt;&lt;br&gt;Atom 1.0 titles of type (X)HTML have all markup (script or otherwise) stripped out, and the remaining text is displayed. </description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#693260</link><pubDate>Wed, 09 Aug 2006 16:21:37 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:693260</guid><dc:creator>Sean Kerner</dc:creator><description>The presentation you mention was only given by Robert Auger. &lt;br&gt;Here's my account of the event which i was at:&lt;br&gt;www.internetnews.com/security/article.php/3624601&lt;br&gt;&lt;br&gt;Does the risk of users that still choose to use something like Bloglines directly still remain?</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#695656</link><pubDate>Fri, 11 Aug 2006 19:19:14 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:695656</guid><dc:creator>Lou</dc:creator><description>see &lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/rssteam/archive/2006/02/24/538493.aspx#comments"&gt;http://blogs.msdn.com/rssteam/archive/2006/02/24/538493.aspx#comments&lt;/a&gt; </description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#701767</link><pubDate>Wed, 16 Aug 2006 02:54:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:701767</guid><dc:creator>peterpla</dc:creator><description>See &amp;lt;&lt;a rel="nofollow" target="_new" href="http://www.spidynamics.com/assets/documents/HackingFeeds.pdf&amp;gt;"&gt;http://www.spidynamics.com/assets/documents/HackingFeeds.pdf&amp;gt;&lt;/a&gt; for the whitepaper &amp;quot;Feed Injection in Web 2.0 - Hacking RSS and Atom Feed Implementations&amp;quot; that was the basis for the Black Hat talk that Walter referenced.</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#711591</link><pubDate>Tue, 22 Aug 2006 05:21:37 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:711591</guid><dc:creator>Martin Szugat</dc:creator><description>Removing all script elements is in conflict with the structured blogging [1] initiative because they use a script element to embed structured content into web pages and XML feeds. I think there will be a good chance that this initiative becomes important in the next month. So I hope developers won't have to decide whether they use the Windows RSS platform or rely on the structured blogging approach but can use structured blogging within the Windows RSS platform.&lt;br&gt;&lt;br&gt;[1] www.structuredblogging.org</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#2507082</link><pubDate>Wed, 09 May 2007 21:07:18 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2507082</guid><dc:creator>Max R.</dc:creator><description>&lt;p&gt;Hello! Very interesting. Thank you.&lt;/p&gt;
</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#4475089</link><pubDate>Mon, 20 Aug 2007 10:04:31 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4475089</guid><dc:creator>program</dc:creator><description>&lt;p&gt;Very good . You are doing a great job.&lt;/p&gt;
</description></item><item><title>Good site</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#4968482</link><pubDate>Tue, 18 Sep 2007 05:35:26 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4968482</guid><dc:creator>ikaoh</dc:creator><description>&lt;p&gt;&amp;lt;a href= &lt;a rel="nofollow" target="_new" href="http://lipstick.com/user/buy_actos/#5"&gt;http://lipstick.com/user/buy_actos/#5&lt;/a&gt; &amp;gt;buy actos&amp;lt;/a&amp;gt;[url=&lt;a rel="nofollow" target="_new" href="http://lipstick.com/user/buy_actos/#5"&gt;http://lipstick.com/user/buy_actos/#5&lt;/a&gt;]buy actos[/url]&amp;lt;a href= &lt;a rel="nofollow" target="_new" href="http://lipstick.com/user/buy_adalat/#3"&gt;http://lipstick.com/user/buy_adalat/#3&lt;/a&gt; &amp;gt;order adalat&amp;lt;/a&amp;gt;[url=&lt;a rel="nofollow" target="_new" href="http://lipstick.com/user/buy_adalat/#3"&gt;http://lipstick.com/user/buy_adalat/#3&lt;/a&gt;]order adalat[/url]&amp;lt;a href= &lt;a rel="nofollow" target="_new" href="http://lipstick.com/user/ActoPlus_Met/#1"&gt;http://lipstick.com/user/ActoPlus_Met/#1&lt;/a&gt; &amp;gt;ActoPlus Met online&amp;lt;/a&amp;gt;[url=&lt;a rel="nofollow" target="_new" href="http://lipstick.com/user/ActoPlus_Met/#1"&gt;http://lipstick.com/user/ActoPlus_Met/#1&lt;/a&gt;]ActoPlus Met online[/url]&lt;/p&gt;
</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#7161046</link><pubDate>Sat, 19 Jan 2008 15:37:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7161046</guid><dc:creator>Webdesign</dc:creator><description>&lt;p&gt;The presentation you mention was only given by Robert Auger. &lt;/p&gt;
&lt;p&gt;Here's my account of the event which i was at: &lt;/p&gt;
&lt;p&gt;www.internetnews.com/security/article.php/3624601 &lt;/p&gt;
&lt;p&gt;Does the risk of users that still choose to use something like Bloglines directly still remain?&lt;/p&gt;
</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#7161056</link><pubDate>Sat, 19 Jan 2008 15:38:01 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7161056</guid><dc:creator>Tweaks</dc:creator><description>&lt;p&gt;&amp;quot;I guess this does not apply to Atom 1.0 when atom:title[type=&amp;quot;xhtml&amp;quot;] or atom:title[type=&amp;quot;html&amp;quot;].&amp;quot; &lt;/p&gt;
&lt;p&gt;A good point that deserves some clarification: &lt;/p&gt;
&lt;p&gt;Atom 1.0 titles of type (X)HTML have all markup (script or otherwise) stripped out, and the remaining text is displayed. &lt;/p&gt;
</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#7161065</link><pubDate>Sat, 19 Jan 2008 15:39:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7161065</guid><dc:creator>Webhosting</dc:creator><description>&lt;p&gt;Removing all script elements is in conflict with the structured blogging [1] initiative because they use a script element to embed structured content into web pages and XML feeds. I think there will be a good chance that this initiative becomes important in the next month. So I hope developers won't have to decide whether they use the Windows RSS platform or rely on the structured blogging approach but can use structured blogging within the Windows RSS platform. &lt;/p&gt;
&lt;p&gt;[1] www.structuredblogging.org&lt;/p&gt;
</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#7161068</link><pubDate>Sat, 19 Jan 2008 15:39:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7161068</guid><dc:creator>LFERC</dc:creator><description>&lt;p&gt;Removing all script elements is in conflict with the structured blogging [1] initiative because they use a script element to embed structured content into web pages and XML feeds. I think there will be a good chance that this initiative becomes important in the next month. So I hope developers won't have to decide whether they use the Windows RSS platform or rely on the structured blogging approach but can use structured blogging within the Windows RSS platform. &lt;/p&gt;
&lt;p&gt;[1] www.structuredblogging.org&lt;/p&gt;
</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#7161069</link><pubDate>Sat, 19 Jan 2008 15:40:07 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7161069</guid><dc:creator>Meubelstoffering</dc:creator><description>&lt;p&gt;The presentation you mention was only given by Robert Auger. &lt;/p&gt;
&lt;p&gt;Here's my account of the event which i was at: &lt;/p&gt;
&lt;p&gt;www.internetnews.com/security/article.php/3624601 &lt;/p&gt;
&lt;p&gt;Does the risk of users that still choose to use something like Bloglines directly still remain?&lt;/p&gt;
</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#8326576</link><pubDate>Thu, 20 Mar 2008 02:58:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8326576</guid><dc:creator>encyclopedia reference</dc:creator><description>&lt;p&gt;Thanks for claryfying the problem. I'm learning a lot here. Cheers!&lt;/p&gt;
</description></item><item><title>Good site</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#8406037</link><pubDate>Fri, 18 Apr 2008 06:26:50 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8406037</guid><dc:creator>balabo_ri</dc:creator><description>&lt;p&gt;&amp;lt;a href= &lt;a rel="nofollow" target="_new" href="http://index1.magazi.us"&gt;http://index1.magazi.us&lt;/a&gt; &amp;gt;pastor salaries according to membership&amp;lt;/a&amp;gt; &amp;lt;a href= &lt;a rel="nofollow" target="_new" href="http://index2.magazi.us"&gt;http://index2.magazi.us&lt;/a&gt; &amp;gt;lady lake fl millage rates&amp;lt;/a&amp;gt; &amp;lt;a href= &lt;a rel="nofollow" target="_new" href="http://index4.magazi.us"&gt;http://index4.magazi.us&lt;/a&gt; &amp;gt;mack truck branches&amp;lt;/a&amp;gt; &amp;lt;a href= &lt;a rel="nofollow" target="_new" href="http://index3.magazi.us"&gt;http://index3.magazi.us&lt;/a&gt; &amp;gt;dale earnhardt jr&amp;lt;/a&amp;gt; &lt;/p&gt;
</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#8531618</link><pubDate>Thu, 22 May 2008 14:13:54 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8531618</guid><dc:creator>Typy</dc:creator><description>&lt;p&gt;Hello, great article!&lt;/p&gt;
&lt;p&gt;Tom, admin&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.bukmacherzy365.info/"&gt;http://www.bukmacherzy365.info/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#8612203</link><pubDate>Tue, 17 Jun 2008 21:44:23 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8612203</guid><dc:creator>MSI</dc:creator><description>&lt;p&gt;Thank you for grat piece of info :)&lt;/p&gt;
</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#8900045</link><pubDate>Wed, 27 Aug 2008 16:46:10 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8900045</guid><dc:creator>Bread bins</dc:creator><description>&lt;p&gt;I'm searching for this solution. Thank you!&lt;/p&gt;
</description></item><item><title>re: Script in Feeds</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#8950508</link><pubDate>Sat, 13 Sep 2008 20:24:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8950508</guid><dc:creator>Rules</dc:creator><description>&lt;p&gt;I think there will be a good chance that this initiative becomes important in the next month. So I hope developers won't have to decide whether they use the Windows RSS platform or rely on the structured blogging approach but can use structured blogging within the Windows RSS platform. &lt;/p&gt;
</description></item><item><title>quiz career find</title><link>http://blogs.msdn.com/rssteam/archive/2006/08/07/Script-in-Feeds.aspx#8974890</link><pubDate>Fri, 03 Oct 2008 06:00:19 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8974890</guid><dc:creator>ctl00$_$ctl00$_$ctl02$_$form$_$tbname</dc:creator><description>&lt;p&gt;major career quiz &amp;lt;a href= &lt;a rel="nofollow" target="_new" href="http://regionprovence.cn/career-quiz.html"&gt;http://regionprovence.cn/career-quiz.html&lt;/a&gt; &amp;gt;quiz career find&amp;lt;/a&amp;gt; [url=&lt;a rel="nofollow" target="_new" href="http://regionprovence.cn/career-quiz.html"&gt;http://regionprovence.cn/career-quiz.html&lt;/a&gt;]quiz career find[/url]&lt;/p&gt;
</description></item></channel></rss>